Comments
-
Any movement on this?
-
I have a couple of switches pointing to it, but nothing yet. The agents installed on some Windows 2008r2/2012 servers won't pull in anything regarding ports/protocols/services being used by the server or applications? I have some windows servers with IIS, and I would love to see when/who/what is hitting the server from a…
-
Already, may have missed a step somewhere. I did the first portion of the rule: ProcessStart.ImageFile = iexplore.exe And that would be marked as an incident. Well nothing happened. Worked on the 6.0.1 upgrade (which failed, then the next day...everything started working again, odd). Well, now I'm on 6.0.1, and that rule…
-
This should work. I'll implement it and see what happens. I guess I should have elaborated a bit more earlier....my only focus is on the servers. Admins are the only ones that have access. There should be no browsing from the servers. That's the intent of the check. Browsing from the server is just asking for trouble.
-
Having a similar issue. On Kiwi, see lots of log activity. In LEM, barely see any action.