Tchater maintenant avec le support
Tchattez avec un ingénieur du support

Change Auditor 7.5 - Quick Start Guide

Before you begin an installation

Quest recommends that you perform the following steps before you begin installing Change Auditor:

Review Installation Notes and Best Practices in the Change Auditor Installation Guide

Installation overview

Quest recommends installing the Change Auditor components in the following order:

Step 1: Install a coordinator

User account installing the coordinator:

The user account that is installing the coordinator must have permission to perform the following tasks on the target server:

The user account must also be a member of the Domain Admins group in the domain where the coordinator is being installed.

Service account running the coordinator service (LocalSystem by default):

If you are running the coordinator under a service account (instead of LocalSystem), define a Manual connection profile where you can specify the IP address of the server hosting the coordinator. You can specify and select connection profiles whenever you open the Change Auditor client. See the Change Auditor User Guide or online help for more information about defining and selecting a connection profile.

SQL Server database access account specified during installation:

Create an account that the coordinator service can use on an ongoing basis for access to the SQL Server database. This account must have a SQL Login and be assigned the following SQL permissions:

Must be assigned the db_owner role on the Change Auditor database
1
Verify that the user account used to run the coordinator installation is at least a Domain Admin in the domain to which the coordinator server belongs.
1
From the member server, browse to the folder where the Change Auditor package was downloaded, and run the Quest Change Auditor Coordinator(x64).msi file to open the Change Auditor Coordinator Setup wizard.

Licenses

Click Open License Dialog to locate and apply a license.

After licensing the product, the setup wizard prompts you to enter a unique installation name to identify the database to which the coordinator will connect.

ChangeAuditor Installation Name

Enter a unique Change Auditor installation name that identifies the current installation within your Active Directory environment. An installation name is required; has a limit of 22 characters; can only contain alphanumeric characters and underscores; and is converted to all caps.

SQL Server and Instance

Enter the server name or IP address (member server running the SQL instance) and the SQL instance name for the Change Auditor coordinator database such as, <FQDN of the SQL server>\<instance name> or browse your Active Directory network to locate the required instance.

Azure SQL Managed Instance:

Name of database catalog

Enter the name to assign to the Change Auditor database.

Authentication/ Credentials

Use the authentication section to specify whether to use Windows authentication or SQL authentication when communicating with the SQL database instance. (The authentication method is set up when SQL is installed.)

NOTE: If Windows Authentication is used to access the designated SQL instance, a verification screen is displayed. Verify that the server name, SQL instance name, and credentials are correct before proceeding. Incorrect entries cause the Change Auditor coordinator service to fail on startup.

Encryption

NOTE:  

Select the appropriate level of encryption for the data sent between the coordinator and SQL server.

Strict (SQL Server 2022): Select this option for SQL Server 2022 and Azure SQL Managed Instance or when the instance has Force Strict Encryption enabled.
Mandatory: Select this option when the instance has Force Encryption enabled. It can also be used when no encryption is configured for the instance, but Trust server certificate is enabled. While this method is less secure than installing a trusted certificate, it does support an encrypted connection.

Enabling Trust server certificate, when 'Optional' or 'Mandatory' encryption is selected, or if the server enforces encryption, means that SQL Server will not validate the server certificate on the client computer when encryption is enabled for network communication.

Under Host name in the certificate, you can provide an alternate, yet expected, Common Name (CN) or Subject Alternative Name (SAN) in the server certificate. You would use this option when the server name does not match the CN or SAN, for example, when using DNS aliases.

Leaving this option blank allows certificate validation to confirm that the CN or SAN matches the server name.

Add the current user to the “ChangeAuditor Administrators - <InstallationName>” security group

This check box is selected by default and adds the current user to the ChangeAuditor Administrators — <InstallationName> group.

Any user that is running a Change Auditor client must be added to either this security group or the ChangeAuditor Operators security group.

In addition, users responsible for deploying Change Auditor agents must be a member of the ChangeAuditor Administrators group in the specified ChangeAuditor installation.

See the Change Auditor Installation Guide for more information about these security groups and how to add more user accounts.

By default Change Auditor dynamically assigns communication ports to use to communicate with each installed coordinator. However, using the port settings on this screen you can specify static SCP listening ports to use instead.

Client Port

Enter the static port number for the Change Auditor client to communicate with the coordinator.

Public SDK Port

Enter the static port number for external applications to access the coordinator.

Agent Port (Legacy)

Enter the static port number for legacy (5.x) Change Auditor agents to communicate with the coordinator.

Agent Port

Enter the static port number for Change Auditor 6.x agents to communicate with the coordinator.

Specify the authentication method to use to make Active Directory requests.

3
After you have entered all the requested information, click Install to start the installation process.
4
Verify that the coordinator service has been installed by right-clicking the Change Auditor coordinator icon in the system tray and clicking Coordinator Status. Check for the correct version and that the Coordinator Status is 'Running'.

Step 2: Install the client

The client connects directly to the coordinator or to an archive database and is the user interface that provides immediate access to key configuration change information.

1
On a workstation, laptop or member server, browse to the folder where the Change Auditor package was downloaded, and run the Quest Change Auditor Client (x64).msi file to open the Change Auditor Client Setup wizard.
2
Select Install Change Auditor Client to open the Client Setup wizard.
NOTE: If Microsoft .NET is not installed on the computer, an extra screen is displayed explaining that this application was not found and the install cannot continue. Click Close to stop the client install. Download and install the required .NET version. After .NET is successfully installed, restart the client installation.
7
Click Install.
Documents connexes

The document was helpful.

Sélectionner une évaluation

I easily found the information I needed.

Sélectionner une évaluation