Blog entries by technology: Safed

01. 07. 2019 MarinovMihail Downloads / Release Notes

Updated Safed Agent v1.10.1 for UX

The Safed agent for AIX version 7.1 now supports TLS 1.3 based on WolfSSL 3.15.7. The Safed agent 1.10.1 for UX is available on our github repository. Follow the steps described in the README file to compile and install both wolfssl 3.15.7 and safed 1.10.1 After that is will be possible to configure the secure…

Read More
29. 03. 2019 Angelo Rosace Log Management, NetEye

Host Creation via Icingacli Commands for Monitoring and Deploying a Safed Agent Configuration

Creating hosts in NetEye’s Director module can sometimes be time-consuming and a repetitious, tiring and boring job. Especially if you have to populate Director with a large number of hosts for setting up a test environment, for example. One solution is to create a script consisting of nothing but icingacli commands. Each command line instruction…

Read More
25. 03. 2019 Oreste Attanasio Log Management, Log-SIEM, NetEye, Unified Monitoring

Safed improvements since 1.10.1

The Safed agent keeps track of the events it receives from the Eventlog by keeping the LastEventID in registry. At start time the agent tries to retrieve all events from Windows Eventlog since starting from the LastEventID. When the amount of events since LastEventID is too large or the LastEventID has been removed from the…

Read More
20. 03. 2019 MarinovMihail Downloads / Release Notes, Log Management

Updated Safed Agent v1.10.1

– Retrieved events from eventlog (win 2008 +) starts from bookmark but should not be older than defined cache days

Read More
07. 02. 2019 MarinovMihail Log-SIEM, NetEye

Secure Connections for the Safed Agent

The Safed agent can be configured via https and send its collected logs to the log collector though a TLS connection. The latest released version – 1.9.1 – supports TLS 1.2 (at a minimum) and TLS 1.3. The first step is to upload the private key, the local certificate and the CA certificate to the…

Read More
03. 12. 2015 MarinovMihail NetEye

Login/Logoff-Aktivitäten des Windows Administrators mit Safed verfolgen

Aufgrund der aktuellen gesetzlichen Richtlinien, aber auch aus ganz einfachen Security-Überlegungen (siehe dazu auch unseren Artikel “Was tun mit den ganzen Logs“), ist es notwendig die Login/Logoff Aktivitäten des Admins mitzuloggen. Der Safed Agent für Windows kann ganz einfach so konfiguriert werden, dass alle Login/Logoff-Versuche des Admins aufgezeichnet werden. Der Agent verfügt über ein „System…

Read More
03. 12. 2015 MarinovMihail Log Management, NetEye

Trace Windows Administrators Login Activities with Safed

Sometimes it is required to trace login/logoff activities of the administrator in order to be compliant with legal guidelines or simply for security reasons (see also our article “What to do with all those logs“). The Safed agent for Windows can be easily configured to collect administrator’s login/logoff. The agent is deployed with some administrator discovery commands,…

Read More
03. 12. 2015 MarinovMihail NetEye

Monitorare le attività di login/logoff degli amministratori Windows con Safed

Per poter adempiere alle richieste del Garante della Privacy, ma anche per motivi di sicurezza (vedi anche il nostro articolo “Archiviazione dei log e poi?“), è necessario registrare tutte le attività di login/logoff degli amministratori di sistema. L’agente Safed per Windows può essere configurato in modo da raccogliere tutti i tentativi di login e logoff…

Read More
12. 08. 2015 Thomas Forrer Downloads / Release Notes, Log Management, NetEye

Updated Safed Agent v1.8.1

Read More
12. 08. 2015 Thomas Forrer NetEye

Updated Safed Agent v1.8.1

Read More
12. 08. 2015 Thomas Forrer NetEye

Updated Safed Agent v1.8.1

Read More
10. 08. 2015 MarinovMihail Downloads / Release Notes

Safed 1.8.0

The new 1.8.0 version of Safed enables the collection of log events from Applications and Services Logs (custom EventLogs). An example of custom log collection configuration is shown in the following screenshot. In the custom dropdown list the registered Applications and Services Logs are shown. The same list can be seen using the Windows Event…

Read More
03. 07. 2014 MarinovMihail Uncategorized

Monitoraggio delle porte USB con Safed

Talvolta, specialmente per questioni di sicurezza è importante sapere, se le porte USB di un server siano state usate, e se sì, quali attività sono state effettuate. Con la nuova versione dell’agente Safed 1.7.0 possiamo monitorare le porte USB per Windows Vista 2008 e versioni superiori. L’agente può ricevere notifiche di eventi WMI che riguardano…

Read More
03. 07. 2014 MarinovMihail Uncategorized

Überwachung von USB-Ports mit Safed

Oft ist es wichtig zu wissen ob die USB-Ports eines Servers benutzt wurden und falls ja, welche Operationen durchgeführt wurden. Mit der neuen Version des Safed Agent 1.7.0 ist es möglich USB-Ports für Windows Vista 2008 und höhere Versionen, zu überwachen. Der Agent kann WMI-Event-Notifikationen, welche die Zielinstanz „Win32_PnPEntity“ betreffen, empfangen. Die Events der Klassen…

Read More
03. 07. 2014 MarinovMihail Service Management

Monitoring USB Ports with Safed

Sometimes, especially for security reasons, it is important to know if the USB ports of a server have been used and what kind of operation has been carried out. Well, with the new version 1.7.0 of the Safed agent it is possible to monitor the USB ports for Windows Vista 2008 and later versions. Now…

Read More

Archive