

SolarWinds Security Event Manager
By SolarWinds Worldwide, LLC
Implementing SolarWinds Security Event Manager (SEM) involves several key steps:
Preparation:
System Requirements: Ensure your environment meets SEM's hardware and software prerequisites.
Deployment Planning: Decide on deployment specifics, such as virtualization platforms and network configurations.
Installation:
Deploy SEM Appliance: Use the SolarWinds Installer to set up the SEM virtual appliance on your chosen platform
.
Network Configuration: Configure network settings, including IP addresses and hostnames, to integrate SEM into your network.
Agent Deployment:
Identify Log Sources: Determine which devices and systems will send logs to SEM.
Install Agents: Deploy SEM agents on target systems to collect and forward log data.
Connector Configuration:
Select Connectors: Choose appropriate connectors for each log source to normalize incoming data.
Configure Connectors: Set up and activate connectors to start processing log data.
Console Access:
Log In: Access the SEM console to monitor events and manage configurations.
User Management: Set up user accounts and permissions as needed.
Policy and Rule Setup:
Define Rules: Create correlation rules to detect and respond to specific events.
Automate Responses: Configure automated actions for identified threats.
Testing and Optimization:
Validate Configuration: Ensure SEM is accurately collecting and processing log data.
SolarWinds Security Event Manager (SEM) offers extensive customization options to align with specific business requirements. Key customizable features include:
Correlation Rules: SEM allows the creation and modification of correlation rules to detect and respond to security events tailored to your organization's unique environment.
Dashboard and Widgets: Users can customize the SEM dashboard by adding, removing, or configuring widgets to display critical information relevant to their operational needs.
Compliance Reporting: SEM provides built-in, customizable reports to meet specific business requirements, facilitating compliance with standards such as SOX, HIPAA, and PCI DSS.
File Integrity Monitoring (FIM): Users can configure FIM settings to monitor specific files and directories, ensuring the protection of sensitive information.
User and Role Management: SEM enables the customization of user roles and permissions, ensuring appropriate access controls aligned with organizational policies.
SolarWinds Security Event Manager (SEM) offers a comprehensive range of training and support resources to assist new users in effectively deploying and utilizing the software. These resources include:
1. Onboarding Programs:
Self-Led Onboarding: Provides users with project plans, video walkthroughs, and access to technical documentation for independent installation and configuration.
2. SolarWinds Academy:
Virtual Classrooms: Interactive, instructor-led sessions covering various aspects of SEM, allowing users to engage in real-time learning.
eLearning Videos: On-demand tutorials focusing on key features and functionalities of SEM, enabling users to learn at their own pace.
3. SolarWinds Certified Professional (SCP) Program:
Certification Preparation: Resources and study guides to help users prepare for the SCP exam, validating their expertise in managing and optimizing SEM.
4. Technical Support:
24/7 Support: Round-the-clock assistance for troubleshooting, product-related issues, and technical questions.
5. Documentation and Community Resources:
Comprehensive Documentation: Detailed guides, including installation, configuration, and troubleshooting manuals, to assist users in effectively managing SEM.
SolarWinds Security Event Manager (SEM) implements a range of security measures to protect data and enhance organizational security posture:
Real-Time Event Correlation: SEM processes and normalizes log data before it's written to the database, enabling accurate, real-time correlation of events to detect potential security breaches promptly.
Automated Threat Response: SEM can automatically respond to security, operational, and policy-driven events using predefined actions, such as quarantining infected machines, blocking IP addresses, terminating malicious processes, and adjusting Active Directory settings.
File Integrity Monitoring (FIM): Embedded FIM capabilities monitor changes to files and folders, tracking modifications, deletions, and permission changes to identify suspicious activities that could indicate potential data breaches.
USB Device Monitoring and Control: SEM provides real-time notifications when USB devices connect to the network and can automatically block unauthorized devices, helping prevent endpoint data loss and protect sensitive information.
Integrated Threat Intelligence: SEM incorporates regularly updated threat intelligence feeds to automatically identify and tag malicious activity from known bad IP addresses, enhancing the ability to detect and respond to emerging threats.
Centralized Log Management: SEM aggregates logs from multiple devices and applications across the network into a centralized location, facilitating efficient monitoring, analysis, and retention of log data for security and compliance purposes.
SolarWinds Security Event Manager (SEM) maintains clear policies regarding data ownership and portability:
Data Ownership:
Customer Data Retention: For both perpetual and subscription licenses, customers retain ownership of all collected data. In the event a subscription license ends, no new data will be collected, and support and maintenance services will terminate. However, for perpetual licenses, even if support and maintenance services are discontinued, the product continues to operate, and new data will still be collected.
Data Portability:
SolarWinds Security Event Manager (SEM) offers flexible licensing options to accommodate the evolving needs of organizations. As your requirements change, SEM provides mechanisms to scale your deployment accordingly:
Scaling Up:
Universal License Expansion: SEM's Universal License allows monitoring of various devices, including servers, switches, routers, and firewalls. To increase capacity, you can purchase additional universal node licenses, enabling the monitoring of more devices as your infrastructure grows.
Additional Polling Engines (APEs): To distribute the processing load and enhance performance, especially in large environments, SEM supports the deployment of Additional Polling Engines. APEs help balance the workload and ensure efficient data collection across extensive networks.
Scaling Down:
License Adjustment: If your organization's monitoring requires decrease, you may have the option to adjust your licensing agreement upon renewal. It's advisable to discuss potential changes with your SolarWinds sales representative to align your licensing with current requirements.
Implementation Considerations:
License Activation: Activating additional licenses or adjusting existing ones can be managed through the SolarWinds License Manager within the SEM console. This tool facilitates the seamless addition or modification of licenses as organizational needs evolve.
SolarWinds Security Event Manager (SEM) has established terms and conditions governing contract renewal and cancellation to ensure clarity and mutual understanding between the company and its customers:
Contract Renewal:
Automatic Renewal: SEM contracts are designed to renew automatically upon the expiration of the initial term. The renewal term typically mirrors the length of the initial term unless specified otherwise at the time of renewal.
Renewal Notification: To assist in timely renewals, SolarWinds provides tools such as the Renewal Budget Calculator and maintenance pages, offering customers resources to manage and plan for renewals effectively.
Contract Cancellation:
Customer Termination Rights: Customers may terminate their agreement by providing at least thirty (30) days' prior written notice before the end of the current term. This notice ensures that the termination aligns with the contract's natural conclusion.
Termination for Cause: If SolarWinds commits a material breach that remains unrectified thirty (30) days after receiving written notice, customers have the right to terminate the agreement for cause.
Effect of Termination: Upon termination, customers are obligated to cease using the services, software, and documentation. Additionally, they must destroy or return all copies as requested by SolarWinds. It's crucial to note that fees paid prior to termination are non-refundable, and any outstanding amounts up to the termination date remain payable.
Data Handling Post-Termination:
Data Retrieval: Customers are responsible for retrieving their data within five (5) business days following the agreement's termination. Post this period, SolarWinds reserves the right to delete the data, and once deleted, recovery is not possible.
Support and Maintenance Considerations:
Perpetual Licenses: For customers with perpetual licenses, discontinuing support and maintenance services means they will no longer receive product updates. However, the product will continue to operate, and new data will still be collected.
SolarWinds Security Event Manager (SEM) is designed to assist organizations in meeting various regulatory compliance requirements by providing tools for log collection, monitoring, and reporting. SEM includes over 300 built-in report templates tailored to specific compliance standards, facilitating the generation of necessary documentation for audits and assessments.
By leveraging these features, SEM helps organizations address the requirements of multiple compliance standards, including:
PCI DSS (Payment Card Industry Data Security Standard): SEM offers predefined rules and reports to identify policy violations and generate audit trails for PCI-related events, aiding in adherence to PCI DSS requirements.
HIPAA (Health Insurance Portability and Accountability Act): Through real-time log analysis and event correlation, SEM assists healthcare organizations in monitoring access to sensitive patient information, supporting HIPAA compliance efforts.
SOX (Sarbanes-Oxley Act): SEM provides centralized log management and predefined report templates to help organizations demonstrate compliance with SOX IT controls and auditing requirements.
GLBA (Gramm-Leach-Bliley Act): By monitoring and analyzing events across IT infrastructures, SEM aids financial institutions in protecting customer information, aligning with GLBA mandates.