Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Image may be NSFW.
Clik here to view.

Email Alerts - Does anyone know how to change the "From:" address of an email...

This is what I've tried so far (without success)...     I created a new user (LEM Role: Contact) under Build --> Users.     I changed the email template to reflect the newly created user (the...

View Article


Exporting syslog from PulseSecure (formerly Juniper) SA4500 appliances into LEM

I'm adding our SA4500 cluster to export syslog to the LEM. No firewall rules or any other things in the way.I've followed Juniper's KB for setting up export - very straightforward.However, I'm not...

View Article


Re: Email Alerts - Does anyone know how to change the "From:" address of an...

There are two ways to change this in 11.0 and higher:  To change an individual alert (Or in versions prior to 11.0): Go to log into the server that contains your Orion platform, go to Advance Alerts,...

View Article

Re: Email Alerts - Does anyone know how to change the "From:" address of an...

Warren, I appreciate the response however my question applies to the Log Event Manager (not Orion)

View Article

Re: Email Alerts - Does anyone know how to change the "From:" address of an...

I apologize, then let me start with a different point. Have you created a new Email Active response Connector under the LEM Manager? The steps according to SolarWinds are as follows: Log into the LEM...

View Article


Re: Email Alerts - Does anyone know how to change the "From:" address of an...

I haven't tried that, as I already have the Email Active Response connector there however maybe recreating/reconfiguring that connector will do it.  I'll try that as soon as I have a chance.

View Article

Image may be NSFW.
Clik here to view.

Re: How do I export all raw data from Logs/Data?

Makes sense, but this was a security audit and we really wanted them to examine LEM data. Don't think they would use LEM though...

View Article

Image may be NSFW.
Clik here to view.

Re: Email Alerts - Does anyone know how to change the "From:" address of an...

warren.dilger is correct, these values are defined in the Email Active Response Connector: 

View Article


Re: Exporting syslog from PulseSecure (formerly Juniper) SA4500 appliances...

The first thing I would do is make sure you have the latest connector pack from the Customer Portal or this page: SolarWinds Knowledge Base :: How to apply a LEM connector update package It's possible...

View Article


Re: LEM OPS Center - View Historical Data

The Ops Center widgets are driven by the filters in the Monitor tab, and these filters start counting from the moment the console is opened.  nDepth and the Reports Console are the only way to get...

View Article

Image may be NSFW.
Clik here to view.

Re: Alerts on Event Viewer items

Can you be a little more precise on what events you need?  The codes 4099 and 4098 could appear in multiple logs (System, Security, Application, etc) or from multiple applications and mean different...

View Article

Image may be NSFW.
Clik here to view.

Re: I'm getting the following when trying to create a cert request to our CA...

Nicole; Yes I worked with support and finally after several calls and web-ex we figured this out.  It was Tim Rush that got me going and he did a GREAT job.  I was able to perform the same task on our...

View Article

LEM Events stop updating Filters

  All,     Monitoring LEM over the last two months, I have noticed LEM has twice had a database issue causing LEM not to display any events.  On both occasions, LEM syslog shows LEM receives data from...

View Article


Re: LEM Events stop updating Filters

Can you SSH into the LEM and run a VIEWSYSINFO under the MANAGER menu and show the output?

View Article

Re: LEM Events stop updating Filters

Curtis, Yes. Following are the first couple of lines from the viewsysinfo.Is there something in the output of viewsysinfo that would give me an indication why Events were not displaying in the Filters...

View Article


How do I access the LEM web console?

I did the install into VMware.  I then went to the console screen.  No URL was listed, as was no IP address. Using the cmc commands, I set the IP address.  I figured entering the IP address into my...

View Article

Re: How do I access the LEM web console?

Figured it out.  There was a reverse DNS entry for the IP address I previously assigned it.  I changed the IP address to one that didn't have a reverse DNS entry and the console fired right up.

View Article


Image may be NSFW.
Clik here to view.

Re: LEM OPS Center - View Historical Data

Thanks for your response, I will look into the alternatives.

View Article

Re: Filtering Certain Windows Security Events Before the LEM Agent Sends to...

Hi Chadd I have raised this too with the guys from SolarWinds on the stand at InfoSec in London and with the LEM support department manager in the US it would be a huge benefit to us too

View Article

Re: LEM Events stop updating Filters

You need to set reservations for the LEM's memory and CPU, or this issue will continue to occur.  Reservations should be set equal to the currently assigned resources, in your case the 8GB of memory...

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>