Quantcast
Channel: THWACK: Popular Discussions - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5911 articles
Browse latest View live

LEM Connector Updates

It appears when using the console for auto-updates of LEM connectors, it's trying to go out port 80 to Akamai CDN.  Is it Solarwinds recommendation to allow the server outbound port 80 to any...

View Article


Node discovered with wrong connector

Hello! I recently got Patch Manager squared away (mostly) for our network, so I've moved on to learning LEM and getting it set up with our network.  I have a feeling I'm going to be asking a llloootttt...

View Article


McAfee

Hello, How to show logs from McAfee, when McAfee can't work for specific user. Thanks

View Article

How do i add a static route in LEM 6.0

Hey guys; can someone tell me how to add a static route in LEM 6.0.  For security reasons 1 run 2 firewalls, one is my default gateway which handles 95% of my servers and one is my backend firewall...

View Article

e-mail notification

Hi all, I have configured the LEM to send me an e-mail notification when certain events occur but it doesn't work. Please help me in how to solve such problem

View Article


Does LEM offer a generic txt/log file connector that we can use to collect...

Almost like the McAfee Connector.  I basically just point it to the scan.log and can receive the data that populates in the log file.

View Article

Backup Notification SMS

Hi All, I have my E-mail Active Response working and it's sending e-mail correctly, However I was wondering if LEM can send alerts as SMS?My main concern here is to have a backup notification if the...

View Article

Why is it when, I try to use nmap to verify the ports on Windows Server is...

Good day everyone, I had idea to make sure that new windows servers that will be added to the LEM ports are open. Ports I am talking about is TCP 37890-37896I was trying to use NMAP nmap -sT -p...

View Article


Domain Admin account lockout alert

Hello everyone, I have an alert that tells me when an account is locked out. It works very nicely. Every once and a while it alerts me that my domain\administrator account is being locked out, but when...

View Article


Image may be NSFW.
Clik here to view.

LEM - Where is Everything

Ever wondered what goes on in the background behind the blue LEM appliance screen? We will have a look even though it is slightly concerning i can do this bur nevermind.Fistly all your logs are stored...

View Article

Why is Windows event 4627 tagged as MachineLogonFailure in LEM?

From what I've read online, it's a normal event that returns Group Membership Information.  It appears in the logs between events 4624 (An account was successfully logged on) and 4634 (An account was...

View Article

Checkpoint connector for r75.40 SPLAT

Hi guru, Please help me to get Checkpoint r75.40 SPLAT log into LEMI tried OPSEC/Check Point NG LEA Client but it fails to startMany thanks

View Article

LEM Linux agent connects but no logs

I am struggling with getting a Open SuSE Linux server to log to my LEM. Details:LEM 5.4Linux Client 5.3.1Linux OpenSuSE 11.2 It installed and even connected to the console. I created the Pam, Audit and...

View Article


How to capture failed 'Run as Administrator' events on a Windows domain?

Does anyone have insight into how MS Audit Policy can be used to capture failed 'Run as Administrator' attempts without having to install LEM agents on all workstations?  I've been attempting to...

View Article

Severity Levels: How are they determined?

Hey all, Does anyone know how the severity levels are determined?  We are trying to correlate the severity of Windows Events with the severity levels in LEM, so we can build a filter for just critical...

View Article


Image may be NSFW.
Clik here to view.

System Audit Policy Changed - 22 alerts

Combed the LEM documentation, couldn't find a clue (it might be ind documentation somewhere, I couldn't find it after an hour of digging) This morning I got 22 TriGeo alerts in this pattern: system...

View Article

Possible to monitor disk space remaining?

I'm currently using EventSentry to alert me if drives on Windows 2008/2012 virtual machines are running below 5% available space. Can I use LEM to replace EventSentry?

View Article


MSSQL Audit from remote MSSQL server problem

Hi,before I describe my problem, this is my environment:1 VM that runs SQL Server 2008R2 (from which I need to collect log)1 VM that runs Solarwinds LEM Manager appliance1 VM that runs SQL Profiler,...

View Article

MSSQL Auditor - Won't start with domain user

Hello, I'm fairly new to the MSSQL Auditor and I'm trying to get it working.  I had it working with just a single server and I wanted to expand that server to monitor others.  I added the other servers...

View Article

Does LEM work with Panda Cloud Antivirus (Paid Version) and Informix DB 6.1

Hi all, I am wondering if anyone with more extensive experience with LEM have managed to or knows how to get LEM to work with Panda Cloud Antivirus and Informix DB 6.1. Any response is very much...

View Article
Browsing all 5911 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>