Configure user-defined groups in LEM
User-defined groups contain values relevant to your IT environment, such as user and computer names, sensitive file locations, trusted IP addresses, and so on. Like other groups, they contain information that you can use in rules and filters. This topic provides steps to add and edit values in user-defined groups. You can also create rules that auto-populate user-defined groups with values. See Auto-populate user-defined groups using a LEM rule for details.
If Active Directory is available, use directory service groups to add user and computer accounts to rules and filters. A user-defined group cannot be synchronized with Active Directory, but a directory service group can synchronize with Active Directory every five minutes. See Configure directory service groups in LEM for details.
How rules and filters use user-defined groups
Following are a few rules that depend on user-defined groups:
- A rule that stops LEM from blocking accounts in a user-defined group of trusted administrator accounts.
- A second rule that sends out an alert when an account in the same user-defined group of trusted admin accounts logs in or makes changes.
- A rule that checks a user-defined group containing trusted IP addresses to see if it should block a certain IP address.
Rules and filters typically make use of user-defined groups in slightly different ways:
- In a rule, user-defined groups are typically used like a white list or black list that tell LEM which events it should include or ignore.
- In a filter, user-defined groups limit the scope of the filter to items that belong to the group.
Rules that use user-defined groups include:
- Authentication - Unknown User
- Critical Account Logon Failures
- Detach Unauthorized USB Devices
- File Audit - Delete Sensitive Files
- Non-Admin Server Logon
- Vendor - Unauthorized Server Logon
Filters that use user-defined groups include:
Admin Account Authentication
Domain Controllers (all)
The Domain Controllers (all) filter uses a connector profile in the constant position by default. You can replace the profile with a user-defined group or a directory service group if the tool profile is not sufficient for your environment. For additional information about connector profiles, see Create connector profiles to manage and monitor LEM Agents.
See Add a new group or Edit a group to get started adding or editing a group. You can create as many user-defined groups as you need to support your rules and filters. Well-planned groups provide flexibility.
You can only add a group to one LEM Manager at a time. To copy a group for use with another LEM Manager, export the group and then import it into the other Manager's Groups grid. See Export a group for steps.
The following image shows the user-defined group form. The form lists the elements that are configured for the group.
The following table describes how to configure the form fields for user-defined groups.
|Name||Enter a name for the group.|
|Description||Briefly describe the purpose of the group.|
Click the Manager drop-down list and select the Manager that will host the group.
If you are editing an existing group, this field displays the hosting Manager.
|Click at the bottom of the form to add an element to the group. When you finish entering values, click Save at the bottom of the Element Details form.|
|Click to remove an element from the group.|
Name – The name of the data element.
Data – The specific element that you want to include or ignore in your rules and filters. You can use an asterisk (*) as a wild card to include all similar data elements.
Description – A description of the element and its intended use.
|Save||Click Save in the lower-right corner to make your group changes permanent.|
Customize the blank and sample user-defined groups included with LEM
SolarWinds recommends customizing the following blank and sample user-defined groups for your environment:
- Admin accounts
- Admin groups
- Approved DNS servers
- Authorized USB devices
- Authorized VPN users
- Sensitive files
- Service accounts
- Suspicious external machines
- Suspicious local machines
- Trusted IPs
- Trusted server sites
- Vendor and contractor accounts
- Vendor-authorized servers
The Admin Accounts group is used in several template rules as a placeholder for a custom list of administrative users. This group represents the default administrative accounts in Windows and Unix/Linux environments. SolarWinds recommends that you clone this group before you customize it so that you can use it in both capacities. See Clone a group for more information.
Customize user-defined groups
SolarWinds recommends cloning any group that contains a default or suggested value before you alter it. This practice ensures that you have a backup of the default group should you need it later. See Clone a group for more information.
Complete the following procedure to customize any or all the user-defined groups listed above.
On the LEM toolbar, navigate to Build > Groups.
Locate the group you want to edit.
Use the search box or Type menu on the Refine Results pane, if necessary.
Next to the group, click , and then select Edit.
If you want to clone the group, select Clone instead, and then repeat this step for the cloned group.
Add an element to the group.
Click Add Element, denoted by at the bottom of the details pane.
In the Name field, enter a nickname for the element. This value is for reference only.
In the Data field, enter a value to define the element (required). Consider using wildcard characters, such as asterisks (*), to abbreviate these entries as illustrated in the example at the end of this procedure.
In the Description field, enter a description (Optional).
To modify an element, click the element in the details grid, and then modify it in the Element Details form just as you would when adding a new element.
To remove an element, click the element in the details grid, and then click Remove Element, denoted by at the bottom of the details pane.
- If you are finished editing the group, click Save.
Use the pre-populated user-defined groups as examples of what your custom groups might look like. The Data field is used for the correlation, while the Name field is for reference, and the Description is optional.
The following is an excerpt from the default Admin Groups User-Defined Group:
Group Name: Admin Groups
|Backup Operators||*backup oper*|