Security Compliance

How to collect various SEM Logs

This article provides a brief overview of how to collect various types of Security and Event Manager (SEM) logs, including Appliance, Windows and Linux agent and report Console logs

First published date

10/30/2018 8:20 PM

Last published date

1/6/2022 2:38 PM

Overview

This article provides steps on  how to collect various log types in SEM Security Event Manager (formerly Log & Event Manager. Based on the type of problem you are facing, support might ask you to provide a one of the following logs or a combination after re-producing the steps.
  • SEM Appliance
  • Windows Agent
  • Linux/Unix agent
  • Reports console

Product section

Security Event Manager

Cause

NA

Resolution

1. When troubleshooting SEM Agent related issues upload the Agent + SEM appliance logs together.

  • Windows Agent with SEM 6.3.1 HF1 and below
    • Get the spoplog.txt file located under C:\windows\syswow64\ContegoSPOP\
  • Windows Agent with SEM 6.3.1 HF2 and above
  1. Log into the Agent Node and Locate the file C:\windows\syswow64\ContegoSPOP\collectLogs.bat
  2. Right-click and select runas-administrator.
  3. Grab the resultant file created C:\windows\syswow64\ContegoSPOP\semAgentLogs.cab and send to support.
  • Linux / Unix Agents
    • Get the most recent spoplog.txt file located under
      • Linux/Unix: /usr/local/contego/ContegoSPOP/
      • Mac: /Applications/TriGeoAgent/
2. Solarwinds SEM Reports Console Logs
  • When troubleshooting any Solarwinds SEM reports related issues, enable Reports console logging as per steps below sample and reproduce the issue with few different reports and share Report Logs + SEM Appliance logs.
  • Enable logging for SEM Reports:
    1. Right-click the Reports Console icon and select Properties.
    2. On the Shortcut tab, add /L at the end of the Target field. For example:
      C:\Program Files (x86)\SolarWinds Log and Event Manager Reports\SWSEMReports.exe /L
    3. Reproduce the issue with few reports that are failing and share the below logs and SEM appliance logs (see below) to support
    • C:\Program Files (x86)\SolarWinds Log and Event Manager Reports\SWSEMReports.log
    • C:\Program Files (x86)\SolarWinds Log and Event Manager Reports\crystaljrc.log
3. Solarwinds SEM Appliance Logs 
Starting with SEM version 2019.4 and higher, you can download Appliance debug logs with one click. To Learn more Click here.

To get the logs old way:
  1. Connect to your SolarWinds SEM via SSH tool like putty - you must have your "cmc" user password of your SEM/SIEM appliance and IP address or hostname. If connecting via VMware/Hyper-v console directly to your SolarWinds SEM, you do not need the cmc password.
  2. If using SSH, you must connect on Port 32022 / 22. Log in with the username of cmc and the password.
  3. Type manager, and then press Enter. This takes you to the manager sub-menu.
  4. Type debug, and then press Enter. This starts the debug script.
  5. Follow the prompts to either e-mail the debug to yourself or save on network share and then forward it to SolarWinds Support. (network share example \\192.168.1.1\c$) You will need a domain, username and password that have to write privileges at the network share location.
  • If the debug files are under 10 MB, please attach them to your reply to the ticket. This will ensure that they are connected to your support case and the rep is notified immediately.
  • If the log bundle is more than 10 MB, you can contact support for upload instructions if you don't already have an SFTP upload link when you created the ticket.

  • Support reps are not automatically notified that diagnostics are already available, which might cause a delay in troubleshooting. So, a quick email to confirm logs have been uploaded and you are waiting on support.