Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Infer Alert

I have noticed that a lot of the OOB rules in LEM have the Infer Alert action setup.  I may be a bit remedial for asking but I would love to see both the thought and/or some use cases behind the Infer...

View Article


Image may be NSFW.
Clik here to view.

Success Stories of gaining operational value from LEM

I would really love to hear specific success stores of where people have gained operational value from LEM.  I am hoping that by sharing some stories or examples we might all be able to gain new...

View Article


Re: Syslog Issue

Hey Lewis, info on how to download latest connector is here in this KB (anyone can download): SolarWinds Knowledge Base :: How to apply a LEM connector update package

View Article

Re: LEM; How to debug email configuration.

This KB might help: SolarWinds Knowledge Base :: Troubleshooting LEM Rules and Email Responses You should see additional events in the "SolarWinds Events" filter (or start with the word Internal) that...

View Article

Re: How can I set up an alert for a new device

Hey Mike, Which SolarWinds tool are you using? SAM? Virtualization Manager? I want to redirect this to the right place.

View Article


Re: Infer Alert

The big use case for the infer alert action is to escalate normal activity to abnormal activity without generating email alerts and other actions.  For example, the OOTB rules try to identify things...

View Article

How do you view all of the logs from a particular node in nDepth.

Just wondering if anyone's done this, I'm sure it's some simple thing, but if I wanted to view all the logs from my AD box, or all of the ones from one of the routers, then how would you open it up in...

View Article

Re: Success Stories of gaining operational value from LEM

We just surveyed our customers and related customers using log data for SIEM/IT Ops/Compliance and got a lot of interesting insight into what features people are using. We're hoping to get some cool...

View Article


Re: Email alert consolidation and organization

That sounds more like Alert Central than LEM, to be honest, but it depends on what you're trying to do. If you want to send log data to a single system and alert on it from one place rather than...

View Article


Re: Upgrading LEM L4 Appliances to 6.0.1 - Any Problems with Reports?

There is some uniqueness to the dedicated database/L4 setup - with 6.0.1 we introduced the authenticated reports, so the appliance has to act as a pass-through. I can't find a knowledge base article...

View Article

Re: Email alert consolidation and organization

Thank you for the info! I will check it out.Craig Sent from my iPhone

View Article

Image may be NSFW.
Clik here to view.

Re: How do you view all of the logs from a particular node in nDepth.

Hi , Best way is to filter your source/Destination and it will show in console and then you can try it in nDepth. RegardsPrak

View Article

Re: I am going to be testing out LEM. I would like to know if i can install...

LEM is its own virtual appliance, so it IS a standalone VM  And, it is structured such that the logs do need to go directly to LEM. You can forward logs you're already collecting in Orion to LEM, but...

View Article


Re: FIM on 6.0.1

I'm also having a problem with folders, and subfolders changes not getting picked up by FIM.  I tested it by making the folder/subfolder mask recursive, and created and deleted some folders.  I had...

View Article

Re: Upgrading LEM L4 Appliances to 6.0.1 - Any Problems with Reports?

Nicole, Thanks.  You might also want to check out the other case #696092 we worked on for several weeks which covers the initial problem after 6.0.1 upgrade: The Manager was receiving events from...

View Article


Re: Need LEM agent UNinstaller

Could you tell me where I can download this "Remote Agent UnInstaller" because I can't find it anywhere. I am also evaluating LEM and can't uninstall my agents. The Remote Agent Installer only puts the...

View Article

Re: Need LEM agent UNinstaller

Just for anyone else who runs into this, I created an uninstall batch file that I placed as a startup script using Group Policy. The script uninstalls the agent service and the usb defender service and...

View Article


Brocade ICX

Hey All, New to the Solar Winds LEM.... Trying to get my Brocade ICX's to log to it. So far no luck. Tried the different canned connectors for Brocade and then tried the Add Node just choosing Brocade...

View Article

Re: Success Stories of gaining operational value from LEM

Thanks for sharing Nicole!  I would be interested in hearing specifically how the system was configured or what it was configured to look at in the specific scenarios that lead to the success. 

View Article

Re: Infer Alert

Interesting concepts.  I am glad you mentioned the Incident Action because I had never really noticed that before.  Now that you mentioned it I was able to go check it out and see how it correlates to...

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>