Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Help with LEM Filters and/or Alerts

$
0
0

We use LEM for many reasons, but one important one is to monitor if any folders are moved/deleted on a secure network drive.  This drive holds all our patient information which is regulated by HIPAA.  I wanted to set up an alert that notified a group any time one of the folders on that drive was moved or deleted with who did it, and what folder was affected.  It was simple enough, however I had to take out the folder name because the folders are named after the patients.  So all of John Q. Public's medical records are stored like this "HIPAA\\General Hospital\2015\A-P\Public, John Q\".  One of the HIPAA regulations is that we can't transmit a patients name unsecured.  Unfortunately by putting the name of the folder that was moved in the alert is a HIPAA violation.  Without that all we're alerted to is the time/date a folder was moved and the name of the person who moved it.  We don't know what folder was actually moved until we look into LEM.  If I'm not around to look into LEM, then the manager has to wait until I'm available to find out what folder was moved and where it was moved to.  First I was hoping there was a way to only show the root folder (ie. \\General Hospital) but there wasn't anyway to limit the characters or hide part of the file name in the alert.  So my next hope is that there is a way to use a logic if-then statement.  For example, if FileAudit.FileName = *General Hospital*, report "General Hospital".   That way if the folder is "HIPAA\\General Hospital\2015\A-P\Public, John Q\" using the * wildcard search it will see "General Hospital" and report whatever name I choose.  Which in this case would just be "General Hospital".  It's the only other way I can come up with reporting the folder without reporting the entire path.  It would be a pain because I'd have to go through and create an if-then for EVERY hospital we have accounts with, but at least it would report which folder was touched so the managers can at least look for the moved folder if I'm sick, on vacation, or not available.  Unless you VERY SMART & CREATIVE GENIUSES THAT I ENVY can think of another out of the box solution? I'm not even sure there's a way to use the logic statements in LEM I'm just hoping there's a way.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>