I am new to LEM which seems to have a bit of a steep learning curve. I have watched the videos and gone through parts of the Administrators guide but am still having trouble understanding several aspects of the product such as the following...
- Advanced LEM architecture for long term retention of Syslog data
- Setting up a separate LEM syslog server
- Setting up a separate LEM database server
- How to tell what the different tools/connectors are actually watching for
- How to tell what different alerts do
- Many of the Alerts that can be used in the Correlations section of the rules are not clear to me as to what they are looking for
- For example I can put TCPPortScan as a Correlation for a rule but I have no idea to tell what will actually match this or what it's looking for
- How to make any syslogs that are forwarded to LEM viewable and searchable in the LEM dashboard
I imagine this stuff is documented and I just haven't found it yet; however, I have a very short period of time to come up to speed and evaluate the product for a possible service offering that our company is putting together for Log management so any help would be much appreciated!
P.S. If the service offering comes together as we would like I imagine we could be purchasing a lot of LEM in the future. 