Solarwinds Ncm Latest Version

0 views
Skip to first unread message

Hilma Klingaman

unread,
Aug 5, 2024, 6:32:48 AM8/5/24
to turnprogerve
Thelegacy syslog and traps functionality has been retired and replaced with new functionality called SolarWinds Log Viewer, which can be upgraded to Log Analyzer for additional capabilities. Current rules and history will automatically be migrated to the new logging functionality (SolarWinds Log Viewer or Log Analyzer). The functionality of SolarWinds Log Viewer and Log Analyzer has been improved to more closely match legacy functionality. See LA 2022.3 release notes for details.

For modules based on Orion Platform 2020.2.6 and earlier, SolarWinds has announced end-of-life plans. As always, SolarWinds recommends you upgrade to the latest version of your products at your earliest convenience.


Deprecated platforms and features are still supported in the current release. However, they will be unsupported in a future release. Plan on upgrading deprecated platforms, and avoid using deprecated features.


Network Atlas is deprecated as of Orion Platform 2020.2. It is still available and supported in the current release, but will be removed in a future release. Deprecation is an indication that you should avoid expanded use of this feature and formulate a plan to discontinue using the feature. SolarWinds recommends that you start using Intelligent Maps in the SolarWinds Platform Web Console to display maps of physical and logical relationships between entities monitored by the SolarWinds Platform products you have installed.


This document may not be reproduced by any means nor modified, decompiled, disassembled, published or distributed, in whole or in part, or translated to any electronic medium or other means without the prior written consent of SolarWinds. All right, title, and interest in and to the software, services, and documentation are and shall remain the exclusive property of SolarWinds, its affiliates, and/or its respective licensors.


SOLARWINDS DISCLAIMS ALL WARRANTIES, CONDITIONS, OR OTHER TERMS, EXPRESS OR IMPLIED, STATUTORY OR OTHERWISE, ON THE DOCUMENTATION, INCLUDING WITHOUT LIMITATION NONINFRINGEMENT, ACCURACY, COMPLETENESS, OR USEFULNESS OF ANY INFORMATION CONTAINED HEREIN. IN NO EVENT SHALL SOLARWINDS, ITS SUPPLIERS, NOR ITS LICENSORS BE LIABLE FOR ANY DAMAGES, WHETHER ARISING IN TORT, CONTRACT OR ANY OTHER LEGAL THEORY, EVEN IF SOLARWINDS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.


The SolarWinds, SolarWinds & Design, Orion, and THWACK trademarks are the exclusive property of SolarWinds Worldwide, LLC or its affiliates, are registered with the U.S. Patent and Trademark Office, and may be registered or pending registration in other countries. All other SolarWinds trademarks, service marks, and logos may be common law marks or are registered or pending registration. All other trademarks mentioned herein are used for identification purposes only and are trademarks of (and may be registered trademarks) of their respective companies.


Monitor, analyze, diagnose, and optimize database performance and data ops that drive your business-critical applications. Unify on-premises and cloud database visibility, control, and management with streamlined monitoring, mapping, data lineage, data integration, and tuning across multiple vendors.


Modernize your service desk with intelligent and automated ticketing, asset, configuration, and service-level agreement (SLA) management; a knowledge base; and a self-service portal with secure remote assistance. SolarWinds offers an easy-to-use IT service management (ITSM) platform designed to meet your service management needs to maximize productivity while adhering to ITIL best practices.


Ensure user experience with unified performance monitoring, tracing, and metrics across applications, clouds, and SaaS. Robust solutions offering rich visualization, synthetic and real user monitoring (RUM), and extensive log management, alerting, and analytics to expedite troubleshooting and reporting.


Reduce attack surface, manage access, and improve compliance with IT security solutions designed for accelerated time-to-value ranging from security event management, access rights management, identity monitoring, server configuration monitoring and patching, and secure gateway and file transfer.


Orion Platform version 2020.2.5 adds to these enhancements with additional security fixes and protections. We recommend you upgrade to the latest available release (2020.2.5) as soon as is practical. For more information, review the Release Notes here, and KB article here.


If you have recently upgraded to 2020.2.1 HF2 or 2019.4 HF 6, you are also protected from SUNBURST and SUPERNOVA. However, as part of our response to the SUNBURST vulnerability, the code-signing certificate used by SolarWinds to sign the affected software versions was revoked March 8, 2021, and you may experience performance issues if you do not apply the more recent updates. Please visit our SolarWinds New Digital Code-Signing Certificate page at solarwinds.com/trust-center/new-digital-certificate for more information.


Disconnecting any product from the internet can reduce your attack surface. The Orion Platform is fully functional without an internet connection. Based on our investigations to date, SUNBURST requires an internet connection to be activated and disconnecting your Orion server from the internet should immediately protect your environment from SUNBURST. The vulnerability in the product that allows for the deployment of SUPERNOVA, however, may still be exploited by a malicious actor who accesses your network from inside and not over the internet. Disconnecting from the internet will limit the ability of an external actor exploiting this vulnerability over an internet connection.


IMPORTANT NOTE: Disconnecting from the internet is not a recommended substitute for upgrading your Orion software to versions 2019.4.2, 2020.2.4, or 2020.2.5, or applying appropriate patches to older versions if a full upgrade is not possible at this time.


We strongly encourage customers to upgrade their Orion products to the latest versions available in the Customer Portal at customerportal.solarwinds.com that are designed to protect you from SUNBURST and SUPERNOVA. Doing so allows you to the get the full benefit of our updates, improvements, and enhancements.


* As a part of the ongoing investigation, we have determined that Orion Platform version 2019.4 unpatched, released in October 2019, contained test modifications to the code base. While this version is not impacted by the SUNBURST vulnerability, it is the first version in which we have seen activity from the attacker at this time. Subsequent releases 2019.4 HF 1, 2019.4 HF 2, 2019.4 HF 3, and 2019.4 HF 4 did not include either test modifications contained in the 2019.4 version or the SUNBURST vulnerability contained in 2019.4 HF 5, 2020.2 unpatched, and 2020.2 HF 1.


** If you apply a SUPERNOVA security patch per the above chart, please visit this KB article to validate the patch was applied to all Orion Platform web servers. If you reinstall your Orion server, you will need to reapply the respective patch.




*** If you used the SUPERNOVA Mitigation Script to address the Supernova vulnerability, use the guidance in the document within that package to confirm the temporary patch. Please note that this script has only been tested down to NPM 11.x. If you reinstall your Orion server, you will need to reapply this script.


All recommended upgrade versions are currently available at customerportal.solarwinds.com. All hotfix updates are cumulative and can be installed from any earlier version. There is no need to install previously released updates.


While there has been speculation by various sources, based on our investigations to date, we do not have a definitive answer at this time. SolarWinds continues to work closely with federal agencies and third-party cybersecurity firms to determine the answer.


As announced by SolarWinds President and CEO Sudhakar Ramakrishna in his Orange Matter blog, Our Plan for a Safer SolarWinds and Customer Community, we are taking key steps to ensure the security and integrity of the software that we deliver to customers.


All new hotfixes and patches we have released since SUNBURST was detected have undergone these new levels of scrutiny. SolarWinds is increasing existing actions and taking additional actions across the enterprise to further harden and improve the security of our environment and products:


Orion Platform versions 2019.4.2 and 2020.2.4 were designed to protect you from both the SUNBURST vulnerability and the SUPERNOVA malware and have been re-signed with our newly obtained digital-signing certificate.


To get started, please review the Security Advisory page on our website, as we update it with the latest information. Next, determine if your environment is at risk by verifying the version of the Orion Platform you have installed here, and verify which hotfix updates you have installed here.


Since the cyberattack on our customers and SolarWinds, we've worked around the clock to support our customers. As we shared in our recent update, we're partnering with multiple industry-leading cybersecurity experts to strengthen our systems, further enhance our product development processes, and adapt the ways that we deliver powerful, affordable, and secure solutions to our customers. Read more on the latest findings from our investigation of SUNBURST here.


We have retained third-party cybersecurity experts to assist in an investigation of these matters, including whether a vulnerability in the Orion Platform products was exploited as a point of any infiltration of customer systems, and in the development of appropriate mitigation and remediation plans. SolarWinds is cooperating and sharing information with partners, vendors, law enforcement, and the intelligence and government agencies around the world to assist in investigations related to this incident.

3a8082e126
Reply all
Reply to author
Forward
0 new messages