Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5385 articles
Browse latest View live

Re: Hi all, I'm new to Solarwinds and can use your help.

Hi chydyke, It's better to post your question (and to include as much information as you can about your infrastructure) in the Server & Application Monitor forum. Also, there is a Library &...

View Article


Re: Hi all, I'm new to Solarwinds and can use your help.

Thanks maria

View Article


Re: Hi all, I'm new to Solarwinds and can use your help.

Thanks Maria!

View Article

Re: Reports by user

That's brilliant! Exactly what I was hoping to get!

View Article

Image may be NSFW.
Clik here to view.

Re: Reports by user

Hi rufat87Another option would be to use something like LANGuardian to capture the user information\metadata from network traffic and then integrate this with your SolarWinds views. You can see an...

View Article


LEM email alerts don't contain the proper information

We've created a basic email template that should contain info like $user $date $info but when we get the emails, none of that information is contained in the email. The subject and sender info is...

View Article

Re: LEM email alerts don't contain the proper information

I had the same problem when first setting up email alerts. In the Rule, under the email template, there are boxes next to the variables. You need to go to the Events or Event Groups and the drag the...

View Article

Image may be NSFW.
Clik here to view.

Re: LEM email alerts don't contain the proper information

Thank you for the reply, I tried what you suggested and still get a blank email.  This is my rule configuration. I wanted to be alerted when a user is added to a domain group. It triggers just fine and...

View Article


Image may be NSFW.
Clik here to view.

Re: LEM email alerts don't contain the proper information

Did you remember to save, then activate the rule. I have forgotten the activate button before and until it is applied the old rule remains in affect. 

View Article


Re: LEM email alerts don't contain the proper information

Thanks for the follow up, I had forgotten the activate rules button but after trying that the email was still blank. I created a new rule and have it working successfully so I'm not sure if there was...

View Article

Re: Info logging vs Warning

That makes sense about the connector.  Some devices I found were sending me almost everything like the Cisco ASA but a Cisco Switch would only send me events with higher severity.

View Article

Image may be NSFW.
Clik here to view.

Re: LEM email alerts don't contain the proper information

You got this solved, but maybe the next person will benefit.  I did a walk-through of resolving this problem on YouTube. 

View Article

Image may be NSFW.
Clik here to view.

Re: VPN Down with No Up after 5 minutes rule?

Nicole I have the same issue going on here at my location. I had my lem connector built to provide unique ID in the sourceaccount field. I have been working with Jason Dee on Case number 798758. If you...

View Article


Re: Hi all, I'm new to Solarwinds and can use your help.

Do you have LEM installed on a Windows Server or do you have it installed as a Stand-alone Server using a CLI?

View Article

Image may be NSFW.
Clik here to view.

Re: Hi all, I'm new to Solarwinds and can use your help.

Hey danielr79, some questions to ask yourself are:Do you have any compliance or auditing concerns?What standards are you trying to meet?What systems do you have that need to be monitored? Have you...

View Article


USB Defender stopped and then USB Defender running?

Hi  For some reason I am getting daily on some PCs events which display effectively simultaneously; USB Defender stopped, and USB Defender running. These events have Service Stop, and Service Start in...

View Article

Re: USB Defender stopped and then USB Defender running?

Something I've just noticed: the Detection Time on the stopped event is wildly different to the Insertion Time. For example, I have event with an Insertion Time of 8:31 Mon 11th, but a Detection Time...

View Article


ChangeDomainMember; what is going on?

For some reason I get an awful lot of ChangeDomainMember events stating: Computer account "DOMAIN\PCNAME$" changed "-".  The insertion IP is from one or the other of our DCs. Any ideas what causes...

View Article

Re: USB Defender stopped and then USB Defender running?

Detection time is the original time stamp in the vent log, so that means the events were logged to the original system on Friday the 8th.Insertion time is when the LEM actually got the event and put it...

View Article

Re: USB Defender stopped and then USB Defender running?

Ah okay, that explains the disparity. But why are these events occurring?

View Article
Browsing all 5385 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>