Security Compliance

What can the SEM Agent do when it is disconnected from the SEM Manager

This article discusses the behavior of the SEM Agent when it is disconnected from SEM.

First published date

10/17/2018 5:55 PM

Last published date

10/17/2018 5:55 PM

Overview

When the SolarWinds Security Event Manager Agent service is running, it collects and normalizes log data from its host's operating system and any third party security product it is configured to monitor. When the SEM Agent is connected to a SEM Manager, it sends the normalized log data to the SEM Manager in real time, resulting in a constant, secure, bandwidth-friendly flow of data.

Product section

Security Event Manager

Resolution

When the SEM Agent is not connected to its SEM Manager (for example, when a laptop disconnects from the network), it queues the normalized log data until it is reconnected to the network. The reconnected SEM Agent then sends the queued data to the SEM Manager to be displayed and stored.

 

The major difference is that most rules on the SEM Manager are set to not fire on alerts more than five minutes old, so queued alerts typically won't trigger them. Similarly, when a SEM Agent is not connected to its SEM Manager, its traffic will not trigger any rules in real time either, since the rules, along with their active responses, reside on the SEM Manager, not the SEM Agent.

 

The one exception is when the SEM Agent has the USB Defender Local Policy tool configured. This tool allows SEM administrators to maintain a list of approved users and devices that is stored locally with USB Defender on the SEM Agent. Once in place, the USB Defender Local Policy tool will automatically detach any USB mass storage device that does not match one or the other criterion, regardless of whether the SEM Agent is connected to the SEM Manager.


The maximum size for the agent cache is 500 MB. Once that limit is reached, SEM stops reading logs on that agent. The logs are persisted until transmitted to the SEM appliance.