Quantcast
Channel: THWACK: Popular Discussions - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5911

In-line filter of Windows events from LEM agent

$
0
0

Hi All,

 

I am new to LEM and currently getting up to speed with it's capabilities. As part of getting to grips with this product, I installed the Windows Agent to my Windows 7 workstation as a means of filtering events generated.

 

When the connector is enabled for Vista Security, the agent reports 2 events per second. Below is a sanitised output from my LEM nDepth search query of the events in question:

 

Event NameEventInfoInsertionIPManagerDetectionIPInsertionTimeDetectionTimeSeverityToolAliasInferenceRuleProviderSIDExtraneousInfoUniqueIDEventMessageImageFileParentPIDProcessIDSourceAccountSourceDomainSourceLogonIDStopCondition
ProcessStopProgram exited "C:\Windows\System32\SearchProtocolHost.exe" PID 0x1e68 user "DOMAIN\machinename$"machinename.domain.spacepros-lem-01machinename.domain.spaceWed Aug 28 15:46:19 GMT+0100 2013Wed Aug 28 14:18:00 GMT+0100 20134Vista SecurityMicrosoft-Windows-Security-Auditing 4689C:\Windows\System32\SearchProtocolHost.exe3.13035E+19Program "C:\Windows\System32\SearchProtocolHost.exe" exited0x1e68machinename$DOMAIN0x3e7Normal
ProcessStartExec "SearchProtocolHost.exe" by "DOMAIN\machinename$"machinename.domain.spacepros-lem-01machinename.domain.spaceWed Aug 28 15:46:19 GMT+0100 2013Wed Aug 28 14:18:00 GMT+0100 20134Vista SecurityMicrosoft-Windows-Security-Auditing 4688C:\Windows\System32\SearchProtocolHost.exe3.13035E+19C:\Windows\System32\SearchProtocolHost.exe0xd340x2574machinename$DOMAIN0x3e7

 

 

These events occur in pairs and repeat per second.

 

 

I am interested to know how to omit these events from being reported to LEM. As a workaround, I can stop the Vista Security Connector, but this omits other security events reported by the Operating System. If logging of process start and stop has to be disabled at the Operating System, this may be the solution, else I would like to know if the agent can be configured with in-line filtering to omit sending Process Start and Stop events to LEM.

 

Thanks in Advance,

 

Garreth


Viewing all articles
Browse latest Browse all 5911

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>