Skip to main content

File System Solution

The core components for Netwrix Access Analyzer (formerly Enterprise Auditor) are the Access Analyzer Console server, SQL Server, and Access Information Center. See the Requirements topic for the core requirements.

You can configure the File System solution to use Proxy servers, either as an applet or as a service. See the File System Scan Options topic for additional information.

You also need to integrate with either Netwrix Activity Monitor or Netwrix Threat Prevention to scan event activity data. See the Netwrix Activity Monitor Documentation or the Netwrix Threat Prevention Documentation for installation requirements and information on collecting activity data.

See the following topics for target environment requirements:

File System Solution Requirements on the Access Analyzer Console

RAM, CPU, and Disk Space

These depend on the size of the target environment:

EnvironmentEnterpriseExtra-LargeLargeMediumSmall
Definition800+ million files and foldersUp to 800 million files and foldersUp to 500 million files and foldersUp to 200 million files and foldersUp to 100 million files and folders
RAM24 GB24 GB16 GB12 GB4 GB
Cores8 CPU8 CPU8 CPU4 CPU2 CPU
Disk Space1.5 TB770 GB470 GB270 GB130 GB

This recommended disk space sizing information is based on the needs of Access Analyzer as well as the File System solution for running Permission scans with default configuration (500 MB per million files and folders), that means no tag collection, file-level scanning, activity, or sensitive data.

  • For tag collection, add 125 MB per million documents to these totals
  • For activity collection, add 250 MB per million files and folders and another 125 MB per million activity events to these totals
  • For sensitive data collection, add 500 MB per million files and folders and another 1%-10% of the total size of the documents scanned for sensitive data (depending on targeted document types and selected criteria) to these totals

For example, to scan 200 million files and folders, of which 10 million files will be scanned for tag collection and sensitive data with a total size of 6 TB, you would need: 160 GB for permission collection + 1.25 GB for tag collection (10x125 MB) + 100 GB for sensitive data collection (200x500 MB) + 600 GB additional for sensitive data collection (10% of 6 TB) = 861.25 GB total disk space.

note

If you run Sensitive Data Discovery (SDD) scans, you need to increase the minimum amount of RAM. Each thread requires a minimum of 2 additional GB of RAM per host. By default, SDD scans are configured to run two concurrent threads. For example, if the job is configured to scan 8 hosts at a time with two concurrent SDD threads, then an extra 32 GB of RAM are required (8x2x2=32).

Additional Server Considerations for File System Scans

If Data Activity Tracking for NAS is required or if NetApp Filers running Clustered Data ONTAP are in scope, you should reduce latency between the scanning server and the target device. Additional hardware may be required, especially if the target NAS devices aren't collocated with the Access Analyzer Console server.

Sensitive Data Discovery Auditing Requirement

note

The appropriate JDK (Java) version for Sensitive Data Discovery is installed on the server. The JDK deployed is prepackaged and doesn't require any configuration; it's preconfigured to work with Access Analyzer, so don't customize it through Java. It will not conflict with other JDKs or Java Runtimes in the same environment.

Permissions on the Console Server to Run File System Scans

In most cases the Access Analyzer user is a member of the local Administrators group on the application server. However, if you use Role Based Access, the user assigned the role of Job Initiator (for manual execution) or the credential used for the Schedule Service Account (for scheduled execution) must have the following permissions to execute File System scans in local mode, applet mode, or proxy mode with applet:

  • Group membership in either of the following local groups:

    • Backup Operators
    • Administrators

These permissions grant the credential the ability to create a high integrity token capable of leveraging the “Back up files and directories” right on the host where the Access Analyzer executable runs.

Additionally, the credential must have WRITE access to the …\StealthAUDIT\FSAA folder in the installation directory. Either the user account running the Access Analyzer application (when manually executing jobs from the console) or the Schedule Service Account assigned within Access Analyzer (when running jobs as scheduled tasks) needs this access.

See the File System Scan Options topic and the File System Supported Platforms topic for permissions required to scan the environment.

File System Solution Requirements on the SQL Server

RAM, CPU, and Disk Space

These depend on the size of the target environment.

EnvironmentEnterpriseExtra-LargeLargeMediumSmall
Definition800+ million files and foldersUp to 800 million files and foldersUp to 500 million files and foldersUp to 200 million files and foldersUp to 100 million files and folders
RAM64 GB64 GB32 GB16 GB8 GB
Cores16 CPU16 CPU12 CPU8 CPU4 CPU
Number of Disks44444
Operating System Disk160 GB160 GB160 GB160 GB160 GB
SQL Database Disk1.6 TB830 GB530 GB400 GB170 GB
SQL Transaction Log Disk390 GB200 GB170 GB130 GB70 GB
SQL TEMP DB Disk1 TB530 GB400 GB270 GB130 GB

Additional SQL Server Requirements for File System Scans

The following are additional requirements for the SQL Server specifically for the File System solution:

  • For File-level Auditing – SQL Server standard edition or higher required
  • For File Activity Auditing – SQL Server Enterprise Edition is required