Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Re: LEM - MS Lync logs not appearing within LEM

Thanks for the response.I have now submitted a request for the Lync connector to be created, im suprised it doesnt have one already considering the size of the product and how long it's been around...

View Article


Performance Issues with latest LEM release

Has anyone else noticed a huge performance hit when it comes to searching for events within nDepth?  Ever since we've gone to the latest edition of LEM it takes almost 5 times longer to search for...

View Article


Re: LEM - MS Lync logs not appearing within LEM

Connectors usually seem to turn around in a couple weeks, though that depends on if we have a reader that already understands the log formatting, if we can use previous connectors as a starting point,...

View Article

Re: LEM - MS Lync logs not appearing within LEM

Thanks for the reply, i have already submitted some information to Solawrinds and they informed me it would be forwarded to their developers. I have also just opened a feature request for this so...

View Article

Re: Multiple Failed Login attempts by different users but same IP

Thanks, will give it a try and do some testing. Appreciate your help on this.

View Article


Image may be NSFW.
Clik here to view.

I have LEM 5.4, We own a 6.0 licence. Can someone show me where to download...

I have LEM 5.4,   We own a 6.0 licence.  I know that you have to upgrade to 5.6 and then to 6.0.  Can someone show me where to download the 5.6  and the 6.0 upgrades?  Thanks....Rick

View Article

Image may be NSFW.
Clik here to view.

Re: I have LEM 5.4, We own a 6.0 licence. Can someone show me where to...

Rick, In your customer portal, go to License Management --> My Downloads.  Change the drop-down to LEM, then pick these: 

View Article

SoftwareInstall Event

Does the SoftwareInstall event only trigger when an MsiInstaller event is triggered? I noticed that when one of my staff installed Notepad++ that it didn't trigger. I can see the install as a...

View Article


How do i add a static route in LEM 6.0

Hey guys; can someone tell me how to add a static route in LEM 6.0.  For security reasons 1 run 2 firewalls, one is my default gateway which handles 95% of my servers and one is my backend firewall...

View Article


Image may be NSFW.
Clik here to view.

Re: SoftwareInstall Event

I'm new to LEM/SolarWind (2 days old to be precise) so my answer may be riddled with bad practices... In any case, like you, I just discovered that SoftwareInstall events are primarily MSI executables...

View Article

Image may be NSFW.
Clik here to view.

When you send a response to an agent machine, where is it logged?

When you send a response to an agent machine, where is it logged? 

View Article

Image may be NSFW.
Clik here to view.

Re: SoftwareInstall Event

Better to use event groups!  

View Article

Re: How do i add a static route in LEM 6.0

Jeremy, There's no way for a customer to add a static route, but if you contact support, they can make the changes. The caveat is that these changes may be over-written in a future upgrade, so when 6.1...

View Article


Image may be NSFW.
Clik here to view.

Re: When you send a response to an agent machine, where is it logged?

I just tested this, and it showed up in my LEM Internal Events filter. In nDepth, you could search for Event Name = Internal Commands, InferenceRule = Kill Proc Name and ExtraneousInfo = [machine, user...

View Article

Re: SoftwareInstall Event

It appears that SoftwareInstall is looking for the MSIInstaller events, like 1033.  If the installer isn't going to call the Windows Application Installer service, it'll throw different events.

View Article


Re: How do i add a static route in LEM 6.0

Another possibility is to have your backend firewall send to a different syslog server such as kiwi syslog server. Install an LEM agent on the syslog server, and enable the relevant connector on the...

View Article

Monitor Simultaneous Logins on LEM

Hi All, Is there a way on LEM wherein I can configure the appliance to monitor simultaneous logins on our system? I plan to create a rule that whenever LEM received a logon events, it will...

View Article


Re: When you send a response to an agent machine, where is it logged?

Thanks for responding... I had missed it because my LEM Internal Events is flooded by an Unmatched  Logd Data message for one of my devices...

View Article

Image may be NSFW.
Clik here to view.

Re: Monitor Simultaneous Logins on LEM

Here's what I would use: First, create a User Defined Group like this one:Then, in your rule for logins, make is something like this:(This is an awful rule, you'd probably want some NOT statements to...

View Article

what happens to event logs if LEM Agents (windows) cannot connect to LEM Manager

can you point me to a KB article that describes how long LEM Agents can be out of contact with their LEM Manager . (For example, if i need to reboot the ESX server, what happens to the events while the...

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>