Comments
-
Any update on this @"izzy2021"? Bill
-
That was just an example of something we added to the out of box SEM experience. I'm working in the same environment as you. I'm not an ISSO/ISSM but do support the tools they use for satisfying DCSA. Some more examples of added rules: Roxio Secure Burn alert message - Alerts a user to complete all logging requirements…
-
I worked with UX team (Ashley O.) on the SEM interface html5 reporting and ditching the Crystal Reports is one of the best things SEM has going for it now! Bill
-
I understand what you're getting at for the STIGs. What you need to do is identify the windows events you want to filter on and come up with a filter for it which you can create a rule for. Here is some info about priv usage on windows:…
-
That's pretty crafty bob!
-
You can also let it make a graph of the data if you want in add report after you select the data you want. Bill
-
I wonder if it's possible it's not recognized because it was End of LIfe February 4, 2014? Regardless you could do a UnDP for it like like @stuartd said. Bill
-
Usually whenever I've seen this it's because a polling engine is either overloaded or is having issues. This should not happen on a correctly loaded polling engine. You might want to run some tests on the polling engine this happened on. It's possible it would eventually happen with other nodes as well... I suppose unless…
-
So you can add &isNOCView=true too a link to 3rd party page and embed it in a classic view and it'll rotate with the others?
-
Ah I see the name and website part isn't showing or the link... perhaps those aren't being evaluated correctly from changes you made or something is missing.
-
It looks like it's getting all the information for a few of your certs to me. Some of those may not be classical regular certs is my guess.
-
This is an interesting topic. Due to STIG's and 800-53 security controls I get a LOT of events per minute. I'm interested in hearing more about dealing with many events and best ways to use SEM search and reporting features. I worked with UX team on replacement for Crystal Reports. What do you modify in your SEM to assist…
-
Mine are windows machines. I wonder if the fact that they're STIG'd has anything to do with it? Bill
-
Also the source account always seems to be machine account like something hostname$
-
I'm getting these too from multiple detection IP's: UserLogonFailure Logon Failure "\" They're all Kerberos and Logon Process Authz Some are webservers and some are sqlservr.exe in extraneous info field. Bill
-
Would be pretty nice aye!
-
Is this ACS as in Cisco Access Control Server?
-
The UI team is one of the best teams SW has going. By asking us what works and what doesn't it really helps make things better.
-
We we would love any new HTML5 interface reporting at this point. One of the main things I always had to use it for was capacity information that the application just didn't show. The new KPI Widget helps some with this. Bill
-
I haven't figured out private messages yet so ;^} Case # 00732298
-
Thanks Chris! I guessed that was the case but I'm always extra careful with this specific VM. The nice thing it is a VM so worst case I can roll back to snapshot of it or even a Commvault backup if there wasn't a snapshot. Bill
-
You can see why I was a little hesitant at first.
-
Author: Jared Jackson [technicalsupport@solarwinds.com] Recipient: william.eckler@gd-ms.com documentation.solarwinds.com/.../SEM_2020-4-1_Release_Notes.htmBill, I opened the link you sent and it states the same thing I just sent you. You will need to upgrade to 2020.2.2 before you can upgrade to 2020.4.1. Also, if you were…
-
@"Radioteacher" Me too... gate was way before my time really. I'm lucky with one system and the other is offline right now. I'm hoping SEM has nothing to do with this. I'm pretty sure it's a totally different codebase and totally different developers. It seems this may have been done to target specific targets. The DHS…
-
I completely agree... sometimes you don't have a choice with these things. Bill
-
Nice sharing this information... this is what thwack is really good for! You helped save 3 people we know of and probably even more we didn't hear about. Bill
-
In some crazy way if FireEye hadn't noticed the breach they had this could have gone on a lot longer. Of those of us affected it's a drag but geesh if this hadn't been noticed and kept going on just think what it could have meant. This isn't some kid in his basement that did this. It's actually pretty elegant how this APT…
-
Yes me too! We really liked the old platform and from what I hear it's been greatly improved and has many new features now. Bill
-
@"Radioteacher" once again with the best information. The best details of the incident are in: FIREEYE: https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html The github link contains tools/filters to help see the APT. Bill
-
I know it's a little confusing with the different modules. The NTA HF2 isn't the same thing as the hopefully coming soon 2020.2.1 HF 2 for Orion Platform. I don't think it's been released yet. Bill