Documentation forSecurity Event Manager

Get started adding systems and devices to SEM

This section describes how to add Agent devices (servers, domain controllers, and workstations), and non-Agent devices (firewalls, router, and switches) to SEM.

There are two ways to configure computers and devices on your network to send log events to SEM:

  • To add servers, domain controllers, and workstations, install a SEM Agent.
  • To add firewalls, routers, or switches, configure your devices to send log events directly to the SEM VM using syslog or SNMP traps. After configuring your device to log to SEM, configure the appropriate connectors directly on the SEM Manager.

Click the video icon to view a tutorial about adding devices to SEM.

About the SEM Agent

Install the SEM Agent on servers, domain controllers, and workstations to monitor local events on the systems in your network. The SEM Agent is a stand-alone service that collects and normalizes log data on the remote system before it is sent to the SEM Manager for processing.

See Install SEM Agents to protect servers, domain controllers, and workstations in the SEM Installation Guide for installation steps.

SEM Agents can:

  • Capture events in real time.
  • Encrypt and compress the data for efficient and secure transmission to the SEM Manager.
  • Buffer the events locally if the Agent loses network connectivity to the SEM Manager.

In addition to monitoring local events, the Agent provides event alerting on workstations and servers. It is also required for some active responses, including logging off a user, shutting down a computer, and detaching a USB device. You can trigger actions manually from the SEM console using the Respond menu, or you can create rules to take specific actions automatically.

Install the SEM Agent on computers that allow third-party software, including servers, domain controllers, and workstations. On Windows, the SEM Agent captures log information from sources such as Windows Event Logs, a variety of database logs, and local anti-virus logs.

SolarWinds recommends installing the SEM Agent if you have the option. If installing the SEM Agent is not feasible, send log events directly to SEM.

About sending log events directly to SEM

Configure non-Agent devices, such as firewalls, routers, or switches, to send log events directly to the SEM Manager using syslog or SNMP traps. Then, configure the appropriate device connector on the SEM Manager using the SEM console. For a complete list of supported devices, see the SEM Connector List on THWACK.

See Add syslog and agent nodes to SEM for more information about configuring devices that do not allow third-party software.