Filter Ratings and Reviews
Filter 92 vetted SolarWinds Security Event Manager (SEM) reviews and ratings
Reviews (1-25 of 30)
Companies can't remove reviews or game the system. Here's why.
October 13, 2020
We have a deployment of SolarWinds SEM that monitors our Windows and Linux servers currently for login attempts across the whole organization. This allows us to see any possible vulnerabilities in real-time.
- It is flexible with a variety of system connectors.
- Setup is easy.
- Monitoring log size and system resources is simple.
- It is a robust product so, not clear out of the box exactly what it can do.
- Agent installs can sometimes need manual removal.
- If you're running an older version of SEM, migrating clients to a new install isn't clear-cut.
December 11, 2020
SolarWinds SEM is currently being used to aggregate all our event logs for our secure on-premises systems into one place for auditing and security purposes. It allows for easier review of security logs and allows for alerting to be created for certain events avoiding a regular manual review of these events.
- Allows alerts to be generated
- Slots into pre-existing Orion system
- Easy to set up and configure
- Online documentation for setup was not great and at points misleading.
December 08, 2020
SolarWinds has been implemented across our network as a systems management platform for server, applications and high value workstations. I assisted it's implementation with the systems that I administer across the region. It allows us to track the health of critical services and to quickly identify and address problems as they occur.
- We use the client on register systems as event forwarders and log collection.
- It enables us to verify the access security to high value workstations and register systems.
- It provides a repository storage for log files so that they do not solely exist on workstations.
- It helps us ensure PCI standards are being maintained and track security risk issues as well as system health.
- Within the scope of my role I have noticed that the client can be problematic during system startup - some of the register systems we use are older and have lower resolution screens. When the client loads it pops up on screen but completely out of scale (to clarify, it may open a window that is 14x14 inches on a screen that only displays 10x10 inches. This is more frustration than a functional problem.
- Automated rollout would be useful but it is outside of my scope in my job to even know if it already has automated install capability.
- The GUI itself is a little clunky and there is somewhat of a learning curve - training is provided to clients however a friendlier interface would be helpful.
October 23, 2020
We are currently using it within our Operations team to monitor events and alert others of security events and anomalies that it detects. I would like to recommend this product to any business needing to increase their security posture and get better alerts and more reliable data to look at to assist with the root cause and security monitoring.
- Automated threat detection
- Log collection
- Live filtering
- Custom rules
- Alerting can be confusing to configure
- The dashboards and widgets look a little old as with all SolarWinds products
- The initial setup can take a lot of time
October 13, 2020
SolarWinds SEM is used in our operational technology infrastructure to collect and analyze logs from critical systems, those that are part of or manage the infrastructure, and also systems themselves such as the control system(s). It is used to identify issues like account failures and unexpected configuration changes, as well as being a general centralized logging system. The only shortcoming is that it would be great if it could be used as a centralized logging system even for devices that do not have log processors. We have a number of devices not yet supported and just to have the logs in would be useful, rather than setting up a separate Syslog server.
- Visualization: the UI is slick and easy to follow.
- Filtering and Sorting: narrowing down logs is powerful.
- Windows event log parsing
- Device support: less common devices do not have drivers. An SDK or generic one to customize would be useful.
- Generic syslog: some standalone syslog solutions without parsing are more powerful just for log analysis.
- Traceability: tracing log events back to the source needs to be done in the older flash UI until implemented in the new UI.
November 04, 2020
We use Solar Winds Security Event Manager (SEM) across our entire organization. It enables our company to monitor and manage events and provide reporting required for PCI and ISO compliance initiatives.
- Brings together security events from multiple system sources.
- Allows IT to review and manage security related events.
- Provides convenient filters/views allowing us to narrow down the data we want to see.
- Some improvements in user documentation could be helpful.
November 12, 2020

We're using SEM on various networks that need to comply with 800-53 security controls under RMF. We have many security technical implementation guides me must follow with many requirements that need to be followed.
- Easy to install virtual appliance
- Out of the box configuration that works with little modification
- Price isn't based on events it's based on monitored nodes
- It may not scale to millions of nodes
- Searches way back in time take a little longer due to compression
- Not many Cons really!
December 09, 2020

SolarWinds Security Event Manager is utilized by the Information Technology department. Individuals on multiple IT teams have email alerts set up to notify them about events that require action. Additionally, the Security Event Manager is also utilized when there is a need to look at the logs to identify the root cause of a problem. For example, user account lockouts at a time the user wasn't in the office. It addresses multiple business problems by letting us know when something requires our attention.
- Easy to utilize--the rules are straightforward and pre-configured. You just have to customize them to fit your environment.
- Great customer service, which is incredibly useful when you want help with better utilizing the SEM.
- Easy and clear filters when looking for specific information without your environment.
- The SEM can be rather slow--an increase in CPU and RAM appeared to fix this problem fairly easily though.
- The SEM has lately required reboots for us fairly often. This is something we are currently working with support to resolve.
- The SEM could release additional graphic options to help better display data to management.
We use SolarWinds security event manager to help provide insight to all of our logs across our organization. It provides a single pane of glass to this information. We’ve had great success and using the dashboards and some of the automated process is that we can put in place.
- Insight to suspicious events.
- Automated response to common issues.
- Reports.
- Interface.
- Reporting.
- Notifications.
December 08, 2020

The Solarwinds SEM is used for our client for 24/7 incident monitoring and reporting. The primary use is for account events, such as lockouts, disablement, and enablement to both user and computer accounts. It really works well in correlation and helps to stick with the audit and compliance. With a user-friendly web interface and automation modules, SolarWinds is an overall excellent cost-effective SIEM product if the intention is just to monitor for security incidents by manually created correlation rules.
- Has a nice user-friendly interface. Some SIEM can be daunting to learn how to use and get acclimated to, but LEM has an intuitive layout and is very easy to pick up and use.
- The logging agent in the source device is really simple to deploy and integrate.
- Monitoring and reporting the account disablement with detail to whoever disabled an account for audit and compliance.
- Some logs are not parsed well, happen to depend on the external log parser tool.
- The update method needs to be made even simpler, auto update would be better.
- The email alert features with SolarWinds will send a large number of emails if the number of alerts email. The duplication of email alerting needs to be reduced.
November 11, 2020

SolarWinds Security Event Manager is used to collect, review, and analyze system logs from servers, workstations, and network devices. Used by one department, it solves the problem of having to go through long log files trying to find and make sense of an event. It also helps with reporting for compliance purposes.
- Graphs showing important events
- First-time setup and addition of new devices is easy and organized
- Performance is excellent
- Reporting could allow for more customization
- Better integration with other products of SolarWinds line
- More alert options
October 25, 2020

It is being used by the outsider IT company who does Level2 and Level3 support. We use it to audit network device logs with it (Palo Alto Firewalls and Juniper switches). Also we use it to audit Active Directory logons. It is easier to keep these logs in a single place.
- Customizable dashboards, where you can see everything you want.
- Easy to set-up connectors.
- Fully customizable event filters.
- Unable to set up some legacy equipment (Zyxel switches).
- Not an easy to product to learn from scratches.
October 02, 2020

We are using SEM to get all logs from any devices to get an overview on what's going on the network. Also, this tool alerts us of suspicious activities.
- Ease of use.
- Good integration with others products.
- Default detection rules.
- Filter easy to understand.
- Better report generation tool could be made (last version is better, but still room for amelioration).
- Mobile app would be very useful (not web, real app).
It addresses the issue of audit requirement by utilizing log consolidation (syslog, traps, windows log). For windows, an agent needs to be deployed. SEM normalizes the data for several fields so that it is easier to locate the specific event from the 10 million events received per day. The GUI is split into two parts. The first part is part of the new GUI which has dashboard, monitor, nodes, rules, groups (limited). The second is the older GUI where the other functions are. I tend to stay in the older GUI unless the function has been moved over to the new GUI. There is a third interface which can be reached by SSHing to the SEM. This allows to us to diagnosis any issues with the SEM.
It is generally used by the security team, but read-only access has been given to the networking and windows team to enable them to search for specific log entries.
It is generally used by the security team, but read-only access has been given to the networking and windows team to enable them to search for specific log entries.
- Parses the logs into several comment fields to make the search easier
- Can scale up to 218 million per day
- For large amount of events, there is an unreasonable amount of CPUs and Memory needed
- Reporting function has not been updated in many years and is very difficult to write
July 21, 2020

Our organization chose to invest in SolarWinds Security Event Manager because we needed a centralized log management and correlation solution that can be quickly and seamlessly integrated into our global infrastructure. It is very easy to provision by simply installing additional modules onto the Solarwinds server and pointing all of the network/systems devices to it. Having log data in one central location has a huge benefit. For example, troubleshooting an issue on a network can now be done by multiple teams where everyone with access to SEM can search the log repository. The live filtering and historical search capabilities make it easy to get the necessary evidence and the time stamp of what the issue is and when it started. The built-in templates are also helpful in analyzing and targeting specific log data.
- Advanced search capabilities across all log data, powered by a quick engine to minimize the delay.
- Built-in or customized templates.
- Alerting capabilities.
- More advanced log correlation mechanisms with better filtering capabilities.
August 17, 2020

It is being used across our Presort division. It allows us to monitor daily issues and hiccups so that we can address them from anywhere in the country. With it, I'm able to track my local facility while still traveling to the other facilities in the country. It is a lifesaver when I need to be flexible and have the ability to travel or even stay home.
- Centralized log collection and normalization.
- Automated threat detection and response.
- Integrated compliance reporting tools.
- Auto report sending alerting.
- no training
April 03, 2020

We use SolarWinds SEM to monitor all production systems Canada-wide. Often times when troubleshooting devices or applications from a administrative position or help desk it can be very time consuming to pull logs from each device and filter out what you're looking for. By using the SolarWinds SEM tool you can forward all relevant logs and filter out what you don't want to see, which reduces time spent resolving tickets and helps to better locate those pesky problems.
- Log Filtering
- Alerting
- Monitoring
- SEM does have some efficiency issues, other tools have been able to handle millions of logs per hour but SEM seems to get overloaded quickly.
- The UI is slow to respond after the solution has been running for a while.
- Some of the logic is fairly limited with the UI, maybe they could improve the usability of the UI.
January 31, 2020

SolarWinds Security Event Manager is a log and event manager that we implemented to replace our Cisco MARS appliance. This system is used by our security team to monitor and log events throughout the entire organization. From an alerting point of view, SolarWinds Security Event Manager makes our monitoring simpler and more refined. By allowing us to create and set email alerts on important and critical events, SolarWinds Security Event Manager allows a hands-off approach, so that we don't have to review hundreds of lines of alerts to get the critical information, saving us time and effort.
- Allows log collecting from almost any source of data, using multiple types of authentication and collection (i.e. SNMP, WMI, etc.)
- Allows customization of dashboards per user, so that you can quickly find the information relevant to your position.
- The dashboard and reports use javascript, which can be slow to load.
- To get it up and running was fast, however, to correctly configure proper alerts, you have to spend a ton of time.
November 16, 2019
SolarWinds Security Event Manager is being used by our networking and security team on a daily basis. Often times changes to accounts or to your Microsoft Active directory will be logged, but not alerted. This can lead to a false sense of the current state of your accounts and can make a team "blind" to what is happening inside systems. SolarWinds SEM allows teams to receive emails based on pre defined parameters.
- SolarWinds easily provides the much needed visibily into changes in an Active Directory (AD) environment. Email alerting can be configured to alert a team if an account is locked out, disabled by another users, or if users and/or computers accounts are created.
- SolarWinds allowed a searchable audit feature. Microsoft Windows can be configured to log many different parts of a system, but search those logs can be difficult. SEM allows you to search for specific users or events.
- All SolarWinds product suffer from slow response times in management portals. SolarWinds SEM is no exception. While it is much preferred over a "thick client" there is much room for improvement in speed.
- If you use the email alert features with SolarWinds make sure to prepare you staff and team for the large amount of emails they could receive. Make sure to reduce the number of alerts so your team does not ignore the alerts.
January 15, 2020
It is being used, at this time, only by my department. We use it to collect logs from all our network devices, servers, and other devices we use to support our services. It is useful for us to have all of our logs in a single place and searchable.
- SEM normalizes logs very well. It is simple to be able to compare fields in logs from say a Cisco router and a Windows server, especially timestamps.
- SEM has great flexibility in customizing its various aspects, especially its correlation rules and reports.
- SEM doesn't support out-of-the-box several device manufacturers that are used in my environment. For example, Peplink and Netonix.
- I have to purchase a separate log parser tool rather than having it included in SEM.
December 28, 2019

We are using the Security Event Manager to keep track of a number of things.
Configuration changes for our Core network And campus devices which include nexus and Cisco iOS routers, switches and firewalls. We use it as a way to audit admin login failures. Our Device Syslog is sent to it. We use it to keep analyze network traffic when troubleshooting.
- It does a great job of notifying us when accounts have been locked out. We can then find out the device on the network where the login attempt occurred.
- Searching for incidents is now a lot faster with the implementation of the HTML 5 interface.
- Some aspects have not been fully integrated into HTML 5. Those are still a bit slow to access.
- Need an easier way to upgrade the software. SSH to the console and running the commands to connect to the TFTP server is archaic. Needs an “update” button.
October 09, 2019

We initially started using SolarWinds Security Event Manager(previously Log and Event Manager) to meet a security compliance requirement. Once I spent some time with it, I realized that I could use it for alerting on specific events and activities that our users were interested in. For instance, we used the File Integrity Module on our HR file share to alert the HR manager when files were added or deleted, and then we sent a weekly report to that department with all read/write activity. We also used it to monitor AD changes, and the email alerts were really useful in producing historical information about what changes had been made recently.
- Compared to other SIEMs, it's relatively easy to get up and running. The virtual appliance is easy to maintain.
- Support was top notch. The support team really knows their stuff when you run into an issue.
- The email alert system is easy to use and attach to a fired rule.
- Compared to other SIEMs, there are features that are missing. Machine learning, automatic event correlation, ability to correlate multiple sources together.
- The UI is clunky, and the *New* event log analyzer page felt really disjointed from the rest of the product.
- In my experience, the dashboards were almost unusable. They persisted across login per device, and even then they sometimes would reset and go back to the ''Getting Started'' look.
We are mostly using it to track logs from our Windows Server. We do also have some networking equipment sending syslog to it as well. Primarily we use it to help track down password lockouts. Its terrible UI doesn't allow for much more than that. It would be nice if there were some nice looking always on dashboard type screens we could use.
- I honestly don't have too many good things to say about it. It was cheap compared to other products like Splunk and that's why we bought it.
- Even though this is like 90X cheaper than other products like Splunk, etc. - It's still overpriced because it's terrible.
- Flash, Java, Really? Who still uses this? Also, why is this not integrated with Orion and useable from the same Solarwinds dashboard as all our other Solarwinds products?
February 04, 2019
As an organization with many types of hardware/software, we needed something to gather logging output using industry standards. We already use SolarWinds for network monitoring so SolarWinds Log & Event Manager (LEM) seemed to fit the bill. We had a vendor assist with the initial installation and configuration. Then it was just a matter of the various teams (Network/MS Server/VM/Unix) to configure their nodes to point to LEM so the data collection could commence.
- SolarWinds LEM has not bogged down with the amount of logging data we throw at it. This is comforting because we can rest assure that we can continue to add new nodes to it.
- The SolarWinds LEM platform is very stable. The main part is the collector appliance and the second part is the reporting server which you can generate either custom or canned reports for regulatory compliance certification.
- When configuring the collectors, you are able to customize the gathering of data to make sure you are getting exactly what you need.
- While the initial setup was straightforward, customizations to reports can be a little daunting. Luckily SolarWinds has videos available on steps to proceed and their tech support reps are very helpful too.
- The frequency of version updates is few and far between. This may be a good thing and should be expected since it is a set it and forget it kind of virtual appliance.
- It would be helpful if SolarWinds LEM had Wizards built-in that could assist in adding new types of devices. At times, I've had to go with trial and error until SolarWinds LEM would actually start collecting data from a particular one-off node.
February 28, 2019
As a Network Monitoring Engineer and instructor, I see many Government and Military IT Organizations choose LEM as their primary Security Event and Incident Manager(SEIM) across all of their networks. LEM allows them to have a consolidated, normalized view of both their server and network environments. Having a consolidated view provides SolarWinds customers with the ability to correlate multiple security events across disparate systems and greatly reduces the amount of time and effort to detect and respond to potential security intrusions.
- One of the most valuable features of SolarWinds LEM is its ability to normalize logs from differing systems into one common format. LEM normalization saves time and effort in doing forensic analysis by letting security personnel see the "whole picture" of their network in one place.
- LEM's Active Response capability makes it easy to watch a security event happen in real time and to take immediate action. For example, LEM can very efficiently allow security personnel to logoff suspect users or even restart important Windows Server processes in real time, before further intrusion can happen.
- LEM has a lot of out of the box features that allow for the quick implementation of security policy across many industries. LEM can provide immediate compliance monitoring and management for standards such as PICA, HIPAA and DISA-STIG.
- The number one challenge for SolarWinds customers I see is LEM's reporting software. LEM Reporter, a standalone Windows Application, is not as intuitive as customers would like and they report some instability in the application itself. Customers tend to use LEM's search scheduling as a more effective way to report on security events.
- Performance has been an issue based on LEM's use of a Flash interface. This has been a limitation for a long time. However, with the transition of the LEM interface from Flash to HTML5, customers are reporting much better performance starting in LEM 6.5
- Every one of my customers makes some comment about LEM's very high learning curve. LEM is not very intuitive, requiring a lot of rote learning through repetition. Many LEM customers request some type of training to help them learn to use it.
SolarWinds Security Event Manager (SEM) Scorecard Summary
Feature Scorecard Summary
What is SolarWinds Security Event Manager (SEM)?
SolarWinds Security Event Manager (previously know as Log & Event Manager) is presented by the vendor as a powerful and award-winning SIEM. It is an on-prem deployed tool that collects, consolidates, and analyzes logs and events from firewalls, IDS/IPS devices
and applications, switches, routers, servers, operating system logs, and other applications.
The main applications are threat detection, automated incident analysis and response, and compliance reporting for IT infrastructure.
The main applications are threat detection, automated incident analysis and response, and compliance reporting for IT infrastructure.
Categories: Security Information and Event Management (SIEM)
SolarWinds Security Event Manager (SEM) Screenshots
SolarWinds Security Event Manager (SEM) Video
Security Event Manager - Overview
SolarWinds Security Event Manager (SEM) Downloadables
SolarWinds Security Event Manager (SEM) Competitors
Splunk Enterprise Security, LogRhythm NextGen SIEM Platform, ManageEngine EventLog Analyzer
SolarWinds Security Event Manager (SEM) Pricing
- Has featureFree Trial Available?Yes
- Does not have featureFree or Freemium Version Available?No
- Does not have featurePremium Consulting/Integration Services Available?No
- Entry-level set up fee?No
SolarWinds Security Event Manager (SEM) Support Options
Free Version | Paid Version | |
---|---|---|
Phone | ||
Forum/Community | ||
FAQ/Knowledgebase | ||
Video Tutorials / Webinar |
SolarWinds Security Event Manager (SEM) Technical Details
Deployment Types: | On-premise |
---|---|
Operating Systems: | Windows |
Mobile Application: | No |