Quantcast
Channel: THWACK: Popular Discussions - Security Event Manager (SEM) - Formerly Log & Event Manager
Browsing all 5911 articles
Browse latest View live

Default Filters

My work center is relatively new for the use of LEM.  We are trying to set up an account for the techs to use that is pre-loaded with a set of filters that the administrators prepare for them to be...

View Article


How To Create LEM Reports in Reporting Tool?

I am new to LEM and am curious if it's possible to create your own reports in the reporting applicaiton that comes with LEM and if so, how? Thanks in advance for any help with this.

View Article


Need some help creating an alert

So I had this email enabled alert created before (prior to one of my previous upgrades) and it was working great. However at some point during one of our LEM upgrades the alert appears to have stopped...

View Article

Help with local admin filter

What is the event name if i want to track new/deleted local admin? Would event name NEWGROUPMEMBER with DestinationDomain of "builtin" work? Basically anytime a user is added to the...

View Article

monitor AD group membership changes

All-I have a large number of active directory groups that need to be monitored. the groups in question all have a naming convention of "SG-servername_Support". I want to be able to have an notification...

View Article


Active Directory Disabled accounts

In the "directory service" group for "domain admins", i am seeing accounts which are disabled in the domain.Is there an indicator to show disabled accounts in the group? Are they supposed to show at all?

View Article

Kaspersky Endpoint 10

I am trying to get LEM to monitor our Kaspersky administration server.  I have the Kaspersky Administration Kit connector enabled on the node that is our Kaspersky Administration server. I am not sure...

View Article

Image may be NSFW.
Clik here to view.

Authentication - Unknown User Rule isuue

Hi All, I am new to LEM and have been learning the system for the last week or two, I have searched the internet to find the so;ution to no avail.Anyone can assist me on fixing this issue? How can I...

View Article


Looking for any and all sources for clicks to a specific URL

Suspect URL:click.diversifiedemail.com/  I'm trying to find out what hostnames have been the source of clicks to that URL.  not usernames, that doesn't help me, just hostnames. Any ideas? I've dug...

View Article


LEM: Connector profile setting for Windows Server 2012 and MSSQL 2012

Hi, I am trying to create a connector profile for Windows Server 2012 and MSSQL 2012, below are my requirements:   SQL VersionServer OS2012 R2Windows Server 2012 R2 Standard2012 R2Windows Server 2012...

View Article

Image may be NSFW.
Clik here to view.

Login failed LEM reports

i am trying to get all log messages from the LEM reports. I installed the Reports and Crystal runtime file on my computer which was not a big issue. But everytime i try to add a manager i can"t ping...

View Article

LEM Database

Can you get access to the LEM database to do direct SQL queries?  Ever since upgrading to 5.7 from 5.4 (via 5.6), the reporting has been unusably slow (if it works at all, yes there is a call open but...

View Article

Web Console Access from other subnet

We have downloaded the 30 day trial of LEM and it's working fine when accessed from a workstation in the same subnet (172.27.27.0/24) but from other subnets the console login screen appears but when...

View Article


Alert and Rule Explanations

Hello Thwackies, I am trying to find a document which discusses (and defines) each filter and rule headers to figure out what each one does and the Event Groups they match up with.  Does such a...

View Article

monitor AD group membership changes

All-I have a large number of active directory groups that need to be monitored. the groups in question all have a naming convention of "SG-servername_Support". I want to be able to have an notification...

View Article


Palo Alto config with LEM

Hi All, I'm new to both LEM and PA so looking to make sure I have the correct setup.  I've read the KB article SolarWinds Knowledge Base :: Integrating your Palo Alto Firewall with SolarWinds LEM and...

View Article

IP or Hostname or appliance key

Hello All, I am new to Solarwinds and wanted to know how it recognize the firewall/gateway appliances. For example, there are two firewall appliances behind single public IP. They are sending syslogs...

View Article


LEM with multiple domains

I'm trying to get LEM to resolve the IP addresses to host names.  The problem I'm having is we have two domains xxxx.com and xxxx.net.  When I configure the LEM appliance it only allows the entry of...

View Article

Filters do not export

When I am trying to export a filter it is not downloading to the file location that I request (or anywhere for that matter).  Does the export/import need to be turned on in the virtual appliance or is...

View Article

Log Forwarder Syslog Message Text missing

Guys, I'm running the log forwarder on my Windows 2008 SP2 (not R2) domain controllers and subscribing to many events that I forward to my Kiwi Syslogger running on Windows 2012 R2. From there I have...

View Article
Browsing all 5911 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>