SlideShare une entreprise Scribd logo
1  sur  12
Unraveling the Mysteries of Log
            and Event Management
                                                                    with SolarWinds LEM
                                                                           FEBRUARY 16, 2012



Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
Unraveling the Mysteries . . .
Hosts:
   Gerry Pond – Education & Certification Specialist
   Chris Jeffreys – Sales Engineer


Producer:
   Catherine Jackson




                                                     Are you Certified?
Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
Agenda

 Introductions & Housekeeping

 Best Practices - What and Where to Look

 Capturing Network Activities and Events – Filters

 One-Stop Monitoring – Creating an effective LEM Dashboard

 On-The-Fly Analysis – Event Explorer and nDepth

 Taking Action against Potential Threats – Active and Reactive

 Reporting – Scheduled and Ad Hoc

 Summary and Q&A


Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
Housekeeping
      Today’s content will range from discussion to
       demonstration
              We only have an hour


      Ask questions!!!
              Don’t be afraid to ask deeper questions
              Don’t wait until the end – ask away


      Today’s session is being recorded
              Recorded session on SolarWinds.com
              Slides available on slideshare.com
Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
What to Look for and Where
   Change Management
                   Domain Controllers (DC’s)
                           Change Management Filter
                                   What changes are being made? – Alert Name/EventInfo
                                   Who’s making those changes? – SourceAccount
                                   Are those changes authorized? – Internal Policy




Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
What to Look for and Where (continued)


      Company Policy Violations
              Playing games on company time/equipment

              Installing unauthorized software
                     Individual agents – Process Auditing

              Accessing inappropriate websites
                     Proxy server – WebTraffic




Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
What to Look for and Where (continued)
       Accessing Sensitive Files
               Specific file server(s)
                       FileAuditing




                        ** Data is obtained from logs – LEM does not audit the files themselves **


Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
What to Look for and Where (continued)
       USB Activities
               Servers, Critical Agents, Agents
                       Any alert where ProviderSID = “ *USB* ”




                                                          Copyright © iStockPhoto




Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
What to Look for and Where (continued)
       Unusual spikes in network traffic
               Firewall/Proxy Servers
                       TCP/UDT/WebTrafficAudit alerts




Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
One-Stop Monitoring
  Filters, filters and more filters
     OPS Center Dashboard
Reporting
    Reports Console
            Scheduled reports (including “batch reports)

            Ad Hoc reports

    nDepth
            Export Result Details as a *.csv

            Export *.pdf document of all data and graphs




Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
End of Presentation

Thank you for attending!
To learn more or to download free 30-day
trials of SolarWinds products visit:

www.SolarWinds.com


For Log & Event Manager Support:

Open a ticket via your customer portal
                   or
    call toll-free: 866-668-6064


P.S. Remember to renew your maintenance!!!
Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.

Contenu connexe

Plus de SolarWinds

Plus de SolarWinds (20)

Government Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of ObservabilityGovernment Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of Observability
 
Government and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack ObservabilityGovernment and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack Observability
 
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
 
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsBecoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
 
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsGovernment and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
 
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...
 
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
 
Government and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsGovernment and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT Operations
 
Government and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceGovernment and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application Performance
 
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceGovernment and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid Workforce
 
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
 
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
 
Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion
 
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
 
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning
 
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkGovernment and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your Network
 
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
 
Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges
 
Government and Education Webinar: SQL Server—Indexing for Performance
Government and Education Webinar: SQL Server—Indexing for PerformanceGovernment and Education Webinar: SQL Server—Indexing for Performance
Government and Education Webinar: SQL Server—Indexing for Performance
 
Government Webinar: Monitoring Azure and Deploying SolarWinds on Azure Govern...
Government Webinar: Monitoring Azure and Deploying SolarWinds on Azure Govern...Government Webinar: Monitoring Azure and Deploying SolarWinds on Azure Govern...
Government Webinar: Monitoring Azure and Deploying SolarWinds on Azure Govern...
 

Dernier

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Dernier (20)

2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 

Unraveling the Mysteries of Log & Event Management: Advanced Training

  • 1. Unraveling the Mysteries of Log and Event Management with SolarWinds LEM FEBRUARY 16, 2012 Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
  • 2. Unraveling the Mysteries . . . Hosts: Gerry Pond – Education & Certification Specialist Chris Jeffreys – Sales Engineer Producer: Catherine Jackson Are you Certified? Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
  • 3. Agenda  Introductions & Housekeeping  Best Practices - What and Where to Look  Capturing Network Activities and Events – Filters  One-Stop Monitoring – Creating an effective LEM Dashboard  On-The-Fly Analysis – Event Explorer and nDepth  Taking Action against Potential Threats – Active and Reactive  Reporting – Scheduled and Ad Hoc  Summary and Q&A Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
  • 4. Housekeeping  Today’s content will range from discussion to demonstration  We only have an hour  Ask questions!!!  Don’t be afraid to ask deeper questions  Don’t wait until the end – ask away  Today’s session is being recorded  Recorded session on SolarWinds.com  Slides available on slideshare.com Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
  • 5. What to Look for and Where  Change Management  Domain Controllers (DC’s)  Change Management Filter  What changes are being made? – Alert Name/EventInfo  Who’s making those changes? – SourceAccount  Are those changes authorized? – Internal Policy Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
  • 6. What to Look for and Where (continued)  Company Policy Violations  Playing games on company time/equipment  Installing unauthorized software  Individual agents – Process Auditing  Accessing inappropriate websites  Proxy server – WebTraffic Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
  • 7. What to Look for and Where (continued)  Accessing Sensitive Files  Specific file server(s)  FileAuditing ** Data is obtained from logs – LEM does not audit the files themselves ** Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
  • 8. What to Look for and Where (continued)  USB Activities  Servers, Critical Agents, Agents  Any alert where ProviderSID = “ *USB* ” Copyright © iStockPhoto Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
  • 9. What to Look for and Where (continued)  Unusual spikes in network traffic  Firewall/Proxy Servers  TCP/UDT/WebTrafficAudit alerts Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
  • 10. One-Stop Monitoring  Filters, filters and more filters  OPS Center Dashboard
  • 11. Reporting  Reports Console  Scheduled reports (including “batch reports)  Ad Hoc reports  nDepth  Export Result Details as a *.csv  Export *.pdf document of all data and graphs Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.
  • 12. End of Presentation Thank you for attending! To learn more or to download free 30-day trials of SolarWinds products visit: www.SolarWinds.com For Log & Event Manager Support: Open a ticket via your customer portal or call toll-free: 866-668-6064 P.S. Remember to renew your maintenance!!! Copyright © 2011, SolarWinds Worldwide, LLC. All rights reserved.