Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Re: Log & Event Manager API / REST/ Cmdline

Nope.  We do have this, though:Create LEM Custom Reports Using Crystal Reports - SolarWinds Worldwide, LLC. Help and Support

View Article


Image may be NSFW.
Clik here to view.

Re: LEM losing Events?

The connector in that example is for a Windows Security log, so I'm guessing the machine under your scribble might be losing the events. Is the source message a 4612?Windows Security Log Event ID 4612...

View Article


SQL Query results to LEM

HI all, we have an application that does not have syslog or RESTAPI support but logs all audit information into a SQL database. Is there a way to grab this data and push it into LEM, Thank you.

View Article

Palo Alto Firewall + LEM = Random Nodes?

We put in a Palo Alto firewall and set up syslog to report to the firewall. Since doing so, I am getting random 13 digit "nodes" reporting in too. I cannot find any actual information being reported...

View Article

Re: Palo Alto Firewall + LEM = Random Nodes?

Sounds like somehow time is getting grabbed instead of the ip address.  Make sure you have the latest version of connectors and if you do then I would open up a case with support in order to help get...

View Article


Re: SQL Query results to LEM

There are connectors in existence that connect into a database at regular intervals to pull log data (the Kaspersky enterprise DB is one example), but this would be a feature request via Support to get...

View Article

Re: Palo Alto Firewall + LEM = Random Nodes?

Have you created any custom rules around the Palo Alto data?  I've seen this behavior if you have a rule with an action like "InferAlert" or "IncidentAlert" but the .DetectionIP field is being...

View Article

Re: Automatic connector restart

Thanks for all the replies.  We have an open case with Solarwinds now to try and resolve this as well as our agent-based machines losing connectivity.  I will give an update when we get a resolution.

View Article


Is there any way to report on a filter?

Hello All,     I'm a newbie to LEM but have found help on thwack for a few weeks. I have a need to report on cisco VPN connects / disconnects that I don't think are available in the standard reports. I...

View Article


Re: Is there any way to report on a filter?

You can create an nDepth search from the filter and schedule that search to run.  You can even email like the first 10 MB of results, I believe.

View Article

Image may be NSFW.
Clik here to view.

Re: Is there any way to report on a filter?

Thanks blsanner !!! It appears you can only email a PDF which is too bad but still helpful. If you click on the settings on the top right of the result detail report itself you can export to csv. Thank...

View Article

Kron Job for Manager service restart on LEM

It seems we need to restart the manager service on our LEM pretty much daily.  Is there a way to set up a kron job or something that can do that for us automagically?

View Article

Image may be NSFW.
Clik here to view.

Re: Kron Job for Manager service restart on LEM

Restarting is not something that is normally needed.  Typically it has to do with reservations or something else that is happening.  I would highly suggest you open up a support case to help find the...

View Article


Image may be NSFW.
Clik here to view.

Re: Logon After Hours Alert Not Working

Any other thoughts on the matter?

View Article

Re: Logon After Hours Alert Not Working

I would actually start at testing this as a filter. You can then see in real time which events arrive in based on the conditions you have in the filter.Start with the very first condition, and add the...

View Article


Re: Kron Job for Manager service restart on LEM

Ditto was Wolram has said. Manager service should not be restarted so often, it could eventually lead to further issues in the background. do you have enough free memory? Go to cmc > manager >...

View Article

LEM Agent Footprint on Windows System?

I would like to know what the expected resource footprint the LEM agent has on a Windows system?  If this is already documented I apologize for the post but I was unable to find this in the...

View Article


Re: LEM Agent Footprint on Windows System?

SolarWinds LEM Agent Installer for Windows - SolarWinds Worldwide, LLC. Help and Support HardwareRequirementRAM64 MBDisk Space130 MBI see CPU usage of less than 1% on most modern systems.

View Article

Image may be NSFW.
Clik here to view.

Re: LEM Agent Footprint on Windows System?

Awesome, thanks so much curtisi for the super fast response!

View Article

license recycling for non agent

We have recently began to use license recycling and it has worked for agent nodes. The non agent nodes do not recycle using the license recycling. Specifically, for every new VPN connection, a new...

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>