Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

LEM mass file change alerts

I want to configure LEM to alert me when multiple files change (windows file servers). For example, I've had virus/malware change multiple files and want to get alerted when activity of this nature...

View Article


File writes to a server or share

          I'm looking for a way to get notified when anyone or anything writes a file to a share on a specific server.

View Article


Image may be NSFW.
Clik here to view.

LEM rule for four specific alerts...help

I have a specific server that our DBA wants four services monitored if they stall or stop. Only these four services. I've contacted tech support twice and each time he's made adjustments to the rule,...

View Article

Re: LEM Agent for Linux sends logs to manager from wrong IP address

Yeah, the flux capacitor is detected from the logs, so they are both caused by the same problem. I would suggest sending this thread over to support and see what the best way to help you is. There are...

View Article

Re: LEM rule for four specific alerts...help

You have a lot of ORs there, so effectively any ONE of those things will trigger your rule to fire. Are your other events getting generated from services being stopped on your Avantis server...

View Article


Re: LEM Agent for Linux sends logs to manager from wrong IP address

Thank you for your help.  I will post an update here as to what they ask me to do.

View Article

Re: LEM rule for four specific alerts...help

The goal is to have the alert trigger if any of the four services stall or stop.

View Article

Re: LEM session timeout for CMC console

Are you talking about accessing CMC from SSH?  Or from the virtual appliance console in Hyper-V or VMware?

View Article


Re: Agent Cache Size

According to some documentation I found internally, it's 10MB. This can be managed by modifying the spop.conf for the Agent, located at:Windows 64-bit: C:\Windows\SysWOW64\ContegoSPOP\spop.confWindows...

View Article


Image may be NSFW.
Clik here to view.

Re: LEM Agent for Linux sends logs to manager from wrong IP address

If you open the spop.conf file: Windows 64-bit: C:\Windows\SysWOW64\ContegoSPOP\spop.confWindows 32-bit: C:\Windows\System32\ContegoSPOP\spop.confLinux: /usr/local/contego/ContegoSPOP Add this line:...

View Article

Re: LEM rule for four specific alerts...help

I have no other rules for this specific server and no other events are backed up.

View Article

Re: LEM rule for four specific alerts...help

In nDepth, can you search for "InternalRuleFired.ExtraneousInfo = *email*"? Pick one of the results, click on the small EXPLORE button in the upper-right corner of the screen, pick "Event." Can you...

View Article

Image may be NSFW.
Clik here to view.

Re: LEM rule for four specific alerts...help

View Article


Re: LEM rule for four specific alerts...help

Click the line above the one you have selected, then click the "Event Details" button.  Expand the frame, and screenshot that.

View Article

Image may be NSFW.
Clik here to view.

Re: LEM rule for four specific alerts...help

View Article


Re: LEM rule for four specific alerts...help

Can you export your rule and attach it to this thread or send it to me in a private message?

View Article

Re: LEM rule for four specific alerts...help

I don't see a method to send it to you in a private message or get it uploaded in this thread.  ~Steve

View Article


Re: LEM rule for four specific alerts...help

If you pick the "Advanced Editor" (which you can't do from your inbox for some reason) it should allow you attach a file.

View Article

Re: LEM rule for four specific alerts...help

Sorry I'm not following where or how to enable the advanced editor.

View Article

Image may be NSFW.
Clik here to view.

Re: LEM rule for four specific alerts...help

I think I managed to send you a private message with the exported rule. Thank you,~Steve

View Article
Browsing all 5385 articles
Browse latest View live