Submit a ticketCall us

Don’t fall victim to a ransomware attack
Backups are helpful, but sometimes that’s not enough to protect your business against ransomware. At our live webcast we will discuss how to protect against ransomware attacks with SolarWinds® Patch Manager and how to leverage log data to detect ransomware. Register now for our live webcast.

Home > Success Center > Log & Event Manager (LEM) > Enable or Disable Threat Feeds

Enable or Disable Threat Feeds

Table of contents
Created by Erica Gill, last modified by Tim Rush on Jul 07, 2017

Views: 44 Votes: 1 Revisions: 7

Overview

This article describes how to enable  or disable Threat Feeds. LEM (versions 6.2 & newer) introduced the feature of Threat Feeds, which allow recognizing known and proven threats. Rules can make use of this data to automatically take action on Threat Feeds. 

 

Other references:

Environment

LEM 6.2 and newer

Steps

 

  1. Log onto the LEM Web or Air Console.

  2. Click Manage > Appliances.

  3. Go to the Settings tab and select or deselect Allow Log & Event Manager to detect threats based on lists of known malicious IP addresses.
    Enable Threat Feeds

  4. To verify that your Threat Feed is updating every morning, you can run the following nDepth search and look for this recurring event that comes in every morning at 3:14 AM:
    InternalInfo.EventInfo = *threat*

 

 

 

 

 

Last modified
18:26, 6 Jul 2017

Tags

Classifications

Public