Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Re: Extend data retention

curtisi, thanks for the explanation. That makes sense. What about the backup archive. Could that be a mechanism to extend retention? I'm aware that you can't merge the archive back into the live data....

View Article


Re: Extend data retention

Yes, it could expand retention.  No, you can't search the archive from the console of your live LEM. The way this works would be:Setup the ARCHIVECONFIG command on your production LEM.  This copies DB...

View Article


Re: Extend data retention

curtisi, awesome answer. I'm sorry, I should have been more clear with the question. I was looking for both a performance and storage comparison between searching the live data versus the archive....

View Article

Image may be NSFW.
Clik here to view.

Re: Extend data retention

No problem!

View Article

Image may be NSFW.
Clik here to view.

Re: OPSEC connector session error

Hi Curtisi yeah! I sure did install policy on Checkpoint.Environment have two production devices. for management and gateway.The OPSEC build on management server.And, I done successful open Checkpoint...

View Article


Re: OPSEC connector session error

Is your client DN exactly as you copied it from the application settings? This may be totally stupid, but I don't know that the connector can handle an application with a name other than "solarwinds"...

View Article

Re: How do I import my CA's certificate into LEM?

Any instructions on this task?

View Article

viewsysinfo shows clock sync is disabled and time is off

How do I set the clock on my virtual appliance LEM 6.1 with hotfix 1 to sync?

View Article


Re: OPSEC connector session error

Hi Curtisi I think this issue has been cleared up.Checkpoint connector for r75.40 SPLAT your post.All uppercase and lowercase not usefully in my OPSEC sync.Mixed-case is powerful work in CheckPoint...

View Article


Re: viewsysinfo shows clock sync is disabled and time is off

You should be able to use the ntpconfig command to set it up to sync with an ntp server, or alternatively use the tzconfig command to manually set the time zone.  These should be listed in the...

View Article

Image may be NSFW.
Clik here to view.

Just stood up LEM, and admin account is read-only?

We just stood up three LEM servers (on different networks) and I am able to login with the default admin account. The first thing I tried to do was create a user... but when I went to Users, all the...

View Article

Image may be NSFW.
Clik here to view.

Re: Just stood up LEM, and admin account is read-only?

That sure seems weird.  Can you try some tests?- Can you reload the console in your browser?- Can you try another browser?- Can you try clearing your browser cache and cookies?- Can you clear your...

View Article

Re: viewsysinfo shows clock sync is disabled and time is off

Another option is to set the time on the hypervisor, LEM will by default try to sync guest to host OS. There seems to be some delay in this approach especially on first boot of a new LEM eval, so you...

View Article


Re: Extend data retention

We can actually deploy a dedicated database appliance if it's necessary, but we've found in our experience that's rarely the case. I can't say we've had a customer go this route in a very long time,...

View Article

Re: Apache Tomcat for LEM

In addition to curtis's notes, the Tomcat version is sometimes not enough to go off of. Patches can be backported, and the version may appear to be out of date when in fact it's just a patched older...

View Article


Re: VPN Down with No Up after 5 minutes rule?

To follow up a little, the tricky part of this will be that it has to be two different event types to trigger the rule. Check out the other thread for the basics, but basically you'll want: VPN Down...

View Article

Re: LEM Alerts - Save to a file?

Yeah, "Append to Text File" only lets you save a single field (I think we have a feature request to append to text more fields or something like a template). I think if you use "send popup message" it...

View Article


Full or incremental backup?

Ok, I'm aware of the built-in backup capability of LEM using archiveconfig. I'm also aware that if the backup is scheduled, the first backup is a full backup whereas any subsequent backups are...

View Article

Re: LEM Alerts - Save to a file?

I appreciate your thinking outside the box for me, but this would be overkill to send a UserID and File Name out.  If I could get Lync somehow integrated that would be even better! I guess we have to...

View Article

Image may be NSFW.
Clik here to view.

Re: LEM Alerts - Save to a file?

Alas, since LEM can't execute a script action, that's not an option yet either, but that would probably be another way... I found some references to being able to send a Lync message as a script. There...

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>