Tom Endean recently published a review of Log & Event Manager (LEM) 
It is a comprehensive look at LEM, from installation to utilization. The review includes details on the real time analysis and nDepth search features of LEM. It has a couple of fun examples of LEM in action with Active Response:
- Showing LEM catching a user who is playing an unauthorized game at work. LEM terminates the game and scolds the user in an alert window on the offending machine.
- Showing LEM notifying Tom Solarwinds via email that a user has been added to the Domain Admins group.
Check it out, it is well-written and entertaining, with a dash of British Humor. It's also a great intro to LEM.