Security Compliance

Reconnect a SEM agent

This article describes what you can do when a SEM agent gets disconnected and the service is still running on the client machine.

First published date

11/29/2018 10:55 PM

Last published date

5/14/2019 2:18 PM

Overview

This article describes what you can do when a Security Event Manager (formerly Log & Event Manager) agent gets disconnected and the service is still running on the client machine.

Product section

Security Event Manager

Resolution

  1. Remote into the client machine where the agent is installed.
  2. Launch Services.msc.
  3. Stop the Solarwinds SEM Agent Service.
  4. Navigate to C:/Windows/SysWow64/ContegoSpop/spop.
  5. Delete all six files, but not the folders.
  6. Navigate back to Services.msc.
  7. Start the SolarWinds SEM Agent Service.
  8. All six files could now be recreated in C:/Windows/SysWow64/ContegoSpop/spop. You will now see a new node connected in the SEM Console.
  9. Delete the disconnected agent node.