Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -6,14 +6,13 @@ sidebar_position: 30

# Configure Audit Object Access Policy

Netwrixrecommends you to avoid linking a GPO to the top level of the domain due to the potential
Configure the Audit object access policy on the OU that contains your Dell Data Storage appliance.

Netwrix recommends that you avoid linking a GPO to the top level of the domain due to the potential
impact. Instead, create a new organization unit for your file servers within your domain and assign
GPO there. For detailed instructions on how to create a new OU, refer to the following Microsoft
article:
GPO there. For instructions on creating a new OU, see the Microsoft article
[Create a New Organizational Unit](https://technet.microsoft.com/en-us/library/cc771564.aspx).

Follow the steps to configure Audit Object Access Policy:

**Step 1 –** Open the **Group Policy Management** console on any domain controller in the target
domain: navigate to Start > Windows Administrative Tools**→ Group Policy Management.**

Expand Down Expand Up @@ -49,8 +48,8 @@ node on the left and navigate to **Policies → Windows Settings → Security Se

where `<NAS Server Name>` is the name of the target Unity\VNX server.

To update group policies for Dell VNX you must be logged in as the 'nasadmin' user.
To update group policies for Dell VNX, you must log in as the `nasadmin` user.

You can configure advanced audit policy to narrow the range of events tracked and recorded by the
product, thus preventing your AuditArchive and the Security event log from overfilling. See the
[Configure Security Event Log Maximum Size](/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md) topic for additional information.
You can configure advanced audit policy to narrow the range of events Auditor tracks and
records. This prevents your AuditArchive and the Security event log from overfilling. See the
[Configure Security Event Log](/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md) topic for additional information.
Original file line number Diff line number Diff line change
Expand Up @@ -6,37 +6,39 @@ sidebar_position: 10

# Dell Data Storage

**NOTE:** Dell VNX, VNXe, Celerra, and Unity NAS devices are collectively referred to as Dell Data
Storage.
:::note
Dell Data Storage collectively refers to Dell VNX, VNXe, Celerra, and Unity NAS devices.
:::

Netwrix Auditor relies on native logs for collecting audit data. Therefore, successful change and
access auditing requires a certain configuration of native audit settings in the audited environment
and on the Auditor console computer. Configuring your IT infrastructure may also include enabling
certain built-in Windows services, etc. Proper audit configuration is required to ensure audit data
integrity, otherwise your change reports may contain warnings, errors or incomplete audit data.
certain built-in Windows services, etc. You must configure auditing properly to ensure audit data
integrity; otherwise, your change reports may contain warnings, errors, or incomplete audit data.

**CAUTION:** Folder associated with Netwrix Auditor must be excluded from antivirus scanning. See
the
:::warning
You must exclude the folder associated with Netwrix Auditor from antivirus scanning. See the
[Antivirus Exclusions for Netwrix Auditor](/docs/kb/auditor/system-administration/security-hardening/antivirus-exclusions-for-netwrix-auditor)
knowledge base article for additional information.
:::

You can configure your IT Infrastructure for monitoring in one of the following ways:

- Automatically through a monitoring plan – This is a recommended method. If you select to
automatically configure audit in the target environment, your current audit settings will be
checked on each data collection and adjusted if necessary.
- Manually – Native audit settings must be adjusted manually to ensure collecting comprehensive and
reliable audit data. You can enable Auditor to continually enforce the relevant audit policies or
automatically configure audit in the target environment, Auditor checks your current audit
settings on each data collection and adjusts them if necessary.
- Manually – You must adjust native audit settings manually to collect comprehensive and reliable
audit data. You can enable Auditor to continually enforce the relevant audit policies or
configure them manually:

- On the Dell Data Storage device:

- CIFS Network Protocol support is required
- Security Event Log Maximum Size must be set to 4GB.
- The Audit object access policy must be set to _"Success"_ and "Failure" in the Group
Policy of the OU where the audited Dell VNX/VNXe/Unity/Celerra appliance belongs to.
- Audit settings must be configured for CIFS File Shares. For a security principal (e.g.,
Everyone), the following options must be set to "Success" and "Fail" in the **Advanced
- Enable CIFS Network Protocol support.
- Set the security event log maximum size to 4 GiB (4294901760 bytes).
- Set the Audit object access policy to _"Success"_ and "Failure" in the Group Policy of
the OU that contains the audited Dell VNX/VNXe/Unity/Celerra appliance.
- Configure audit settings for CIFS File Shares. For a security principal (e.g.,
Everyone), set the following options to "Success" and "Fail" in the **Advanced
Security** > **Auditing** settings for the audited shared folders:

- List Folder / Read Data (Files only)
Expand All @@ -52,16 +54,17 @@ You can configure your IT Infrastructure for monitoring in one of the following
- On the Auditor console computer:

- If your file shares contain symbolic links and you want to collect state-in-time data for
these shares, the local-to-local, local-to-remote, remote-to-local, and remote-to-remote
symbolic link evaluations must be enabled on the computer that hosts Auditor Server.
these shares, you must enable the local-to-local, local-to-remote, remote-to-local, and
remote-to-remote symbolic link evaluations on the computer that hosts Auditor Server.

First, you should decide on the objects and actions you want to track. Consider the following:
First, decide on the objects and actions you want to track. Consider the following:

- Actions reported by Auditor vary depending on the file server type and the audited object (file,
- The actions Auditor reports vary depending on the file server type and the audited object (file,
folder, or share).
- Besides, monitoring and reporting of the Dell Data Storage systems may not provide the results you
expect — due to native Dell audit peculiarities. See the [File Servers](/docs/auditor/10.7/configuration/fileservers/overview.md) topic for
additional information.
- Monitoring and reporting of the Dell Data Storage systems may not provide the results you expect,
because Dell's native auditing doesn't record every action Auditor can report on. See the
[File Servers](/docs/auditor/10.7/configuration/fileservers/overview.md) topic for additional
information.

For example, the _change_ operation (in Auditor terminology) includes creation, modification, and
deletion.
Expand All @@ -71,21 +74,20 @@ deletion.
To collect comprehensive audit data, you must configure your file shares for monitoring. Consider
the following:

**Step 1 –** [Configure Security Event Log Maximum Size](/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md) to avoid overwriting
of the security logs; it is recommended to set security log size to a maximum (4GB). Auditor does
not clean Dell Unity logs automatically, the log will start overwriting when it goes beyond the
By default, the security log overwrites events older than 10 days, and its size is 512 KB. The
default location for the security.evt log is **C:\security.evt**, which corresponds to the root
partition of the Data Mover. To increase the security log size, you must move it from the Data
Mover root folder.

**Step 1 –** [Configure Security Event Log](/docs/auditor/10.7/configuration/fileservers/delldatastorage/securityeventlog.md) to set the log path, maximum size, and retention so that the log holds enough events between data collections. Auditor
doesn't clean Dell Unity logs automatically, so the log starts overwriting when it exceeds the
limit. See the
[Unity Family Security Configuration Guide](https://support.emc.com/docu69321_Unity-Family-Security-Configuration-Guide.pdf?language=en_US) for
additional information on how to set logs roll over manually.

**Step 2 –** By default, the security log is set to overwrite events that are older than 10 days,
and its size is set to 512 KB. The default location for the security.evt log is **C:\security.evt**,
which corresponds to the root partition of the Data Mover. To be able to increase the security log
size, you must move it from the Data Mover root folder.
additional information about configuring log rollover manually.

**Step 3 –** [Configure Audit Object Access Policy](/docs/auditor/10.7/configuration/fileservers/delldatastorage/objectaccess.md). Set the Audit object access
policy to "Success" and "Failure" in the Group Policy of the OU where your Dell
VNX/VNXe/Unity/Celerra appliance belongs to. For more information on VNX/VNXe/Unity/Celerra GPO
support, refer to documentation provided by Dell.
**Step 2 –** [Configure Audit Object Access Policy](/docs/auditor/10.7/configuration/fileservers/delldatastorage/objectaccess.md). Set the Audit object access
policy to "Success" and "Failure" in the Group Policy of the OU that contains your Dell
VNX/VNXe/Unity/Celerra appliance. For more information on VNX/VNXe/Unity/Celerra GPO support, refer
to the documentation Dell provides.

**Step 4 –** [Configure Audit Settings for CIFS File Shares on Dell Data Storage](/docs/auditor/10.7/configuration/fileservers/delldatastorage/cifss.md)
**Step 3 –** [Configure Audit Settings for CIFS File Shares on Dell Data Storage](/docs/auditor/10.7/configuration/fileservers/delldatastorage/cifss.md)
Original file line number Diff line number Diff line change
@@ -1,25 +1,75 @@
---
title: "Configure Security Event Log Maximum Size"
description: "Configure Security Event Log Maximum Size"
title: "Configure Security Event Log"
description: "Configure Security Event Log path, maximum size, and retention on Dell Data Storage devices"
sidebar_position: 20
---

# Configure Security Event Log Maximum Size
# Configure Security Event Log

Follow the steps to configure Event Log maximum size:
Configure the security event log path, maximum size, and retention on your Dell Data
Storage device so that you don't lose audit data when the log fills. Create the file
system in the Dell Web UI, configure the registry values in Registry Editor, then
verify them in the Computer Management console.

**Step 1 –** On your file server, create a new file system where the security log will be stored.
## Create the file system for the security log

**Step 2 –** Mount this file system on a mount point, e.g., **/events**.
**Step 1 –** In the Dell **Web UI**, navigate to **Storage → File → File System** and
click **+** to create a file system. Name it `events` and set its size to at least
4 GiB. This file system stores the security log.

**Step 3 –** Make sure that it is accessible via the **\\`<file_server_name>`\C$\events** UNC path.
**Step 2 –** Confirm that the account you specified for data collection in the
monitoring plan can read the share at `\\<file_server_name>\C$\events`.

**Step 4 –** On the computer where Auditor Server is installed, open **Registry Editor**: navigate
to **Start → Run** and type _"regedit"_.
## Configure Event Log values in Registry Editor

**Step 5 –** Navigate to **File → Connect Network Registry** and specify the file server name.
**Step 1 –** On the computer that hosts Auditor Server, open **Registry Editor**:
navigate to **Start → Run** and type `regedit`.

**Step 6 –** Navigate to **HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security**
and set the **File** value to _"C:\events\security.evt"_.
**Step 2 –** Navigate to **File → Connect Network Registry** and specify
`<file_server_name>`.

**Step 7 –** Set the **MaxSize** value to _"4 000 000 000 (decimal)"_.
**Step 3 –** Navigate to
**HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security**.

**Step 4 –** Set the **File** value to `C:\events\security.evt`.

**Step 5 –** Set the **MaxSize** value to `ffff0000` (hexadecimal) or `4294901760`
(decimal). Select the matching **Base** option in the **Edit DWORD Value** dialog
before you enter the value.

**Step 6 –** Set the **Retention** value to `0`. The value is the same in
hexadecimal and decimal. This configures the log to overwrite events as needed
instead of retaining them.

## Verify Event Log settings in the Computer Management console

**Step 1 –** On the computer that hosts Auditor Server, open **Computer Management**:
navigate to **Start → Run** and type `compmgmt.msc /computer=<file_server_name>`.
Alternatively, right-click **Start**, select **Computer Management**, then right-click
**Computer Management (Local)**, select **Connect to another computer**, and specify
`<file_server_name>`.

**Step 2 –** Navigate to **System Tools → Event Viewer → Windows Logs**, then
right-click **Security** and select **Properties**.

**Step 3 –** Confirm the following values:

- **Log name**: `\\<file_server_name>\C$\events\security.evt`
- **Maximum log size**: `4,194,240 KB`
- **Overwrite events as needed**: selected

If any value doesn't match, correct it in **Registry Editor** and reopen this dialog.

:::note
The **Security Properties** dialog fields map to the following registry values:

| Security Properties field | Registry value |
|---|---|
| Log name | `File` |
| Maximum log size | `MaxSize` (`4,294,901,760 bytes = 4,194,240 KB`) |
| Overwrite events as needed | `Retention = 0` |

The MaxSize registry value uses bytes, while Maximum log size in Security Properties
uses KB. You can't change **Log name** from the **Security
Properties** dialog — use **Registry Editor** instead.
:::
Original file line number Diff line number Diff line change
Expand Up @@ -6,14 +6,13 @@ sidebar_position: 30

# Configure Audit Object Access Policy

Netwrix recommends you to avoid linking a GPO to the top level of the domain due to the potential
Configure the Audit object access policy on the OU that contains your Dell Data Storage appliance.

Netwrix recommends that you avoid linking a GPO to the top level of the domain due to the potential
impact. Instead, create a new organization unit for your file servers within your domain and assign
GPO there. For detailed instructions on how to create a new OU, refer to the following Microsoft
article:
GPO there. For instructions on creating a new OU, see the Microsoft article
[Create a New Organizational Unit](https://technet.microsoft.com/en-us/library/cc771564.aspx).

Follow the steps to configure Audit Object Access Policy:

**Step 1 –** Open the **Group Policy Management** console on any domain controller in the target
domain: navigate to Start > Windows Administrative Tools**→ Group Policy Management.**

Expand Down Expand Up @@ -49,8 +48,8 @@ node on the left and navigate to **Policies → Windows Settings → Security Se

where `<NAS Server Name>` is the name of the target Unity\VNX server.

To update group policies for Dell VNX you must be logged in as the 'nasadmin' user.
To update group policies for Dell VNX, you must log in as the `nasadmin` user.

You can configure advanced audit policy to narrow the range of events tracked and recorded by the
product, thus preventing your AuditArchive and the Security event log from overfilling. See the
[Configure Security Event Log Maximum Size](/docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md) topic for additional information.
You can configure advanced audit policy to narrow the range of events Auditor tracks and
records. This prevents your AuditArchive and the Security event log from overfilling. See the
[Configure Security Event Log](/docs/auditor/10.8/configuration/fileservers/delldatastorage/securityeventlog.md) topic for additional information.
Loading