Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Mystery Nodes - LEM

$
0
0

Good questions here.  Most times a mystery node comes in if a object has multiple communication IPs and the logs come out of different interfaces.  My suggestion would be to audit why the email appliance has multiple IPs and if you can customize what port the logs are sent from if these are SYSLOG sources.  If is a Windows log source make sure you do not have traps or syslogs coming out if you are also using the LEM agent  That will add weird duplicate sources.

 

Hope that helps.  Let me know.

 

Thanks


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>