Recommended Configuration for the File System Solution
By default, the File System Solution inherits settings from the FileSystem > Settings node for most jobs. However, as a best practice, assign the host list and the Connection Profile at the data collection level. After you assign these to the job, you can run it manually or schedule it.
Remember, the scan mode you select affects the credential permissions required for the scan and host lists. See the File System Scan Options topic for additional information.
Dependencies
- The .Active Directory Inventory Job Group needs to be executed before running the File System Solution
- File System Proxy deployed to targeted proxy servers (for proxy scanning architecture only)
- Activity Monitor deployed, configured, and services running (for Activity Auditing only)
- Sensitive Data Discovery Add-On installed on the Enterprise Auditor Console server (for Sensitive Data Discovery Auditing only)
- Sensitive Data Discovery Add-On installed on the proxy server (for Sensitive Data Discovery Auditing via proxy scanning architecture only)
Targeted Hosts
Assign the host list under the FileSystem > 0.Collection > [job] > Host node. Use a custom list of the file system environments you want to target. Check the box for the custom-created host list. The …System Scans jobs and the corresponding …Bulk Import jobs must use the same host lists.
The 0-FSDFS System Scans Job is an exception and is set to the Default domain controller. For standalone namespaces, modify this host list to target the File Systems or Storage Controllers you want to scan.
If you target Nasuni Edge Appliances, assign the 0-FS_Nasuni Job a custom host list containing all on-premise Nasuni Edge Appliances and cloud filers.
If you use multiple proxy servers, configure them within a different custom-created host list. Then assign the proxy servers host list on the FSAA: Applet Settings page of the File System Access Auditor Data Collector Wizard within the following jobs in the 0.Collection Job Group according to the type of auditing being conducted:
- 1-FSAA System Scans Job for Access Auditing
- 1-FSAC System Scans Job for Activity Auditing
- 1-SEEK System Scans Job for Sensitive Data Discovery Auditing
Windows clusters have special needs for the host list and host inventory data. You must target the Windows File Server Cluster (name of the cluster) of interest when running a scan against a Windows File System Cluster. The Enterprise Auditor Master Host Table must include a host entry for the cluster as well as for each node. Additionally, each of these host entries must have the name of the cluster in the WinCluster column in the host inventory data. You may need to update this manually. See the Host Inventory topic for additional information.
The host targeted by the File System scans is only the host entry for the cluster. For
example, the environment has a Windows File System Cluster named ExampleCluster1 with three nodes
named ExampleNodeA, ExampleNodeB, and ExampleNodeC. There would be four host entries in the
Enterprise Auditor Master Host Table: ExampleCluster1, ExampleNodeA, ExampleNodeB, and
ExampleNodeC. Each of these four entries would have the same value of the cluster name in the
WinCluster column: ExampleCluster1. Only the ExampleCluster1 host would be in the host list
targeted by the File System scans.
For the selected scan mode to apply accurately to the target file system, host inventory must match the values in the table for OSType:
| Devices | OSType Value |
|---|---|
| Windows | Windows |
| NetApp | NAS |
| Celerra | N/A or Unknown |
| Isilon | NAS |
| Nasuni | NAS |
| ARX | N/A or Unknown |
| UNIX | N/A or Unknown |
Connection Profile
The FSAA Data Collector requires permissions based on the platform being targeted for data collection and the scan mode selected. See the File System Scan Options topic and the File System Supported Platforms topic for necessary permissions for the supported target platforms. See the Netwrix Activity Monitor Documentation for the necessary permission for collecting activity data. Then create a custom Connection Profile containing the appropriate credentials for the targeted environment.
The Connection Profile should be assigned under the FileSystem > 0.Collection job’s Properties window on the Connection tab. It is set to Use the Default Profile, as configured at the global settings level. However, since this may not be the Connection Profile with the necessary permissions for the assigned hosts, click the radio button for the Select one of the following user defined profiles option and select the appropriate Connection Profile dropdown menu.
Remember, if you target Nasuni Edge Appliances, assign the 0-FS_Nasuni Job a custom Connection Profile containing the API Access Key and Passcode for each on-premise Nasuni Edge Appliance and cloud filer in the target environment. Nasuni API key names are case sensitive. Enter them in the exact case in which they were generated.
See the Connection topic for additional information.
Schedule Frequency
One of the most important decisions to make is how frequently to collect this data. This is dependent on the size of the target environment. The FileSystem Solution can be scheduled to run weekly or as desired depending on the types of auditing being conducted and the scope of the target environment.
For example, in large environments, you might run Activity Auditing collection jobs daily, but run Access Auditing and Sensitive Data Discovery Auditing collection jobs only weekly, followed by the analysis and reporting job groups.
Run Order
Regardless of the schedule frequency you configure, streamline the collection jobs to only those you need. Run the jobs in the 0.Collection Job Group in order for the auditing type. Run …System Scans jobs and then the corresponding …Bulk Import jobs according to the desired workflow.
The other File System Solution sub-job groups can be run together or individually in any order, after running the 0.Collection Job Group. The FileSystemOverview Job pulls information from both the 0.Collection Job Group and the other sub-job groups, and the report may contain blank sections if you run only select sub-job groups.
If you conduct only one or two types of auditing, scope the solution by disabling the undesired collection jobs. Disabling them allows the solution to run more efficiently. Don't delete any jobs. See the Disable or Enable a Job topic for additional information.
If targeting Nasuni Edge Appliances, add the 0-FS_Nasuni Job to the 0.Collection Job Group.
Query Configuration
This solution can be run with the default query configuration. However, the most common customizations include:
-
Use proxy scanning architecture, see the File System Data Collection Configuration for Proxy as a Service topic for instructions
-
Default Scoping Options page > File Properties tab, optionally configure the following:
-
In the Scan for Probable Owner section, limit the number of probable owners to return per folder
-
In the Scan for File Types section, add comma-separated values to limit the file types returned
-
Opt to collect file Microsoft Office metadata tags and add comma-separated values to limit the metadata tags collected.
-
Set on the following 0.Collection Job Group jobs:
- 1-FSAA System Scans Job for Access Auditing
-
-
Default Scoping Options page > File Details tab, configure the file detail collection
-
By default, file detail scans are disabled
-
Select the type of file data to collect and optionally add filters
-
Set on the following 0.Collection Job Group jobs:
- 1-FSAA System Scans Job for Access Auditing
-
-
Applet Settings page, optionally configure the applet settings:
-
Opt to enable strong proxy affinity (only run scans on last proxy to scan host, unless no longer in proxy host list)
-
Configure the following:
- Maximum concurrent scans to run on any single applet host
- Maximum waiting time for strong proxy affinity
- Scan cancellation timeout
-
Set on the following 0.Collection Job Group jobs:
- 1-FSAA System Scans Job for Access Auditing
- 1-FSAC System Scans Job for Activity Auditing
- 1-SEEK System Scans Job for Sensitive Data Discovery Auditing
-
-
Scan Server Selection page, set the type of mode the scans will run on
-
The mode configured must align with the provisioning of the credential and environment. See the File System Scan Options topic and the File System Supported Platforms topic for additional information.
-
Local Mode – The Enterprise Auditor Console server conducts all data collection processing across the network
-
Applet Mode – When the job runs, it deploys the File System applet to the target host to collect data. The applet collects data on the Windows target host where it's deployed. The final step compresses and transfers the collected data in the SQLite databases, or Tier 2 databases, back to the Enterprise Auditor Console server. If the target host is a NAS device, the File System scans default to local mode for that host.
-
Proxy Mode with Applet – When the job runs, it deploys the File System applet to the Windows proxy server to collect data. The proxy server where the applet is deployed initiates data collection processing and uses a local mode-type scan against each target host. The final step compresses and transfers the collected data in the SQLite databases, or Tier 2 databases, back to the Enterprise Auditor Console server.
-
Proxy Mode as a Service – You must install the File System Proxy Service on the Windows proxy servers before running the scans. The proxy server where the service runs conducts data collection processing and uses a local mode-type scan against each target host. The final step compresses and transfers the collected data in the SQLite databases, or Tier 2 databases, back to the Enterprise Auditor Console server. The assigned Connection Profile must include the credential granted rights to interact with the service.
-
Set on the following 0.Collection Job Group jobs:
- 1-FSAA System Scans Job for Access Auditing
- 1-FSAC System Scans Job for Activity Auditing
- 1-SEEK System Scans Job for Sensitive Data Discovery Auditing
-
-
Default Scoping Options page > Scan Settings tab, configuring the subfolder depth
-
Recommendation (allows for a proper assessment on runtime for the targeted environment):
- For first time execution, recommend setting to 0
- For second execution, recommend setting to 2
- Then set to the depth you want.
-
Set on the following 0.Collection Job Group jobs:
- 1-FSAA System Scans Job for Access Auditing
- 1-SEEK System Scans Job for Sensitive Data Discovery Auditing
-
-
SDD Criteria Settings page, scope to scan for specific criteria or customizing criteria for Sensitive Data Discovery Auditing
- Set on the 0.Collection > 1-SEEK System Scans Job
-
Activity Settings page, configure data retention period
- Recommendation to run with default setting of 60 days
- Set on the 0.Collection > 1-FSAC System Scans Job for Activity Auditing
Analysis Configuration
This solution should be run with the default analysis configuration. Most of these analysis tasks are preconfigured and shouldn't be modified or deselected. There are a few which are deselected by default, as they are for troubleshooting purposes.
Though the analysis tasks shouldn't be deselected, the following parameters can be modified:
-
The .Active Directory Inventory Solution defines large groups, deeply nested groups, stale users, and users with large tokens. These parameters can be customized and are applicable to any solution, including File System, which incorporates this analyzed data into further analysis.
- Customize within .Active Directory Inventory > 3-AD_Exceptions Job analysis tasks
-
Activity Exception parameters which identify potential security concerns
- Customize within 0.Collection > 3-FSAC Exceptions Job analysis tasks
-
Broken inheritance is defined by default to only analyze resources with changed permissions from parent
- Customize within 3.Broken Inheritance > FS_BrokenInheritance Job analysis task
-
Probable owner calculations include folder depth parameters
-
Customize within 6.Probable Owner > FS_ProbableOwner Job analysis task
noteChanges to an exception’s definition will impact all jobs dependent upon that exception as well as all AIC Active Directory Exceptions reports.
-
There are also a few Notification analysis tasks which can be configured and then enabled in the following jobs:
- 5.Activity > Forensics > FS_Deletions Job
- 5.Activity > Forensics > FS_PermissionChanges Job
- 5.Activity > Suspicious Activity > FS_HighestHourlyActivity Job
See the appropriate topics for details on these tasks.
Additional Consideration
The Ad Hoc Audits Job Group works independently from the rest of the solution but depends on the 0.Collection Job Group. The jobs are scoped to specific shares and trustees within an analysis task.
The jobs contained in the group use custom SQL scripts to render views on collected data. SQL views populate report element tables and graphs. Changing or modifying the group, job, or table names results in no data displayed within the reports or the AIC.
Remember, scope the 0.Collection Job Group to include only the collection components you want by disabling the undesired collection jobs. Disabling them allows the solution to run more efficiently. Don't delete any jobs.