Please share with the community what you think needs improvement with SolarWinds Security Event Manager .
What are its weaknesses? What would you like to see changed in a future version?
Under the new system, it is not upgradable the way they say. When you try to do an upgrade, it doesn't really work unless you dump everything and start from scratch. You lose a lot of your nodes. Whenever you set your nodes up and everything else, they don't want to bring those nodes back in, so you have to really go back and restructure all your nodes. I went from version 6.5 to version 6.6 and then to version 6.7. I then went to version 2019, and now it is version 2020. It would be good if we can upgrade without having to delete everything and start from scratch. They can maybe build more KPIs and other things for the dashboard. Some of the other systems already have built-in KPIs. SolarWinds is starting to catch up, but it is not there yet. They can include some of the business or industry standards for tracking the time, that is, the meantime to detect (MTTD) and the meantime to resolve (MTTR). They can also find a way to build a KPI that measures the number of instances of port scans experienced in a week or a month.
They need to do better with the Connectors. I had to battle with the IIS Web server Connector that comes built in with this product. No matter how I configured the IIS Web connector, I never saw SW pull in any IIS logs from my hosts , where Agent was installed.? They have over 500 connectors, but in my experience only handful work. Also there's no PowerShell Logging connectors, if you want to pull in PowerShell Logging logs from your hosts into the SIEM.
Some things on the roadmap could be improved but I understand they're working on those issues. The main area that would mean a big improvement for me would be for the product to include multiple dashboards. I would love to see a multi-page dashboard where you could see information side-by-side; to slice through the dashboard to see specific topics. For example, one network dashboard, one active directory dashboard, one VMware dashboard, etc. That feature is something they could include in the next release - the ability for a report to flip to different technologies. And it would be nice if there were some pretty configured templates for the dashboard so that you don't have to fill all the data in. For example, a template for active directory or KPIs, or a template for VMware KPIs.
It takes a long time to perform a root cause analysis. I would like to have a more customizable dashboard.
The dashboard is running in Adobe Flash and this should be changed because there are vulnerabilities that are related to the browser. We constantly have to patch the system. There is no information provided in terms of security. The licensing model is poor, which in turn affects the scalability. There is no correlation made between log entries, so no threat information is presented. The performance degrades when there is a lot of traffic.
I think the product can use some improvement on the reporting side. The reporting could be easier and more robust. I also think the NetFlow Analyzer component can be improved substantially in the way it is integrated with SolarWinds and with Orion. In my opinion, you are not able to drill down enough into traffic flows. It can be a lot more granular and that will make it a lot more useful in comparison to how it is incorporated at the moment. I think that incorporating a security management platform would also be good. This would be a solution like a dashboard or control panel where you can just snap-in modules. A global dashboard where you can snap in all the different types of solutions or the different types of services and products that you will leverage would be a great step forward in ease-of-use by making integration easier.
The query capability in this solution needs improvement. When you watch to fetch logs at specific times, sometimes there are issues. The filtering engine needs to be improved to make it more accurate. When you are filtering, it comes with a lot of unwanted data. I would like to be able to dig deeper into the visibility of events or incidents to determine whether they are malicious, such as by doing behavior analysis.
We're currently looking for an application monitoring solution and maybe a DHCP management module. It would be ideal if the solution could add these in its next release. The solution should offer better support and better SLAs.
The flash-based interface can be improved because sometimes, the speed of monitoring is reduced. The interface should be replaced with something else. Training for this solution needs to be improved, as new employees are sometimes unfamiliar with the product. The gadgets in SolarWinds should all be in one place. There should be a default template because as it is now, the user has to create one for each and everything.
We all know it's really hard to get good pricing and cost information.
Please share what you can so you can help your peers.