Security Compliance
SEM - Common support issues and resolutions
This article lists several support issues encountered with SEM, and applicable resolutions.
First published date
Last published date
Overview
The following are the most common issues encountered in Security Event Manager (formerly Log & Event Manager)
- Getting past Windows SMB/CIFS mount errors.
- How to create, validate, and test Rules.
- Setting up connectors in SEM.
- Getting Agents to connect with the SEM.
- How can I create and use my own CA certificate.
- How do I install and configure the reports application.
- Using nDepth searches to find information.
- Connecting the Web console to the SEM.
- Understanding the difference in events between nDepth searches and Reports console.
- Performance issues caused by improper configuration settings.
Product section
Resolution
How to create, validate, and test rules
Because of the way SEM can react to specific events real-time traffic and fire rules to cause a specified action, a greater level of caution is needed when configuring rules.
- Cloning rules
- Add rules
- Test, enable, and disable rules in SEM
- SEM Rule for when users connect to a specific website
Setting up connectors in SEM to receive syslog events
SEM has over 500 different connectors to receive log data from most common network devices and logs on a computer with the SEM Agent installed. The syslog can be confusing because log data is sent to a standard Syslog-NG application in SEM. Avoid sending the wrong data to the right connector, or the right data to the wrong connector.
Getting Agents to connect with SEM
Agents are used to collect data on Windows, Linux and Unix computers, because Agents can handle a greater volume of traffic when the client computer requires it. Client computers are not always able to access SEM directly because of network routing and host firewall restrictions.
- Remote Agent Installer is hanging or failing to install on specific hosts
- Some agent nodes are duplicated and show as a non-agent node
- Troubleshoot SEM Agents and network devices
How to create and use a CA certificate
SEM has it's own self-signed certificates, but if a higher level of security is needed, a CA-signed certificate is required. Contact support for details. Here are some articles that help describe the certificate process.
How do I install and configure the reports application
The SEM reports application is a separate application that helps you satisfy auditing requirements, and provide detailed information about collected log data. Reports requires the additional installation of Crystal Reports 11 (runtime), and can also be configured to collect/transfer the data securely across the network.- Install the SEM reports application
- Setting up the SEM reports application
- Troubleshoot the SEM reports application
- Error -2147189176 when running a SEM report
Using nDepth search to find information
- About SEM nDepth search
- Manage nDepth search queries: Save, schedule, run on-demand, and more
- Send Filters to nDepth for Historical Search
- nDepth searches are slow or return a timeout error before finishing
- nDepth Error: Search ended prematurely
Connecting the Web console to SEM
Changes in browser security settings, use of proxy servers, and basic limitations in the volume of traffic that a browser can handle, will contribute to viewing the SEM console.
- SEM Console Takes a Long Time to Log in Using Internet Explorer 11
- No events in SEM Console
- Flex Error #1001 in Web Console after upgrading SEM appliance
- Locked out of SEM and how to reset the admin password
Understanding the difference in events between nDepth searches and the Reports console
Understanding Windows events is a challenge by itself, and combining all other types of events from all other vendors is a far greater challenge. We are working on providing more information in this area.
- Audit Policies and Best Practices for SEM
- Configure SEM to monitor files for unauthorized changes (FIM)
- Enable File Auditing in Windows
- Monitor software installation and uninstallation events
- SEM detecting incorrect event types or not parsing events properly
- SEM Administrator Guide
Performance issues caused by improper configuration settings
A properly configured SEM can handle up to 200 million events per day, or 2,000 EPS (events per second). Conversely, limiting the 'reservations' (appropriate CPU and RAM) will result in poor performance and instability.