SolarWinds Security Event Manager (SEM)
Overview
What is SolarWinds Security Event Manager (SEM)?
SolarWinds LEM is security information and event management (SIEM) software.
Easy to install and easy to use
SolarWinds SEM helps system administrator analyze issues on network and server
Set-and-Forget with as needed functionality
SEM - a great product that's even better if you can dedicate the time to learn it.
SEM - Powerful and Affordable
Security Event Manager (SEM) - An intuitive and inexpensive product if you need a reliable Syslog manager in a classical network deployment
SEM provides easy, affordable SIEM appliance
SolarWinds SEM is easy to setup and (mostly) manageable
Superior Product, Easy to Implement and Very Reliable!
Easy product for Security Information and Event Management (SIEM)
S-Short E-Effective M-Monitoring Solution!!!
A boring review. It just works.
Log Police - The Best at Logging Events and Collection
Review of SolarWinds Security Event Manager
Great for Continental Enterprises
Awards
Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards
Popular Features
- Centralized event and log data collection (17)8.585%
- Deployment flexibility (17)7.979%
- Event and log normalization/management (17)7.373%
- Custom dashboards and workspaces (16)4.949%
Pricing
What is SolarWinds Security Event Manager (SEM)?
SolarWinds LEM is security information and event management (SIEM) software.
Entry-level set up fee?
- No setup fee
Offerings
- Free Trial
- Free/Freemium Version
- Premium Consulting/Integration Services
Would you like us to let the vendor know that you want pricing?
38 people also want pricing
Alternatives Pricing
What is Microsoft Sentinel?
Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.
What is Sumo Logic?
Sumo Logic is a log management offering from the San Francisco based company of the same name.
Features
Security Information and Event Management (SIEM)
Security Information and Event Management is a category of security software that allows security analysts to look at a more comprehensive view of security logs and events than would be possible by looking at the log files of individual, point security tools
- 8.5Centralized event and log data collection(17) Ratings
Effectiveness of real-time centralized event and log data collection
- 7.6Correlation(14) Ratings
Correlation of logs and events to pinpoint significant threats
- 7.3Event and log normalization/management(17) Ratings
Ability to normalize event syntax so that logs can be compared and are machine-understandable
- 7.9Deployment flexibility(17) Ratings
Ability to tune system to maximize threat detection and minimize false positives
- 7.9Integration with Identity and Access Management Tools(12) Ratings
Integration with access control tools like Active Directory and LDAP
- 4.9Custom dashboards and workspaces(16) Ratings
dashboards that can be customized to meet the needs of specific groups
- 10Host and network-based intrusion detection(3) Ratings
Ability to detect both endpoint intrusion and network ingress detection
Product Details
- About
- Competitors
- Tech Details
- Downloadables
- FAQs
What is SolarWinds Security Event Manager (SEM)?
The main applications are threat detection, automated incident analysis and response, and compliance reporting for IT infrastructure.
SolarWinds Security Event Manager (SEM) Features
Security Information and Event Management (SIEM) Features
- Supported: Centralized event and log data collection
- Supported: Correlation
- Supported: Event and log normalization/management
- Supported: Deployment flexibility
- Supported: Integration with Identity and Access Management Tools
- Supported: Custom dashboards and workspaces
SolarWinds Security Event Manager (SEM) Screenshots
SolarWinds Security Event Manager (SEM) Video
SolarWinds Security Event Manager (SEM) Competitors
SolarWinds Security Event Manager (SEM) Technical Details
Deployment Types | On-premise |
---|---|
Operating Systems | Windows |
Mobile Application | No |
SolarWinds Security Event Manager (SEM) Downloadables
Frequently Asked Questions
Comparisons
Compare with
Reviews and Ratings
(120)Community Insights
- Pros
- Cons
- Recommendations
Easy Configuration Process: Many users have expressed their positive experiences with the configuration process of SolarWinds, noting that it is easy and straightforward. This indicates that the product provides a user-friendly interface for making necessary adjustments, making it convenient for users to set up and customize according to their needs.
Excellent Customer Support: Several reviewers have praised the expertise and effectiveness of SolarWinds' customer support team in resolving issues. They have found the assistance provided by the support team to be valuable in addressing any concerns or difficulties they encountered while using the product.
Efficient Log Collection and Normalization: Users appreciate the centralized log collection and normalization feature offered by SolarWinds. This functionality streamlines the monitoring and analysis process by efficiently collecting logs from various sources and normalizing them into a consistent format. This allows for easier management and analysis of log data, saving users time and effort.
Confusing User Interface: Users have expressed dissatisfaction with the confusing user interface of SolarWinds SEM, which has made tasks difficult to accomplish. Many reviewers have specifically mentioned that they struggled to navigate and understand the UI.
Limited Reporting Capabilities: Users have found the reporting capabilities of SEM to be limited and not intuitive. They have suggested the need for a better report generation tool that offers more flexibility and customization options.
Poor Integration with Other Products: Several users desired better integration between SEM and other products in the SolarWinds line, such as NPM. They mentioned difficulties in achieving seamless integration, which hindered their ability to effectively manage their network infrastructure.
Users have provided several recommendations based on their experiences with SolarWinds Security Event Manager. The three most common recommendations are:
-
It is important to have a detailed plan before deploying the tool. This will help meet expectations and ensure effective usage.
-
Users highly recommend SolarWinds Security Event Manager as a reliable security solution. It provides comprehensive log monitoring and is particularly useful for tracking equipment, communication lines, and backup programming.
-
Before making a decision, users suggest evaluating whether SolarWinds Security Event Manager meets the specific requirements of your company. Consider factors such as company size, data protection needs, scalability, user intuitiveness, ease of installation, and cost-effectiveness.
It's worth noting that while some users find the software easy to use and understand, others mention concerns about its pricing and suggest exploring alternative options like PRTG or OpManager.
Attribute Ratings
Reviews
(1-25 of 27)- quickly find top logon failure user, which is suspect of malware infection
- easily find most visited port on the routers to find possible attack
- SEM traffic type sort report is useful tool to control unnecessary network usage
- wish SEM could update by itself
Set-and-Forget with as needed functionality
- Runs without issue
- Logs extensive detail
- The user interface to be more user friendly
- The query builder is tedious to use
- Log collection
- User-friendly and Easy dashboards
- Queries seeped (according to our size)
- log data parsing is good. if you upgrade some systems, most likely SEM will recognize it
- Agent installations are easy but there are some meaningless steps
- Can be add an advanced reporting process or module
S-Short E-Effective M-Monitoring Solution!!!
- Log collection.
- Graphical representation of collected logs.
- Rules to trigger and send emails for quick identification and monitoring.
- File Integrity Monitoring
- Better UI to search and track logs
- Connectors compatibility issues
Log Police - The Best at Logging Events and Collection
- Customizable event filters
- Awesome user interface
- Easy to configure connectors
- Needs better integration with SolarWinds NPM. This is the only Solarwinds product we use that isn't integrated.
- It needs a more lightweight client.
Review of SolarWinds Security Event Manager
- Collect logs.
- Generate reports.
- Great user interface.
- I would like the client to be more lightweight.
- I would like a mobile app.
Great for Continental Enterprises
- SOC Dashboard
- Compliance Reporting
- Node Health
- User Logon Events Dashboard
- Poor Performance for 10,000+ elements
- Poor Performance for real-time dashboard when over 10K nodes
- Poor database performance for extra large global enterprise
Solarwinds (SEM) experience
- It gives you [the] ability to see logs in one central location
- Inbuilt rules and filters
- How to build custom [rules] for individual purposes (e.g. rules for Admin users on critical systems, log on, log off, brute force, scanning)
- Customer support should be timely and available
- Videos to onboarding systems should be made ( e.g, websites, servers, wireless access point, active directories, firewalls, Domain controls, etc)
- Hard to achieve unwanted logs
- Updates for SEM users should be made available (New features and usability)
- No user-friendly support
- No health check of the SEM by Solarwinds
- Support needs to improve
- Videos to be sent to users on how to create custom rules to fit individual purposes
- Training on each feature of the SEM tool should be made available in a specific location on SolarWinds website
- Best practice videos and use cases should be made available
SolarWinds Security Event Manager Review
- Easy to utilize--the rules are straightforward and pre-configured. You just have to customize them to fit your environment.
- Great customer service, which is incredibly useful when you want help with better utilizing the SEM.
- Easy and clear filters when looking for specific information without your environment.
- The SEM can be rather slow--an increase in CPU and RAM appeared to fix this problem fairly easily though.
- The SEM has lately required reboots for us fairly often. This is something we are currently working with support to resolve.
- The SEM could release additional graphic options to help better display data to management.
SEM is a good product
- Insight to suspicious events.
- Automated response to common issues.
- Reports.
- Interface.
- Reporting.
- Notifications.
The SolarWinds SEM: Cost effective centralized log management tool that helps your audit and security.
- Has a nice user-friendly interface. Some SIEM can be daunting to learn how to use and get acclimated to, but LEM has an intuitive layout and is very easy to pick up and use.
- The logging agent in the source device is really simple to deploy and integrate.
- Monitoring and reporting the account disablement with detail to whoever disabled an account for audit and compliance.
- Some logs are not parsed well, happen to depend on the external log parser tool.
- The update method needs to be made even simpler, auto update would be better.
- The email alert features with SolarWinds will send a large number of emails if the number of alerts email. The duplication of email alerting needs to be reduced.
Solarwinds - great product with a few small flaws.
- We use the client on register systems as event forwarders and log collection.
- It enables us to verify the access security to high value workstations and register systems.
- It provides a repository storage for log files so that they do not solely exist on workstations.
- It helps us ensure PCI standards are being maintained and track security risk issues as well as system health.
- Within the scope of my role I have noticed that the client can be problematic during system startup - some of the register systems we use are older and have lower resolution screens. When the client loads it pops up on screen but completely out of scale (to clarify, it may open a window that is 14x14 inches on a screen that only displays 10x10 inches. This is more frustration than a functional problem.
- Automated rollout would be useful but it is outside of my scope in my job to even know if it already has automated install capability.
- The GUI itself is a little clunky and there is somewhat of a learning curve - training is provided to clients however a friendlier interface would be helpful.
SolaWinds SEM--Worth every penny!
- Graphs showing important events
- First-time setup and addition of new devices is easy and organized
- Performance is excellent
- Reporting could allow for more customization
- Better integration with other products of SolarWinds line
- More alert options
SEM - Good product, reasonable price point
- Brings together security events from multiple system sources.
- Allows IT to review and manage security related events.
- Provides convenient filters/views allowing us to narrow down the data we want to see.
- Some improvements in user documentation could be helpful.
SEM review of a SolarWinds fanboy at heart
- Automated threat detection
- Log collection
- Live filtering
- Custom rules
- Alerting can be confusing to configure
- The dashboards and widgets look a little old as with all SolarWinds products
- The initial setup can take a lot of time
- Advanced search capabilities across all log data, powered by a quick engine to minimize the delay.
- Built-in or customized templates.
- Alerting capabilities.
- More advanced log correlation mechanisms with better filtering capabilities.
SolarWinds Security Event Manager: A "log" above everyone else
- Allows log collecting from almost any source of data, using multiple types of authentication and collection (i.e. SNMP, WMI, etc.)
- Allows customization of dashboards per user, so that you can quickly find the information relevant to your position.
- The dashboard and reports use javascript, which can be slow to load.
- To get it up and running was fast, however, to correctly configure proper alerts, you have to spend a ton of time.
- SEM normalizes logs very well. It is simple to be able to compare fields in logs from say a Cisco router and a Windows server, especially timestamps.
- SEM has great flexibility in customizing its various aspects, especially its correlation rules and reports.
- SEM doesn't support out-of-the-box several device manufacturers that are used in my environment. For example, Peplink and Netonix.
- I have to purchase a separate log parser tool rather than having it included in SEM.
- It does a great job of notifying us when accounts have been locked out. We can then find out the device on the network where the login attempt occurred.
- Searching for incidents is now a lot faster with the implementation of the HTML 5 interface.
- Some aspects have not been fully integrated into HTML 5. Those are still a bit slow to access.
- Need an easier way to upgrade the software. SSH to the console and running the commands to connect to the TFTP server is archaic. Needs an “update” button.
It does well with monitoring for suspicious activity. It can alert you if It sees a client is trying to circumvent DNS so they can go through proxy avoidance tactics.
These Events will "Blow" You Away!
- SolarWinds easily provides the much needed visibily into changes in an Active Directory (AD) environment. Email alerting can be configured to alert a team if an account is locked out, disabled by another users, or if users and/or computers accounts are created.
- SolarWinds allowed a searchable audit feature. Microsoft Windows can be configured to log many different parts of a system, but search those logs can be difficult. SEM allows you to search for specific users or events.
- All SolarWinds product suffer from slow response times in management portals. SolarWinds SEM is no exception. While it is much preferred over a "thick client" there is much room for improvement in speed.
- If you use the email alert features with SolarWinds make sure to prepare you staff and team for the large amount of emails they could receive. Make sure to reduce the number of alerts so your team does not ignore the alerts.
SolarWinds LEM: Useful and Low Cost SIEM Solution for SMBs
- Compared to other SIEMs, it's relatively easy to get up and running. The virtual appliance is easy to maintain.
- Support was top notch. The support team really knows their stuff when you run into an issue.
- The email alert system is easy to use and attach to a fired rule.
- Compared to other SIEMs, there are features that are missing. Machine learning, automatic event correlation, ability to correlate multiple sources together.
- The UI is clunky, and the *New* event log analyzer page felt really disjointed from the rest of the product.
- In my experience, the dashboards were almost unusable. They persisted across login per device, and even then they sometimes would reset and go back to the ''Getting Started'' look.
Bigger companies or companies with dedicated security staff will likely look at other options. This seems like an entirely mid-market only purchase. If you want to be able to correlate events from multiple sources, not just agent-based windows logs, you'll likely need to look elsewhere. While you can also forward syslog to the appliance, you can't enrich any data or use sources like NIDS/HIDS logs. This product will not give you a true single pane of glass like some offerings.
SolarWinds Log & Event Manager: Exactly as Advertised
- Monitors account lockouts and reports them with detail so that it is easier to solve this with end users.
- Monitors and reports account disablement with detail to whoever disabled an account, for audit and accountability.
- Also, monitors and reports account enablement with detail to whoever enabled an account, again for audit and accountability.
- Flash-based UI can lag, HTML5 would be preferred
- Availability for custom widgets, but you need a bit of training to get things done right unless you have time for trial and error.
- It only knows what it knows for account lockouts. If a source machine isn't available in the Event Viewer ID that triggers the alert, it does not have any extra tools to help it determine the issue.
LEM, your one stop shop for Security Event and Incident Management!
- One of the most valuable features of SolarWinds LEM is its ability to normalize logs from differing systems into one common format. LEM normalization saves time and effort in doing forensic analysis by letting security personnel see the "whole picture" of their network in one place.
- LEM's Active Response capability makes it easy to watch a security event happen in real time and to take immediate action. For example, LEM can very efficiently allow security personnel to logoff suspect users or even restart important Windows Server processes in real time, before further intrusion can happen.
- LEM has a lot of out of the box features that allow for the quick implementation of security policy across many industries. LEM can provide immediate compliance monitoring and management for standards such as PICA, HIPAA and DISA-STIG.
- The number one challenge for SolarWinds customers I see is LEM's reporting software. LEM Reporter, a standalone Windows Application, is not as intuitive as customers would like and they report some instability in the application itself. Customers tend to use LEM's search scheduling as a more effective way to report on security events.
- Performance has been an issue based on LEM's use of a Flash interface. This has been a limitation for a long time. However, with the transition of the LEM interface from Flash to HTML5, customers are reporting much better performance starting in LEM 6.5
- Every one of my customers makes some comment about LEM's very high learning curve. LEM is not very intuitive, requiring a lot of rote learning through repetition. Many LEM customers request some type of training to help them learn to use it.
- Able to ingest full Syslog output from three enterprise firewalls.
- Able to detect and alert on specific Active Directory events.
- The interface for creating alerts is onerous. It is necessary to dig out the exact event ID of anything you want to alert on.
- Early versions required a separate server to host a FastBit database, but that requirement has been eliminated with the latest release; SQL is now required.
- LEM's console interface works well to narrow down all the logs into a view able format.
- You can customize alerting triggers off of any event conditions.
- the logging agent is relatively small and easy to deploy.
- In order to navigate the console smoothly and set alerting in place, you need to go through their training.
- All your configuration is done by hand. There are no built in analytics or alerting to help you.
- I've found the reporting, real time and otherwise, to be slow and unruly. There are some updates and work a rounds that we have applied to help optimize the process, but if you try to pull to many logs, or over too long a period of time it will often time out.
- The logging and reporting is dependent on the server automatically determining the type of server and logs it is getting. If it doesn't properly tag the logs, then they are essentially gone, lost, unsearchable. There is no good way to manually tell the server to classify the logs, which makes the process either difficult or impossible at times.