Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Re: Configuring Cisco ASA Syslog to LEM

Thank you for the quick response!  That did it.  I must have missed where that was specified somewhere in the documentation.

View Article


Re: How to customized reports solarwinds LEM

Below is a link to the KB article on how to create custom reports using the LEM Reporting application.  I hope this helps! SolarWinds Knowledge Base :: Creating a Custom Filtered Report

View Article


Image may be NSFW.
Clik here to view.

Re: How to customized reports solarwinds LEM

Unfortunately reporting is one of the weaknesses in the LEM product.  The Reporting application has some good canned reports but if you want anything beyond what is in those you begin to run into...

View Article

MSSQL Auditor - Won't start with domain user

Hello, I'm fairly new to the MSSQL Auditor and I'm trying to get it working.  I had it working with just a single server and I wanted to expand that server to monitor others.  I added the other servers...

View Article

Re: MSSQL Auditor - Won't start with domain user

I just fought this for a couple days.  Part of my issue was that I broke the Local Profile Service in Windows, so if you've got users getting logged into TEMP profiles, that seems to break things....

View Article


Unable to perform backup/archive in LEM 6.2 after migrating to NetApp Cluster...

Issue: Administrators can no longer perform backupconfig, archiveconfig, or logbackupconfig through cmc.  When entering the username/password for accessing CIFS share, credentials are validated but the...

View Article

Image may be NSFW.
Clik here to view.

Re: MSSQL Auditor - Won't start with domain user

Thanks for the help, it lead me in the correct direction!   Turns out the user account I was trying to use didn't have the "logon a service" right on the server it was installed on.  I gave it that...

View Article

email alerts with more content

All,   I'm trying to figure out if there is a way to get the email alerts from LEM to have more descriptive content.  For example below is an alert I just got:  writing configuration at 2016-01-13...

View Article


Re: email alerts with more content

Hey Jeff, Please see this video (kudos to curtisi) for steps on how to add more information to e-mail alerts: LEM Resolving Email Alerts with No Information Any problems let me know.

View Article


Image may be NSFW.
Clik here to view.

IE Taking Forever To Load Your LEM Resolved

Put the ip address of your LEM or hostname into the Compatibility View Under Tools in Internet Explorer, that will resolve the issue.

View Article

Re: email alerts with more content

So that helped a great deal.  However, now I'm trying to find a listing of all the Event fields like $EventInfo, just so I know what's possible.  I've looked all through the LEM manual and appendices...

View Article

Re: email alerts with more content

The fields I use in the video are "made up" in the sense that you can put anything in the variable names.  You could have variables called bacon, ham, egg, and potatoes.  If you want to use the same...

View Article

Re: email alerts with more content

Thanks.  Understood.  I had figured out that the email template parameters were just descriptive place holders and I had picked up some of the event parameter variables by looking at various rules.  I...

View Article


File Integrity Monitoring - So many events generated for a single file copy -...

I started using FIM today.  I copied a single .exe file to C:\ on a system I monitor with FIM Connector.  This generated 80 events with identical information.  Is there a way to reduce the number of...

View Article

Re: RECOMMEND LEM ON SPREAD THE WORD FOR A $25 AMAZON GIFT CARD!

Life was a pain trying to manage the other SIEMS before I learned about LEM (Logging and Event Manager)!!!in Spread the WordJeff Mathis asked6 days agoI have used a number of SIEMs including Logrhythm,...

View Article


Image may be NSFW.
Clik here to view.

Re: How to  customized reports solarwinds LEM

Hi Byrona Thank for your information

View Article

Re: How does the "IsThreat" value determined?

Thanks!

View Article


Re: email alerts with more content

The fields you can assign depend on the event type - there's about a dozen that ALL events have (the ones up to ExtraneousInfo if you're looking in the console), then stuff like source/destination IPs...

View Article

Re: Can't connect to AD using Directory Service Query Tool

Glad to hear you got sorted

View Article

Lem, can you move an nDepth search into a rule?

First post here.  Thanks for reading. Is there an easy way to export a search from nDepth into another area of LEM like rules? I am new to LEM and have been asked to setup some complex email...

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>