Quantcast
Channel: THWACK: Popular Discussions - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5911 articles
Browse latest View live

Creating a Custom Filtered Report

Hello, After reading this article SolarWinds Knowledge Base :: Creating a Custom Filtered Report have a feeling that LEM report is not strong side of Solarwind. Few thing i didnt like:1) Quote: "Note:...

View Article


LEM Report/Alert for Cisco ASA VPN Usage

We would like to create a report for VPN logins/logouts and also have a real time alert for when someone is logged in or out.  The device is a Cisco ASA.  Any help on whether this is possible or not...

View Article


LEM Log Retention settings

Hi All, How can I check LEM log retention settings? I've already read some discussion about this and learned that LEM is configured to automatically purge the oldest logs, but how can I check if our...

View Article

LEM - Log Retention

I recently purchased LEM50.  I have two groups of servers sending events to LEM.  Some require 90 day retention and some require 13 months retention.  It appears that my only option is to retain all...

View Article

Distributed architecture?

Does LEM support any form of distributed architecture that would allow you to have collectors at different locations and/or networks where the data is then rolled up into a single interface for...

View Article


LEM -- add new node

Hello, I have installed LEM v 5.7.0 for testing.   As a first step, I am trying to add a new node (Cisco router) but it's failing. I have configured the router to send syslog and I can see the packets...

View Article

LEM Group Filters I Don't See

I've been using LEM for a while now and have a good number of alerts successfully built, so I am getting fairly comfortable with everything.  One thing I have not been able to figure out is why I don't...

View Article

I can not get my SWLEMReports.exe to run.

When I try to run my Reports 6.0 I get error msg: "The Crystal Reports run-time engine is missing" and  sometimes, "cslibu-2-0-0.dll missing".   Uninstalled, Re-ran ReportsAndCrystal.exe, deleted dir,...

View Article


Collecting Logs for DHCP Server Configuration Changes

Hey all,I'm setting up Log & Event Manager for the first time and I can't seem to figure out how to properly collect the logs I want from a windows DHCP server. I want to be able to collect the...

View Article


New Log & Event Manager (LEM) Library & Support Page!

We've updated the Log & Event Manager (LEM) - Updated September 16, 2014 support page.  This serves as a one-stop shop for all your LEM documentation, how-to's, troubleshooting, and more.  You can...

View Article

LEM agent question

Does the spop.conf query its info directly from a file on the LEM box?  For some reason when installing the agent on a brand new machine the spop.conf is populating with the old appliance IP address....

View Article

snort output server setup

I have a physical snort box, and I am trying to get it to send logs to my SolarWinds LEM, I set it to the output to the IP of the SolarWinds LEM but it doesn't pick up anything. I am using OpenSuse...

View Article

Email Notifications How-To

Hey All,Since we haven't had any LEM discussions yet, I thought I'd post a quick how-to on setting up custom notifications. There's a couple of really common use cases for going beyond the out of the...

View Article


FIM is setup. Getting .tmp alerts

I setup the file integrety management (FIM).  However when I setup a directory to monitor I setup  *.zipx files only.  I wanted to be notified when a .zipx file in my directory was deleted.  This...

View Article

Question on "Correlation Time" in LEM Rules

I am trying to understand this section better.  I need to send an email for when I have "host flapping" on an interface.  Problem is, I need to alert on the first log (unique to device and port) but...

View Article


LEM as an alternative to purpose-built AD auditing products (ManageEngine,...

We're a LEM customer and are successfully leveraging it for some basic info now.In tandem, I've been running some trial/demo installations of other products that specifically target the AD/NTFS pieces...

View Article

IIS 6 & 7 logs into LEM

We've tried to configure 3 servers to get IIS to log into the LEM without success. 1 server is running Server 2008 with IIS 7. 2 servers are running Server 2003 with IIS 6. I believe that we have the...

View Article


file audit nt authority

Greetings, I just rolled out SLEM 6.0 (and updated the agents) and turned on the new FIM feature.  In theory this is an awesome thing to have, but it's proving to be useless to me at the moment. Every...

View Article

How do I build my filters in LEM off of a report.

I new to the LEM world and have a buch of question about the app. We are trying to build all of our filter off one of the reports, lets say the Financial  SOX report. How do I import each item in this...

View Article

diskusage stats

Why does disk usage stats say only 50% for Logs/Data (via diskusage command) but it is not retaining the logs older then 2 months? Am I missing something?Partition Disk Usage:        LEM:...

View Article
Browsing all 5911 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>