Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Store and Retrieve Windows Event Logs

$
0
0

Yes, you need a separate manager to restore logs.  The new manager, however, does not require a license.  LEM licenses are consumed when you have new data coming from sources, so since there'll be no new data coming in, the manager you spin up to look at restored logs will not need a license.  Spin up a 30 day eval, and Support can restore the logs to that device.  Even when the eval expires, the nDepth and Report features will still work (the eval just cuts off new data, which again, you don't have any).

 

If we restore the backups over a production LEM, the old data will over-write the current database, which is bad.  You can spin up a "data warehouse" appliance and run it indefinitely for free, but Support is required to get the data imported into the new device.

 

Caution: Backups have to restored to their originating version! If your data was collected with LEM 5.6 and you rolled it off to cold-storage from 5.6, the LEM you spin up needs to be 5.6!  This applies to all LEM versions, at least as of 6.2.1.


Viewing all articles
Browse latest Browse all 5385

Trending Articles