jhynds ✭✭✭✭✭

Comments

  • Hey, LEM performs health checks on the database at regular intervals (on an hourly basis I think) - these events appear as InternalInfo events. You could build a custom rule based on these events. A disk usage event appears like this within the web console: So, you could build a rule like this to alert if disk usage for…
  • Sorry to hear you are running into issues with SEM. A member of our Support team will be in touch to schedule a WebEx session with both Support and Engineering to determine the root cause. Thanks for bearing with us!
  • Glad to hear the update went will Bill
  • Hi Mike, There should be a connector on your appliance that supports NX-OS logs: If you follow the steps in the guide you attached, but simply apply the above connector, rather than the Cisco PIX & IOS connector mentioned in the guide, LEM should then pickup the Nexus logs. Any problems/questions let me know
  • No such thing as a silly question, only a silly answer Uploading a text file will overwrite the original whitelist, so you should be maintaining a single file. We're currently working on migrating the groups to our new UI, which includes importing and exporting to a CSV rather than the current proprietary format. Phones…
  • You are correct - the best approach is to deploy a new appliance on VMware & then contact Solarwinds Support to assist with migration.
  • The manual activation isn't dependent on the version of LEM you are running, so that shouldn't be an issue. Is there a particular error you are seeing? If you could send me your Unique Machine ID via private message, I can generate another .lic for you incase it's an issue with the file you are currently using.
  • Can you confirm which version of LEM you are running? As Justin said above, it's generally down to the Windows logs themselves but there was a known bug with name resolution in some older versions of LEM, which has been resolved since LEM 6.4 Hotfix 7 and later.
  • Hi Justin, The Windows Security connector does capture the 5140 event ID, however they are not mapped to the ObjectAuditFailure event name. Could you please raise a support ticket & provide them with a log sample - we can adjust the connector to correct the mapping for you. Jamie
  • Happy to announce that the Patch Manager catalog now includes Flash PPAPI installers. -Jamie
  • If you have a connector configured to look for syslog data in a particular facility, and matching logs from a new node appear in that facility, the node will automatically be added to LEM. e.g. You've configured the Cisco IOS connector to monitor local2.log for IOS logs. If a number of Cisco IOS devices start transmitting…
  • Moving from LEM forum to Alert Lab.
  • While Windows 10 1809 and Server 2019 are not yet officially supported by Patch Manager, we always do our upmost to support the latest versions of Windows Operating Systems, SCCM and WSUS as quickly as possible. We certainly plan on supporting both of these. I will update the Thwack Community as soon as official support…
  • Can you apply the registry change mentioned here and try to generate again?
  • The LM search functionality is based on SQL Full Text Search, so it is mainly focused on keyword searching without the need for complex query language. Could you give me an example of a complex search you'd typically need to run?
  • I'd recommend raising a ticket with Tech Support to investigate the issue. If you can provide them with the LEM agent logs from that machine, it should point to the root cause. If you ping me the case number once you raise the ticket, I can keep an eye on it for you. 
  • Unfortunately the WSUS Cleanup wizard does not remove declined/not approved updates - I've come across several threads on MS Technet that report this limitation on the WSUS side. WSUS Automated Maintenance​ seems to be a very popular tool to remove obsolete and declined updates, amongst other tasks too. I can't vouch for…
  • Hey Timothy, Firstly, the USB Extended connector is typically used if customers want to detach peripherals like keyboard, mice, etc - so if you just want to detach USB storage devices I would recommend just using the standard USB Defender. - How do I test this on a limited set of machines, while being absolutely SURE it…
  • Hey, Patch v2.1.4 is now available which includes support for Windows Server 2016.
  • Apologies for the delay in getting back to you. Filtering based on Time of Day Sets was an issue in the Flash console, however it been fixes as part of the Events Console. Could you try viewing the filter in the HTML5 Events Console and confirm if your 'non-business hours' filter is working ok? In order to access the HTML5…
  • I'm able to reproduce the issue in my lab, so you may have found a bug. I'll do some investigation and report back to you.
  • SEM 6.7.1 is now available on your Customer Portal and includes a fix for the e-mail alert issue. Apologies for any inconvenience caused as a result of the issue, I understand it was frustrating. Thanks for bearing with us!
  • I would recommend creating a Tech Support ticket in order to resolve the issue. There may be an issue with the user profile where the e-mail alert is being sent, Support should be able to resolve it for you.
  • Hey, Looks like 49.0.1 was released in the Patch Manager catalogue yesterday:
  • I'd recommend opening a support ticket so we can investigate the root case. Can you please send me the Case ID so I can track internally? Thanks!
  • Are the old machines still reporting to WSUS? When you ran the Server Cleanup Wizard did you select the option to delete computers that haven't connected in X days (30 days by default but can be adjusted)? Once those old PC's have been removed from WSUS, it's best to run a WSUS and Patch Manager Inventory task, which…
  • The vCenter connector is designed to monitor flat files such as vpxd.log. There is no vCSA connector available currently, however if you can supply a log sample I can determine the feasibility of building a connector for these logs. If you'd like to send me a direct message, we can discuss further.
  • Hey - some great information in this thread: Patch Manager - Can it be installed on the same server as other Orion modules? Typically, customers would deploy Patch Manager on a separate server to Orion & just install the web console component of Patch Manager on the Orion server. Hope that helps.
  • Generally speaking, packets originate from the interface closest to the destination (SEM), which could explain why the MPLS IP address is the source IP of the syslog messages. Cisco have a command called logging source-interface which allows you to specify which interface the syslog is transmitting from. You could try…
  • There is currently no Patch Manager API available to meet the use case you've described. There is a related Feature Request which you can vote for here: