Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Re: Help with Advanced Rule & Email Template creation

The LEM captures and populates based on what's in the Windows Event fields.  Windows logs the whole path, there isn't a way to make LEM mask that.

View Article


Re: Email Alerting stopped

I have had the same problem repeatedly over the past year or so... cases 693580 and 739367... I always end up having to reboot the appliance because I can't leave it down waiting for a response to the...

View Article


Re: Way to modify events collected by LEM agents?

thanks curtisi, I have since figured how to modify some of the connectors to do some of what I need.  However I did want to ask a follow up question.  So there is no way to clone and customize the...

View Article

Re: Help with Advanced Rule & Email Template creation

I was afraid that was going to be the answer, but thought there may be a creative solution I hadn’t thought of.  Thank you for your help!

View Article

Re: Way to modify events collected by LEM agents?

There's no supported or official way, but they're just files like anything else.

View Article


Image may be NSFW.
Clik here to view.

Re: How do I import my CA's certificate into LEM?

I would also be interested knowing the answer if someone can find documentation on how to do it.

View Article

LEM, VMware and Symantec NetBackup

I'm currently doing my LEM database backups to a Windows share, as documented in the manuals.  What I'd really like to do is handle the LEM VM on my VMware host the same as my other VMs -- backup the...

View Article

Re: How do I import my CA's certificate into LEM?

I would also like instructions for this

View Article


Image may be NSFW.
Clik here to view.

Help with LEM Filters and/or Alerts

We use LEM for many reasons, but one important one is to monitor if any folders are moved/deleted on a secure network drive.  This drive holds all our patient information which is regulated by HIPAA....

View Article


Lem with Symantec Data Center Security

I am trying to set up LEM to work with Symantec Data Center Security, but struggling with this as there is no connector available. The product puts logs into an SQL database but these need to be then...

View Article

LEM Agent on Hyper-V Host

We are just starting work with Hyper-V and I had a few questions regarding running a LEM agent on a Hyper-V host system: Are there any known issues with running a LEM agent on a Hyper-V host...

View Article

Applications and Services Logs in LEM

Hello, I'm trying to get Applications and Services Logs into LEM and I can't manage to figure out which connector I have to use.I'm interested in TerminalServices-Gateway Logs. The exact path in...

View Article

VPN Down with No Up after 5 minutes rule?

I have a rule in LEM that alerts me when a VPN tunnel goes down and I have a 2nd rule that tells me when the VPN tunnel comes back up.  I am curious how I might create a rule to only trigger if the...

View Article


Image may be NSFW.
Clik here to view.

Re: Help with LEM Filters and/or Alerts

I'm still a LEM newbie myself but I like your thinking. I just want to clarify - your concern about securing the patient name is in regards to an email alert, right? Because the email would contain the...

View Article

Re: Receive only Windows security log by default?

This looks promising, however for now at least I reverted to switching off the application and system logs per node.  I created a profile and stopped these connectors but the next node I added to the...

View Article


Re: Receive only Windows security log by default?

- You can manually apply the profile to specific nodes-  On/Off is not persistent after a Reboot by design. It is not an enable/disable setting.

View Article

Re: Help with LEM Filters and/or Alerts

The server is internal, and we have setup e-mail encryption.  If we put the keyword  in the subject line it’s forwarded through the encryption appliance.  However, it’s only setup to work internal to...

View Article


Image may be NSFW.
Clik here to view.

Apache Tomcat for LEM

Hello, I have a few questions with regards to Apache Tomcat for LEM.  Has any updated the version of Apache Tomcat on their SWLEM server ? Another issue is that entering an incorrect address gives the...

View Article

Re: Success Stories of gaining operational value from LEM

We have Checkpoint Firewalls, after a while trying to make the block IP workand several issues opened with Solarwinds we found that the response works wonders. Many times hackers try to issue all kinds...

View Article

Image may be NSFW.
Clik here to view.

Re: Help with LEM Filters and/or Alerts

Well that makes sense. I can't really think of another way to do it than the direction you are heading. I hope it works out...  good luck!

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>