Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Node Name

$
0
0

I was able to get into the filters and groups and created some user-defined of both, so I do see what you mean about the operational functionality of LEM. So i ( as a user) can deal with what amounts to poor aesthetics of the manage->nodes page with just ips and no names. i just thought that if the node name was immaterial to the operational nature of LEM then why can't that field be editable?

 

Also for Security auditing purposes, I need to be able to verify that all network nodes in Solarwinds NPM that can be logged are indeed being logged. Since the polling interface and the syslog interface are not necessarily the same interface (don't ask because I do not know why either) it usually requires another attribute to perform the matching, thus the hostname would  make this rather easy. Maybe if a connector between LEM and ORION/NPM is created this will not be an issue but in the interim I have a security team and a team of auditors that must be appeased.

 

In addition our Security team uses another SIEM product (Qradar) which I have to match up to for auditing and validation processes. They are currently disenfranchised with their product and have been waiting to see what LEM can do. 

 

In the meanwhile I have issues just getting devices added to LEM, I have configured 60 devices and LEM only detects 20 (yes i have validated the network path and generated log entries) and every person that logs into it has to stop and ask me about the node name field. Unfortunately this is becoming a very slow implementation, especially for a solarwinds product.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>