Security Compliance

SEM reboot for troubleshooting

This article provides guidance about when to reboot SEM. Rebooting SEM rarely fixes problems, but it can delay figuring out why a reboot was needed to begin with.

First published date

10/12/2018 7:28 PM

Last published date

3/28/2019 5:25 PM

Overview

This article provides brief information on rebooting Security Event Manager (formerly Log & Event Manager) for troubleshooting.

Product section

Security Event Manager

Cause

  1. Sudden burst of events
  2. Low resource allocation.
  3. Mis-configured rules / Alerts
  4. Underlying Infrastructure issues

Resolution

SEM is a Linux-based hardened-appliance that has been virtualized. Common misconception: Rebooting SEM fixes issues.


Fact: A reboot rarely fixes any problem, but may delay getting to the cause for why the reboot was considered.


A reboot will do the following:

  1. Clear out cached log data.
  2. Re-connect all agents after it starts up.

A reboot may be required when all other troubleshooting has failed, or recommended by SolarWinds Support.

Otherwise, if you changed the hostname, changed the network configurations, or imported a "backupconfig" (used for migrating to different VM platform, disaster recovery testing, or to restore the rules/groups).