Re: Using nDepth explorer to create on demand tables/charts
This was where I had a hard time also! A great LEM tech taught me how to go into nDepth and click Event Groups in the 2nd column of the screen, then click on the Any Alert Event Grop, then below that...
View ArticleRe: ndepth query
I don't think there's a max as long as you were logging that far back. A great LEM tech taught me how to go into nDepth and click Event Groups in the 2nd column of the screen, then click on the Any...
View ArticleLEM Retention
How far back or how many events does the LEM store? Is there a way to access this information?
View ArticleRe: Mystery Nodes - LEM
I try to keep as few agents on my devices as possible, when I have alternatives. If the problem resurfaces, I may try this option.
View ArticleRe: Mystery Nodes - LEM
I deleted the mystery nodes, and so far they haven't come back... so far. In the past, they've come back, but this seems to be a longer period of time. I did review all my rules and alerts, and...
View ArticleRe: LEM Retention
Have you checked out this KB on the Success Center? Live Data Storage Retention - SolarWinds Worldwide, LLC. Help and Support
View ArticleSystem Audit Policy Changed - 22 alerts
Combed the LEM documentation, couldn't find a clue (it might be ind documentation somewhere, I couldn't find it after an hour of digging) This morning I got 22 TriGeo alerts in this pattern: system...
View ArticleRe: System Audit Policy Changed - 22 alerts
Hard one because MSFT is logging it as a change Windows Security Log Event ID 4719 - System audit policy was changed
View ArticleRe: System Audit Policy Changed - 22 alerts
I don't think this is an instance of something just being enumerated again. A couple of fields to look at in those events. First, the ChangeDetails field shows that failure auditing was removed,...
View ArticleRe: System Audit Policy Changed - 22 alerts
Blsanner, yes, you're correct. Looking in the host machine's logs, I see an informational entry at the correct time stamp: Event 1704 "Security policy in the Group policy objects has been applied...
View ArticleFIM: identifying false positives
this question is not related to LEM, but i was wondering if there are tools out there which would help identify file (not just extension) to make the association if its false positive. There are plenty...
View ArticleLEM Version 6.2.1 hotfix 2 restore - https down
I had removed a server node and wanted to just roll back to my configuration backup I had scheduled for Sundays to put the node and all connectors back. The restore was successful, but I did not notice...
View ArticleRe: System Audit Policy Changed - 22 alerts
This happened four more times over the weekend. Same host, same batch of 22 alerts. Something automated? Not a the same time each day, however.
View ArticleRe: ndepth query
When did you start logging to LEM? as said just in the comment above, As long as you were logging that far back then you should be able to reach that date.
View ArticleRe: Unable to get E-Mails. How can I temporarily get the notifications from a...
Hi, You can try perhaps, pop up messages, or SNMP trap notifications Send SNMP Trap notifications from LEM - SolarWinds Worldwide, LLC. Help and SupportPerhaps creating a weekly report might also help.
View ArticleNdepth scheduled search limit
I found the link below from solarwinds stating the ndepth export for CSV at 500,000 events, however one of my scheduled reports only showed 50,000. Is this a bug? nDepth export to CSV/PDF limitation -...
View ArticleRe: ndepth query
You'll have to use the Reports app, per this article.No nDepth results older than a month - SolarWinds Worldwide, LLC. Help and Support
View ArticleRe: Using nDepth explorer to create on demand tables/charts
nDepth has limitations for data older than a month also, per this article: No nDepth results older than a month - SolarWinds Worldwide, LLC. Help and Support
View ArticleRe: Collect events from Novell eDirectory on SuSE
Doesn't look like anyone every resolved this one. I am trying to set this up and am very new to LEM. I have all the xdas audit pieces setup on the NetIQ SuSE Linux server running eDirectory. I am...
View Article