Security Compliance

Monitor Windows firewall logs in SEM

This article describes how to monitor Windows firewall logs in the SEM Web Console.

First published date

10/17/2018 2:12 PM

Last published date

10/17/2018 2:12 PM

Overview

This article describes how to monitor Windows firewall logs in the Security Event Manager (formerly Log & Event Manager) Web Console.

Product section

Security Event Manager

Resolution

SEM Flash console

  1. Install the SEM agent on the Windows nodes where you want to monitor the Windows firewall.
  2. Configure Windows firewall logging for different operating system by following all Microsoft recommendations.
  3. Verify that you can view the logs in the log files.
  4. Log in to the SEM Web Console.
  5. Go to Manage > Nodes.
  6. Click the target node and then click Connectors.
  7. Search for Windows Firewall and enable that connector.

    The connector is set to monitor C:\Windows\pfirewall.log by default. Change the default value if you have a custom location.

  8. Verify that the connector is started.
HTML5 console (versions 6.6 and newer)
  1. Install the SEM agent on the Windows nodes where you want to monitor the Windows firewall.
  2. Configure Windows firewall logging for different operating system by following all Microsoft recommendations.
  3. Verify that you can view the logs in the log files.
  4. Log in to the SEM Events Console, and then click the Nodes tab.
  5. Select your node, and then click Manage node connectors. 
  6. In the search box, enter Windows firewall.
  7. Select the Windows Firewall connector, and then click Add Connector.
  8. Enter a new name, or maintain the default, and then click Add.
  9. Under Configured connectors, select the connector, and then click Start.

Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.