Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Re: LEM Agent - Uninstall

THANK YOU SO MUCH!!! HolyGuacamode@

View Article


Re: LEM Agent - Uninstall

THANK YOU SO MUCH!!! HolyGuacamode@

View Article


Image may be NSFW.
Clik here to view.

Reports

Is it possible to create your own report in the LEM Reports application?I want to run some reports of a few filters that i have created, but don't see any report tittle related to this. For example i...

View Article

Re: Emails Stopped

MG2, I had the same problem a few weeks back,  After I upgraded from 5.9 to 6.1. I had to reactivate the solar winds License in order for this to start working again.  After I reentered my license...

View Article

Re: Reports

You can create a custom report, you just have to run a standard report then filter out using the filter expert.  Here is how I create a custom report for failed login attempts for domain admin accounts...

View Article


No log event in MONITOR tab

Hi Team, Need your assistance.Upon checking on my LEM console, we have seen the logs under OPS tab, but in MONITOR tab there is no event log on all filtered categories/event (0). Please advise. Initial...

View Article

Image may be NSFW.
Clik here to view.

Re: Reports

Thanks for the reply. But i found a report title i actually need. That is the User Authorization Audit in Resource Audit. With this i can get the exact report of the cisco VPN. Thanks Buddy.

View Article

PBX

Hi, We are using Sangoma free PBX that is installed on Linux.Is it possible to receive log and events from the PBX?If so. Which connector do i have to use for this?

View Article


Re: No log event in MONITOR tab

That could be corruption of the user profile, and that will probably need support to fix it.

View Article


Image may be NSFW.
Clik here to view.

Re: PBX

Searching their Wiki, it doesn't appear that they produce syslogs, only SNMP.  It might make more sense to send that to NPM or SAM and let that monitor the health of the system.

View Article

group changed "builtin\administrators" security enabled local group

Hi,I'm fairly new to LEM, loving it so far!  Since I had set it up, the following alert "group changed "builtin\administrators" security enabled local group at" has been triggering every 15 - 20...

View Article

Image may be NSFW.
Clik here to view.

LEM - email template

I have created the email template to trigger in the case of server logs being cleared. The rule fires fine and sends me an email, but all I get in the email body is a very vanilla bit of content with...

View Article

Re: LEM - email template

Just tried a different rule and it doesn't seem to want to use a customized email template either. So user-friendly...

View Article


Re: LEM - email template

Turns out you have to click "Activate Rule" after you save the rule with your template in it. #DumbThings

View Article

Re: PBX

Is there a documentation or something how to do this?

View Article


Re: group changed "builtin\administrators" security enabled local group

So you're getting an e-mail? Go to nDepthUnder Events, find "InternalRuleFired"In the fields, find "Extraneous Info"Drag "Extraneous Info" to the search bar at the top of the nDepth screenIn the field,...

View Article

Re: LEM - Logs on Windows file copy

Did you ever get an answer to this? Many thanks, Martin.

View Article


Image may be NSFW.
Clik here to view.

Does anyone know if LEM supports VMXNet3 NIC from VMWare

Everyone; My supervisor asked me if LEM supported the VMXNet3 NIC provided with VMware tools.  If someone knows please respond. Thank You All Steve

View Article

Re: group changed "builtin\administrators" security enabled local group

Hi Curtisi,I think I figured out which rule is getting fired here thanks to your help    Event Info:  The "Group Events" rule Fired. So I cloned the original Rule and modified it by adding this...

View Article

Image may be NSFW.
Clik here to view.

Re: group changed "builtin\administrators" security enabled local group

You're on the right track with your thinking, so it's details. The default rule is correlating off the [Auditable Group Events] Event Group, so you'll want to use the same Event Group for the...

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>