Security Compliance

SEM - Common support issues and resolutions

This article lists several support issues encountered with SEM, and applicable resolutions.

First published date

10/10/2018 1:41 PM

Last published date

6/3/2019 5:09 PM

Overview

The following are the most common issues encountered in Security Event Manager (formerly Log & Event Manager)

  • Getting past Windows SMB/CIFS mount errors.
  • How to create, validate, and test Rules.
  • Setting up connectors in SEM. 
  • Getting Agents to connect with the SEM.
  • How can I create and use my own CA certificate.
  • How do I install and configure the reports application.
  • Using nDepth searches to find information.
  • Connecting the Web console to the SEM.
  • Understanding the difference in events between nDepth searches and Reports console.
  • Performance issues caused by improper configuration settings.

Product section

Security Event Manager

Resolution

How to create, validate, and test rules

Because of the way SEM can react to specific events real-time traffic and fire rules to cause a specified action, a greater level of caution is needed when configuring rules.

Setting up connectors in SEM to receive syslog events 

SEM has over 500 different connectors to receive log data from most common network devices and logs on a computer with the SEM Agent installed. The syslog can be confusing because log data is sent to a standard Syslog-NG application in SEM. Avoid sending the wrong data to the right connector, or the right data to the wrong connector.

Getting Agents to connect with SEM 

Agents are used to collect data on Windows, Linux and Unix computers, because Agents can handle a greater volume of traffic when the client computer requires it. Client computers are not always able to access SEM directly because of network routing and host firewall restrictions.

How to create and use a CA certificate 

SEM has it's own self-signed certificates, but if a higher level of security is needed, a CA-signed certificate is required. Contact support for details. Here are some articles that help describe the certificate process.

How do I install and configure the reports application 

The SEM reports application is a separate application that helps you satisfy auditing requirements, and provide detailed information about collected log data. Reports requires the additional installation of Crystal Reports 11 (runtime), and can also be configured to collect/transfer the data securely across the network.

Using nDepth search to find information 

Connecting the Web console to SEM 

Changes in browser security settings, use of proxy servers, and basic limitations in the volume of traffic that a browser can handle, will contribute to viewing the SEM console.

Understanding the difference in events between nDepth searches and the Reports console 

Understanding Windows events is a challenge by itself, and combining all other types of events from all other vendors is a far greater challenge. We are working on providing more information in this area.

Performance issues caused by improper configuration settings 

A properly configured SEM can handle up to 200 million events per day, or 2,000 EPS (events per second). Conversely, limiting the 'reservations' (appropriate CPU and RAM) will result in poor performance and instability.