2019-08-12T05:55:00Z

What needs improvement with SolarWinds Security Event Manager ?

Julia Miller - PeerSpot reviewer
  • 0
  • 2
PeerSpot user
16

16 Answers

AA
Real User
Top 5
2024-01-15T14:41:20Z
Jan 15, 2024

One of the drawbacks of being so flexible is that it is also a fairly complicated software application to install, configure, and maintain. Standardizing the monitoring configuration is difficult, and there can be some drift between monitoring targets in terms of the monitoring thresholds. It is quite a lot of work to ensure that everything is set up according to a specific baseline.

Search for a product comparison
Akram Zaki Hussein - PeerSpot reviewer
Real User
Top 5Leaderboard
2023-09-25T14:11:14Z
Sep 25, 2023

The installation proved to be significantly challenging. The inconvenience lies in the fact that SolarWinds is not VirtualBox-friendly and installation can be cumbersome. Figuring out the login credentials added another layer of complexity. The price is a big issue. The hardware requirements are demanding and expensive, adding to the overall high cost. Compatibility issues were a significant headache, as it didn't seamlessly integrate with many other software applications. Testing and figuring out the software's functionality took several months, especially considering the variety of software in use. It has limitations in terms of compatibility with certain security systems and solutions, being somewhat restricted in its adaptability.

IG
Real User
Top 5
2023-05-11T14:48:00Z
May 11, 2023

The product should improve the ease with which you can create event alerts. They are not as hard now but you need to have an easier way.

Ryan Dave Brigino - PeerSpot reviewer
Real User
Top 5Leaderboard
2023-01-12T15:19:14Z
Jan 12, 2023

The only issue is the pricetag. SolarWinds is a costly solution.

JT
Real User
Top 5
2022-09-19T17:33:00Z
Sep 19, 2022

I don't think SolarWinds is scalable enough. It is somewhat limited when I need to deploy it across multiple environments in a distributed architecture.

RM
Real User
2021-12-01T20:47:19Z
Dec 1, 2021

It is a very technical program. They can simplify it so that it isn't so hard to deal with. You can be notified of various things, but you have to configure them. That's the downside. You got to work with it and configure it.

Learn what your peers think about SolarWinds Security Event Manager . Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
765,386 professionals have used our research since 2012.
SJ
Real User
2021-10-06T16:34:00Z
Oct 6, 2021

SolarWinds should improve its correlation capabilities. The correlation does not automatically detect and reduce the events fast enough. You have to manually do a correlation report, which means the tool is not scalable in many ways. Another area that needs improvement is the integration of the IT framework. We are automating the framework using their tools. I think that automation will help.

JJ
Real User
2020-10-08T07:25:26Z
Oct 8, 2020

Under the new system, it is not upgradable the way they say. When you try to do an upgrade, it doesn't really work unless you dump everything and start from scratch. You lose a lot of your nodes. Whenever you set your nodes up and everything else, they don't want to bring those nodes back in, so you have to really go back and restructure all your nodes. I went from version 6.5 to version 6.6 and then to version 6.7. I then went to version 2019, and now it is version 2020. It would be good if we can upgrade without having to delete everything and start from scratch. They can maybe build more KPIs and other things for the dashboard. Some of the other systems already have built-in KPIs. SolarWinds is starting to catch up, but it is not there yet. They can include some of the business or industry standards for tracking the time, that is, the meantime to detect (MTTD) and the meantime to resolve (MTTR). They can also find a way to build a KPI that measures the number of instances of port scans experienced in a week or a month.

KM
Real User
2020-09-27T04:09:00Z
Sep 27, 2020

They need to do better with the Connectors. I had to battle with the IIS Web server Connector that comes built in with this product. No matter how I configured the IIS Web connector, I never saw SW pull in any IIS logs from my hosts , where Agent was installed.? They have over 500 connectors, but in my experience only handful work. Also there's no PowerShell Logging connectors, if you want to pull in PowerShell Logging logs from your hosts into the SIEM.

Daniel Penn - PeerSpot reviewer
Real User
Top 10
2020-02-24T06:02:00Z
Feb 24, 2020

Some things on the roadmap could be improved but I understand they're working on those issues. The main area that would mean a big improvement for me would be for the product to include multiple dashboards. I would love to see a multi-page dashboard where you could see information side-by-side; to slice through the dashboard to see specific topics. For example, one network dashboard, one active directory dashboard, one VMware dashboard, etc. That feature is something they could include in the next release - the ability for a report to flip to different technologies. And it would be nice if there were some pretty configured templates for the dashboard so that you don't have to fill all the data in. For example, a template for active directory or KPIs, or a template for VMware KPIs.

SK
Real User
Top 5
2020-01-30T07:55:37Z
Jan 30, 2020

It takes a long time to perform a root cause analysis. I would like to have a more customizable dashboard.

KG
Real User
2020-01-26T09:26:00Z
Jan 26, 2020

The dashboard is running in Adobe Flash and this should be changed because there are vulnerabilities that are related to the browser. We constantly have to patch the system. There is no information provided in terms of security. The licensing model is poor, which in turn affects the scalability. There is no correlation made between log entries, so no threat information is presented. The performance degrades when there is a lot of traffic.

AF
Real User
2019-12-23T07:05:00Z
Dec 23, 2019

I think the product can use some improvement on the reporting side. The reporting could be easier and more robust. I also think the NetFlow Analyzer component can be improved substantially in the way it is integrated with SolarWinds and with Orion. In my opinion, you are not able to drill down enough into traffic flows. It can be a lot more granular and that will make it a lot more useful in comparison to how it is incorporated at the moment. I think that incorporating a security management platform would also be good. This would be a solution like a dashboard or control panel where you can just snap-in modules. A global dashboard where you can snap in all the different types of solutions or the different types of services and products that you will leverage would be a great step forward in ease-of-use by making integration easier.

it_user1137249 - PeerSpot reviewer
Real User
2019-09-15T16:43:00Z
Sep 15, 2019

The query capability in this solution needs improvement. When you watch to fetch logs at specific times, sometimes there are issues. The filtering engine needs to be improved to make it more accurate. When you are filtering, it comes with a lot of unwanted data. I would like to be able to dig deeper into the visibility of events or incidents to determine whether they are malicious, such as by doing behavior analysis.

AN
Real User
2019-09-03T08:57:00Z
Sep 3, 2019

We're currently looking for an application monitoring solution and maybe a DHCP management module. It would be ideal if the solution could add these in its next release. The solution should offer better support and better SLAs.

SG
Real User
2019-08-12T05:55:00Z
Aug 12, 2019

The flash-based interface can be improved because sometimes, the speed of monitoring is reduced. The interface should be replaced with something else. Training for this solution needs to be improved, as new employees are sometimes unfamiliar with the product. The gadgets in SolarWinds should all be in one place. There should be a default template because as it is now, the user has to create one for each and everything.

When TriGeo was acquired by SolarWinds, TriGeo SIM became known as SolarWinds Log & Event Manager. This product is a leading Security Information and Event Management (SIEM) product and log management solution, which provides log collection, analysis, and real-time correlation.
Download SolarWinds Security Event Manager ReportRead more

Related Q&As