Comments
-
This is interesting stuff!
-
I came from 2022.2.1
-
I've found, even with Orion, that the Linux agent really makes monitoring linux much easier.
-
This is a good point though since those of us with HCO have all the modules. I'm not there yet but this will be first time I have all the tools in one place. Bill
-
Unfortunately for some of us... the AI is out of the question if you can't connect to AWS or Azure or some other cloud service doing the inference.
-
This really stinks that groups aren't advanced enough to allow node down alert to not alert on nodes in a group??? I can't believe this! Which means going back to what we did in ancient Orion... using custom properties you have to set on every node and using them or keep us posted someone can come up with a generic query…
-
I got this figured out by having it allowed in ZScaler.
-
I figured out how to get this to go away and get past the install tab for SAM by changing advanced setting from x86 to 64bit but after the monitors are installed everything is still red all the time using the correct oracle credentials.
-
Security tools including Chrome browser itself are blocking downloading from PSGallery... is there a better place to download the swis-powershell module in nupkg format for loading in air gapped network? I saw some posts that said just install the OrionSDK.msi to get it? I got v3.2.0.50049 today will that have it in there?…
-
I wonder if you could add an additional webserver to Advanced without buying enterprise-scale?
-
I'd like to know how this works too...
-
Yep I keep my database at around 2.5TB so I can keep enough data to make SEM usable over at least a year. I keep physical RAW logs for windows, linux, and solaris but forward them directly to a NAS for keeping long term ie. now 5 years minimum. Bill
-
Just checked yes it's new feature in 2022.4: Export nodes * All or selected node information can be exported as a CSV file on the Configure > Nodes page.
-
I think this feature was added right after 2022.2.1
-
Funny thing I got 3 Nutanix servers that are really re-badged Dell servers and ended up just loading ESXi on them.
-
You guys are good! Bill
-
Luckily we got export/import... before that it was a nightmare trying to standardize filters if you have 10 SEM instances in different places. What I really need are 800-53 security control filters SEM is capable of seeing. It's been a journey to say the least! Bill
-
Add in applying the STIGs to everything and yeah... you get a LOT of logs and yes there is some duplication since the DCs see a lot going on with clients. I've found doing SIEM is a little bit of an art and not completely a science. Even after having for years we get turnover in IA and it means a whole new group needing to…
-
SAM can get expensive. I have two SLX licenses which helps but I totally agree with your comment about how components were... you really need unlimited components to do a lot with SAM. Bill
-
Let us know how this goes... I also am still using SEM on multiple networks and haven't seen this yet. I also can only register offline.
-
Yep and we don't get points when people download what we shared anymore I don't think. I'm ok with the XML but yeah it's harder to read but that's the "cloud" right? Bill
-
I do this and it does work.
-
Seems worth trying to me!
-
SWQL is also a lot safer! We used to all use SQL but that changed a long long time ago. Also like Kevin said... they kept changing how the database was laid out so if we made customizations using SQL upgrades often broke them. Bill
-
Kinda seems like a catch-22. Bill
-
Or even trying to see the newest comments sometimes is confusing... maybe I'm not getting it?
-
Thanks for the tip @"izzy2021"!
-
I've always had good support from SEM team but haven't used recently since June. Actually I've gotten better support from SEM team than Orion support overall. Bill
-
I think it must log locally on the appliance in /var/log somewhere? I think you could configure it to log to itself. This is a workaround mind you. You'll also need the root password for you appliance (which you have to get from support). I may look into this myself later this week now that you brought it up. Bill
-
Also FWIW we use Centrify for logging of full text Privileged Commands which also helps greatly with 2FA for linux and Solaris and also PAM for windows. It essentially give you group policy for Linux and Solaris. I hope to do some integration between Centify and SEM this year. Bill