Security Compliance

SEM Appliance Security Information

The Security Event Manager (formerly Log & Event Manager) is a virtual appliance that is an all-in-one SIEM tool IT and security pros used to simplify detecting and investigating security issues using event log data. The SEM appliance makes use of various methods to secure the event data stored within to prevent tampering and ensure strict compliance.

First published date

10/10/2018 2:08 PM

Last published date

3/15/2023 1:01 AM

Overview

Security Event Manager (formerly Log & Event Manager) is delivered as a virtual appliance with several related security features and functionality. This article lists appliance and console security features that are common information requests from customers.

Product section

Security Event Manager

Cause

N/A

Resolution

  • The Security Event Manager virtual appliance is a hardened Linux operating system. This means we install minimal software, keep it patched regularly with SEM updates, have minimal ports open, and provide the ability for customers to restrict or limit most external access.
  • Customers do not have root access to the operating system, but they can use a limited command shell. OS access via root or other mechanisms is only used by SolarWinds Technical Support under certain circumstances, and EVERY SEM appliance has a different and unique root password that our support team does not know in advance.
  • When making changes to the appliance through the customer command shell, the activity is logged. This log can be reviewed, and changes may also be reviewed in the SEM console and reports application.
  • Access to the command shell requires direct access to the appliance virtual console (via the hypervisor) or SSH access. If a customer is using SSH, they can further restrict access to an acceptable list of IP addresses.
  • Communication to and from the appliance, where technically possible, is encrypted. This includes ALL agent-to-manager (and reverse) communication.
  • Communication to and from the SEM console is encrypted as long as port 8443 is being used. Non-encrypted traffic can be disabled entirely in the appliance command shell.
  • Access to the SEM console uses a set of different roles that can be used for limiting visibility and the ability to make changes within the SEM system. Customers can also use Active Directory user/group integration to ensure no out-of-band users are being used. The SEM data store only supports write access from the internal application using credentials and connection details that are embedded in the application, and are neither editable nor accessible. External access to the database is read-only, and can be limited by IP address by the administrator in the appliance command shell.
  • Activity performed in the console, including changes and access to certain SEM features, is audited. This activity can be reported on or searched for using SEM reports and the SEM console.
  • Installation of third party applications or services inside the SEM appliance is not possible and not supported.