To enable EMC auditing, create a template for each EMC file server (CIFS) to audit. Each template defines the location of the EMC file server to be audited, the auditing scope, and the agents to receive the events.
|
3 |
Select EMC in the Auditing | NAS task list to open the EMC Auditing page. |
This opens the EMC Auditing wizard, which steps you through the process of defining the EMC file server (CIFS) to be audited, the auditing scope, and the agents that are to receive the EMC events.
|
▪ |
EMC File Server (CIFS) - Select the EMC file server (CIFS) from the drop-down list. Or enter the Netbios name or IP address of the EMC file server (CIFS) to be audited. |
|
▪ |
Audit Path - Select File. Enter a file name and path (i.e., < ShareName>\<Path>\<FileName>) to audit or click the browse button to locate and select a file. Click Add to move the specified audit path to the selection list. |
|
▪ |
Events tab - Select the file events to audit for the file selected in the selection list. |
Repeat this step to add additional files to this auditing template.
|
|
NOTE: Selecting the File Events check box at the top of the events list on the Events tab will select all of the events listed. Similarly, clearing this check box will clear all of the selected events. |
To add an agent to the EMC Auditing template:
If the agents that are to capture EMC events are not already specified in the cepp.conf file (pool namesakes servers entry), you will need to enter the credentials required to access the EMC Control Station.
Click Set Credentials and enter the following information:
|
▪ |
User - enter the user name of an account with Administrative rights (required to create or modify the cepp.conf file) on the selected EMC Control Station. |
|
▪ |
Password - enter the password associated with the user name entered above. |
|
▪ |
Data Mover - select the data mover that hosts the CIFS file server specified on the first page of the wizard. |
Click Test to validate the credentials. Once the credentials are validated, click OK to set the credentials as entered and close the dialog.
The cepp.conf file will be created based on the information specified in the EMC Auditing wizard. Click Next to view the current and proposed settings for the cepp.conf file.
Use the buttons above the Current cepp.conf File text box, as described below:
|
9 |
Click Finish to close the wizard and create the template. |
|
3 |
Select EMC in the Auditing | NAS task list to open the EMC Auditing page. |
|
▪ |
EMC File Server (CIFS) - Select the EMC file server (CIFS) from the drop-down list. Or enter the Netbios name or IP address of the EMC file server (CIFS) to be audited. |
|
▪ |
Audit Path - Select Folder. Enter a folder name and path (i.e., < ShareName>\<FolderName>) to audit or click the browse button to locate and select a folder. |
|
|
NOTE: Isilon file server auditing:
When specifying file and folder paths to be audited, the file or folder’s absolute path should be used. Path values in Isilon events captured by Change Auditor are also represented in absolute paths. For example, if a share called ‘MyTestShare’ is sharing the path ‘\\isilon\ifs\test’, add the path ‘ifs\test’ in the auditing template to audit changes through the share. Change Auditor uses the default ‘ifs’ share for Isilon file/folder permission change events. If you have renamed this share, please specify the new share name on this page to continue support for these events. To change the default ifs share name, click the "Isilion admin share name" link on the top right hand corner of the page. |
Click Add to add the specified folder to the Selection list.
|
▪ |
This object only- select this option to audit only the selected folder, not its files or subfolders. |
In addition, when the folder entry is selected in the Selection list, the tabs across the bottom of the page are activated. The settings specified on these tabs apply to the entry selected.
|
|
NOTE: Selecting the File Events or Folder Events check box at the top of the events list on the Events tab will select all of the events listed. Similarly, clearing these check boxes will clear all of the selected events. |
Enter a file mask to specify what is to be included in the audit. The file mask can contain any combination of the following:
For example, entering * will include all subfolders and files in the selected audit path.
You can also enter the name of an individual subfolder or file to be audited. However, if you enter the name of a subfolder, you will only receive events for operations performed against the specified subfolder. You will not receive events for operations performed against any child objects under the specified subfolder.
Once you have specified the subfolders/files to be included, click the Add button to add it to the Inclusion list at the bottom of the page.
Repeat this step to add additional subfolders and files to the Inclusion list.
Enter a file mask to specify the name and path of subfolders and files to be excluded from auditing. The file mask can contain any combination of the following:
For example, entering *.log will exclude all files in the audit folder with the .log file extension. Whereas, entering **.log will exclude all files with the .log file extension found in the audit folder or in any subfolders.
You can also enter the name of an individual subfolder or file to be excluded.
Once you have specified a subfolder or file for exclusion, use the appropriate Add command to add it to the Exclusion list at the bottom of the page:
|
▪ |
Add | Folder - use this option to exclude activity against files/subfolders in any folders that match the exclusion string. |
|
▪ |
Add | File - use this option to exclude activity against any files that match the exclusion string. |
Repeat this step to add additional subfolders and files to the Exclusion list.
Click Next.
If the Change Auditor agents that are to capture EMC events are not already specified in the cepp.conf file (pool name=quest servers entry), you will need to enter the credentials to be used to access the EMC Control Station.
Click the Set Credentials button and enter the following information:
|
▪ |
User - enter the user name of an account with Administrative rights (rights to create or modify the cepp.conf file) on the selected EMC Control Station. |
|
▪ |
Password - enter the password associated with the user name entered above. |
|
▪ |
Data Mover - select the data mover that hosts the CIFS file server specified on the first page of the wizard. |
Click Test to validate the credentials entered. Once the credentials are validated, select OK to set the credentials as entered and close the dialog.
The required cepp.conf file will be created based on the information specified in the EMC Auditing wizard. Click Next to view the current and proposed settings for the cepp.conf file.
Use the buttons above the Current cepp.conf File text box, as described below:
|
12 |
Click Finish to close the wizard and create the EMC Auditing template. |
|
▪ |
EMC File Server (CIFS) - Select the EMC file server (CIFS) from the drop-down list. Or enter the Netbios name or IP address of the EMC file server (CIFS) to be audited. |
|
▪ |
Audit Path - Select Volume. Enter a volume name (i.e., < VolumeName>) to be audited or click the browse button to locate and select a volume. |
Click Add to add the specified volume to the Selection list.
Select the volume entry in the Selection list to activate the tabs across the bottom of the page. The settings specified on these tabs apply to the entry selected.
|
|
NOTE: Selecting the File Events or Folder Events check box at the top of the events list on the Events tab will select all of the events listed. Similarly, clearing these check boxes will clear all of the selected events. |
Enter a file mask to specify what is to be included in the audit. The file mask can contain any combination of the following:
For example, entering * will include all subfolders and files in the selected audit path.
You can also enter the name of an individual subfolder or file to be audited. However, if you enter the name of a subfolder, you will only receive events for operations performed against the specified subfolder. You will NOT receive events for operations performed against any child objects under the specified subfolder.
Once you have specified the subfolders/files to be included, click Add to add it to the Inclusion list at the bottom of the page.
Repeat this step to add additional subfolders and files to the Inclusion list.
Enter a file mask to specify the name and path of subfolders and files to be excluded from auditing. The file mask can contain any combination of the following:
For example, entering *.log will exclude all files in the audit folder with the .log file extension. Whereas, entering **.log will exclude all files with the .log file extension found in the audit folder or in any subfolders.
You can also enter the name of an individual subfolder or file to be excluded.
Once you have specified a subfolder or file for exclusion, use the appropriate Add command to add it to the Exclusion list at the bottom of the page:
|
▪ |
Add | Folder - use this option to exclude activity against files/subfolders in any folders that match the exclusion string. |
|
▪ |
Add | File - use this option to exclude activity against any files that match the exclusion string . |
Repeat this step to add additional subfolders and files to the Exclusion list.
Click Next.
If the Change Auditor agents that are to capture EMC events are not already specified in the cepp.conf file (pool name=quest servers entry), you’ll need to enter the credentials to be used to access the EMC Control Station.
Click Set Credentials and enter the following information:
|
▪ |
User - enter the user name of an account with Administrative rights (rights to create or modify the cepp.conf file) on the selected EMC Control Station. |
|
▪ |
Password - enter the password associated with the user name entered above. |
|
▪ |
Data Mover - select the data mover that hosts the CIFS file server specified on the first page of the wizard. |
Click Test to validate the credentials. Once the credentials are validated, click OK to set the credentials as entered and close the dialog.
The required cepp.conf file will be created based on the information specified in the EMC Auditing wizard. Click Next to view the current and proposed settings for the cepp.conf file.
Use the buttons above the Current cepp.conf File text box, as described below:
|
9 |
Click Finish to close the wizard and create the template. |
|
10 |
On the Administration Tasks tab, click Configuration. Select Agent in the Configuration task list to open the Agent Configuration page. This will ensure the agents are using the latest configuration. |
The disable feature allows you to temporarily stop auditing the specified audit path without having to remove the auditing template or individual audit path from a template.
The entry in the Status column for the template will change to ‘Disabled’.
The entry in the Status column for the selected file path will change to ‘Disabled’.