Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Is it possible to import Windows Security Event log into LEM from a node without LEM agent?

$
0
0

So I'm going to start by saying the simple answer is basically no, but depending on how much tenacity you have some work arounds could be potentially rigged up.  I would say they are all a lot more complex or brittle than I would be willing to spend time on, so I would be focusing on making the case to whoever is standing in the way of using the agent as the tool you bought was designed to work.  Whatever assurances they want to have should be fairly easy to meet as LEM is installed on hundreds of thousands of domain controllers across the globe and I would be truly surprised if yours were special in some way that requires them to be any different.

 

Solarwinds offers a windows event log forwarder that takes all the events and shoots them out as syslogs which you could pick up on a node with an agent (or possibly even directly on the appliance, I never checked that).  But this still requires installing software on the DC which seems like it would be in conflict with your policy, since im hard pressed to imagine they won't let you install the native log parser/forwarder but would allow some other one that does the same thing, but less efficiently. FREE Event Log Forwarder for Windows | SolarWinds

 

I also see this procedure to allow the lem agent to read archived copies of the windows event logs. Import Archived Windows Event Logs to LEM - SolarWinds Worldwide, LLC. Help and Support

You might be able to rig up some kind of scheme to have the DC periodically archive its logs, ship them out to a remote system and then ideally script up a process to periodically load that archive, have the lem connector read it and ship the results. 

 

Another option is along the lines discussed in this thread regarding building a DIY LEM connector, Does LEM offer a generic txt/log file connector that we can use to collect log data from any 3rd party application?

It has been done before, but its completely unsupported.  In theory you could build your own connector to parse your CSV/archive files.  Doing so would probably require you to have a master level grasp on regex and obviously some pretty deep understanding of LEM itself.

 

All of these seems super unnecessarily complex though and would probably really complicate your whole process for setting up rules and reports, especially given that a big chunk of the juicy stuff in LEM that people tend to write rules and reports for takes place on a DC.  At the very least this will turn your monitoring from real time to some kind of batch fed process.  I also looked into some tools that agentlessly collect windows event logs but the ones I saw matched up to my suspicion that remotely querying events is too slow of a process to keep up with the volumes of data you would expect to get from a DC.  Just answering those remote calls would definitely cause MUCH more of an impact on your DC than the agent itself does.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>