Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Image may be NSFW.
Clik here to view.

Re: Recognizing A Sequence of Events

Aha.  Thanks for that. So...  Based upon the Correlation image you included above, and assuming that URL-A and URL-B are different enough that they won't ever occur at the same time on a log record,...

View Article


LEM Report Manager fails ping test

Just installed the LEM reporting tool on a Windows server. LEM is running 6.1, Report Manager is 6.1. When I try and configure the manager info I get ping failed using the manager name or the IP. I can...

View Article


Switching from old LEM to a new LEM for agents

We recently switched from one LEM to a new LEM. This was done to start over since the old LEM was barely usable. The new LEM has the same IP and host name the old one did. The old one has been changed...

View Article

Re: LEM Report Manager fails ping test

First, the latest version of LEM is 6.3.1HF4 (as of May 11 2017).  Upgrade the appliance and the Reports console! Second, I see the ping fail when Reports isn't running "As Administrator."  Even if...

View Article

Image may be NSFW.
Clik here to view.

Re: Switching from old LEM to a new LEM for agents

Shawn, The Agents won't automatically reconnect.  When they connected to your original LEM, they would have exchanged certificates for encrypting the log traffic.  These certificates are not going to...

View Article


Image may be NSFW.
Clik here to view.

WannaCry Alert

Has anyone created a WannaCry LEM alert. This threat might have subsided due to the Kill switch but I am thinking others are coming.  Based on a few blog posts I have read I created a rule that looks...

View Article

Image may be NSFW.
Clik here to view.

Cluster Mode Netapp File Auditing

I cannot seem to get LEM to read the .evtx file that Netapp is generating.This postNetapp Clustered Data ONTAP CIFS auditing to LEM has been answered but in the same post at a later date is this...

View Article

Re: WannaCry Alert

I have it sending an email and disabling networking

View Article


Re: WannaCry Alert

Well i wanted to have it kill network but its asking me for an agent and i don't know what to put in there.

View Article


Re: LEM Report Manager fails ping test

Running as an administrator resolved the issue. Thanks for that tip. I'll take a look at the upgrade process for the LEM appliance once I've had a chance to play with the reporting functions a little.

View Article

Re: WannaCry Alert

Are you able to monitor file creation without the agent and FIM going?

View Article

Re: WannaCry Alert

I got an error when i added in the action disable Networking, needs agent details. 

View Article

Image may be NSFW.
Clik here to view.

Re: WannaCry Alert

View Article


Image may be NSFW.
Clik here to view.

Re: WannaCry Alert

My question is that I am only getting logs from my file server. The file server is my biggest concern, it has the LEM agent installed and is setup as FIM.  So if my PC writes a file to the file server...

View Article

Re: WannaCry Alert

What kind of setup do you have in your FIM connector to detect file name changes? I have not been able to get a combination that will detect file name changes for some reason yet.I think your rule...

View Article


Image may be NSFW.
Clik here to view.

Re: WannaCry Alert

Here's my attempt: WanaCrypt v1 Detection Rule

View Article

Image may be NSFW.
Clik here to view.

Re: WannaCry Alert

jeremymayfield ... I believe you would just drag the FileAudit.DetectionIP over to that field: 

View Article


Image may be NSFW.
Clik here to view.

Re: WannaCry Alert

dcokers ... That would be normal.... You would have to be specifically monitoring those nodes in LEM in order to get alerts from or disable them.

View Article

Re: WannaCry Alert

Didn't work for me, still errors on that field.

View Article

Image may be NSFW.
Clik here to view.

Re: WannaCry Alert

I lied, used the wrong one, its good now.  thank you.

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>