Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Image may be NSFW.
Clik here to view.

Re: Checkpoint Firewall monitoring using LEM

There is a Checkpoint connector for syslog messages from Checkpoint EdgeX listed as "Checkpoint Edge X Firewall".  It is possible it may work with the one you are asking about.  Sometimes venders use...

View Article


Image may be NSFW.
Clik here to view.

Re: LEM not saving my credentials

This is a known bug in LEM 6.3.1 which we are working to resolve, JIRA case LEM-2001. I cannot commit to a time frame at present but I'll make sure to keep you updated on progress. Please feel free to...

View Article


LEM Ingest Rate

How can I determine LEM's ingest rate? I.E., how much data (in terms of size, rather than number of events) is coming in everyday?

View Article

How do you like LEM especially when compared to Splunk?

We are currently leveraging Splunk for security data and correlation, sever / desktop event filtering, dashboarding of customer service and BI data, etc. Recently we lost both of our Splunk admins and...

View Article

Re: How do you like LEM especially when compared to Splunk?

I've used both -- I was the Splunk admin at my last job, and my new company has been using LEM for a couple of years now.   In my opinion, if you are used to using Splunk you will be severely...

View Article


Re: Configuring SSO for LEM

Is SSO my only option for AD authentication? SSO wont work for me as my organization uses distinct admin IDs for each engineer. If they use SSO from their workstations it would pass the standard...

View Article

Image may be NSFW.
Clik here to view.

Re: Configuring SSO for LEM

You can use just LDAP.  You do not need to configure SSO. Make sure you are on 6.3.1 hotfix 2 since the groups now have a configurable name.   Here is an article to follow.  There is a newer article...

View Article

Image may be NSFW.
Clik here to view.

Re: LEM Ingest Rate

I'd take a look at the Database Maintenance Reports, from the LEM Reports app.

View Article


Image may be NSFW.
Clik here to view.

I'm trying to create Remedy tickets from alerts

Trying to create Remedy tickets form SW alerts, I've worked with my Remedy developers and can now create a ticket from email - how do I read the response email from Remedy back into SW to pull out...

View Article


Image may be NSFW.
Clik here to view.

Re: I'm trying to create Remedy tickets from alerts

LEM doesn't parse e-mails sent to it, so if they're sending back to the LEM's from address, that information is being lost in the void.  WHD could replace Remedy and receive alerts from LEM, or you...

View Article

Re: I'm trying to create Remedy tickets from alerts

Curtisi I’m hoping to generate an email from an event in NPM so wasn’t planning on using LEM (not on purpose anyway ) Just all the reading I’ve done seems to show WHD being an email receiver – If I...

View Article

Re: I'm trying to create Remedy tickets from alerts

You posted your question in the LEM community, so I assumed LEM was involved.  You may want to try asking this in the NPM area and see if they have a better answer.

View Article

Image may be NSFW.
Clik here to view.

Re: I'm trying to create Remedy tickets from alerts

You would have to have remedy write the ticket and some correlating bit of info to a log file that orion is watching. Now with that said you might not be able to link the ticket to the event.  If you...

View Article


Image may be NSFW.
Clik here to view.

Re: I'm trying to create Remedy tickets from alerts

Curtisi Ok I think I shouldn’t have posted in LEM I’ll try NPM – all I want to do is take an event in SolarWinds, format a structured email to a Remedy webserver and cut a ticket, and then read back in...

View Article

LEM agent unable to connect Manager

Installed LEM agent on windows 7, but on the LEM manager can't discover the node. It seems there is a communication problem between agent and LEM appliance. Below is a bit of the log event from the...

View Article


Re: I'm trying to create Remedy tickets from alerts

fellowsm, look at my response above your last one...  There is not a native way to do that.You will have to do it out of band.  Been there...was not worth the headache of building that interface to...

View Article

Re: LEM agent unable to connect Manager

A couple things to check here....First verify that the agent service is actually running on the machine.Check the spop.conf file in the same directory as your log file you posted and make sure that the...

View Article


Image may be NSFW.
Clik here to view.

Changing the name of a LEM node

I just added my first node in LEM (a Cisco switch) and trying to figure out how to change the name of the node from the IP address to a friendly name? Dan

View Article

Re: Changing the name of a LEM node

Agents on nodes attempt to resolve their own names via DNS.  Was there a DNS entry for the node in question? Syslog nodes typically get whatever name is included in the syslog messages they send, so if...

View Article

Add e-mails to Directory Service Group members

We started using Directory Service Group logins to LEM before we had e-mail addresses in AD. Now that e-mails are in AD, how do we sync that with LEM so that we can set up alerts? In particular, is it...

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>