Documentation forSecurity Event Manager

Install the SEM Agent on Windows

The Windows Agent installer allows you to install SolarWinds Security Event Manager Agents locally on a variety of Windows operating systems. Once installed, the SEM Agent automatically starts and connects to your SEM Manager.

Installer notes

  • The Local Agent Installer is Windows-only.

  • SEM Agents are installed to the following folders:


    Installation Folder





  • A reboot is not required.

Antivirus Recommendations

Set an exception in your antivirus or anti-malware scanning software for the ContegoSPOP folder where the SEM Agent will be installed. The alerts are kept in queue files, which change constantly as they are normalized and encrypted.

Turn off any anti-malware or endpoint protection applications on host systems during the installation process, as they can affect the process by which installation files are transferred to the hosts.

Warning: Uninstall the old version of the SEM Agent before upgrading to the new version.

If you are using a trial version of SEM, download the SEM Agent installer from the SEM console (Configure > Nodes > Add agent node), or contact SolarWinds for assistance.

  1. Download the installer from the SolarWinds Customer Portal. Log in with your SWID if necessary.

  2. Find SEM in the product list, and then select and download the Local Agent Installer from the Agent Downloads list.

  3. Extract the contents of the installer ZIP file to a local or network location.
  4. Run setup.exe, and then click Next to start the installation wizard.
  5. Accept the End User License Agreement if you agree, and then click Next.
  6. Enter the hostname of your SEM Manager in the Manager Name field, and then click Next.
  7. Do not change the default port values.

    Note: Use the fully qualified domain name for your SEM Manager when you deploy SEM Agents on a different domain. For example, enter

  8. Confirm the Manager Communication settings, and then click Next.
  9. Specify whether or not you want to install USB-Defender with the SEM Agent, and then click Next. The installer includes USB-Defender by default. To omit this from the installation, Clear the Install USB-Defender box.

    Note: We recommend installing USB-Defender on every system. USB-Defender will never detach a USB device unless you have explicitly enabled a rule to do so. By default, USB-Defender simply generates alerts for USB mass storage devices attached to your SEM Agents.

  10. Confirm the settings on the Pre-Installation Summary, and then click Install.
  11. Once the installer finishes, it will start the SEM Agent service when you click Next.
  12. Inspect the Agent Log for any errors, and then click Next.
  13. Click Done to exit the installer.

The SEM Agent continuously runs on your computer unless you uninstall or manually stop it. It begins sending alerts to your SEM Manager immediately.

In installations of SEM 6.7 and newer, corresponding agent versions communicate by default using a secure certificate, which no longer requires TLS 1.0, 3DES, or anonymous cipher. If you need to connect to earlier agent versions, navigate to the SEM Console security tab (Settings > Security), and switch the toggle button to enable lower security settings.