diff --git a/docs/auditor/10.7/configuration/fileservers/delldatastorage/objectaccess.md b/docs/auditor/10.7/configuration/fileservers/delldatastorage/objectaccess.md index 9df7b2d40e..7df3821798 100644 --- a/docs/auditor/10.7/configuration/fileservers/delldatastorage/objectaccess.md +++ b/docs/auditor/10.7/configuration/fileservers/delldatastorage/objectaccess.md @@ -6,14 +6,13 @@ sidebar_position: 30 # Configure Audit Object Access Policy -Netwrixrecommends you to avoid linking a GPO to the top level of the domain due to the potential +Configure the Audit object access policy on the OU that contains your Dell Data Storage appliance. + +Netwrix recommends that you avoid linking a GPO to the top level of the domain due to the potential impact. Instead, create a new organization unit for your file servers within your domain and assign -GPO there. For detailed instructions on how to create a new OU, refer to the following Microsoft -article: +GPO there. For instructions on creating a new OU, see the Microsoft article [Create a New Organizational Unit](https://technet.microsoft.com/en-us/library/cc771564.aspx). -Follow the steps to configure Audit Object Access Policy: - **Step 1 –** Open the **Group Policy Management** console on any domain controller in the target domain: navigate to Start > Windows Administrative Tools**→ Group Policy Management.** @@ -49,8 +48,8 @@ node on the left and navigate to **Policies → Windows Settings → Security Se where `` is the name of the target Unity\VNX server. - To update group policies for Dell VNX you must be logged in as the 'nasadmin' user. + To update group policies for Dell VNX, you must log in as the `nasadmin` user. -You can configure advanced audit policy to narrow the range of events tracked and recorded by the -product, thus preventing your AuditArchive and the Security event log from overfilling. See the -[Configure Security Event Log Maximum Size](/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md) topic for additional information. +You can configure advanced audit policy to narrow the range of events Auditor tracks and +records. This prevents your AuditArchive and the Security event log from overfilling. See the +[Configure Security Event Log](/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md) topic for additional information. diff --git a/docs/auditor/10.7/configuration/fileservers/delldatastorage/overview.md b/docs/auditor/10.7/configuration/fileservers/delldatastorage/overview.md index 0f93beaf94..e0ee813503 100644 --- a/docs/auditor/10.7/configuration/fileservers/delldatastorage/overview.md +++ b/docs/auditor/10.7/configuration/fileservers/delldatastorage/overview.md @@ -6,37 +6,39 @@ sidebar_position: 10 # Dell Data Storage -**NOTE:** Dell VNX, VNXe, Celerra, and Unity NAS devices are collectively referred to as Dell Data -Storage. +:::note +Dell Data Storage collectively refers to Dell VNX, VNXe, Celerra, and Unity NAS devices. +::: Netwrix Auditor relies on native logs for collecting audit data. Therefore, successful change and access auditing requires a certain configuration of native audit settings in the audited environment and on the Auditor console computer. Configuring your IT infrastructure may also include enabling -certain built-in Windows services, etc. Proper audit configuration is required to ensure audit data -integrity, otherwise your change reports may contain warnings, errors or incomplete audit data. +certain built-in Windows services, etc. You must configure auditing properly to ensure audit data +integrity; otherwise, your change reports may contain warnings, errors, or incomplete audit data. -**CAUTION:** Folder associated with Netwrix Auditor must be excluded from antivirus scanning. See -the +:::warning +You must exclude the folder associated with Netwrix Auditor from antivirus scanning. See the [Antivirus Exclusions for Netwrix Auditor](/docs/kb/auditor/system-administration/security-hardening/antivirus-exclusions-for-netwrix-auditor) knowledge base article for additional information. +::: You can configure your IT Infrastructure for monitoring in one of the following ways: - Automatically through a monitoring plan – This is a recommended method. If you select to - automatically configure audit in the target environment, your current audit settings will be - checked on each data collection and adjusted if necessary. -- Manually – Native audit settings must be adjusted manually to ensure collecting comprehensive and - reliable audit data. You can enable Auditor to continually enforce the relevant audit policies or + automatically configure audit in the target environment, Auditor checks your current audit + settings on each data collection and adjusts them if necessary. +- Manually – You must adjust native audit settings manually to collect comprehensive and reliable + audit data. You can enable Auditor to continually enforce the relevant audit policies or configure them manually: - On the Dell Data Storage device: - - CIFS Network Protocol support is required - - Security Event Log Maximum Size must be set to 4GB. - - The Audit object access policy must be set to _"Success"_ and "Failure" in the Group - Policy of the OU where the audited Dell VNX/VNXe/Unity/Celerra appliance belongs to. - - Audit settings must be configured for CIFS File Shares. For a security principal (e.g., - Everyone), the following options must be set to "Success" and "Fail" in the **Advanced + - Enable CIFS Network Protocol support. + - Set the security event log maximum size to 4 GiB (4294901760 bytes). + - Set the Audit object access policy to _"Success"_ and "Failure" in the Group Policy of + the OU that contains the audited Dell VNX/VNXe/Unity/Celerra appliance. + - Configure audit settings for CIFS File Shares. For a security principal (e.g., + Everyone), set the following options to "Success" and "Fail" in the **Advanced Security** > **Auditing** settings for the audited shared folders: - List Folder / Read Data (Files only) @@ -52,16 +54,17 @@ You can configure your IT Infrastructure for monitoring in one of the following - On the Auditor console computer: - If your file shares contain symbolic links and you want to collect state-in-time data for - these shares, the local-to-local, local-to-remote, remote-to-local, and remote-to-remote - symbolic link evaluations must be enabled on the computer that hosts Auditor Server. + these shares, you must enable the local-to-local, local-to-remote, remote-to-local, and + remote-to-remote symbolic link evaluations on the computer that hosts Auditor Server. -First, you should decide on the objects and actions you want to track. Consider the following: +First, decide on the objects and actions you want to track. Consider the following: -- Actions reported by Auditor vary depending on the file server type and the audited object (file, +- The actions Auditor reports vary depending on the file server type and the audited object (file, folder, or share). -- Besides, monitoring and reporting of the Dell Data Storage systems may not provide the results you - expect — due to native Dell audit peculiarities. See the [File Servers](/docs/auditor/10.7/configuration/fileservers/overview.md) topic for - additional information. +- Monitoring and reporting of the Dell Data Storage systems may not provide the results you expect, + because Dell's native auditing doesn't record every action Auditor can report on. See the + [File Servers](/docs/auditor/10.7/configuration/fileservers/overview.md) topic for additional + information. For example, the _change_ operation (in Auditor terminology) includes creation, modification, and deletion. @@ -71,21 +74,20 @@ deletion. To collect comprehensive audit data, you must configure your file shares for monitoring. Consider the following: -**Step 1 –** [Configure Security Event Log Maximum Size](/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md) to avoid overwriting -of the security logs; it is recommended to set security log size to a maximum (4GB). Auditor does -not clean Dell Unity logs automatically, the log will start overwriting when it goes beyond the +By default, the security log overwrites events older than 10 days, and its size is 512 KB. The +default location for the security.evt log is **C:\security.evt**, which corresponds to the root +partition of the Data Mover. To increase the security log size, you must move it from the Data +Mover root folder. + +**Step 1 –** [Configure Security Event Log](/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md) to set the log path, maximum size, and retention so that the log holds enough events between data collections. Auditor +doesn't clean Dell Unity logs automatically, so the log starts overwriting when it exceeds the limit. See the [Unity Family Security Configuration Guide](https://support.emc.com/docu69321_Unity-Family-Security-Configuration-Guide.pdf?language=en_US) for -additional information on how to set logs roll over manually. - -**Step 2 –** By default, the security log is set to overwrite events that are older than 10 days, -and its size is set to 512 KB. The default location for the security.evt log is **C:\security.evt**, -which corresponds to the root partition of the Data Mover. To be able to increase the security log -size, you must move it from the Data Mover root folder. +additional information about configuring log rollover manually. -**Step 3 –** [Configure Audit Object Access Policy](/docs/auditor/10.7/configuration/fileservers/delldatastorage/objectaccess.md). Set the Audit object access -policy to "Success" and "Failure" in the Group Policy of the OU where your Dell -VNX/VNXe/Unity/Celerra appliance belongs to. For more information on VNX/VNXe/Unity/Celerra GPO -support, refer to documentation provided by Dell. +**Step 2 –** [Configure Audit Object Access Policy](/docs/auditor/10.7/configuration/fileservers/delldatastorage/objectaccess.md). Set the Audit object access +policy to "Success" and "Failure" in the Group Policy of the OU that contains your Dell +VNX/VNXe/Unity/Celerra appliance. For more information on VNX/VNXe/Unity/Celerra GPO support, refer +to the documentation Dell provides. -**Step 4 –** [Configure Audit Settings for CIFS File Shares on Dell Data Storage](/docs/auditor/10.7/configuration/fileservers/delldatastorage/cifss.md) +**Step 3 –** [Configure Audit Settings for CIFS File Shares on Dell Data Storage](/docs/auditor/10.7/configuration/fileservers/delldatastorage/cifss.md) diff --git a/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md b/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md index ec3ee353a8..e2ec500e4c 100644 --- a/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md +++ b/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md @@ -1,25 +1,75 @@ --- -title: "Configure Security Event Log Maximum Size" -description: "Configure Security Event Log Maximum Size" +title: "Configure Security Event Log" +description: "Configure Security Event Log path, maximum size, and retention on Dell Data Storage devices" sidebar_position: 20 --- -# Configure Security Event Log Maximum Size +# Configure Security Event Log -Follow the steps to configure Event Log maximum size: +Configure the security event log path, maximum size, and retention on your Dell Data +Storage device so that you don't lose audit data when the log fills. Create the file +system in the Dell Web UI, configure the registry values in Registry Editor, then +verify them in the Computer Management console. -**Step 1 –** On your file server, create a new file system where the security log will be stored. +## Create the file system for the security log -**Step 2 –** Mount this file system on a mount point, e.g., **/events**. +**Step 1 –** In the Dell **Web UI**, navigate to **Storage → File → File System** and +click **+** to create a file system. Name it `events` and set its size to at least +4 GiB. This file system stores the security log. -**Step 3 –** Make sure that it is accessible via the **\\``\C$\events** UNC path. +**Step 2 –** Confirm that the account you specified for data collection in the +monitoring plan can read the share at `\\\C$\events`. -**Step 4 –** On the computer where Auditor Server is installed, open **Registry Editor**: navigate -to **Start → Run** and type _"regedit"_. +## Configure Event Log values in Registry Editor -**Step 5 –** Navigate to **File → Connect Network Registry** and specify the file server name. +**Step 1 –** On the computer that hosts Auditor Server, open **Registry Editor**: +navigate to **Start → Run** and type `regedit`. -**Step 6 –** Navigate to **HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security** -and set the **File** value to _"C:\events\security.evt"_. +**Step 2 –** Navigate to **File → Connect Network Registry** and specify +``. -**Step 7 –** Set the **MaxSize** value to _"4 000 000 000 (decimal)"_. +**Step 3 –** Navigate to +**HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security**. + +**Step 4 –** Set the **File** value to `C:\events\security.evt`. + +**Step 5 –** Set the **MaxSize** value to `ffff0000` (hexadecimal) or `4294901760` +(decimal). Select the matching **Base** option in the **Edit DWORD Value** dialog +before you enter the value. + +**Step 6 –** Set the **Retention** value to `0`. The value is the same in +hexadecimal and decimal. This configures the log to overwrite events as needed +instead of retaining them. + +## Verify Event Log settings in the Computer Management console + +**Step 1 –** On the computer that hosts Auditor Server, open **Computer Management**: +navigate to **Start → Run** and type `compmgmt.msc /computer=`. +Alternatively, right-click **Start**, select **Computer Management**, then right-click +**Computer Management (Local)**, select **Connect to another computer**, and specify +``. + +**Step 2 –** Navigate to **System Tools → Event Viewer → Windows Logs**, then +right-click **Security** and select **Properties**. + +**Step 3 –** Confirm the following values: + +- **Log name**: `\\\C$\events\security.evt` +- **Maximum log size**: `4,194,240 KB` +- **Overwrite events as needed**: selected + +If any value doesn't match, correct it in **Registry Editor** and reopen this dialog. + +:::note +The **Security Properties** dialog fields map to the following registry values: + +| Security Properties field | Registry value | +|---|---| +| Log name | `File` | +| Maximum log size | `MaxSize` (`4,294,901,760 bytes = 4,194,240 KB`) | +| Overwrite events as needed | `Retention = 0` | + +The MaxSize registry value uses bytes, while Maximum log size in Security Properties +uses KB. You can't change **Log name** from the **Security +Properties** dialog — use **Registry Editor** instead. +::: diff --git a/docs/auditor/10.8/configuration/fileservers/delldatastorage/objectaccess.md b/docs/auditor/10.8/configuration/fileservers/delldatastorage/objectaccess.md index fb700bc191..0b3c7e9e52 100644 --- a/docs/auditor/10.8/configuration/fileservers/delldatastorage/objectaccess.md +++ b/docs/auditor/10.8/configuration/fileservers/delldatastorage/objectaccess.md @@ -6,14 +6,13 @@ sidebar_position: 30 # Configure Audit Object Access Policy -Netwrix recommends you to avoid linking a GPO to the top level of the domain due to the potential +Configure the Audit object access policy on the OU that contains your Dell Data Storage appliance. + +Netwrix recommends that you avoid linking a GPO to the top level of the domain due to the potential impact. Instead, create a new organization unit for your file servers within your domain and assign -GPO there. For detailed instructions on how to create a new OU, refer to the following Microsoft -article: +GPO there. For instructions on creating a new OU, see the Microsoft article [Create a New Organizational Unit](https://technet.microsoft.com/en-us/library/cc771564.aspx). -Follow the steps to configure Audit Object Access Policy: - **Step 1 –** Open the **Group Policy Management** console on any domain controller in the target domain: navigate to Start > Windows Administrative Tools**→ Group Policy Management.** @@ -49,8 +48,8 @@ node on the left and navigate to **Policies → Windows Settings → Security Se where `` is the name of the target Unity\VNX server. - To update group policies for Dell VNX you must be logged in as the 'nasadmin' user. + To update group policies for Dell VNX, you must log in as the `nasadmin` user. -You can configure advanced audit policy to narrow the range of events tracked and recorded by the -product, thus preventing your AuditArchive and the Security event log from overfilling. See the -[Configure Security Event Log Maximum Size](/docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md) topic for additional information. +You can configure advanced audit policy to narrow the range of events Auditor tracks and +records. This prevents your AuditArchive and the Security event log from overfilling. See the +[Configure Security Event Log](/docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md) topic for additional information. diff --git a/docs/auditor/10.8/configuration/fileservers/delldatastorage/overview.md b/docs/auditor/10.8/configuration/fileservers/delldatastorage/overview.md index 6d763ac158..3ff55baf12 100644 --- a/docs/auditor/10.8/configuration/fileservers/delldatastorage/overview.md +++ b/docs/auditor/10.8/configuration/fileservers/delldatastorage/overview.md @@ -6,37 +6,39 @@ sidebar_position: 10 # Dell Data Storage -**NOTE:** Dell VNX, VNXe, Celerra, and Unity NAS devices are collectively referred to as Dell Data -Storage. +:::note +Dell Data Storage collectively refers to Dell VNX, VNXe, Celerra, and Unity NAS devices. +::: Netwrix Auditor relies on native logs for collecting audit data. Therefore, successful change and access auditing requires a certain configuration of native audit settings in the audited environment and on the Auditor console computer. Configuring your IT infrastructure may also include enabling -certain built-in Windows services, etc. Proper audit configuration is required to ensure audit data -integrity, otherwise your change reports may contain warnings, errors or incomplete audit data. +certain built-in Windows services, etc. You must configure auditing properly to ensure audit data +integrity; otherwise, your change reports may contain warnings, errors, or incomplete audit data. -**CAUTION:** Folder associated with Netwrix Auditor must be excluded from antivirus scanning. See -the +:::warning +You must exclude the folder associated with Netwrix Auditor from antivirus scanning. See the [Antivirus Exclusions for Netwrix Auditor](/docs/kb/auditor/system-administration/security-hardening/antivirus-exclusions-for-netwrix-auditor) knowledge base article for additional information. +::: You can configure your IT Infrastructure for monitoring in one of the following ways: - Automatically through a monitoring plan – This is a recommended method. If you select to - automatically configure audit in the target environment, your current audit settings will be - checked on each data collection and adjusted if necessary. -- Manually – Native audit settings must be adjusted manually to ensure collecting comprehensive and - reliable audit data. You can enable Auditor to continually enforce the relevant audit policies or + automatically configure audit in the target environment, Auditor checks your current audit + settings on each data collection and adjusts them if necessary. +- Manually – You must adjust native audit settings manually to collect comprehensive and reliable + audit data. You can enable Auditor to continually enforce the relevant audit policies or configure them manually: - On the Dell Data Storage device: - - CIFS Network Protocol support is required - - Security Event Log Maximum Size must be set to 4GB. - - The Audit object access policy must be set to _"Success"_ and "Failure" in the Group - Policy of the OU where the audited Dell VNX/VNXe/Unity/Celerra appliance belongs to. - - Audit settings must be configured for CIFS File Shares. For a security principal (e.g., - Everyone), the following options must be set to "Success" and "Fail" in the **Advanced + - Enable CIFS Network Protocol support. + - Set the security event log maximum size to 4 GiB (4294901760 bytes). + - Set the Audit object access policy to _"Success"_ and "Failure" in the Group Policy of + the OU that contains the audited Dell VNX/VNXe/Unity/Celerra appliance. + - Configure audit settings for CIFS File Shares. For a security principal (e.g., + Everyone), set the following options to "Success" and "Fail" in the **Advanced Security** > **Auditing** settings for the audited shared folders: - List Folder / Read Data (Files only) @@ -52,16 +54,17 @@ You can configure your IT Infrastructure for monitoring in one of the following - On the Auditor console computer: - If your file shares contain symbolic links and you want to collect state-in-time data for - these shares, the local-to-local, local-to-remote, remote-to-local, and remote-to-remote - symbolic link evaluations must be enabled on the computer that hosts Auditor Server. + these shares, you must enable the local-to-local, local-to-remote, remote-to-local, and + remote-to-remote symbolic link evaluations on the computer that hosts Auditor Server. -First, you should decide on the objects and actions you want to track. Consider the following: +First, decide on the objects and actions you want to track. Consider the following: -- Actions reported by Auditor vary depending on the file server type and the audited object (file, +- The actions Auditor reports vary depending on the file server type and the audited object (file, folder, or share). -- Besides, monitoring and reporting of the Dell Data Storage systems may not provide the results you - expect — due to native Dell audit peculiarities. See the [File Servers](/docs/auditor/10.8/configuration/fileservers/overview.md) topic for - additional information. +- Monitoring and reporting of the Dell Data Storage systems may not provide the results you expect, + because Dell's native auditing doesn't record every action Auditor can report on. See the + [File Servers](/docs/auditor/10.8/configuration/fileservers/overview.md) topic for additional + information. For example, the _change_ operation (in Auditor terminology) includes creation, modification, and deletion. @@ -71,21 +74,20 @@ deletion. To collect comprehensive audit data, you must configure your file shares for monitoring. Consider the following: -**Step 1 –** [Configure Security Event Log Maximum Size](/docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md) to avoid overwriting -of the security logs; it is recommended to set security log size to a maximum (4GB). Auditor does -not clean Dell Unity logs automatically, the log will start overwriting when it goes beyond the +By default, the security log overwrites events older than 10 days, and its size is 512 KB. The +default location for the security.evt log is **C:\security.evt**, which corresponds to the root +partition of the Data Mover. To increase the security log size, you must move it from the Data +Mover root folder. + +**Step 1 –** [Configure Security Event Log](/docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md) to set the log path, maximum size, and retention so that the log holds enough events between data collections. Auditor +doesn't clean Dell Unity logs automatically, so the log starts overwriting when it exceeds the limit. See the [Unity Family Security Configuration Guide](https://support.emc.com/docu69321_Unity-Family-Security-Configuration-Guide.pdf?language=en_US) for -additional information on how to set logs roll over manually. - -**Step 2 –** By default, the security log is set to overwrite events that are older than 10 days, -and its size is set to 512 KB. The default location for the security.evt log is **C:\security.evt**, -which corresponds to the root partition of the Data Mover. To be able to increase the security log -size, you must move it from the Data Mover root folder. +additional information about configuring log rollover manually. -**Step 3 –** [Configure Audit Object Access Policy](/docs/auditor/10.8/configuration/fileservers/delldatastorage/objectaccess.md). Set the Audit object access -policy to "Success" and "Failure" in the Group Policy of the OU where your Dell -VNX/VNXe/Unity/Celerra appliance belongs to. For more information on VNX/VNXe/Unity/Celerra GPO -support, refer to documentation provided by Dell. +**Step 2 –** [Configure Audit Object Access Policy](/docs/auditor/10.8/configuration/fileservers/delldatastorage/objectaccess.md). Set the Audit object access +policy to "Success" and "Failure" in the Group Policy of the OU that contains your Dell +VNX/VNXe/Unity/Celerra appliance. For more information on VNX/VNXe/Unity/Celerra GPO support, refer +to the documentation Dell provides. -**Step 4 –** [Configure Audit Settings for CIFS File Shares on Dell Data Storage](/docs/auditor/10.8/configuration/fileservers/delldatastorage/cifss.md) +**Step 3 –** [Configure Audit Settings for CIFS File Shares on Dell Data Storage](/docs/auditor/10.8/configuration/fileservers/delldatastorage/cifss.md) diff --git a/docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md b/docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md index ec3ee353a8..e2ec500e4c 100644 --- a/docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md +++ b/docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md @@ -1,25 +1,75 @@ --- -title: "Configure Security Event Log Maximum Size" -description: "Configure Security Event Log Maximum Size" +title: "Configure Security Event Log" +description: "Configure Security Event Log path, maximum size, and retention on Dell Data Storage devices" sidebar_position: 20 --- -# Configure Security Event Log Maximum Size +# Configure Security Event Log -Follow the steps to configure Event Log maximum size: +Configure the security event log path, maximum size, and retention on your Dell Data +Storage device so that you don't lose audit data when the log fills. Create the file +system in the Dell Web UI, configure the registry values in Registry Editor, then +verify them in the Computer Management console. -**Step 1 –** On your file server, create a new file system where the security log will be stored. +## Create the file system for the security log -**Step 2 –** Mount this file system on a mount point, e.g., **/events**. +**Step 1 –** In the Dell **Web UI**, navigate to **Storage → File → File System** and +click **+** to create a file system. Name it `events` and set its size to at least +4 GiB. This file system stores the security log. -**Step 3 –** Make sure that it is accessible via the **\\``\C$\events** UNC path. +**Step 2 –** Confirm that the account you specified for data collection in the +monitoring plan can read the share at `\\\C$\events`. -**Step 4 –** On the computer where Auditor Server is installed, open **Registry Editor**: navigate -to **Start → Run** and type _"regedit"_. +## Configure Event Log values in Registry Editor -**Step 5 –** Navigate to **File → Connect Network Registry** and specify the file server name. +**Step 1 –** On the computer that hosts Auditor Server, open **Registry Editor**: +navigate to **Start → Run** and type `regedit`. -**Step 6 –** Navigate to **HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security** -and set the **File** value to _"C:\events\security.evt"_. +**Step 2 –** Navigate to **File → Connect Network Registry** and specify +``. -**Step 7 –** Set the **MaxSize** value to _"4 000 000 000 (decimal)"_. +**Step 3 –** Navigate to +**HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security**. + +**Step 4 –** Set the **File** value to `C:\events\security.evt`. + +**Step 5 –** Set the **MaxSize** value to `ffff0000` (hexadecimal) or `4294901760` +(decimal). Select the matching **Base** option in the **Edit DWORD Value** dialog +before you enter the value. + +**Step 6 –** Set the **Retention** value to `0`. The value is the same in +hexadecimal and decimal. This configures the log to overwrite events as needed +instead of retaining them. + +## Verify Event Log settings in the Computer Management console + +**Step 1 –** On the computer that hosts Auditor Server, open **Computer Management**: +navigate to **Start → Run** and type `compmgmt.msc /computer=`. +Alternatively, right-click **Start**, select **Computer Management**, then right-click +**Computer Management (Local)**, select **Connect to another computer**, and specify +``. + +**Step 2 –** Navigate to **System Tools → Event Viewer → Windows Logs**, then +right-click **Security** and select **Properties**. + +**Step 3 –** Confirm the following values: + +- **Log name**: `\\\C$\events\security.evt` +- **Maximum log size**: `4,194,240 KB` +- **Overwrite events as needed**: selected + +If any value doesn't match, correct it in **Registry Editor** and reopen this dialog. + +:::note +The **Security Properties** dialog fields map to the following registry values: + +| Security Properties field | Registry value | +|---|---| +| Log name | `File` | +| Maximum log size | `MaxSize` (`4,294,901,760 bytes = 4,194,240 KB`) | +| Overwrite events as needed | `Retention = 0` | + +The MaxSize registry value uses bytes, while Maximum log size in Security Properties +uses KB. You can't change **Log name** from the **Security +Properties** dialog — use **Registry Editor** instead. +::: diff --git a/docs/auditor/10.9/configuration/fileservers/delldatastorage/objectaccess.md b/docs/auditor/10.9/configuration/fileservers/delldatastorage/objectaccess.md index e26d0eb700..2b8b27d3a7 100644 --- a/docs/auditor/10.9/configuration/fileservers/delldatastorage/objectaccess.md +++ b/docs/auditor/10.9/configuration/fileservers/delldatastorage/objectaccess.md @@ -6,14 +6,13 @@ sidebar_position: 30 # Configure Audit Object Access Policy -Netwrix recommends you to avoid linking a GPO to the top level of the domain due to the potential +Configure the Audit object access policy on the OU that contains your Dell Data Storage appliance. + +Netwrix recommends that you avoid linking a GPO to the top level of the domain due to the potential impact. Instead, create a new organization unit for your file servers within your domain and assign -GPO there. For detailed instructions on how to create a new OU, refer to the following Microsoft -article: +GPO there. For instructions on creating a new OU, see the Microsoft article [Create a New Organizational Unit](https://technet.microsoft.com/en-us/library/cc771564.aspx). -Follow the steps to configure Audit Object Access Policy: - **Step 1 –** Open the **Group Policy Management** console on any domain controller in the target domain: navigate to Start > Windows Administrative Tools**→ Group Policy Management.** @@ -49,8 +48,8 @@ node on the left and navigate to **Policies → Windows Settings → Security Se where `` is the name of the target Unity\VNX server. - To update group policies for Dell VNX you must be logged in as the 'nasadmin' user. + To update group policies for Dell VNX, you must log in as the `nasadmin` user. -You can configure advanced audit policy to narrow the range of events tracked and recorded by the -product, thus preventing your AuditArchive and the Security event log from overfilling. See the -[Configure Security Event Log Maximum Size](/docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md) topic for additional information. +You can configure advanced audit policy to narrow the range of events Auditor tracks and +records. This prevents your AuditArchive and the Security event log from overfilling. See the +[Configure Security Event Log](/docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md) topic for additional information. diff --git a/docs/auditor/10.9/configuration/fileservers/delldatastorage/overview.md b/docs/auditor/10.9/configuration/fileservers/delldatastorage/overview.md index 77787cd96a..9244d6f936 100644 --- a/docs/auditor/10.9/configuration/fileservers/delldatastorage/overview.md +++ b/docs/auditor/10.9/configuration/fileservers/delldatastorage/overview.md @@ -6,37 +6,39 @@ sidebar_position: 10 # Dell Data Storage -**NOTE:** Dell VNX, VNXe, Celerra, and Unity NAS devices are collectively referred to as Dell Data -Storage. +:::note +Dell Data Storage collectively refers to Dell VNX, VNXe, Celerra, and Unity NAS devices. +::: Netwrix Auditor relies on native logs for collecting audit data. Therefore, successful change and access auditing requires a certain configuration of native audit settings in the audited environment and on the Auditor console computer. Configuring your IT infrastructure may also include enabling -certain built-in Windows services, etc. Proper audit configuration is required to ensure audit data -integrity, otherwise your change reports may contain warnings, errors or incomplete audit data. +certain built-in Windows services, etc. You must configure auditing properly to ensure audit data +integrity; otherwise, your change reports may contain warnings, errors, or incomplete audit data. -**CAUTION:** Folder associated with Netwrix Auditor must be excluded from antivirus scanning. See -the +:::warning +You must exclude the folder associated with Netwrix Auditor from antivirus scanning. See the [Antivirus Exclusions for Netwrix Auditor](/docs/kb/auditor/system-administration/security-hardening/antivirus-exclusions-for-netwrix-auditor) knowledge base article for additional information. +::: You can configure your IT Infrastructure for monitoring in one of the following ways: - Automatically through a monitoring plan – This is a recommended method. If you select to - automatically configure audit in the target environment, your current audit settings will be - checked on each data collection and adjusted if necessary. -- Manually – Native audit settings must be adjusted manually to ensure collecting comprehensive and - reliable audit data. You can enable Auditor to continually enforce the relevant audit policies or + automatically configure audit in the target environment, Auditor checks your current audit + settings on each data collection and adjusts them if necessary. +- Manually – You must adjust native audit settings manually to collect comprehensive and reliable + audit data. You can enable Auditor to continually enforce the relevant audit policies or configure them manually: - On the Dell Data Storage device: - - CIFS Network Protocol support is required - - Security Event Log Maximum Size must be set to 4GB. - - The Audit object access policy must be set to _"Success"_ and "Failure" in the Group - Policy of the OU where the audited Dell VNX/VNXe/Unity/Celerra appliance belongs to. - - Audit settings must be configured for CIFS File Shares. For a security principal (e.g., - Everyone), the following options must be set to "Success" and "Fail" in the **Advanced + - Enable CIFS Network Protocol support. + - Set the security event log maximum size to 4 GiB (4294901760 bytes). + - Set the Audit object access policy to _"Success"_ and "Failure" in the Group Policy of + the OU that contains the audited Dell VNX/VNXe/Unity/Celerra appliance. + - Configure audit settings for CIFS File Shares. For a security principal (e.g., + Everyone), set the following options to "Success" and "Fail" in the **Advanced Security** > **Auditing** settings for the audited shared folders: - List Folder / Read Data (Files only) @@ -52,16 +54,17 @@ You can configure your IT Infrastructure for monitoring in one of the following - On the Auditor console computer: - If your file shares contain symbolic links and you want to collect state-in-time data for - these shares, the local-to-local, local-to-remote, remote-to-local, and remote-to-remote - symbolic link evaluations must be enabled on the computer that hosts Auditor Server. + these shares, you must enable the local-to-local, local-to-remote, remote-to-local, and + remote-to-remote symbolic link evaluations on the computer that hosts Auditor Server. -First, you should decide on the objects and actions you want to track. Consider the following: +First, decide on the objects and actions you want to track. Consider the following: -- Actions reported by Auditor vary depending on the file server type and the audited object (file, +- The actions Auditor reports vary depending on the file server type and the audited object (file, folder, or share). -- Besides, monitoring and reporting of the Dell Data Storage systems may not provide the results you - expect — due to native Dell audit peculiarities. See the [File Servers](/docs/auditor/10.9/configuration/fileservers/overview.md) topic for - additional information. +- Monitoring and reporting of the Dell Data Storage systems may not provide the results you expect, + because Dell's native auditing doesn't record every action Auditor can report on. See the + [File Servers](/docs/auditor/10.9/configuration/fileservers/overview.md) topic for additional + information. For example, the _change_ operation (in Auditor terminology) includes creation, modification, and deletion. @@ -71,21 +74,20 @@ deletion. To collect comprehensive audit data, you must configure your file shares for monitoring. Consider the following: -**Step 1 –** [Configure Security Event Log Maximum Size](/docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md) to avoid overwriting -of the security logs; it is recommended to set security log size to a maximum (4GB). Auditor does -not clean Dell Unity logs automatically, the log will start overwriting when it goes beyond the +By default, the security log overwrites events older than 10 days, and its size is 512 KB. The +default location for the security.evt log is **C:\security.evt**, which corresponds to the root +partition of the Data Mover. To increase the security log size, you must move it from the Data +Mover root folder. + +**Step 1 –** [Configure Security Event Log](/docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md) to set the log path, maximum size, and retention so that the log holds enough events between data collections. Auditor +doesn't clean Dell Unity logs automatically, so the log starts overwriting when it exceeds the limit. See the [Unity Family Security Configuration Guide](https://support.emc.com/docu69321_Unity-Family-Security-Configuration-Guide.pdf?language=en_US) for -additional information on how to set logs roll over manually. - -**Step 2 –** By default, the security log is set to overwrite events that are older than 10 days, -and its size is set to 512 KB. The default location for the security.evt log is **C:\security.evt**, -which corresponds to the root partition of the Data Mover. To be able to increase the security log -size, you must move it from the Data Mover root folder. +additional information about configuring log rollover manually. -**Step 3 –** [Configure Audit Object Access Policy](/docs/auditor/10.9/configuration/fileservers/delldatastorage/objectaccess.md). Set the Audit object access -policy to "Success" and "Failure" in the Group Policy of the OU where your Dell -VNX/VNXe/Unity/Celerra appliance belongs to. For more information on VNX/VNXe/Unity/Celerra GPO -support, refer to documentation provided by Dell. +**Step 2 –** [Configure Audit Object Access Policy](/docs/auditor/10.9/configuration/fileservers/delldatastorage/objectaccess.md). Set the Audit object access +policy to "Success" and "Failure" in the Group Policy of the OU that contains your Dell +VNX/VNXe/Unity/Celerra appliance. For more information on VNX/VNXe/Unity/Celerra GPO support, refer +to the documentation Dell provides. -**Step 4 –** [Configure Audit Settings for CIFS File Shares on Dell Data Storage](/docs/auditor/10.9/configuration/fileservers/delldatastorage/cifss.md) +**Step 3 –** [Configure Audit Settings for CIFS File Shares on Dell Data Storage](/docs/auditor/10.9/configuration/fileservers/delldatastorage/cifss.md) diff --git a/docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md b/docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md index ec3ee353a8..e2ec500e4c 100644 --- a/docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md +++ b/docs/auditor/10.9/configuration/fileservers/delldatastorage/securityeventlog.md @@ -1,25 +1,75 @@ --- -title: "Configure Security Event Log Maximum Size" -description: "Configure Security Event Log Maximum Size" +title: "Configure Security Event Log" +description: "Configure Security Event Log path, maximum size, and retention on Dell Data Storage devices" sidebar_position: 20 --- -# Configure Security Event Log Maximum Size +# Configure Security Event Log -Follow the steps to configure Event Log maximum size: +Configure the security event log path, maximum size, and retention on your Dell Data +Storage device so that you don't lose audit data when the log fills. Create the file +system in the Dell Web UI, configure the registry values in Registry Editor, then +verify them in the Computer Management console. -**Step 1 –** On your file server, create a new file system where the security log will be stored. +## Create the file system for the security log -**Step 2 –** Mount this file system on a mount point, e.g., **/events**. +**Step 1 –** In the Dell **Web UI**, navigate to **Storage → File → File System** and +click **+** to create a file system. Name it `events` and set its size to at least +4 GiB. This file system stores the security log. -**Step 3 –** Make sure that it is accessible via the **\\``\C$\events** UNC path. +**Step 2 –** Confirm that the account you specified for data collection in the +monitoring plan can read the share at `\\\C$\events`. -**Step 4 –** On the computer where Auditor Server is installed, open **Registry Editor**: navigate -to **Start → Run** and type _"regedit"_. +## Configure Event Log values in Registry Editor -**Step 5 –** Navigate to **File → Connect Network Registry** and specify the file server name. +**Step 1 –** On the computer that hosts Auditor Server, open **Registry Editor**: +navigate to **Start → Run** and type `regedit`. -**Step 6 –** Navigate to **HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security** -and set the **File** value to _"C:\events\security.evt"_. +**Step 2 –** Navigate to **File → Connect Network Registry** and specify +``. -**Step 7 –** Set the **MaxSize** value to _"4 000 000 000 (decimal)"_. +**Step 3 –** Navigate to +**HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security**. + +**Step 4 –** Set the **File** value to `C:\events\security.evt`. + +**Step 5 –** Set the **MaxSize** value to `ffff0000` (hexadecimal) or `4294901760` +(decimal). Select the matching **Base** option in the **Edit DWORD Value** dialog +before you enter the value. + +**Step 6 –** Set the **Retention** value to `0`. The value is the same in +hexadecimal and decimal. This configures the log to overwrite events as needed +instead of retaining them. + +## Verify Event Log settings in the Computer Management console + +**Step 1 –** On the computer that hosts Auditor Server, open **Computer Management**: +navigate to **Start → Run** and type `compmgmt.msc /computer=`. +Alternatively, right-click **Start**, select **Computer Management**, then right-click +**Computer Management (Local)**, select **Connect to another computer**, and specify +``. + +**Step 2 –** Navigate to **System Tools → Event Viewer → Windows Logs**, then +right-click **Security** and select **Properties**. + +**Step 3 –** Confirm the following values: + +- **Log name**: `\\\C$\events\security.evt` +- **Maximum log size**: `4,194,240 KB` +- **Overwrite events as needed**: selected + +If any value doesn't match, correct it in **Registry Editor** and reopen this dialog. + +:::note +The **Security Properties** dialog fields map to the following registry values: + +| Security Properties field | Registry value | +|---|---| +| Log name | `File` | +| Maximum log size | `MaxSize` (`4,294,901,760 bytes = 4,194,240 KB`) | +| Overwrite events as needed | `Retention = 0` | + +The MaxSize registry value uses bytes, while Maximum log size in Security Properties +uses KB. You can't change **Log name** from the **Security +Properties** dialog — use **Registry Editor** instead. +:::