Chat now with support
Chat with Support

NOTICE! We are upgrading our support telephone services, implementing Genesys, starting the week of May 19, 2025

Change Auditor 7.5 - User Guide

Welcome to Change Auditor Help Change Auditor Core Functionality
Change Auditor Core Functionality Change Auditor Overview Agent Deployment Change Auditor Client Overview Overview Page Searches Search Results and Event Details Custom Searches and Search Properties Enable Alert Notifications Administration Tasks Agent Configurations Coordinator Configuration Purging and Archiving your Change Auditor Database Working with Private Alerts and Reports Generate and Schedule Reports SQL Reporting Services Configuration Change Auditor User Interface Authorization Client Authentication Certificate authentication for client coordinator communication Integrating with On Demand Audit Enable/Disable Event Auditing Account Exclusion Registry Auditing Service Auditing Agent Statistics and Logs Coordinator Statistics and Logs Change Auditor Commands Change Auditor Email Tags
Microsoft 365 and Microsoft Entra ID Auditing Change Auditor for Active Directory
Change Auditor for Active Directory Overview Custom Active Directory Searches and Reports Custom Active Directory Object Auditing Custom Active Directory Attribute Auditing Member of Group Auditing Active Directory Federation Services Auditing ADAM (AD LDS) Auditing Active Directory Database Auditing Active Roles Integration Quest GPOADmin Integration Active Directory Protection Event Details Pane About us
Change Auditor for Authentication Services Change Auditor for Defender Change Auditor for EMC Change Auditor for Exchange Change Auditor for Windows File Servers Change Auditor for Active Directory Queries Change Auditor for Logon Activity Change Auditor for NetApp Change Auditor for SharePoint Change Auditor for SQL Server Change Auditor SIEM Integration Guide
Webhooks in Change Auditor Integrating Change Auditor and SIEM Tools Subscription Management
Adding the PowerShell module Viewing available commands and help Connecting to Change Auditor Managing subscriptions Working with event subscriptions in the client Managing a Splunk integration Splunk event subscription wizard Managing an IBM QRadar integration QRadar event subscription wizard Managing a Micro Focus Security ArcSight Logger and Enterprise Security Manager (ESM) integration ArcSight event subscription wizard Managing a Quest IT Security Search integration (Preview) Managing a Syslog integration Syslog event subscription wizard Managing a Microsoft Sentinel integration Microsoft Sentinel event subscription wizard
Webhook technical insights
Change Auditor Threat Detection Deployment Change Auditor Threat Detection Dashboard Change Auditor PowerShell Command Guide Change Auditor Dialogs
Change Auditor dialogs
Quest Change Auditor dialog Add Administrator Add Agents, Domains, Sites dialog Add Container dialog Add Active Directory Container dialog (AD Query) Add Facilities or Event Classes dialog Add Facilities or Event Classes dialog (Add With Events) Add File System Path dialog Add Foreign Forest Credential Add Group Policy Container dialog Add Local Account dialog Add Logons dialog Add Logons dialog (Add With Events) Add Object Classes dialog Add Object Classes dialog (Add With Events) Add Origin dialog Add Origin dialog (Add With Events) Add Registry Key dialog Add Results dialog Add Service dialog Add Service dialog (Add With Events) Add Severities dialog Add Severities dialog (Add With Events) Add SharePoint Path dialog Add SQL Instance dialog Add SQL Data Level Object Add Users, Computers or Groups dialog Add Where dialog Add Who dialog Advanced Deployment Options dialog Agent Assignment dialog Alert Body Configuration dialog Alert Custom Email dialog Auditing and Protection Templates dialog Authorizations: Application Group dialog Authorizations: Operations | Role Definitions | Task Definitions | Application Group Authorizations: Role dialog Authorizations: Task dialog Auto Deploy to New Servers in Forest dialog Browse for Folder dialog Browse SharePoint dialog Comments dialog Configuration Setup dialog Configure cepp.conf Auditing dialog Connection screen Coordinator Configuration tool Coordinator Credentials Required dialog Credentials Required dialog Custom Filter dialog Database Credentials Required dialog Directory object picker Domain Credentials dialog Eligible Change Auditor Agents dialog Event Logging dialog Export/Import dialog Install or Upgrade/Uninstall/Update Foreign Agent Credentials IP Address dialog Log page Logon Credentials dialog (Deployment page) Logon Credentials dialog (EMC Auditing wizard) Manage Connection Profiles dialog New Report Layout dialog Microsoft 365 dialog Rename dialog Save As dialog Select a SQL Instance and Database dialog Select Destination Folder dialog Select Exchange Users dialog Select Registry Key dialog Select SQL Reporting Services Template dialog Shared Mailboxes dialog SharePoint Credentials Required dialog When dialog
About Us

Agent Statistics and Logs

Previous Next


Agent Statistics and Logs

Introduction

Previous Next


Introduction

In addition to the overview information provided in the Top Agent Activity pane and Agent Status pane on the Overview page, you have two additional means of obtaining agent status and statistics:

The Agent Statistics page provides a global view of all installed (and if selected, uninstalled) Change Auditor agents, including the current status and other usage statistics for each agent.
The Change Auditor Agent Status dialog, which is accessed using the Change Auditor agent system tray icon, provides the status and usage statistics for a single agent.

You can also view or retrieve agent trace logs from the Agent Statistics page or by using the agent system tray icon.

Agent Statistics page

Previous Next


Agent Statistics page

Use the View | Statistics | Agent menu command (or Ctrl+F11) to display the Agent Statistics page, which provides a global view of all installed agents. This page contains the following components:

Agent Statistics grid, located at the top of the page, consists of a list of agents and their current status and usage statistics.
Resource Properties pane, located across the bottom of the page, displays additional information about the selected agent.

Agent Statistics grid

Previous Next


Agent Statistics grid

 

The Agent Statistics grid may contain the following information for each agent. The default column identifies the fields that are displayed by default. To display different fields, click the Field Chooser button located to the far left of the column headings and select the columns to be displayed:

Table 1. Agent Statistics page: Field descriptions

Column

Default

Description

Active Directory

No

Indicates whether custom Active Directory auditing or protection has been defined.

ADAM

No

Indicates whether custom ADAM (AD LDS) auditing or protection has been defined.

Agent

Yes

Displays the NetBIOS name of the server that hosts a Change Auditor agent.

Agent FQDN

No

Displays the fully qualified domain name of the agent.

Architecture

No

Displays whether the agent is installed in a 32-bit (x86) or 64-bit (x64) environment.

Configuration

No

Displays the agent configuration assigned to the agent.

Coordinator

No

Displays the computer name of the Change Auditor coordinator(s) to which the agent is connected.

DB Size

Yes

Displays the size of the agent database.

Domain

Yes

Displays the name of the domain where the agent is located.

EMC

No

Indicates whether the agent is assigned to an EMC Auditing template to capture EMC events.

Events Last 24 Hours

No

Displays the number of events encountered on the agent during the past 24 hours from when the dialog is initially opened during the current client session.

The value in this field is a hypertext link and when selected launches a quick search to display the events generated in the last 24 hours.

Events Last Hour

No

Displays the number of events encountered on the agent in the last 60 minutes from when the dialog is initially opened during the current client session.

The value in this field is a hypertext link and when selected launches a quick search to display the events generated in the last 60 minutes.

Events Today

Yes

Displays the number of events encountered on the agent since 12:00 a.m. of the current day (based on the relative coordinator computer's time).

The value in this field is a hypertext link and when selected launches a quick search to display the events generated today.

Events Total

Yes

Displays the number of events encountered since the agent was started.

The value in this field is a hypertext link and when selected launches a quick search to display all events encountered since the agent was started.

Events Yesterday

No

Displays the number of events encountered between 12:00 a.m. yesterday and 12:00 a.m. of the current day (based on the relative coordinator computer's time).

The value in this field is a hypertext link and when selected launches a quick search to display the events generated yesterday.

Exchange

No

For agents hosting Exchange, this column indicates whether Exchange Mailbox auditing or Exchange Mailbox protection has been defined.

Exchange Server

No

Indicates whether the server is an Exchange Server.

Exclude Account

No

Indicates whether an Excluded Accounts Auditing template has been assigned to the agent’s configuration.

File System

No

Indicates whether a File System Auditing template or File System Protection template has been assigned to the agent’s configuration.

Forest

No

Displays the name of the forest where the agent resides.

Group Policy

No

Indicates whether Group Policy protection has been defined.

IP Address

No

Displays the IP address of the agent.

Last Update

Yes

Displays the date and time when the agent configuration was last updated.

Load

Yes

Displays the load status of the agent service in regards to processing events. Valid entries are:

NetApp

No

Indicates whether an agent is assigned to a NetApp Auditing template to capture NetApp filer events.

Registry

No

Indicates whether a Registry Auditing template has been assigned to the agent’s configuration.

Service

No

Displays whether a Service Auditing template has been assigned to the agent’s configuration.

SharePoint

No

Indicates whether an agent is assigned to a SharePoint Auditing template to capture SharePoint events.

SQL

No

Indicates whether a SQL Auditing template has been assigned to the agent’s configuration.

Startup Time

No

Displays the date and time when the agent was last initialized.

Status

Yes

Displays the current status of the agent:

Type

No

Displays the agent platform:

Uptime

Yes

Displays how long the agent has been running.

Version

No

Displays the version number of the agent currently deployed.

Workstation

No

Indicates whether this is a workstation agent.

In addition to selecting the fields to display, you can use the drop-down controls to define what servers/workstations are to be included on the Agent Statistics page.

The following table describes how to use these controls to filter the content displayed on the Agent Statistics page.

Table 2. Agent Statistics page: Filter controls

Control

Description

Type

Use the left-most control to specify the type of objects to be included in the display:

All - select to view all agented servers and workstations (default)
DCs - select to view agented domain controller servers
Servers - select to view agented servers regardless of domain membership
Workstations - select to view agented workstations (including workstations joined to the domain and workstation agents manually installed on non-Active Directory computers)

Active Directory view

By default, the Agent Statistics page provides a forest view of the servers found. However, you can use the right-most controls to limit your view to an individual domain or site.

Use the middle control to select the Active Directory view (forest, domain or site) then use the right-most control to select an individual forest, domain or site for which servers are to be displayed.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating