Skip to content

Update NAS FSA Unity Security Event Log configuration docs - #1418

Open
nwnikacc wants to merge 6 commits into
devfrom
pt4/nb/update-na-fsa-unity-log
Open

Update NAS FSA Unity Security Event Log configuration docs#1418
nwnikacc wants to merge 6 commits into
devfrom
pt4/nb/update-na-fsa-unity-log

Conversation

@nwnikacc

Copy link
Copy Markdown
Contributor

Summary

  • Expand the Security Event Log configuration procedure (10.7-10.9) to cover file path, maximum size, and retention, plus verification steps via Computer Management
  • Fix grammar and spelling issues in the affected pages

References

Test plan

  • Verify rendered pages for 10.7, 10.8, and 10.9 build correctly
  • Confirm steps match the actual NAS FSA Unity log configuration flow

Generated with AI

Co-Authored-By: Claude Code ai@netwrix.com

Expand the procedure to cover file path, maximum size, and retention
across 10.7-10.9, add verification steps via Computer Management, and
fix grammar/spelling issues.

Generated with AI

Co-Authored-By: Claude Code <ai@netwrix.com>
@nwnikacc
nwnikacc requested a review from a team as a code owner August 24, 2026 17:03
@github-actions

Copy link
Copy Markdown
Contributor

Auto-Fix Summary

18 issues fixed, 6 skipped across 3 files

Category Fixes
Substitutions 3
FollowTheStepsTo (rewrite) 3
Dale: misplaced-modifiers 3
Dale: passive-voice 3
Dale: wordiness 3
Dale: xy-slop 3
Skipped (needs manual review) Reason

| docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md:16 — Dale: passive-voice | 'On the computer where Auditor Server is installed' is established repo-wide phrasing (203 occurrences across 166 Auditor files). Changing it only here would break the Consistency standard; also on line 32. |
| docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md:14 — Dale: undefined-acronyms | DPA is product-specific and undefined here, but the intended expansion is ambiguous in this Dell Unity/Unisphere context. Expanding it incorrectly would introduce a factual error. |
| docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md:16 — Dale: passive-voice | 'On the computer where Auditor Server is installed' is established repo-wide phrasing (203 occurrences across 166 Auditor files). Changing it only here would break the Consistency standard; also on line 32. |
| docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md:14 — Dale: undefined-acronyms | DPA is product-specific and undefined here, but the intended expansion is ambiguous in this Dell Unity/Unisphere context. Expanding it incorrectly would introduce a factual error. |
| docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md:16 — Dale: passive-voice | 'On the computer where Auditor Server is installed' is established repo-wide phrasing (203 occurrences across 166 Auditor files). Changing it only here would break the Consistency standard; also on line 32. |
| docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md:14 — Dale: undefined-acronyms | DPA is product-specific and undefined here, but the intended expansion is ambiguous in this Dell Unity/Unisphere context. Expanding it incorrectly would introduce a factual error. |

Ask @claude on this PR if you'd like an explanation of any fix.

Propagate the 10.9 Security Event Log rewrite to 10.7 and 10.8, and fix
inbound links in overview.md/objectaccess.md that still used the old
"Configure Security Event Log Maximum Size" title as link text.

Generated with AI

Co-Authored-By: Claude Code <ai@netwrix.com>
@github-actions

Copy link
Copy Markdown
Contributor

Auto-Fix Summary

81 issues fixed, 9 skipped across 9 files

Category Fixes
FollowTheStepsTo (rewrite) 3
OxfordComma (rewrite) 6
ReferToTheFollowing (rewrite) 3
Dale: misplaced-modifiers 3
Dale: passive-voice 54
Dale: wordiness 12
Skipped (needs manual review) Reason

| docs/auditor/10.7/configuration/fileservers/delldatastorage/overview.md:15 — Dale: passive-voice | 'Proper audit configuration is required to ensure audit data integrity' — any active rewrite either invents an actor or downgrades the requirement to a plain statement of fact |
| docs/auditor/10.7/configuration/fileservers/delldatastorage/overview.md:34 — Dale: passive-voice | 'CIFS Network Protocol support is required' — unclear whether the reader must enable support or whether the device must already have it; an active rewrite would assert one reading |
| docs/auditor/10.7/configuration/fileservers/delldatastorage/overview.md:79 — Dale: wordiness | 'additional information on how to set logs roll over manually' — source phrasing is ambiguous; can't rewrite without guessing the intended meaning |
| docs/auditor/10.8/configuration/fileservers/delldatastorage/overview.md:15 — Dale: passive-voice | 'Proper audit configuration is required to ensure audit data integrity' — any active rewrite either invents an actor or downgrades the requirement to a plain statement of fact |
| docs/auditor/10.8/configuration/fileservers/delldatastorage/overview.md:34 — Dale: passive-voice | 'CIFS Network Protocol support is required' — unclear whether the reader must enable support or whether the device must already have it; an active rewrite would assert one reading |
| docs/auditor/10.8/configuration/fileservers/delldatastorage/overview.md:79 — Dale: wordiness | 'additional information on how to set logs roll over manually' — source phrasing is ambiguous; can't rewrite without guessing the intended meaning |
| docs/auditor/10.9/configuration/fileservers/delldatastorage/overview.md:15 — Dale: passive-voice | 'Proper audit configuration is required to ensure audit data integrity' — any active rewrite either invents an actor or downgrades the requirement to a plain statement of fact |
| docs/auditor/10.9/configuration/fileservers/delldatastorage/overview.md:34 — Dale: passive-voice | 'CIFS Network Protocol support is required' — unclear whether the reader must enable support or whether the device must already have it; an active rewrite would assert one reading |
| docs/auditor/10.9/configuration/fileservers/delldatastorage/overview.md:79 — Dale: wordiness | 'additional information on how to set logs roll over manually' — source phrasing is ambiguous; can't rewrite without guessing the intended meaning |

Ask @claude on this PR if you'd like an explanation of any fix.

… log docs

Fixes structure, arrow/dash consistency, code formatting, and completeness
gaps flagged in PR #1418 review (intro, headings, verification steps,
NOTE-to-admonition conversion). Leaves the mount-point step and 4GiB/4GB
unit conflict untouched per author request.
@github-actions

Copy link
Copy Markdown
Contributor

Documentation PR Review

Editorial Review

This PR applies the same rewrite across three Auditor versions (10.7, 10.8, 10.9). The findings below are detailed once against the 10.7 files and then referenced for 10.8 and 10.9, with one version-specific difference called out on 10.9.

The rewrite is a clear improvement — active voice, real registry values, and a verification section the old topic lacked. The issues below are mostly about the seams the expansion opened up.


docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md

  • Completeness — Line 13: The old Step 2 ("Mount this file system on a mount point, e.g., /events") was dropped, but Step 6 still sets the File value to C:\events\security.evt. A reader who creates a file system named events in the Dell Web UI is never told how it becomes reachable at C:\events on the Data Mover. This is the one gap most likely to leave someone with a non-functional configuration. Suggested fix: restore a mount step after Step 1 — "Mount the new file system at /events. The Data Mover exposes this mount point to Windows as C:\events."

  • Structure — Line 11: The heading reads "…in Registry Editor," but Steps 1 and 2 happen in the Dell Web UI and against a file share — not in Registry Editor. Line 9 repeats the same framing ("Configure the settings in Registry Editor, then verify them…"), so a reader who only skims headings will not expect device-side work. Suggested fix: either split into "Create the file system for the security log" (Steps 1–2) and "Configure Event Log values in Registry Editor" (Steps 3–8), or rename the heading to "Configure the Event Log path, maximum size, and retention."

  • Completeness — Line 33: The two alternatives given are not equivalent. compmgmt.msc /computer=<file_server_name> targets the file server, while "right-click Start and select Computer Management" opens the console against the local computer. A reader who takes the second path will inspect the Auditor Server's own Security log in Step 2 and see values that never match. Suggested fix: drop the local alternative, or make the remote connection explicit — "…or right-click Start, select Computer Management, then right-click Computer Management (Local) and select Connect to another computer to specify <file_server_name>."

  • Structure — Line 37: Verification Step 3 bundles three separate checks plus a remediation instruction into a single step, which conflicts with the Netwrix "one action per step" rule. Suggested fix: convert to a checklist — "Step 3 – Confirm the following values:" followed by bullets for Log name (C:\events\security.evt), Maximum log size (4,194,240 KB), and Overwrite events as needed (selected), then a closing sentence for the "if any value doesn't match" remediation.

  • Clarity — Line 15: "the account used for data collection" is not defined anywhere in this topic, and this is the first mention. Newer readers won't know which account that is. Suggested fix: "Confirm that the account specified for data collection in the monitoring plan can read the share at \\<file_server_name>\C$\events."

  • Clarity — Line 48: "Registry Editor displays Maximum log size in bytes" attributes a Security Properties field name to Registry Editor, which has no such field — it has MaxSize. Suggested fix: "The MaxSize registry value is expressed in bytes, while Maximum log size in Security Properties is expressed in KB."

  • Clarity — Line 28: "(hex or decimal)" reads as an unexplained choice rather than the point being made, which is that zero is identical in both bases. Suggested fix: "Set the Retention value to 0. The value is the same in hexadecimal and decimal. This configures the log to overwrite events as needed instead of retaining them."

  • Structure — Lines 9, 13, 15, 26, 28, 33, 37: The new lines run to 150+ characters, while the surrounding retained content in this and the sibling files wraps at roughly 100. Suggested fix: rewrap the added lines to match the file's existing width.

docs/auditor/10.7/configuration/fileservers/delldatastorage/overview.md

  • Clarity — Line 74: "…to set the log path, maximum size, and retention so that security events aren't overwritten" contradicts both the sentence that follows it ("the log starts overwriting when it goes beyond the limit") and the linked topic itself, which sets Retention = 0 — that is, overwrite events as needed. The stated goal is capacity, not preventing overwrites. Suggested fix: "…to set the log path, maximum size, and retention so that the log holds enough events between data collections."

  • Structure — Lines 80–83: Step 2 contains no action — it explains the default log size and location, which is the rationale for Step 1 rather than a step that follows it. A reader working top to bottom completes Step 1 (which already relocates the log to C:\events) and then reads that they "must move it from the Data Mover root folder." Suggested fix: move this paragraph above Step 1 as unnumbered context and renumber the remaining steps.

  • Completeness — Line 35: "Set Security Event Log Maximum Size to 4GB" no longer matches the topic it summarizes. The linked topic now specifies 4294901760 bytes (4 GiB minus 64 KB) and no longer uses "Security Event Log Maximum Size" as a title. Suggested fix: "Set the security event log maximum size to 4 GB (4294901760 bytes)." — and confirm the unit matches whatever the securityeventlog topic settles on (see the 10.9 note below).

  • Clarity — Line 62: "native Dell audit peculiarities" is vague — it tells the reader that results may differ without telling them why or what to expect. Suggested fix: "…may not provide the results you expect, because Dell's native auditing does not record every action Auditor can report on."

  • Structure — Lines 9 and 18: Both rewritten lines keep the legacy **NOTE:** / **CAUTION:** bold-prefix pattern rather than Docusaurus admonitions. Since both lines were already being rewritten, this is a low-cost opportunity to bring them in line with the documented standard. Suggested fix: convert to :::note and :::warning blocks. (Optional — this pattern is consistent with the rest of the Auditor set, so leaving it is defensible.)

docs/auditor/10.7/configuration/fileservers/delldatastorage/objectaccess.md

  • Structure — Line 12: Removing "Follow the steps to configure Audit Object Access Policy:" leaves the reader dropping from a recommendation about where to link the GPO straight into Step 1 with no signal that a procedure has started. The removed sentence was redundant with the H1, but something has to mark the transition. Suggested fix: open the topic with a one-sentence purpose statement — "Configure the Audit object access policy on the OU that contains your Dell Data Storage appliance." — and keep the GPO placement recommendation as the second paragraph.

  • Clarity — Line 51: "the range of events the product tracks and records" — "the product" is indirect where the file names Auditor elsewhere. Suggested fix: "…to narrow the range of events Auditor tracks and records."

  • Clarity — Line 49: 'nasadmin' uses straight quotes for what is a literal account name. Suggested fix: format as code — "you must log in as the nasadmin user."

docs/auditor/10.8/configuration/fileservers/delldatastorage/objectaccess.md
docs/auditor/10.8/configuration/fileservers/delldatastorage/overview.md
docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md

  • Identical to the 10.7 files. All findings above apply at the same line numbers.

docs/auditor/10.9/configuration/fileservers/delldatastorage/objectaccess.md
docs/auditor/10.9/configuration/fileservers/delldatastorage/overview.md

  • Identical to the 10.7 files. All findings above apply at the same line numbers.

docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md

  • Completeness — Line 13: This version specifies "at least 4 GB" where 10.7 and 10.8 specify "at least 4 GiB" — the three versions describe the same procedure with different units. 4 GB (4,000,000,000 bytes) is smaller than the 4,294,901,760-byte MaxSize set in Step 7, so a reader following the 10.9 text sizes the file system below the configured log maximum. Suggested fix: use "at least 4 GiB" in all three versions to match Step 7, or state the byte figure directly — "set its size to at least 4.3 GB (4294901760 bytes)."

  • All other 10.7 findings apply at the same line numbers.

Summary

15 editorial suggestions across 9 files (12 distinct issues, most repeated across all three versions). The highest-impact items are the dropped mount step in securityeventlog.md line 13, the non-equivalent Computer Management alternatives on line 33, the overwrite contradiction in overview.md line 74, and the 4 GB / 4 GiB mismatch in the 10.9 file. Vale and Dale issues are auto-fixed separately.


What to do next:

Comment @claude on this PR followed by your instructions to get help:

  • @claude fix all issues — fix all editorial issues
  • @claude help improve the flow of this document — get writing assistance
  • @claude explain the voice issues — understand why something was flagged

You can ask Claude anything about the review or about Netwrix writing standards.

Automated fixes are only available for branches in this repository, not forks.

@github-actions

Copy link
Copy Markdown
Contributor

Auto-Fix Summary

24 issues fixed, 10 skipped across 9 files

Category Fixes
Contractions 3
Dale: passive-voice 18
Dale: wordiness 3
Skipped (needs manual review) Reason

| docs/auditor/10.7/configuration/fileservers/delldatastorage/overview.md:15 — Dale: passive-voice | 'Proper audit configuration is required to ensure audit data integrity' is shared boilerplate repeated verbatim across every Auditor file server configuration topic; rewording it only here would diverge from the parallel topics |
| docs/auditor/10.8/configuration/fileservers/delldatastorage/overview.md:15 — Dale: passive-voice | 'Proper audit configuration is required to ensure audit data integrity' is shared boilerplate repeated verbatim across every Auditor file server configuration topic; rewording it only here would diverge from the parallel topics |
| docs/auditor/10.9/configuration/fileservers/delldatastorage/overview.md:15 — Dale: passive-voice | 'Proper audit configuration is required to ensure audit data integrity' is shared boilerplate repeated verbatim across every Auditor file server configuration topic; rewording it only here would diverge from the parallel topics |
| docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md:37 — Dale: passive-voice | 'Overwrite events as needed is selected' describes the state of a Windows UI checkbox the reader is verifying, not an action; any active rewrite would misattribute the agent or change what the reader is asked to confirm |
| docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md:37 — Dale: passive-voice | 'Overwrite events as needed is selected' describes the state of a Windows UI checkbox the reader is verifying, not an action; any active rewrite would misattribute the agent or change what the reader is asked to confirm |
| docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md:37 — Dale: passive-voice | 'Overwrite events as needed is selected' describes the state of a Windows UI checkbox the reader is verifying, not an action; any active rewrite would misattribute the agent or change what the reader is asked to confirm |
| docs/auditor/10.7/configuration/fileservers/delldatastorage/overview.md:37 — Dale: passive-voice | 'the audited Dell VNX/VNXe/Unity/Celerra appliance' and similar 'audited' modifiers are established product terminology throughout the Auditor docs |
| docs/auditor/10.7/configuration/fileservers/delldatastorage/objectaccess.md:52 — Dale: misplaced-modifiers | 'preventing your AuditArchive and the Security event log from overfilling' reads as a result clause attached to the whole action, which is the intended meaning; unchanged pre-existing text |
| docs/auditor/10.8/configuration/fileservers/delldatastorage/objectaccess.md:52 — Dale: misplaced-modifiers | 'preventing your AuditArchive and the Security event log from overfilling' reads as a result clause attached to the whole action, which is the intended meaning; unchanged pre-existing text |
| docs/auditor/10.9/configuration/fileservers/delldatastorage/objectaccess.md:52 — Dale: misplaced-modifiers | 'preventing your AuditArchive and the Security event log from overfilling' reads as a result clause attached to the whole action, which is the intended meaning; unchanged pre-existing text |

Ask @claude on this PR if you'd like an explanation of any fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants