Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Odd answer from Support

$
0
0

I'm assuming there's a LEM agent on the Windows 2008 box, which makes it very strange that the LEM appliance would slow to a crawl.  It may be that the Agent is reading the log files, and sending enough data that the Appliance is bogging down writing it all to the database.

 

With most rotating logs (like IIS and Apache), it's enough to provide the path to the logs, ie: d:\program files\apache group\apache2\logs\ (add that last slash).  In some cases in my experience, I've had to specify and actual log file, but the log reader is smart enough to notice when that file closes and moves to the next one.  I do know that Wildcards are not going to work.

 

Can you SSH into your LEM, go to APPLIANCE and run a TOP command before activating the connector on the Agent?  I'd be curious to see if there's a spike there.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>