SolarWinds Security Event Manager Review

Good log collection and reporting, but it provides no security information and the licensing model needs to be changed

What is our primary use case?

We are using this solution for our internal log event monitoring, as well as for file integrity monitoring.

How has it helped my organization?

SolarWinds LEM performs the job of log collection. It collects logs and nothing more. It does not really provide much in terms of security. It will trigger alerts but it will not give you any recommendations, filter according to rules, or anything other than logging the events if your server is attacked.

What is most valuable?

The most valuable feature is the reporting. The log conversion for generating reports is good.

What needs improvement?

The dashboard is running in Adobe Flash and this should be changed because there are vulnerabilities that are related to the browser. We constantly have to patch the system.

There is no information provided in terms of security.

The licensing model is poor, which in turn affects the scalability.

There is no correlation made between log entries, so no threat information is presented.

The performance degrades when there is a lot of traffic.

For how long have I used the solution?

We have been using SolarWinds LEM for three years.

What do I think about the stability of the solution?

The stability is good when there are a low number of events per second on the servers. However, if there are a lot of events then the server is very slow. 

What do I think about the scalability of the solution?

The scalability is poor because of the licensing. Having to buy blocks of fifty licenses is not good for our business. Our model is that of a managed service provider and our customers are interested in adding two or three nodes at a time. We cannot just keep buying fifty licenses at a time.

How are customer service and technical support?

There is not much in terms of technical support because it is a web-based application. They do not support Adobe Flash because it is a third-party application. The just provide you the knowledge base, as with the other SolarWinds products. Using that, you experiment on your own.

How was the initial setup?

It is a straightforward implementation. The deployment takes about two hours before everything is running.

What's my experience with pricing, setup cost, and licensing?

Licenses can only be purchased in blocks of fifty at a time.

What other advice do I have?

I am not expecting a future release of SolarWinds LEM because they have released another solution. They are continuing with a new security event and information management (SEIM) solution that is more suitable for large-scale enterprises.

I would rate this solution a five out of ten.

Which deployment model are you using for this solution?

**Disclosure: I am a real user, and this review is based on my own experience and opinions.
More SolarWinds Security Event Manager reviews from users
...who work at a Financial Services Firm
...who compared it with IBM QRadar
Add a Comment