Submit a ticketCall us

Training ClassThe Orion® Platform Instructor-led Classes

Provided by SolarWinds® Academy, these trainings will introduce users to the Orion Platform and its features, management, and navigation. These courses are suitable for users looking to discover new tips, tricks, and ways to adapt their Orion products to better suit their monitoring needs:
Deploying the Orion Platform
Configuring Orion views, maps, and accounts
Configuring Orion alerts and reports

Reserve your seat.

Home > Success Center > Log & Event Manager (LEM) > LEM - Knowledgebase Articles > Prevent LEM agent from collecting Windows Application, Security, and System logs

Prevent LEM agent from collecting Windows Application, Security, and System logs

Updated April 27, 2018


By default, the LEM Windows agent will deploy with connectors to read the Windows Application, Security, and System logs. If you do not want to monitor one or more of these logs, see the Resolution below.


  • LEM all versions
  • Agents deployed to Windows hosts


Connectors for Windows Application, Security, and System are installed by default


This is the default and expected behavior. If you wish to stop reading one or more of these log files from a particular agent, you will need to remove the appropriate connector(s) from that node.


  1. Go to Manage > Nodes.
  2. Locate the Window node you want to alter, click its gear icon, and choose Connectors.
  3. Check the Configured box to see the applicable connectors and locate the connector you wish to remove.
  4. Click its gear icon, choose Stop, click the gear icon again, and choose Delete.


Once the connector is removed, events that go to that log file will no longer be collected by LEM.





Last modified