Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Connector for Microsoft Threat Management Gateway Will Not Turn On

$
0
0

Figured it out - the backing code for that connector was released in a hotfix (and subsequent LEM releases). You can download and install the hotfix from here: http://downloads.solarwinds.com/solarwinds/Release/HotFix/LEM-v5.5.0-HF1.zip - you only need the agent side to make it work.

 

Edit - There's a readme in the hotfix but here's the bottom line:

 

Agent Hotfix Installation

 

1. Download and extract the contents of Hotfix_550_1.zip.  There are three folders labeled Manager, Agent, LEM, and a copy of the readme file.

 

2. Open the Agent folder and extract the agent_lem_jars.zip folder (Do not use the lem_jar.zip file that is in the Manager folder).

 

3. When the information extracts you should have these 4 files:

               -lem_agent.jar

               -lem_core.jar

               -lem_tools.jar

               -lem_util.jar

               -openedge.jar

 

4. Remote Desktop into the machine running Microsoft Threat Management Gateway which has a LEM agent running.

 

5. Stop the LEM Agent service.

 

6. Navigate to the LEM Agent installation directory (Windows):

               -32-bit installations: C:\Windows\System32\ContegoSPOP\

               -64-bit installations: C:\Windows\SysWOW64\ContegoSPOP\

 

7. Navigate to the LEM Agent jars folder

               -32-bit installations: C:\Windows\System32\ContegoSPOP\5.3.1\jars

               -64-bit installations: C:\Windows\SysWOW64\ContegoSPOP\5.3.1\jars

 

8. Copy the new files into the applicable jars folder listed in step 7. This overwrites the existing files.

 

9. Start the LEM Agent service.

 

10. After the LEM Agent starts, check the LEM Agent log file to verify that the agent hotfix is in place. The file is called spoplog.txt and is located in the main LEM agent installation directory. Scroll to the bottom of the file and search for this line: Starting TriGeo Agent (Release 5.3.1) build [agent hotfix 3];

               -32-bit installations: C:\Windows\System32\ContegoSPOP\

               -64-bit installations: C:\Windows\SysWOW64\ContegoSPOP\

 

11. Next follow the instructions on deploying the Microsoft Threat Management Gateway connector

 

 

NOTE: This agent hotfix only applies to 5.3.1 version agents. The files in the "manager" and "LEM" directories only apply to version 5.5 appliances. If you aren't running these versions but you found this thread, be sure to check for the latest hotfix or ask before doing any damage. The files in this hotfix are superseded by new LEM releases that already contain these changes.


Viewing all articles
Browse latest Browse all 5385