Get the latest news about SolarWinds Security Event Manager (SEM)
Hi, I'm familiar with the "Continuous Excessive Logon Failure" rule/template. That's great but, I want a little more. What I want to be able to do is create a rule for when a brute force attack is successful. Let's say an account triggered the "Continuous Excessive Logon Failure" rule, repeatedly. So email alerts are sent…
Greetings all, Fairly new to Solarwinds SEM and can't find an answer regarding if the agent can be configure to capture URL from browser workstations? I can't find a specific connector that would indicates it would do this. Any suggestions?
I changed the domain admin password. I am receiving SEM notices like this. This user account: logon failure "inventory\administrator" At: 2022-04-13 01:30:02.0 From: inventory Source Machine: inventory Destination Machine: inventory Destination Account: administrator Reason: unknown user name or bad password. Extraneous…
After looking at the capabilities of USB defender we realized it would not catch all devices including keyboards and mice. On Thwack I have seen comments about the USB Extended connector, but cannot find it anywhere in the SEM. How do I access the USB extended feature?
I am trying to activate SOLARWINDS SEM offline. I have downloaded the license file from the solarwinds customer portal but when i try to activate it on the application it shows an error " License is not for this machine" I have checked the hostname and the machine id to be correct.
Simple question ... but apparently not simple to figure out: How do I create a new group in Live Events? I want to group similar filters together. Thanks,
Hi in SEM how can i find out who has changed SMTP address of AD user? thank you
I am creating a whitelist of USBs and have a few questions. First, almost all of the example rules I have seen only contain SystemStatus.EventInfo = *attached* and do not include SystemStatus.EventInfo = "USB Input" Is there a reason why others have left off these USB alerts? Also when trying to add the USB Input IDs to…
We are trying to get alerts when PowerShell is opened on one of our agent computers, but cannot figure out how to get the alert when the application is opened. Has anyone done this successful and is so how did you do it?
I am trying to get an exported list of my manages nodes in SEM 2021.2.1.
It looks like you're new here. Sign in or register to get started.