Security Compliance
PCI Compliance and Security Event Manager
This article details how SEM can address PCI auditing requirements.
First published date
Last published date
Overview
This article details how Security Event Manager (formerly Log & Event Manager) can address PCI auditing requirements.
Product section
Resolution
SolarWinds Security Information Management in the Payment Card Industry is a SolarWinds whitepaper on how you can use SEM to meet PCI requirements.
Frequently asked questions
Q: Does the SEM virtual appliance support installing an anti-virus client?
A: No. The SEM is a self-contained, hardened Linux virtual appliance which doesn't allow outside software to be installed on it.
Q: Is there a user-configurable firewall on the appliance itself?
A: No. There is a firewall on the Linux OS level, but the OS level is only accessible by SolarWinds Support.
Q: Is it possible to remove data from or delete the SEM database?
A: Being a security appliance used frequently for compliance and auditing reasons, SEM is designed so that it is not possible to remove any part of the database without root access which only SolarWinds Supports has access to.
Q: Can SEM notify me if monitoring stops?
A: Yes, there are several rule templates you can clone and configure that can alert you via email if a SEM Agent goes offline, if there is a database connection issue, etc. Go to Build > Rules, expand Rule Categories & Tags > Devices, and look under Manager for appliance monitoring rules and under Operating Systems for Agent monitoring rules.
SEM is not able to notify you if your devices stop sending syslog events, but you can verify how long it has been since each node in your system sent its most recent event. You will find that in the Node Health widget in the Ops Center.