Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Need to know what date LEM will have snmp v3

What date will LEM support snmp v3?  My company uses DOD requirements for all network gear. Right now LEM is not compliant.  As we are in the testing phase we also realized we cannot change the port...

View Article


LEM keeps freezing

Hi all, Pretty noob to LEM.... Our LEM seems to freeze every now and then....Is there a way of setting up a cron job to either re-start the manager service or reboot the appliance nightly or every...

View Article


Re: IP range exclusion

For your filters/rules/nDepth searches, you would just say something along the lines of: DestinationIP = 192.168* which would, of course, match anything from 192.168.0.1 - 192.168.255.254.  It is...

View Article

Looking for references for L&E Manager.

I'm looking for references for Log and Event Manager, preferably from credit unions in the Northeast United States, preferably from Maine.  Please include contact info.  You can reach out to me via...

View Article

Re: Log Event Manager issue

Believe it or not I'm having the same problem in our network with Cisco devices. Check port 514    To do this (from another computer on the network) -> telnet  192.168.2.1 514 If you get through...

View Article


Image may be NSFW.
Clik here to view.

Re: Network monitoring

Hey nicole pauls, what specifically are the capabilities of LEM with regard to netflow/sflow?  Is this documented somewhere?

View Article

Re: Network monitoring

The only flow capabilities in LEM right now are to collect flows and display top talker info (by bytes or packets per host or port). There hasn't been much drive to utilize flow data further, and some...

View Article

Re: Network monitoring

Awesome, thanks for the quick response Nicole!

View Article


LEM in multiple Microsoft AD Forests (as opposed to multiple domains)

Due to several statutory requirements, we are finding ourselves in need to dividing our existing Microsoft AD forest into multiple separate and distinct forests (as a domain is not a security...

View Article


Image may be NSFW.
Clik here to view.

Re: LEM in multiple Microsoft AD Forests (as opposed to multiple domains)

LEM generally communicates using either an Agent (e.g. on Windows systems), or via syslog or SNMP.All of these technologies are Active Directory agnostic. The User tool allows for the retrieval of user...

View Article

Re: Login Failure Doesn't Detect IP

I guess this is part of the argument for good, consistent host naming conventions, then.  I'm not aware of a setting that would force the LEM to prefer one over the other, but I'll ask around.

View Article

last event over 5 days old

Our VMfarm had issues 5 days ago. The LEM server was on the VMfarm and appeared to come back online.  When we went into LEM today, all of the nodes are showing last event of 5day or so.  I do not see a...

View Article

Re: last event over 5 days old

You can try stopping the SolarWinds Log and Event Manager Agent.  Delete the spop folder from C:\Windows\SysWOW64\ContegoSPOP (depending on what version of Windows is installed).  Then start the agent...

View Article


Re: last event over 5 days old

spop folder is located where? we have a virtual linux server, I am not linux knowledgeable.

View Article

Re: last event over 5 days old

/usr/local/contego/ContegoSPOPKeep in mind this is done on the agents themselves.

View Article


Re: last event over 5 days old

found the folder, deleted it, same issue. 

View Article

Re: last event over 5 days old

Anything in the spoplog?

View Article


Re: last event over 5 days old

(Fri May 02 11:24:23 PDT 2014) II:NOTICE [NioComNetworkParent v24745] {ComModuleSpop:20} Install request completed (not installed);(Fri May 02 11:28:23 PDT 2014) II:NOTICE [NioComNetworkParent v24745]...

View Article

Re: last event over 5 days old

Doesn't look like its connecting.  You should see something like the following: (Fri May 02 13:41:42 CDT 2014) II:NOTICE [NioComNetworkParent v24745] {ComModuleSpop:20} Install request completed...

View Article

Image may be NSFW.
Clik here to view.

Re: last event over 5 days old

I can ping the IP address of the server.  I cannot telnet into it on the port suggested.  the network guy who set up our LEM server also has a second IP address that the LEM GUI connects to on port...

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>