Skip to content

Commit b18a321

Browse files
authored
Updated Activity Monitor 9.0 documentation (#356)
* Updated Activity Monitor 9.0 documentation * Updated Activity Monitor 9.0 documentation * Activity Monitor 9.0 documentation update. * Updated Activity Monitor 9.0 documentation. Fixed typos. * Updated Activity Monitor 9.0 documentation. Addressed review comments. * Updated Activity Monitor 9.0 documentation. Fixed review concerns. * Updated Activity Monitor 9.0 documentation. Fixed a KB article link and removed unused .webp files.
1 parent 12fec1d commit b18a321

File tree

645 files changed

+23595
-1
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

645 files changed

+23595
-1
lines changed
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
{
2+
"label": "Administration",
3+
"position": 40,
4+
"collapsed": true,
5+
"collapsible": true,
6+
"link": {
7+
"type": "doc",
8+
"id": "overview"
9+
}
10+
}
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
{
2+
"label": "Agents Tab",
3+
"position": 10,
4+
"collapsed": true,
5+
"collapsible": true,
6+
"link": {
7+
"type": "doc",
8+
"id": "overview"
9+
}
10+
}
Lines changed: 108 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,108 @@
1+
---
2+
title: "Active Directory Agent Deployment"
3+
description: "Active Directory Agent Deployment"
4+
sidebar_position: 40
5+
---
6+
7+
# Active Directory Agent Deployment
8+
9+
Before deploying the Active Directory (AD) agent, ensure all
10+
[AD Agent Server Requirements](/docs/activitymonitor/9.0/requirements/adagent/adagent.md) have been met. To effectively
11+
monitor Active Directory, it is necessary to deploy an AD agent to every domain controller,
12+
including the read only domain controllers. However, it is possible to deploy the agents in batches.
13+
Follow the steps to deploy the AD agents to the domain controllers in the target domain.
14+
15+
:::note
16+
These steps are specific to deploying AD agents for monitoring Active Directory.
17+
:::
18+
19+
20+
**Step 1 –** On the Agents tab, click Add agent to open the Add New Agent(s) window.
21+
22+
![Install New Agent](/images/activitymonitor/9.0/install/agent/installnew.webp)
23+
24+
**Step 2 –** Click on the Install agents on Active Directory domain controllers link to deploy
25+
activity agents to multiple domain controllers.
26+
27+
:::note
28+
The Activity Monitor will validate the entered Host Name or IP Address entered in the
29+
**Server Name** text box.
30+
:::
31+
32+
33+
![Specify Agent Port](/images/activitymonitor/9.0/install/agent/portdefault.webp)
34+
35+
**Step 3 –** Specify the port that should be used by the new agent(s).
36+
37+
![Agent Install Location](/images/activitymonitor/9.0/admin/agents/add/locationdefault.webp)
38+
39+
**Step 4 –** Select the agent installation path.
40+
41+
:::info
42+
Use the default installation path.
43+
:::
44+
45+
46+
![Active Directory Connection page with blank text boxes](/images/activitymonitor/9.0/admin/agents/add/adconnectionblank.webp)
47+
48+
**Step 5 –** On the Active Directory Connection page, enter the domain, and specify an account that
49+
is a member of BUILTIN\Administrators group on the domain. Then, click **Connect**.
50+
51+
![Example of a successful connection on the Active Directory Connection page](/images/activitymonitor/9.0/admin/agents/add/adconnectionsuccessful.webp)
52+
53+
When the connection is successful, the Next button is enabled. Click Next to continue.
54+
55+
:::note
56+
An Administrator’s credentials are required to test the connection to the server. This is
57+
the only way to enable the Next button.
58+
:::
59+
60+
61+
![Domains to Monitor page](/images/activitymonitor/9.0/admin/agents/add/domainstomonitorpage.webp)
62+
63+
**Step 6 –** On the Domains To Monitor page, available domains display in a list, checked by
64+
default. Check/uncheck the boxes as desired to identify the domains to monitor, then click Next.
65+
66+
![Domain Controllers to Deploy the Agent to page](/images/activitymonitor/9.0/admin/agents/add/dcstodeploytheagenttopage.webp)
67+
68+
**Step 7 –** On the Domain Controllers to deploy the Agent to page, available domain controllers
69+
display in a list, checked by default. Check/uncheck the boxes as desired to identify the domain
70+
controllers where the AD agent is to be deployed.
71+
72+
:::note
73+
Agents can be gradually deployed, but the AD agent needs to be installed on all domain
74+
controllers to monitor all activity of the domain.
75+
:::
76+
77+
78+
![Test Connection to Domain Controller](/images/activitymonitor/9.0/admin/agents/add/dcsdeployagentconnection.webp)
79+
80+
**Step 8 –** Click the **Test** button to verify the connection to the domains selected. Once the
81+
connection is verified, click **Next** to continue.
82+
83+
![Windows Agent Settings Page](/images/activitymonitor/9.0/admin/agents/add/windowsagentsettingspage.webp)
84+
85+
**Step 9 –** On the Windows Agent Settings page, there are two settings to configure.
86+
87+
- Add Windows file activity monitoring – Select the check box to add Windows file activity
88+
monitoring after installing the agent. By default a new agent install monitors nothing. If
89+
administrators want to monitor file activity on Windows servers, it is easier to enable it after
90+
installation of the agent. Windows file activity monitoring can be enabled and configured later in
91+
the console.
92+
- Management Group – By default, the agent only accepts commands from members of the
93+
BUILTIN\Administrators group. Less privilege accounts can be configured to manage the agent with
94+
the Management Group setting. Keep in mind that only administrators can install, update and
95+
uninstall the agent.
96+
97+
**Step 10 –** Click **Finish**. The Add New Agent(s) window closes, and the activity agent is
98+
deployed to and installed on the target host.
99+
100+
During the installation process, the status will be Installing. If there are any errors, the
101+
Activity Monitor stops the installation and lists the errors in the Agent messages box.
102+
103+
![AD Agent Installed](/images/activitymonitor/9.0/admin/agents/add/adagentinstalled.webp)
104+
105+
When the AD agent installation is complete, the status changes to **Installed** and the agent
106+
version populates in the AD Module column. The next step is to configure the domains to be
107+
monitored. See the [Monitored Domains Tab](/docs/activitymonitor/9.0/admin/monitoreddomains/overview.md) section for
108+
additional information.
Lines changed: 138 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,138 @@
1+
---
2+
title: "Linux Agent Deployment"
3+
description: "Linux Agent Deployment"
4+
sidebar_position: 30
5+
---
6+
7+
# Linux Agent Deployment
8+
9+
**Understanding Linux File Activity Monitoring**
10+
11+
The Activity Monitor can be configured to monitor the following:
12+
13+
- Ability to collect all or specific file activity for specific values or specific combinations of
14+
values
15+
16+
It also provides the ability to feed activity data to other Netwrix products:
17+
18+
- Netwrix Access Analyzer
19+
- Netwrix Threat Manager
20+
21+
Prior to adding a Windows host to the Activity Monitor, the prerequisites for the target environment
22+
must be met. See the [Linux Agent Server Requirements](/docs/activitymonitor/9.0/requirements/linuxagent.md) topic
23+
for additional information.
24+
25+
## Deploy Linux Agent
26+
27+
Follow the steps to deploy the agent to the Linux host.
28+
29+
**Step 1 –** On the Agents tab, click Add agent to open the Add New Agent(s) window.
30+
31+
![Install New Agent page of the Add New Agent(s) Wizard](/images/activitymonitor/9.0/install/agent/installnew.webp)
32+
33+
**Step 2 –** On the Install New Agent page, enter the server name for the Linux host. Click
34+
**Next**.
35+
36+
![Specify Agent Port](/images/activitymonitor/9.0/install/agent/portdefault.webp)
37+
38+
**Step 3 –** On the Agent Port page, specify the port to be used by the new agent. The default port
39+
is **4498**. Click **Next**.
40+
41+
![Credentials to Connect](/images/activitymonitor/9.0/admin/agents/add/credentialsservers.webp)
42+
43+
**Step 4 –** On the Credentials To Connect To The Server(s) page, connect to the Linux Server using
44+
either a **User name** and **Password**, or a Public Key.
45+
46+
The options for connecting with a Password are:
47+
48+
- User name
49+
- Password
50+
51+
![Public Key Credentials](/images/activitymonitor/9.0/admin/agents/add/publickey.webp)
52+
53+
The options for connecting with a Public Key are:
54+
55+
- User name
56+
- Private Key
57+
58+
![Client Certificate Credentials](/images/activitymonitor/9.0/admin/agents/add/clientcertificate.webp)
59+
60+
To connect with a Client Certificate, select the **Client Certificate** (for already installed
61+
agents) option. Run the following commands on the Linux machine:
62+
63+
```
64+
cd /usr/bin/activity-monitor-agentd/
65+
./activity-monitor-agentd create-client-certificate --name [name]
66+
```
67+
68+
The Client Certificate option adds an already installed agent to the console without using SSH.
69+
70+
To connect with a public key, select the **Public Key** option. Copy the following command into a
71+
command prompt to generate ECDSA key for public key option:
72+
73+
```
74+
ssh-keygen -m PEM -t ecdsa
75+
```
76+
77+
Netwrix Activity Monitor requires to generate ECDSA Key with a blank passphrase
78+
79+
```
80+
cat ~/.ssh/id_ecdsa.pub >> ~/.ssh/authorized_keys
81+
```
82+
83+
:::note
84+
It is required to add public key to authorized keys for Activity Monitor. By default, a
85+
private key is generated at ~/.ssh/id_ecdsa location along with the public key (.pub file). A user
86+
can use a different file location. Copy the following command into a command prompt to generate a
87+
private key for Activity Monitor to use:
88+
:::
89+
90+
91+
```
92+
cat ~/.ssh/id_ecdsa
93+
```
94+
95+
**Step 5 –** Click **Connect** to test the connection. If the connection is successful, click
96+
**Next**. If the connection is unsuccessful, see the status message that appears for information on
97+
the failed connection.
98+
99+
![Linux Agent Options](/images/activitymonitor/9.0/admin/agents/add/linuxagentoptions.webp)
100+
101+
**Step 6 –** On the Linux Agent Options page, select which user name to use to run the daemon. To
102+
use root, leave the **Service user name** field blank. Click **Test** to test the connection.
103+
104+
**Step 7 –** Click **Finish**. The Add New Agent(s) window closes, and the activity agent is
105+
deployed to and installed on the target host.
106+
107+
During the installation process, the status will be **Installing**. If there are any errors,
108+
Activity Monitor stops the installation and lists the errors in the **Agent messages** box.
109+
110+
![Linux Agent Installed](/images/activitymonitor/9.0/admin/agents/add/activitymonitorwithlinuxagentinstalled.webp)
111+
112+
When the Linux agent installation is complete, the status changes to **Installed**. The Monitored
113+
Host is also configured, and the added Linux host is displayed in the monitored hosts table. See the
114+
[Monitored Hosts & Services Tab](/docs/activitymonitor/9.0/admin/monitoredhosts/overview.md) topic for additional information.
115+
116+
Once a host has been added for monitoring, configure the desired outputs. See the
117+
[Output for Monitored Hosts](/docs/activitymonitor/9.0/admin/monitoredhosts/output/output.md) topic for additional information.
118+
119+
:::info
120+
Activity Monitor Agent uses certificates to secure the connection between the Linux Agent and the Console / API Server.
121+
By default, the Agent uses an automatically generated self-signed certificate. The Console and the API Server do not enforce
122+
validity checks on these self-signed agent certificates.
123+
124+
This self-signed certificate can be replaced with one issued by a Certification Authority. Once replaced, the Console and
125+
the API Server will ensure the validity of the agent’s certificates.
126+
127+
See the [Certificate](/docs/activitymonitor/9.0/admin/agents/properties/certificate.md) topic for additional information.
128+
:::
129+
130+
## Host Properties for Linux
131+
132+
Configuration settings can be edited through the tabs in the host’s Properties window. The
133+
configurable host properties are:
134+
135+
- [Inactivity Alerts Tab](/docs/activitymonitor/9.0/admin/monitoredhosts/properties/inactivityalerts.md)
136+
137+
See the [Host Properties Window](/docs/activitymonitor/9.0/admin/monitoredhosts/properties/overview.md) topic for additional
138+
information.

0 commit comments

Comments
 (0)