Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: LEM Syslog Question

$
0
0

There's a little more configuration that has to happen, so as an addendum to what joelyue posted:

 

You'll need to configure the LEM to have something to do with the raw logs.  Those directions are here: SolarWinds Knowledge Base :: Configuring Your LEM Appliance for Log Message Storage and nDepth Search

 

WARNING: This will impact the retention span of your LEM.

 

If you're using a random syslog connector, having it try to generate Alert data from the syslogs will just fill the LEM with errors and "InternalNewToolData" events.  If all you want is raw logs, just pick "nDepth" for the output.

 

Raw data doesn't show up in Reports, can't be used to trigger rules and won't appear in Filters.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>