Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Re: ManageEngine.xml (Password Manager Pro) Syslog Connector not working

Thanks to support for building a better connector. 

View Article


Re: Log Event Manager issue

Sir, how do i view local2?Please guide me regarding this process and i don't know any commands.

View Article


Creating more in depth widget for logons.

Is it possible to create a widget that shows logon events (both successful and failed) for a specific user. I can see other widgets that show top 10 users for example but I want to keep an eye on just...

View Article

Re: Log Event Manager issue

cmc> appliancecmc::acm# checklogs  Available log files:        [1]: Syslog Log (83M)        [2]: SNMP Trap Log (2.9M)        [3]: Snort Alert Log (Empty)        [4]: Auth Log (12K)        [5]:...

View Article

Image may be NSFW.
Clik here to view.

Re: Creating more in depth widget for logons.

You will have to add the filter first.  Then add the filter from Widget manager. 

View Article


Re: Creating more in depth widget for logons.

Thank you evanr - that's worked perfectly!

View Article

Image may be NSFW.
Clik here to view.

Re: Log Event Manager issue

[14]: syslog local2 log [Empty] its showing empty. Dear Evanr and Curtisi, I did it this process successfully and even i enter to continue and went into vi enviroment but i didn't understand this.Can...

View Article

Re: LEM Rule for Multiple Failed Logins using multiple account

Really helpful, thanks very much. I was going to ask this question also but someone beat me to it! Thanks.

View Article


Image may be NSFW.
Clik here to view.

Re: Log Event Manager issue

Please sir help me to resolve this issue. 14]: syslog local2 log [Empty] its showing empty. Dear Evanr and Curtisi, I did it this process successfully and even i enter to continue and went into vi...

View Article


LEM Console or Web Portal?

As a relatively new user of LEM, I decided to spin up a VM to run the LEM console - thus doing away with the need to open and close the console and lose the visibility of the data shown in the widgets...

View Article

Re: LEM Console or Web Portal?

My thought is that the console isn't really meant to be a full-time monitoring solution.  It's useful if you become aware of something going on in the network (a rule has sent you 14 e-mails that...

View Article

Image may be NSFW.
Clik here to view.

Re: LEM filter issue

Backing up what evanr said: In the case of Cisco Firewalls, the default Tool Alias is Cisco PIX and IOS.  If you have all your Firewalls logging to Local7, you may want to change that to "Cisco...

View Article

Re: LEM Connectors Not Running

Having the same issue, did this ever get resolved?

View Article


Re: LEM Console or Web Portal?

Thanks curtisi for the prompt and helpful response.. That's a bit of a shame. So effectively you're not meant to use the console unless there's an issue you've been made aware of by the rules firing?...

View Article

Re: LEM Console or Web Portal?

The reports and nDepth will give you the whole history, that's true.  The OpsCenter and Monitor sections are good for a high-level over-view, but it's not really intended to be watched 24/7.  Most...

View Article


Re: LEM Connectors Not Running

Are you also running LEM 5.5?  We'd suggest that you upgrade, and make sure your connectors are all up to date.

View Article

Re: LEM Console or Web Portal?

Hi Stu, I would try using a web browser with the console open and soak test this way. I suspect the RDP session does not play well with the Adobe AIR console. It might behave better with the browser as...

View Article


Re: LEM Console or Web Portal?

Great stuff - thank you Gents for your answers. I'll give that a go now and fire up the console in a browser window. Enjoy your weekends

View Article

Image may be NSFW.
Clik here to view.

Re: LEM Console or Web Portal?

Interesting.  In addition to our reports/saved nDepth searches.  I'm on the web portal all day every day.  Maybe I'm a paranoid but I like to see whats going on in real time.  The web portal definitely...

View Article

Re: LEM filter issue

What will i put in the notification option ? I did not get below statement please can you explain me clearly ? "In the case of Cisco Firewalls, the default Tool Alias is Cisco PIX and IOS.  If you have...

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>