SolarWinds Security Event Manager (SEM)
Overview
What is SolarWinds Security Event Manager (SEM)?
SolarWinds LEM is security information and event management (SIEM) software.
Easy to install and easy to use
SolarWinds SEM helps system administrator analyze issues on network and server
Set-and-Forget with as needed functionality
SEM - a great product that's even better if you can dedicate the time to learn it.
SEM - Powerful and Affordable
Security Event Manager (SEM) - An intuitive and inexpensive product if you need a reliable Syslog manager in a classical network deployment
SEM provides easy, affordable SIEM appliance
SolarWinds SEM is easy to setup and (mostly) manageable
Superior Product, Easy to Implement and Very Reliable!
Easy product for Security Information and Event Management (SIEM)
S-Short E-Effective M-Monitoring Solution!!!
A boring review. It just works.
Log Police - The Best at Logging Events and Collection
Review of SolarWinds Security Event Manager
Great for Continental Enterprises
Awards
Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards
Popular Features
- Centralized event and log data collection (17)8.585%
- Deployment flexibility (17)7.979%
- Event and log normalization/management (17)7.373%
- Custom dashboards and workspaces (16)4.949%
Pricing
What is SolarWinds Security Event Manager (SEM)?
SolarWinds LEM is security information and event management (SIEM) software.
Entry-level set up fee?
- No setup fee
Offerings
- Free Trial
- Free/Freemium Version
- Premium Consulting/Integration Services
Would you like us to let the vendor know that you want pricing?
38 people also want pricing
Alternatives Pricing
What is Microsoft Sentinel?
Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.
What is Sumo Logic?
Sumo Logic is a log management offering from the San Francisco based company of the same name.
Features
Security Information and Event Management (SIEM)
Security Information and Event Management is a category of security software that allows security analysts to look at a more comprehensive view of security logs and events than would be possible by looking at the log files of individual, point security tools
- 8.5Centralized event and log data collection(17) Ratings
Effectiveness of real-time centralized event and log data collection
- 7.6Correlation(14) Ratings
Correlation of logs and events to pinpoint significant threats
- 7.3Event and log normalization/management(17) Ratings
Ability to normalize event syntax so that logs can be compared and are machine-understandable
- 7.9Deployment flexibility(17) Ratings
Ability to tune system to maximize threat detection and minimize false positives
- 7.9Integration with Identity and Access Management Tools(12) Ratings
Integration with access control tools like Active Directory and LDAP
- 4.9Custom dashboards and workspaces(16) Ratings
dashboards that can be customized to meet the needs of specific groups
- 10Host and network-based intrusion detection(3) Ratings
Ability to detect both endpoint intrusion and network ingress detection
Product Details
- About
- Competitors
- Tech Details
- Downloadables
- FAQs
What is SolarWinds Security Event Manager (SEM)?
The main applications are threat detection, automated incident analysis and response, and compliance reporting for IT infrastructure.
SolarWinds Security Event Manager (SEM) Features
Security Information and Event Management (SIEM) Features
- Supported: Centralized event and log data collection
- Supported: Correlation
- Supported: Event and log normalization/management
- Supported: Deployment flexibility
- Supported: Integration with Identity and Access Management Tools
- Supported: Custom dashboards and workspaces
SolarWinds Security Event Manager (SEM) Screenshots
SolarWinds Security Event Manager (SEM) Video
SolarWinds Security Event Manager (SEM) Competitors
SolarWinds Security Event Manager (SEM) Technical Details
Deployment Types | On-premise |
---|---|
Operating Systems | Windows |
Mobile Application | No |
SolarWinds Security Event Manager (SEM) Downloadables
Frequently Asked Questions
Comparisons
Compare with
Reviews and Ratings
(120)Community Insights
- Pros
- Cons
- Recommendations
Easy Configuration Process: Many users have expressed their positive experiences with the configuration process of SolarWinds, noting that it is easy and straightforward. This indicates that the product provides a user-friendly interface for making necessary adjustments, making it convenient for users to set up and customize according to their needs.
Excellent Customer Support: Several reviewers have praised the expertise and effectiveness of SolarWinds' customer support team in resolving issues. They have found the assistance provided by the support team to be valuable in addressing any concerns or difficulties they encountered while using the product.
Efficient Log Collection and Normalization: Users appreciate the centralized log collection and normalization feature offered by SolarWinds. This functionality streamlines the monitoring and analysis process by efficiently collecting logs from various sources and normalizing them into a consistent format. This allows for easier management and analysis of log data, saving users time and effort.
Confusing User Interface: Users have expressed dissatisfaction with the confusing user interface of SolarWinds SEM, which has made tasks difficult to accomplish. Many reviewers have specifically mentioned that they struggled to navigate and understand the UI.
Limited Reporting Capabilities: Users have found the reporting capabilities of SEM to be limited and not intuitive. They have suggested the need for a better report generation tool that offers more flexibility and customization options.
Poor Integration with Other Products: Several users desired better integration between SEM and other products in the SolarWinds line, such as NPM. They mentioned difficulties in achieving seamless integration, which hindered their ability to effectively manage their network infrastructure.
Users have provided several recommendations based on their experiences with SolarWinds Security Event Manager. The three most common recommendations are:
-
It is important to have a detailed plan before deploying the tool. This will help meet expectations and ensure effective usage.
-
Users highly recommend SolarWinds Security Event Manager as a reliable security solution. It provides comprehensive log monitoring and is particularly useful for tracking equipment, communication lines, and backup programming.
-
Before making a decision, users suggest evaluating whether SolarWinds Security Event Manager meets the specific requirements of your company. Consider factors such as company size, data protection needs, scalability, user intuitiveness, ease of installation, and cost-effectiveness.
It's worth noting that while some users find the software easy to use and understand, others mention concerns about its pricing and suggest exploring alternative options like PRTG or OpManager.
Attribute Ratings
Reviews
(1-25 of 26)- quickly find top logon failure user, which is suspect of malware infection
- easily find most visited port on the routers to find possible attack
- SEM traffic type sort report is useful tool to control unnecessary network usage
- wish SEM could update by itself
- Make sense of syslog entries from a variety of sources
- Tarck USB device usage
- Track login attempts, successes and failures
- Easier custom reporting
- Automate alerts when certain thresholds are met
- Easier rule writing
- Categorizing of events in different buckets: Security, IT Operations, Change Management, Authentication, Endpoint Monitoring, Compliance.
- Intuitive configuration via Wizards, with meaningful examples and interactive help.
- The ability to create rules and set up actions for select events, using predefined templates.
- Better integration with npm, rather than being a standalone product.
SolarWinds SEM is easy to setup and (mostly) manageable
- Process Syslog/trap and event messages
- Provides an easily understood dashboard
- easily processes events from agent and non-agent devices
- Reporting uses Crystal Reports which is very limited and not intuitive
- Process for building custom filters needs more in-context help tools
- Log collection
- User-friendly and Easy dashboards
- Queries seeped (according to our size)
- log data parsing is good. if you upgrade some systems, most likely SEM will recognize it
- Agent installations are easy but there are some meaningless steps
- Can be add an advanced reporting process or module
S-Short E-Effective M-Monitoring Solution!!!
- Log collection.
- Graphical representation of collected logs.
- Rules to trigger and send emails for quick identification and monitoring.
- File Integrity Monitoring
- Better UI to search and track logs
- Connectors compatibility issues
A boring review. It just works.
- If any account is Enable/Disable, we get an email.
- If any account is locked out, we get an email.
- As nodes are decommissioned, to be able to export just that one server's data.
Log Police - The Best at Logging Events and Collection
- Customizable event filters
- Awesome user interface
- Easy to configure connectors
- Needs better integration with SolarWinds NPM. This is the only Solarwinds product we use that isn't integrated.
- It needs a more lightweight client.
Review of SolarWinds Security Event Manager
- Collect logs.
- Generate reports.
- Great user interface.
- I would like the client to be more lightweight.
- I would like a mobile app.
Great for Continental Enterprises
- SOC Dashboard
- Compliance Reporting
- Node Health
- User Logon Events Dashboard
- Poor Performance for 10,000+ elements
- Poor Performance for real-time dashboard when over 10K nodes
- Poor database performance for extra large global enterprise
SEM is a good product
- Insight to suspicious events.
- Automated response to common issues.
- Reports.
- Interface.
- Reporting.
- Notifications.
The SolarWinds SEM: Cost effective centralized log management tool that helps your audit and security.
- Has a nice user-friendly interface. Some SIEM can be daunting to learn how to use and get acclimated to, but LEM has an intuitive layout and is very easy to pick up and use.
- The logging agent in the source device is really simple to deploy and integrate.
- Monitoring and reporting the account disablement with detail to whoever disabled an account for audit and compliance.
- Some logs are not parsed well, happen to depend on the external log parser tool.
- The update method needs to be made even simpler, auto update would be better.
- The email alert features with SolarWinds will send a large number of emails if the number of alerts email. The duplication of email alerting needs to be reduced.
SolaWinds SEM--Worth every penny!
- Graphs showing important events
- First-time setup and addition of new devices is easy and organized
- Performance is excellent
- Reporting could allow for more customization
- Better integration with other products of SolarWinds line
- More alert options
SEM - Good product, reasonable price point
- Brings together security events from multiple system sources.
- Allows IT to review and manage security related events.
- Provides convenient filters/views allowing us to narrow down the data we want to see.
- Some improvements in user documentation could be helpful.
SEM review of a SolarWinds fanboy at heart
- Automated threat detection
- Log collection
- Live filtering
- Custom rules
- Alerting can be confusing to configure
- The dashboards and widgets look a little old as with all SolarWinds products
- The initial setup can take a lot of time
Very good product, easy to install!
- Ease of use.
- Good integration with others products.
- Default detection rules.
- Filter easy to understand.
- Better report generation tool could be made (last version is better, but still room for amelioration).
- Mobile app would be very useful (not web, real app).
SoalrWinds SEM - great value
It is generally used by the security team, but read-only access has been given to the networking and windows team to enable them to search for specific log entries.
- Parses the logs into several comment fields to make the search easier
- Can scale up to 218 million per day
- For large amount of events, there is an unreasonable amount of CPUs and Memory needed
- Reporting function has not been updated in many years and is very difficult to write
It is not well suited for reporting, as it is very slow, making it almost unusable. The File Integrity Monitor is a good concept but does not work well in the real world. As it generates multiple events for file delete, create, etc.
Solarwinds working for you again!
- Centralized log collection and normalization.
- Automated threat detection and response.
- Integrated compliance reporting tools.
- Auto report sending alerting.
SolarWinds Security Event Manager: A "log" above everyone else
- Allows log collecting from almost any source of data, using multiple types of authentication and collection (i.e. SNMP, WMI, etc.)
- Allows customization of dashboards per user, so that you can quickly find the information relevant to your position.
- The dashboard and reports use javascript, which can be slow to load.
- To get it up and running was fast, however, to correctly configure proper alerts, you have to spend a ton of time.
- SEM normalizes logs very well. It is simple to be able to compare fields in logs from say a Cisco router and a Windows server, especially timestamps.
- SEM has great flexibility in customizing its various aspects, especially its correlation rules and reports.
- SEM doesn't support out-of-the-box several device manufacturers that are used in my environment. For example, Peplink and Netonix.
- I have to purchase a separate log parser tool rather than having it included in SEM.
SolarWinds LEM: Useful and Low Cost SIEM Solution for SMBs
- Compared to other SIEMs, it's relatively easy to get up and running. The virtual appliance is easy to maintain.
- Support was top notch. The support team really knows their stuff when you run into an issue.
- The email alert system is easy to use and attach to a fired rule.
- Compared to other SIEMs, there are features that are missing. Machine learning, automatic event correlation, ability to correlate multiple sources together.
- The UI is clunky, and the *New* event log analyzer page felt really disjointed from the rest of the product.
- In my experience, the dashboards were almost unusable. They persisted across login per device, and even then they sometimes would reset and go back to the ''Getting Started'' look.
Bigger companies or companies with dedicated security staff will likely look at other options. This seems like an entirely mid-market only purchase. If you want to be able to correlate events from multiple sources, not just agent-based windows logs, you'll likely need to look elsewhere. While you can also forward syslog to the appliance, you can't enrich any data or use sources like NIDS/HIDS logs. This product will not give you a true single pane of glass like some offerings.
SolarWinds Log & Event Manager: Exactly as Advertised
- Monitors account lockouts and reports them with detail so that it is easier to solve this with end users.
- Monitors and reports account disablement with detail to whoever disabled an account, for audit and accountability.
- Also, monitors and reports account enablement with detail to whoever enabled an account, again for audit and accountability.
- Flash-based UI can lag, HTML5 would be preferred
- Availability for custom widgets, but you need a bit of training to get things done right unless you have time for trial and error.
- It only knows what it knows for account lockouts. If a source machine isn't available in the Event Viewer ID that triggers the alert, it does not have any extra tools to help it determine the issue.
LEM, your one stop shop for Security Event and Incident Management!
- One of the most valuable features of SolarWinds LEM is its ability to normalize logs from differing systems into one common format. LEM normalization saves time and effort in doing forensic analysis by letting security personnel see the "whole picture" of their network in one place.
- LEM's Active Response capability makes it easy to watch a security event happen in real time and to take immediate action. For example, LEM can very efficiently allow security personnel to logoff suspect users or even restart important Windows Server processes in real time, before further intrusion can happen.
- LEM has a lot of out of the box features that allow for the quick implementation of security policy across many industries. LEM can provide immediate compliance monitoring and management for standards such as PICA, HIPAA and DISA-STIG.
- The number one challenge for SolarWinds customers I see is LEM's reporting software. LEM Reporter, a standalone Windows Application, is not as intuitive as customers would like and they report some instability in the application itself. Customers tend to use LEM's search scheduling as a more effective way to report on security events.
- Performance has been an issue based on LEM's use of a Flash interface. This has been a limitation for a long time. However, with the transition of the LEM interface from Flash to HTML5, customers are reporting much better performance starting in LEM 6.5
- Every one of my customers makes some comment about LEM's very high learning curve. LEM is not very intuitive, requiring a lot of rote learning through repetition. Many LEM customers request some type of training to help them learn to use it.
- LEM's console interface works well to narrow down all the logs into a view able format.
- You can customize alerting triggers off of any event conditions.
- the logging agent is relatively small and easy to deploy.
- In order to navigate the console smoothly and set alerting in place, you need to go through their training.
- All your configuration is done by hand. There are no built in analytics or alerting to help you.
- I've found the reporting, real time and otherwise, to be slow and unruly. There are some updates and work a rounds that we have applied to help optimize the process, but if you try to pull to many logs, or over too long a period of time it will often time out.
- The logging and reporting is dependent on the server automatically determining the type of server and logs it is getting. If it doesn't properly tag the logs, then they are essentially gone, lost, unsearchable. There is no good way to manually tell the server to classify the logs, which makes the process either difficult or impossible at times.
LEM pulls event data from across our network
- LEM is able to pull from a variety of different information sources without requiring a lot of configuration changes to get the data flowing.
- LEM assists in limiting the amount of data required for the business need without requiring a full dump (ie SNMP from all sources).
- LEM does require tweaking in order to get each data source configured. The event data comes into LEM easily, but the kind of data needs to be identified or custom classifications set up to organize the resulting alerts meaningfully.