Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: USB Defender

$
0
0

USB Defender Local Policy runs seperately from the USB rules on LEM.  The point of the UDLP is that, if the Agent is not connected to LEM, it can still block devices that aren't whitelisted.  The whitelist has a different format than the whitelist in LEM, however, so I'm betting that's where the issue lies.

 

For the LEM rule, you're adding devices to a User Defined Group that the rule references, and that list looks something like this:

 

2017-01-30 08_50_03-SolarWinds Log & Event Manager.png

 

I've highlighted an example with a wildcard.

 

The UDLP list, however, is a text file.  It's one-per-line with NO WILDCARDS.  However, it'll do "best match" so if a line terminates early, you can have that in the whitelist.  Ergo, in your UDLP file, if you added a line:

 

USB\VID_148F&PID_761A\

 

And left it at that, it would whitelist all those devices regardless of the specific device ID, where this example only whitelists one exact device:

 

USB\VID_046D&PIND_0825\05D0CF60

 

I hope that helps.

 

Otherwise, with rules in general, the first thing I'd do is confirm that the LEM appliance has the correct time-zone and date/time for your deployment.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>