From 2f72ac2adc5952404b91ca46d910e0538c426a02 Mon Sep 17 00:00:00 2001 From: Zoey Castillo Date: Wed, 12 Nov 2025 10:04:02 -0600 Subject: [PATCH] Fix broken image references and markdown links in KB articles MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Updated 31 KB article image references to use correct relative paths to parent product image directories - 1secure files: changed images/ to ../../images/ (2 levels deep) - auditor files: changed images/ to ../../../images/ (3 levels deep) - Fixed 10 broken markdown links that reference KB articles reorganized into new subfolder structure - Updated links to point to new article locations in categorized subfolders These fixes resolve all MDX compilation errors preventing the build from completing. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude --- ...te_to_prevent_rdp_certificate_warnings).md | 43 ++++++++++--------- ..._to_windows_resources_(psremotingwinrm).md | 5 ++- ...licy-changes-reported-as-made-by-system.md | 5 ++- .../active-directory-object-restore.md | 4 +- ...e-directory-and-entra-id-license-counts.md | 6 ++- ...windows-file-server-compression-service.md | 5 ++- ...y-exists-in-file-server-monitoring-plan.md | 5 ++- ...s-audit-service-terminated-unexpectedly.md | 5 ++- ...ed-error-in-file-server-monitoring-plan.md | 4 +- ...ort-in-netwrix-auditor-for-file-servers.md | 4 +- ...nid-in-netwrix-auditor-for-file-servers.md | 4 +- ...-is-unable-to-start-during-installation.md | 4 +- ...but-still-exists-in-the-services-overvi.md | 4 +- ...-configure-monitoring-of-local-accounts.md | 4 +- ...figure-netwrix-auditor-in-failover-mode.md | 7 ++- .../how-to-install-access-reviews.md | 4 +- ...nts-prior-to-further-clear-installation.md | 5 ++- ...-to-repair-netwrix-auditor-installation.md | 4 +- ...ta-sources-to-use-proxy-server-settings.md | 10 +++-- ...es-with-error-validating-your-account-s.md | 4 +- ...tion-for-microsoft-365-service-accounts.md | 6 ++- ...-auditing-a-microsoft-office-365-tenant.md | 4 +- ...soft_entra_id_(auditor_v10.0_and_older).md | 11 ++--- ...int-online-and-ms-teams-monitoring-plan.md | 4 +- ...arepoint-application-deployment-for-ndc.md | 10 +++-- ...llation-for-netwrix-data-classification.md | 10 +++-- ...hoot_sharepoint_serveron-premise_errors.md | 6 ++- ...ext-error-in-sql-server-monitoring-plan.md | 7 ++- ...not-valid-in-sql-server-monitoring-plan.md | 6 ++- ...-find-stored-procedure-getallproperties.md | 5 ++- ...ver-settings-in-audit-database-settings.md | 7 ++- 31 files changed, 140 insertions(+), 72 deletions(-) diff --git a/docs/kb/1secure/certificate-management/configure_proxy_for_rdp_connections_(installupdate_certificate_to_prevent_rdp_certificate_warnings).md b/docs/kb/1secure/certificate-management/configure_proxy_for_rdp_connections_(installupdate_certificate_to_prevent_rdp_certificate_warnings).md index f58ba64e3d..b11f8df9aa 100644 --- a/docs/kb/1secure/certificate-management/configure_proxy_for_rdp_connections_(installupdate_certificate_to_prevent_rdp_certificate_warnings).md +++ b/docs/kb/1secure/certificate-management/configure_proxy_for_rdp_connections_(installupdate_certificate_to_prevent_rdp_certificate_warnings).md @@ -26,7 +26,7 @@ This article outlines the process for installing or updating a certificate to pr > **IMPORTANT:** The Certification Authority's post-deployment configuration must be completed after installing both prerequisite roles. - ![Certification Authority post-deployment configuration dialog with required options visible](./images/servlet_image_22726c8e5cb9.png) + ![Certification Authority post-deployment configuration dialog with required options visible](../../images/servlet_image_22726c8e5cb9.png) - The domain must have the **Enrollment Policy** set to enable automatic enrollment and renewal. The **Certificate Enrollment Policy** for user and computer certificates is configured in the **Group Policy** snap-in under **Default Domain Policy** (or another group policy applied to all systems that will access an NPS server on a group-by-group basis). To configure this: @@ -40,28 +40,28 @@ This article outlines the process for installing or updating a certificate to pr > **NOTE:** If you already have a certificate to install, you can skip to the **Adding the Certificate to Each SbPAM Proxy Server** section below. 1. Open **Certification Authority**, open your CA, right-click **Certificate Templates**, and click **Manage**. - ![Certification Authority console with Certificate Templates context menu open](./images/servlet_image_ebb3b2e4c66a.png) + ![Certification Authority console with Certificate Templates context menu open](../../images/servlet_image_ebb3b2e4c66a.png) 2. In the **Certificate Templates Console**, right-click **Workstation Authentication**, and click **Duplicate Template**. - ![Certificate Templates Console with Duplicate Template option highlighted](./images/servlet_image_e3eecaa55357.png) + ![Certificate Templates Console with Duplicate Template option highlighted](../../images/servlet_image_e3eecaa55357.png) 3. On the **General** tab, change the name to **Client-Server Authentication** and enable the **Publish certificate in Active Directory** checkbox. - ![General tab of template properties with name and publish option highlighted](./images/servlet_image_35245db9daa9.png) + ![General tab of template properties with name and publish option highlighted](../../images/servlet_image_35245db9daa9.png) 4. On the **Subject Name** tab, enable the **Supply in the request** radio button. - ![Subject Name tab with Supply in the request option selected](./images/servlet_image_2b1a501d40fd.png) + ![Subject Name tab with Supply in the request option selected](../../images/servlet_image_2b1a501d40fd.png) 5. On the **Extensions** tab, select **Application Policies** and click **Edit**. Click **Add**, then select **Server Authentication**. Click **OK** until you return to the **Properties of New Template** dialog. - ![Extensions tab with Application Policies and Server Authentication highlighted](./images/servlet_image_9ccee298858e.png) + ![Extensions tab with Application Policies and Server Authentication highlighted](../../images/servlet_image_9ccee298858e.png) 6. On the **Security** tab, select **Domain Computers** and enable the checkbox to allow **Autoenroll**. Click **OK** and then close the Certificate Templates Console. - ![Security tab with Domain Computers and Autoenroll option checked](./images/servlet_image_d2bd2889a956.png) + ![Security tab with Domain Computers and Autoenroll option checked](../../images/servlet_image_d2bd2889a956.png) 7. Back in **Certification Authority**, right-click **Certificate Templates**, hover over **New**, and click **Certificate Template to Issue**. - ![Certification Authority with Certificate Template to Issue option highlighted](./images/servlet_image_4e7a38bb30d6.png) + ![Certification Authority with Certificate Template to Issue option highlighted](../../images/servlet_image_4e7a38bb30d6.png) 8. Select **Client-Server Authentication** and click **OK**. - ![Certificate Template selection dialog with Client-Server Authentication selected](./images/servlet_image_d8afec47d2b9.png) + ![Certificate Template selection dialog with Client-Server Authentication selected](../../images/servlet_image_d8afec47d2b9.png) 9. On the desktop, create a text file named **request.inf** with the following content (replace the **red** text with your server certificate name): @@ -96,44 +96,44 @@ This article outlines the process for installing or updating a certificate to pr certreq -new request.inf rdp.csr ``` - ![Command Prompt showing certreq command execution](./images/servlet_image_117381e3f99f.png) + ![Command Prompt showing certreq command execution](../../images/servlet_image_117381e3f99f.png) 11. To sign the certificate request, use your preferred signing mechanism. The following example uses Active Directory Certificate Services (`https:///certsrv`). - ![Certificate Services web enrollment home page](./images/servlet_image_c706e5610294.png) ![Certificate Services advanced certificate request page](./images/servlet_image_0f3e849ec385.png) + ![Certificate Services web enrollment home page](../../images/servlet_image_c706e5610294.png) ![Certificate Services advanced certificate request page](../../images/servlet_image_0f3e849ec385.png) Click **Request a certificate**, then click **advanced certificate request**. 12. Open the saved certificate signing request (**rdp.csr**) from the previous step in Notepad. Copy the certificate request into the **Saved Request** field. Select **Client-Server Authentication** from the **Certificate Template** dropdown. Click **Submit**. - ![Certificate request submission form with fields filled](./images/servlet_image_21d63c042bef.png) + ![Certificate request submission form with fields filled](../../images/servlet_image_21d63c042bef.png) Leave other settings at default values, and click **Submit**. 13. Select **DER encoded** and click **Download certificate**. - ![Certificate download page with DER encoded option selected](./images/servlet_image_ff7ee6960cb2.png) + ![Certificate download page with DER encoded option selected](../../images/servlet_image_ff7ee6960cb2.png) 14. Open the downloaded certificate and select **Install Certificate**. Proceed with all default values and complete the wizard. - ![Certificate installation wizard with default options](./images/servlet_image_9751657fe7cd.png) + ![Certificate installation wizard with default options](../../images/servlet_image_9751657fe7cd.png) 15. To export the certificate, view certificates for the current user by launching **certmgr.msc** using the Windows **Run** menu. - ![Windows Run dialog with certmgr.msc entered](./images/servlet_image_f5c0eb62aa44.png) + ![Windows Run dialog with certmgr.msc entered](../../images/servlet_image_f5c0eb62aa44.png) Right-click the installed certificate (the certificate using the **Client-Server Authentication** template) and click **Export...**. - ![Certificate export context menu](./images/servlet_image_4f237c8e6acb.png) + ![Certificate export context menu](../../images/servlet_image_4f237c8e6acb.png) 16. In the **Certificate Export Wizard**, change the **Export Private Key** option to **Yes, export the private key**. - ![Certificate Export Wizard with Export Private Key option selected](./images/servlet_image_9a7649f21943.png) + ![Certificate Export Wizard with Export Private Key option selected](../../images/servlet_image_9a7649f21943.png) 17. For **Export File Format**, select **Personal Information Exchange - PKCS #12 (.PFX)**. Select the following checkboxes: - Include all certificates in the certification path if possible - Enable certificate privacy - ![Export File Format options with PKCS #12 and checkboxes selected](./images/servlet_image_491abdc2366b.png) + ![Export File Format options with PKCS #12 and checkboxes selected](../../images/servlet_image_491abdc2366b.png) 18. For **Security**, enter a password of your choosing and select the AES256-SHA256 encryption option (3DES is no longer recommended by NIST). > **IMPORTANT:** For **File to Export**, the file name **must** be **rdp.pfx**. If it is named anything else, importing the .pfx file on each proxy server will not work. - ![Export dialog with rdp.pfx file name entered](./images/servlet_image_808a1a23eec9.png) + ![Export dialog with rdp.pfx file name entered](../../images/servlet_image_808a1a23eec9.png) 19. This certificate can now be imported to each SbPAM Proxy Server. @@ -149,6 +149,7 @@ This article outlines the process for installing or updating a certificate to pr "C:\Program Files\Stealthbits\PAM\ProxyService\sbpam-proxy.exe" ca import -p [PATH]\rdp.pfx ``` - ![Command Prompt showing sbpam-proxy.exe ca import command](./images/servlet_image_07c7409683d2.png) + ![Command Prompt showing sbpam-proxy.exe ca import command](../../images/servlet_image_07c7409683d2.png) + +3. The new certificate has now been imported to an SbPAM Proxy Server. Repeat this process for all SbPAM Proxy Servers if using more than one. (The default installation of SbPAM uses one proxy service on the SbPAM server itself; however, additional proxy services can be distributed.) -3. The new certificate has now been imported to an SbPAM Proxy Server. Repeat this process for all SbPAM Proxy Servers if using more than one. (The default installation of SbPAM uses one proxy service on the SbPAM server itself; however, additional proxy services can be distributed.) \ No newline at end of file diff --git a/docs/kb/1secure/troubleshooting/troubleshoot_failed_action_service_connections_to_windows_resources_(psremotingwinrm).md b/docs/kb/1secure/troubleshooting/troubleshoot_failed_action_service_connections_to_windows_resources_(psremotingwinrm).md index 0a1aa136e8..bed087f607 100644 --- a/docs/kb/1secure/troubleshooting/troubleshoot_failed_action_service_connections_to_windows_resources_(psremotingwinrm).md +++ b/docs/kb/1secure/troubleshooting/troubleshoot_failed_action_service_connections_to_windows_resources_(psremotingwinrm).md @@ -87,7 +87,7 @@ There are Group Policy settings used to filter the origin of WinRM requests via Learn more about the **Allow remote server management through WinRM** Group Policy setting in [Configure Remote Management in Server Manager − Enabling or Disabling Remote Management ⸱ Microsoft 🡥](https://learn.microsoft.com/en-us/windows-server/administration/server-manager/configure-remote-management-in-server-manager#enabling-or-disabling-remote-management). -![Windows Group Policy: Allow remote server management through WinRM](./images/servlet_image_16fc9e2e2432.png) +![Windows Group Policy: Allow remote server management through WinRM](../../images/servlet_image_16fc9e2e2432.png) ### Allow full control to Remote Management Users @@ -132,4 +132,5 @@ The output indicates that the credentials used can run remote PowerShell command ## Related articles -[Configure Remote Management in Server Manager − Enabling or Disabling Remote Management ⸱ Microsoft 🡥](https://learn.microsoft.com/en-us/windows-server/administration/server-manager/configure-remote-management-in-server-manager#enabling-or-disabling-remote-management) \ No newline at end of file +[Configure Remote Management in Server Manager − Enabling or Disabling Remote Management ⸱ Microsoft 🡥](https://learn.microsoft.com/en-us/windows-server/administration/server-manager/configure-remote-management-in-server-manager#enabling-or-disabling-remote-management) + diff --git a/docs/kb/auditor/configuration-and-setup/active-directory-auditing/active-directory-exchange-and-group-policy-changes-reported-as-made-by-system.md b/docs/kb/auditor/configuration-and-setup/active-directory-auditing/active-directory-exchange-and-group-policy-changes-reported-as-made-by-system.md index 6e55ec7dff..31f7775195 100644 --- a/docs/kb/auditor/configuration-and-setup/active-directory-auditing/active-directory-exchange-and-group-policy-changes-reported-as-made-by-system.md +++ b/docs/kb/auditor/configuration-and-setup/active-directory-auditing/active-directory-exchange-and-group-policy-changes-reported-as-made-by-system.md @@ -24,10 +24,13 @@ knowledge_article_id: kA00g000000H9SmCAK This article contains references to the most popular Active Directory, Exchange, and Group Policy changes which may be reported as made by **System** by Netwrix Auditor: -- [Alert Reported Change Made by System](/docs/kb/auditor/alert-reported-change-made-by-system.md). +- [Alert Reported Change Made by System](/docs/kb/auditor/reports-alerts-and-notifications/report-generation/alert-reported-change-made-by-system.md). - [System Changed Object Path after Account Name Change](/docs/kb/auditor/system-changed-object-path-after-account-name-change.md). - [System Changed Client Operating System](/docs/kb/auditor/system-changed-client-operating-system.md). - [System Changed Directory Objects for Foreign Security Principals](/docs/kb/auditor/system-changed-directory-objects-for-foreign-security-principals.md). - [Workstation Field Reported as Unknown](/docs/kb/auditor/workstation-field-reported-as-unknown.md) - [Duplicate Configuration and Schema Changes for All Monitored Domains in Forest Made by System](/docs/kb/auditor/duplicate-configuration-and-schema-changes-for-all-monitored-domains-in-forest-made-by-system.md). - [System Changed Service Principle Name Attribute](/docs/kb/auditor/system-changed-service-principle-name-attribute.md). + + + diff --git a/docs/kb/auditor/configuration-and-setup/active-directory-auditing/active-directory-object-restore.md b/docs/kb/auditor/configuration-and-setup/active-directory-auditing/active-directory-object-restore.md index 511b2506c0..b3e29addf5 100644 --- a/docs/kb/auditor/configuration-and-setup/active-directory-auditing/active-directory-object-restore.md +++ b/docs/kb/auditor/configuration-and-setup/active-directory-auditing/active-directory-object-restore.md @@ -38,10 +38,12 @@ The Netwrix Active Directory Object Restore tool recovers removed Active Directo The account used for recovery and restore is the same account used for data collection in your Netwrix Auditor Active Directory monitoring plan. -
![Active](images/servlet_image_3823966b1661.png)
+
![Active](../../../images/servlet_image_3823966b1661.png)
> **NOTE:** This tool should **NOT** be used to revert the changes caused by raising the forest functional level. For additional information, refer to the following article: Object Restore for Active Directory. ## Related Link - Object Restore for Active Directory + + diff --git a/docs/kb/auditor/configuration-and-setup/active-directory-auditing/reducing-the-used-active-directory-and-entra-id-license-counts.md b/docs/kb/auditor/configuration-and-setup/active-directory-auditing/reducing-the-used-active-directory-and-entra-id-license-counts.md index d55031d5f0..cd745315e1 100644 --- a/docs/kb/auditor/configuration-and-setup/active-directory-auditing/reducing-the-used-active-directory-and-entra-id-license-counts.md +++ b/docs/kb/auditor/configuration-and-setup/active-directory-auditing/reducing-the-used-active-directory-and-entra-id-license-counts.md @@ -58,11 +58,11 @@ Refer to the following steps to exclude OUs and user objects from the monitoring 2. Select the relevant AD monitoring plan and click **Edit**. 3. Select the data source and click **Edit data source**. -![Edit data source](./images/ka0Qk000000EIjS_0EMQk00000661ik.png) +![Edit data source](../../../images/ka0Qk000000EIjS_0EMQk00000661ik.png) 4. In the left pane, select the **Objects** tab. Select the **Exclude these objects** checkbox, then click **Add** to exclude objects from the monitoring scope. After adding the objects, click **Save & Close**. -![Exclude these objects](./images/ka0Qk000000EIjS_0EMQk000005FPXt.png) +![Exclude these objects](../../../images/ka0Qk000000EIjS_0EMQk000005FPXt.png) Refer to the following examples to learn about how the exclusion rules work for **Objects**. The same logic applies to the inclusion rules: @@ -99,3 +99,5 @@ To exclude specific Entra ID users from the license count, populate the `omitUPN - [Determining the Number of Enabled Microsoft Entra ID Accounts](/docs/kb/auditor/determining-the-number-of-enabled-microsoft-entra-id-accounts.md) - [Active Directory Monitoring Scope](https://docs.netwrix.com/docs/auditor/10_8) - [Microsoft Entra ID Monitoring Scope](https://docs.netwrix.com/docs/auditor/10_8) + + diff --git a/docs/kb/auditor/configuration-and-setup/file-server-auditing/cannot-establish-a-connection-to-a-windows-file-server-compression-service.md b/docs/kb/auditor/configuration-and-setup/file-server-auditing/cannot-establish-a-connection-to-a-windows-file-server-compression-service.md index 9bd884c2d6..13285059da 100644 --- a/docs/kb/auditor/configuration-and-setup/file-server-auditing/cannot-establish-a-connection-to-a-windows-file-server-compression-service.md +++ b/docs/kb/auditor/configuration-and-setup/file-server-auditing/cannot-establish-a-connection-to-a-windows-file-server-compression-service.md @@ -47,5 +47,8 @@ After that, the **Netwrix Auditor Application Deployment Service** appears on th ### Related Articles -- [How to Investigate Compression Services Errors](/docs/kb/auditor/how-to-investigate-compression-services-errors.md) +- [How to Investigate Compression Services Errors](/docs/kb/auditor/troubleshooting-and-errors/data-collection-errors/how-to-investigate-compression-services-errors.md) - [Windows File Servers — Enable Remote Registry Service — v10.8.](https://docs.netwrix.com/docs/auditor/10_8/configuration/fileservers/windows/remoteregistryservice) + + + diff --git a/docs/kb/auditor/configuration-and-setup/file-server-auditing/child-item-with-this-name-already-exists-in-file-server-monitoring-plan.md b/docs/kb/auditor/configuration-and-setup/file-server-auditing/child-item-with-this-name-already-exists-in-file-server-monitoring-plan.md index 1b961345d1..eea481d1fb 100644 --- a/docs/kb/auditor/configuration-and-setup/file-server-auditing/child-item-with-this-name-already-exists-in-file-server-monitoring-plan.md +++ b/docs/kb/auditor/configuration-and-setup/file-server-auditing/child-item-with-this-name-already-exists-in-file-server-monitoring-plan.md @@ -42,5 +42,8 @@ The licensing data was corrupted. ## Resolution - In case you've encountered the issue after a recent upgrade, wait for 24 hours to see if the issue is resolved on its own. -- Reapply the license file. Refer to the following article for additional information: [How to Apply Netwrix Auditor License](/docs/kb/auditor/how-to-apply-netwrix-auditor-license.md). +- Reapply the license file. Refer to the following article for additional information: [How to Apply Netwrix Auditor License](/docs/kb/auditor/system-administration/licensing-and-compliance/how-to-apply-netwrix-auditor-license.md). - In case reapplying the license did not help, contact [Netwrix Technical Support](https://www.netwrix.com/open_a_ticket.html). + + + diff --git a/docs/kb/auditor/configuration-and-setup/file-server-auditing/error-netwrix-auditor-for-file-servers-audit-service-terminated-unexpectedly.md b/docs/kb/auditor/configuration-and-setup/file-server-auditing/error-netwrix-auditor-for-file-servers-audit-service-terminated-unexpectedly.md index 2e4f759461..7a16075c30 100644 --- a/docs/kb/auditor/configuration-and-setup/file-server-auditing/error-netwrix-auditor-for-file-servers-audit-service-terminated-unexpectedly.md +++ b/docs/kb/auditor/configuration-and-setup/file-server-auditing/error-netwrix-auditor-for-file-servers-audit-service-terminated-unexpectedly.md @@ -59,4 +59,7 @@ If you are currently on a 10.5 version and build other than 10950, perform the p ## Related articles -- [How to Upgrade Netwrix Auditor](/docs/kb/auditor/how-to-upgrade-netwrix-auditor.md) +- [How to Upgrade Netwrix Auditor](/docs/kb/auditor/system-administration/migration-and-upgrade/how-to-upgrade-netwrix-auditor.md) + + + diff --git a/docs/kb/auditor/configuration-and-setup/file-server-auditing/symbolic-link-cannot-be-followed-error-in-file-server-monitoring-plan.md b/docs/kb/auditor/configuration-and-setup/file-server-auditing/symbolic-link-cannot-be-followed-error-in-file-server-monitoring-plan.md index 93ac510024..ec065227ce 100644 --- a/docs/kb/auditor/configuration-and-setup/file-server-auditing/symbolic-link-cannot-be-followed-error-in-file-server-monitoring-plan.md +++ b/docs/kb/auditor/configuration-and-setup/file-server-auditing/symbolic-link-cannot-be-followed-error-in-file-server-monitoring-plan.md @@ -52,7 +52,7 @@ Enable all symbolic link types. Once executed, you'll see the settings for symbolic links (enabled or disabled). - ![SymlinkEvaluation output](images/servlet_image_3823966b1661.png) + ![SymlinkEvaluation output](../../../images/servlet_image_3823966b1661.png) 2. To enable a symlink type, run the following command: @@ -63,3 +63,5 @@ Enable all symbolic link types. The `R2L:1` stands for remote-to-local enabled. You can change `R` to `L` and vice versa to enable the disabled symlink. Learn more about fsutil syntax in the Microsoft documentation: https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-behavior (fsutil behavior ⸱ Microsoft) + + diff --git a/docs/kb/auditor/configuration-and-setup/file-server-auditing/volume-shadow-copy-service-support-in-netwrix-auditor-for-file-servers.md b/docs/kb/auditor/configuration-and-setup/file-server-auditing/volume-shadow-copy-service-support-in-netwrix-auditor-for-file-servers.md index 3197a34604..77d2f418c4 100644 --- a/docs/kb/auditor/configuration-and-setup/file-server-auditing/volume-shadow-copy-service-support-in-netwrix-auditor-for-file-servers.md +++ b/docs/kb/auditor/configuration-and-setup/file-server-auditing/volume-shadow-copy-service-support-in-netwrix-auditor-for-file-servers.md @@ -32,8 +32,10 @@ The **Volume Shadow Copy Service** (hereafter **VSS**) can be enabled via **Netw 1. Navigate to **Managed Objects -> your_File_Servers_Managed_Object_name -> File Servers.** 2. Click **Configure** next to **Advanced Settings** and select the **Enable file versioning and rollback capabilities (based on Volume Shadow Copy).** -![User-added image](images/ka04u000000HcNV_0EM700000007LkF.png) +![User-added image](../../../images/ka04u000000HcNV_0EM700000007LkF.png) ## Where Shadow Copy data is stored The **Shadow Copy** data is stored on the audited file server. **VSS** is a built-in **Windows** service, and when you enable the VSS support, **Netwrix Auditor** just triggers creation of a snapshot. If you have not configured **VSS**, you may want to turn it off (especially if you do not have enough space on that server). To know precisely where the **Shadow Copy** data is stored, refer to the **Shadow Copy** information on the drive volume. + + diff --git a/docs/kb/auditor/configuration-and-setup/file-server-auditing/what-is-sessionid-in-netwrix-auditor-for-file-servers.md b/docs/kb/auditor/configuration-and-setup/file-server-auditing/what-is-sessionid-in-netwrix-auditor-for-file-servers.md index 024cc54f99..91c2591d98 100644 --- a/docs/kb/auditor/configuration-and-setup/file-server-auditing/what-is-sessionid-in-netwrix-auditor-for-file-servers.md +++ b/docs/kb/auditor/configuration-and-setup/file-server-auditing/what-is-sessionid-in-netwrix-auditor-for-file-servers.md @@ -33,7 +33,7 @@ This attribute is based on the user’s logon ID within the current session. Bei Session IDs are used to identify changes made by users with unique logon ID's. Session IDs are a combination of both the logon ID itself and the current session associated with this logon ID, to help identifying who made the change. Thus, session ID can be changed due to the fact that Netwrix would count that as a separate activity record too. -![User-added image](images/ka0Qk0000001OrV_0EMQk000002Tph8.png) +![User-added image](../../../images/ka0Qk0000001OrV_0EMQk000002Tph8.png) In addition, Netwrix Auditor generates the following attribute besides Session ID, associated with the object and reserved for internal use: @@ -44,3 +44,5 @@ Since the product associates Session IDs with the current session of the user, t ### Related Article - [How Does Merging Logon Activity Events Work?](/docs/kb/auditor/how-does-merging-logon-activity-events-work.md) + + diff --git a/docs/kb/auditor/configuration-and-setup/general-configuration/ale-service-is-unable-to-start-during-installation.md b/docs/kb/auditor/configuration-and-setup/general-configuration/ale-service-is-unable-to-start-during-installation.md index 13cdb8f4d8..49a966848e 100644 --- a/docs/kb/auditor/configuration-and-setup/general-configuration/ale-service-is-unable-to-start-during-installation.md +++ b/docs/kb/auditor/configuration-and-setup/general-configuration/ale-service-is-unable-to-start-during-installation.md @@ -23,7 +23,7 @@ knowledge_article_id: kA00g000000H9YCCA0 During installation of NetWrix Account Lockout Examiner on **Windows 2003**, a "Service 'NetWrix Account Lockout Examiner' (ALService) failed to start" message is received that the service cannot be started due to insufficient permissions. The account in use is a domain admin. -![User-added image](images/ka04u000000HcRH_0EM700000004wmJ.png) +![User-added image](../../../images/ka04u000000HcRH_0EM700000004wmJ.png) ## Cause @@ -39,3 +39,5 @@ Also: 1. Verify that the account specified during installation is a local admin. 2. Check that there are no restrictive policies for this account to run services. 3. Try entering another local admin or domain admin account during the installation. + + diff --git a/docs/kb/auditor/configuration-and-setup/general-configuration/compression-service-does-not-appear-under-installed-programs-but-still-exists-in-the-services-overvi.md b/docs/kb/auditor/configuration-and-setup/general-configuration/compression-service-does-not-appear-under-installed-programs-but-still-exists-in-the-services-overvi.md index 3e455f906d..84ee4e278e 100644 --- a/docs/kb/auditor/configuration-and-setup/general-configuration/compression-service-does-not-appear-under-installed-programs-but-still-exists-in-the-services-overvi.md +++ b/docs/kb/auditor/configuration-and-setup/general-configuration/compression-service-does-not-appear-under-installed-programs-but-still-exists-in-the-services-overvi.md @@ -38,7 +38,7 @@ You can manually delete the Service and its components. For that: 1. Open the **Services** snap-in and open properties of the problematic service. 2. Copy the full name of the service and the path to executable, for example, to a **Notepad** document. - ![User-added image](images/ka0Qk0000001hxN_0EMQk000002u2KX.png) + ![User-added image](../../../images/ka0Qk0000001hxN_0EMQk000002u2KX.png) 3. Run the command prompt as administrator and run the following command: ```bat @@ -47,3 +47,5 @@ You can manually delete the Service and its components. For that: where the `` is the full name of the service you copied on the step 2. 4. After that, navigate to the file path you copied earlier and delete all the files. + + diff --git a/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-configure-monitoring-of-local-accounts.md b/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-configure-monitoring-of-local-accounts.md index dac8335baf..3ec0b84d06 100644 --- a/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-configure-monitoring-of-local-accounts.md +++ b/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-configure-monitoring-of-local-accounts.md @@ -29,6 +29,8 @@ Netwrix Account Lockout Examiner can be set to monitor local machine event logs 5. In the next dialog box, select the **Domain Controller** radio button and enter the the name of workstation local events of which you want to monitor 6. Press the **OK** button. Press the **OK** button again. -[![User-added image](images/ka04u000000HcWP_0EM700000004wxl.png)](https://netwrix.secure.force.com/kb/servlet/rtaImage?eid=ka40g000000kAbY&feoid=00N700000032Pj2&refid=0EM700000004wxl) +[![User-added image](../../../images/ka04u000000HcWP_0EM700000004wxl.png)](https://netwrix.secure.force.com/kb/servlet/rtaImage?eid=ka40g000000kAbY&feoid=00N700000032Pj2&refid=0EM700000004wxl) **Note:** Make sure that the account used to run the Account Lockout Examiner service has administrative access to the machine you are adding. + + diff --git a/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-configure-netwrix-auditor-in-failover-mode.md b/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-configure-netwrix-auditor-in-failover-mode.md index 2fc3ff43a6..eb2c3a4e45 100644 --- a/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-configure-netwrix-auditor-in-failover-mode.md +++ b/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-configure-netwrix-auditor-in-failover-mode.md @@ -36,7 +36,7 @@ Refer to the following steps to configure Netwrix Auditor in failover mode: > **NOTE:** If Netwrix Auditor is already installed on a physical machine, consider migrating it to a virtual box. Some vendors support "physical to VM" migration." -2. Configure the Long-Term Archive (LTA) to be stored on a remote location, such as a shared iSCSI volume. Refer to the following Netwrix knowledge base article for instructions on how to move LTA to a new location: [How to Move Long-Term Archive to a New Location](/docs/kb/auditor/how-to-move-long-term-archive-to-a-new-location.md) +2. Configure the Long-Term Archive (LTA) to be stored on a remote location, such as a shared iSCSI volume. Refer to the following Netwrix knowledge base article for instructions on how to move LTA to a new location: [How to Move Long-Term Archive to a New Location](/docs/kb/auditor/features-and-operations/glossaries-and-faqs/how-to-move-long-term-archive-to-a-new-location.md) 3. For setting up backup and failover, ensure that the volume under LTA and Working Folder is redundant enough to survive failure. @@ -60,4 +60,7 @@ For alternative backup and failover options, refer to the steps below. ## Related Articles -- How to Move Long-Term Archive to a New Location: [How to Move Long-Term Archive to a New Location](/docs/kb/auditor/how-to-move-long-term-archive-to-a-new-location.md) +- How to Move Long-Term Archive to a New Location: [How to Move Long-Term Archive to a New Location](/docs/kb/auditor/features-and-operations/glossaries-and-faqs/how-to-move-long-term-archive-to-a-new-location.md) + + + diff --git a/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-install-access-reviews.md b/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-install-access-reviews.md index fbc3761a9d..54c17e8d53 100644 --- a/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-install-access-reviews.md +++ b/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-install-access-reviews.md @@ -35,4 +35,6 @@ In case you're planning the on-premise deployment, click **On-premises Deploymen For the VM deployment, proceed with the **Virtual Appliance** option and select the suitable package. Netwrix Auditor Access Reviews will come preinstalled for the VM of your choice. -![pI1UIaaJkT.png](images/ka04u00000116Ju_0EM4u000008LKrz.png) +![pI1UIaaJkT.png](../../../images/ka04u00000116Ju_0EM4u000008LKrz.png) + + diff --git a/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-properly-remove-auditor-components-prior-to-further-clear-installation.md b/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-properly-remove-auditor-components-prior-to-further-clear-installation.md index c15e850d6e..c9a030eb4f 100644 --- a/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-properly-remove-auditor-components-prior-to-further-clear-installation.md +++ b/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-properly-remove-auditor-components-prior-to-further-clear-installation.md @@ -53,4 +53,7 @@ In most cases, yes it does. However, for the proper uninstallation of all compre ### Related Article -- [Migrating Auditor to New Server](/docs/kb/auditor/migrating-auditor-to-new-server.md) +- [Migrating Auditor to New Server](/docs/kb/auditor/features-and-operations/glossaries-and-faqs/migrating-auditor-to-new-server.md) + + + diff --git a/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-repair-netwrix-auditor-installation.md b/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-repair-netwrix-auditor-installation.md index 4db814d712..0c9c30345c 100644 --- a/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-repair-netwrix-auditor-installation.md +++ b/docs/kb/auditor/configuration-and-setup/general-configuration/how-to-repair-netwrix-auditor-installation.md @@ -37,7 +37,7 @@ How to repair a Netwrix Auditor installation in our environment? 2. Proceed to your **My Products** page to download the executable for the corresponding version. Refer to the following link: [Netwrix — My Products](https://www.netwrix.com/my_products.html). 3. Run the downloaded executable. Once the files are extracted, a setup screen will be prompted. - ![Install Netwrix Auditor setup screen](images/ka04u00000117fh_0EM4u000008MBTP.png) + ![Install Netwrix Auditor setup screen](../../../images/ka04u00000117fh_0EM4u000008MBTP.png) 4. Select **Install** under **Install Netwrix Auditor**. 5. Click **Next**, and select **Repair**. @@ -48,3 +48,5 @@ How to repair a Netwrix Auditor installation in our environment? ## Related articles - [How to Find Out My Netwrix Auditor Version](/docs/kb/auditor/how-to-find-out-my-netwrix-auditor-version.md) + + diff --git a/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/configure-microsoft-365-data-sources-to-use-proxy-server-settings.md b/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/configure-microsoft-365-data-sources-to-use-proxy-server-settings.md index fa698b07ad..5d6c82a8b4 100644 --- a/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/configure-microsoft-365-data-sources-to-use-proxy-server-settings.md +++ b/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/configure-microsoft-365-data-sources-to-use-proxy-server-settings.md @@ -41,7 +41,7 @@ Exchange Online relies on PowerShell gathering proxy settings from the network a netsh winhttp show proxy ``` - ![netsh winhttp show proxy output](images/ka0Qk0000000ws1_0EM4u000008MMY1.png) + ![netsh winhttp show proxy output](../../../images/ka0Qk0000000ws1_0EM4u000008MMY1.png) 2. If the system prompts **Direct settings**, configure the network adapter to use the correct proxy settings: @@ -51,7 +51,7 @@ Exchange Online relies on PowerShell gathering proxy settings from the network a Replace the proxy server settings in the line with your actual settings. - ![netsh winhttp set proxy example](images/ka0Qk0000000ws1_0EM4u000008MMY6.png) + ![netsh winhttp set proxy example](../../../images/ka0Qk0000000ws1_0EM4u000008MMY6.png) ### Microsoft Entra ID (formerly Azure AD) @@ -84,11 +84,11 @@ After editing: Before editing image: -![Before editing configuration](images/ka0Qk0000000ws1_0EM4u000008MMXd.png) +![Before editing configuration](../../../images/ka0Qk0000000ws1_0EM4u000008MMXd.png) After editing image: -![After editing configuration](images/ka0Qk0000000ws1_0EM4u000008MMYB.png) +![After editing configuration](../../../images/ka0Qk0000000ws1_0EM4u000008MMYB.png) Replace `***.***.***.***:port` with your actual proxy settings. @@ -110,3 +110,5 @@ Replace `proxyaddress="***.***.***.***:port"` with your actual proxy settings. ### Microsoft Teams To use proxy server settings for the Teams audit, set up both Microsoft Entra ID and SharePoint Online settings. + + diff --git a/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/connection-to-microsoft-365-tenant-in-netwrix-auditor-completes-with-error-validating-your-account-s.md b/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/connection-to-microsoft-365-tenant-in-netwrix-auditor-completes-with-error-validating-your-account-s.md index 3740e5766c..59b217fdaf 100644 --- a/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/connection-to-microsoft-365-tenant-in-netwrix-auditor-completes-with-error-validating-your-account-s.md +++ b/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/connection-to-microsoft-365-tenant-in-netwrix-auditor-completes-with-error-validating-your-account-s.md @@ -45,6 +45,8 @@ Make sure you provided the same parameters in a Netwrix Auditor monitoring plan 1. **Tenant name** in Netwrix should equal the `Directory (tenant) ID` in Microsoft Office 365 Admin center. 2. **Modern authentication application ID** should equal `Application (client) ID` in Microsoft Office 365 Admin center. -![00371273 O365 Tenant.PNG](images/ka04u00000117A1_0EM4u000008LuEC.png) +![00371273 O365 Tenant.PNG](../../../images/ka04u00000117A1_0EM4u000008LuEC.png) For additional information on configuring Office 365 tenant, refer to the following article: Microsoft 365. Select the data source you want to audit and review the corresponding section. + + diff --git a/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/disable-multi-factor-authentication-for-microsoft-365-service-accounts.md b/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/disable-multi-factor-authentication-for-microsoft-365-service-accounts.md index cf8b1fa683..60a66c2f3e 100644 --- a/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/disable-multi-factor-authentication-for-microsoft-365-service-accounts.md +++ b/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/disable-multi-factor-authentication-for-microsoft-365-service-accounts.md @@ -46,7 +46,7 @@ To disable MFA for your data-collecting account in any Microsoft 365 source, use 3. Select the service user to be used in the **Select excluded users and groups** window, and click **Select**. 4. To complete the setup, click **Save** in the bottom left corner. - ![Exclude user from MFA policy](images/ka0Qk0000001LLl_0EM4u000008MMJG.png) + ![Exclude user from MFA policy](../../../images/ka0Qk0000001LLl_0EM4u000008MMJG.png) - To exclude an app from the MFA policy: 1. Click the highlighted text under the **Target sources** section. @@ -54,7 +54,7 @@ To disable MFA for your data-collecting account in any Microsoft 365 source, use 3. Select the app to be used in the **Select excluded cloud apps** window, and click **Select**. 4. To complete the setup, click **Save** in the bottom left corner. - ![Exclude app from MFA policy](images/ka0Qk0000001LLl_0EM4u000008MMJL.png) + ![Exclude app from MFA policy](../../../images/ka0Qk0000001LLl_0EM4u000008MMJL.png) Refer to the following articles for additional information on data-collecting account setup for your Microsoft 365 sources: @@ -72,3 +72,5 @@ Refer to the following articles for additional information on data-collecting ac - Microsoft 365 — Permissions for Exchange Online Auditing ⸱ v10.6 https://docs.netwrix.com/docs/auditor/10_8 - Microsoft 365 — Permissions for SharePoint Online Auditing ⸱ v10.6 https://docs.netwrix.com/docs/auditor/10_8 - Microsoft 365 — Permissions for Teams Auditing ⸱ v10.6 https://docs.netwrix.com/docs/auditor/10_8 + + diff --git a/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/how-to-count-number-of-licenses-required-for-auditing-a-microsoft-office-365-tenant.md b/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/how-to-count-number-of-licenses-required-for-auditing-a-microsoft-office-365-tenant.md index d0bed15c93..ba208c8ddb 100644 --- a/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/how-to-count-number-of-licenses-required-for-auditing-a-microsoft-office-365-tenant.md +++ b/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/how-to-count-number-of-licenses-required-for-auditing-a-microsoft-office-365-tenant.md @@ -44,7 +44,7 @@ To determine the actual number of licenses you need to purchase from Netwrix, do 3. Enter your Office 365 account credentials when prompted and click **OK**. 4. When the script completes, you will see the number of mailbox accounts for which you need to purchase licenses: -![User-added image](./images/ka04u000000HcMr_0EM0g000000hNsh.png) +![User-added image](../../../images/ka04u000000HcMr_0EM0g000000hNsh.png) ## For MFA-enabled account @@ -60,3 +60,5 @@ $userMailboxes.count 3. The displayed number represents how many mailbox accounts you need to purchase licenses for. Original KB Article 2082 + + diff --git a/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/permission_manifests_for_auditing_office_365_and_microsoft_entra_id_(auditor_v10.0_and_older).md b/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/permission_manifests_for_auditing_office_365_and_microsoft_entra_id_(auditor_v10.0_and_older).md index 444069ed64..2716fae958 100644 --- a/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/permission_manifests_for_auditing_office_365_and_microsoft_entra_id_(auditor_v10.0_and_older).md +++ b/docs/kb/auditor/configuration-and-setup/microsoft-365-integration/permission_manifests_for_auditing_office_365_and_microsoft_entra_id_(auditor_v10.0_and_older).md @@ -32,7 +32,7 @@ This article contains permission manifests for Microsoft 365 and Microsoft Entra 3. Select the app you would like to configure. 4. In the left pane of the new **Overview** window, select the **Manifest** tab. You can either edit the manifest in the web-based manifest editor, or select **Download** to edit the manifest locally to **Upload** it to reapply it to your application. - ![Manifest tab in the Overview window](./images/servlet_image_31a741be3a3d.png) + ![Manifest tab in the Overview window](../../../images/servlet_image_31a741be3a3d.png) 5. After opening the manifest file, replace the contents of **requiredResourceAccess** with the data provided below. 6. Once changes are introduced, save the manifest and grant administrator permissions in the **API Permissions** tab. @@ -41,15 +41,15 @@ You can use the following screenshots for permissions reference: - **SharePoint Online** - ![SharePoint Online permissions](./images/servlet_image_b88c6cd43443.png) + ![SharePoint Online permissions](../../../images/servlet_image_b88c6cd43443.png) - **Exchange Online** - ![Exchange Online permissions](./images/servlet_image_a59a6a87d3a0.png) + ![Exchange Online permissions](../../../images/servlet_image_a59a6a87d3a0.png) - **Microsoft Entra ID** - ![Microsoft Entra ID permissions](./images/servlet_image_bcb70814f4ea.png) + ![Microsoft Entra ID permissions](../../../images/servlet_image_bcb70814f4ea.png) ### Manifest for SharePoint Online @@ -193,4 +193,5 @@ You can use the following screenshots for permissions reference: - [Microsoft 365 — Permissions for Exchange Online Auditing ⸱ v10.6](https://docs.netwrix.com/docs/auditor/10_8/configuration/microsoft365/exchangeonline/permissions) - [Microsoft 365 — Permissions for SharePoint Online Auditing ⸱ v10.6](https://docs.netwrix.com/docs/auditor/10_8/configuration/microsoft365/sharepointonline/permissions) - [Microsoft 365 — Permissions for Teams Auditing ⸱ v10.6](https://docs.netwrix.com/docs/auditor/10_8/configuration/microsoft365/teams/permissions) -- [Microsoft Entra Admin Center ⸱ Microsoft 🡥](https://entra.microsoft.com) \ No newline at end of file +- [Microsoft Entra Admin Center ⸱ Microsoft 🡥](https://entra.microsoft.com) + diff --git a/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/cannot-find-the-application-error-in-sharepoint-online-and-ms-teams-monitoring-plan.md b/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/cannot-find-the-application-error-in-sharepoint-online-and-ms-teams-monitoring-plan.md index 9f65d06ac8..e4bffc70e0 100644 --- a/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/cannot-find-the-application-error-in-sharepoint-online-and-ms-teams-monitoring-plan.md +++ b/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/cannot-find-the-application-error-in-sharepoint-online-and-ms-teams-monitoring-plan.md @@ -50,7 +50,7 @@ Cannot find the application. - Review the Application ID provided. You can find the Application ID of your app in the **Overview** page once you select the app in the **App registrations** section. Refer to the following Netwrix Auditor article for additional information on the initial Azure app setup: Netwrix Auditor — Permissions for SharePoint Online Auditing − Creating and registering a new app in Microsoft Entra ID ⸱ v10.6. For additional information on creating an app for Teams auditing, refer to the following Netwrix Auditor article: Netwrix Auditor — Permissions for Teams Auditing − Create and Register a New App in Microsoft Entra ID ⸱ v10.6. -![SPOAppID](images/ka0Qk0000001L8r_0EM4u000008MV3l.png) +![SPOAppID](../../../images/ka0Qk0000001L8r_0EM4u000008MV3l.png) - Review the app API permissions granted. You can either specify API permissions manually or use a manifest. Refer to the following Netwrix Auditor article for additional information on granting permissions: Netwrix Auditor — Permissions for SharePoint Online Auditing − Granting required permissions ⸱ v10.6. For additional information on permissions for Teams auditing, refer to the following Netwrix Auditor article: Netwrix Auditor — Permissions for Teams Auditing − Grant Required Permissions ⸱ v10.6. @@ -63,3 +63,5 @@ Cannot find the application. - Netwrix Auditor — Permissions for SharePoint Online Auditing − Granting Required Permissions ⸱ v10.6 - Netwrix Auditor — Permissions for Teams Auditing − Grant Required Permissions ⸱ v10.6 + + diff --git a/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/sharepoint-application-deployment-for-ndc.md b/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/sharepoint-application-deployment-for-ndc.md index c65a250c89..da77a870ee 100644 --- a/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/sharepoint-application-deployment-for-ndc.md +++ b/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/sharepoint-application-deployment-for-ndc.md @@ -31,18 +31,20 @@ To enable the app you will need to add the app to the **App Catalog** then deplo 1. Navigate to the **App Catalog** → **Site Contents** and ensure you are using the classic experience. 2. Click **Add an app** and select `conceptClassifierApp`. -![User-added image](images/ka04u000000HcXd_0EM4u000002D96q.png) +![User-added image](../../../images/ka04u000000HcXd_0EM4u000002D96q.png) 3. Click **Trust It** to accept the app permissions and allow the app to be installed into the App Catalog. - ![User-added image](images/ka04u000000HcXd_0EM4u000002D975.png) + ![User-added image](../../../images/ka04u000000HcXd_0EM4u000002D975.png) 4. Once the app has been added to the App Catalog, configure the deployment by hovering over the app then clicking on the ellipsis in the top right corner of the app and clicking **Deployment**. - ![User-added image](images/ka04u000000HcXd_0EM4u000002D97U.png) + ![User-added image](../../../images/ka04u000000HcXd_0EM4u000002D97U.png) 5. Select how to deploy the app to a combination of specific Sire Collections, by pats, and by a template. Click **OK**. **Note:** The default order of the page is to show the newest app first, so you should see the app as one of the first options (if you do not you can search for “conceptClassifierApp”): 6. The app will then be scheduled for deployment to the chosen Site Collections. This can take a few minutes and on completion, `conceptClassifierApp` will appear in the Site Contents of these Site Collections. -![User-added image](images/ka04u000000HcXd_0EM4u000002D97j.png) +![User-added image](../../../images/ka04u000000HcXd_0EM4u000002D97j.png) 7. To complete the setup, navigate to the **Site Collection** → **Site Contents** and select `conceptClassifierApp`. This will complete the installation of the app on the Site Collection and allow you to configure the writing of classifications (if licensed). + + diff --git a/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/sharepoint-application-installation-for-netwrix-data-classification.md b/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/sharepoint-application-installation-for-netwrix-data-classification.md index b5cb2cc1db..df8a2e6785 100644 --- a/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/sharepoint-application-installation-for-netwrix-data-classification.md +++ b/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/sharepoint-application-installation-for-netwrix-data-classification.md @@ -32,22 +32,22 @@ The `conceptClassifierAppInstaller.exe` can be used to install or upgrade the `c Extract the files and run `conceptClassifierAppInstaller.exe`. -![User-added image](images/ka04u000000HcXh_0EM4u000002Qx7U.png) +![User-added image](../../../images/ka04u000000HcXh_0EM4u000002Qx7U.png) 1. Click *next* after reading the wizard introduction and recommendations. Read and confirm that you accept the EULA and click *next*. -![User-added image](images/ka04u000000HcXh_0EM4u000002Qx7Z.png) +![User-added image](../../../images/ka04u000000HcXh_0EM4u000002Qx7Z.png) Specify connection details for your organization's app catalog (you may have more than one of these if you are working across multiple web applications; if so, you will need to run the installer once per app catalog). -![User-added image](images/ka04u000000HcXh_0EM4u000002Qx7t.png) +![User-added image](../../../images/ka04u000000HcXh_0EM4u000002Qx7t.png) Enter the location of the conceptSearching server (which must be installed onto a secure server with a secure (HTTPS) endpoint): in the case of SharePoint Online, the certificate used must be externally verifiable (from a trusted source). Select the **Use SharePoint Online Login** checkbox if you want to use the new authentication method. -![User-added image](images/ka04u000000HcXh_0EM4u000002Qx8I.png) +![User-added image](../../../images/ka04u000000HcXh_0EM4u000002Qx8I.png) Please also note, the HTTPS binding in IIS should have the host header specified — in the case of the above example the host header would be `secure.conceptsearching.com`. To do this please follow these steps: @@ -122,3 +122,5 @@ Please complete the necessary fields. If you are an Office 365 customer you will ### If you would like to continue with the deployment of the SharePoint Application: [Follow this article](https://kb.netwrix.com/5505) + + diff --git a/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/troubleshoot_sharepoint_serveron-premise_errors.md b/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/troubleshoot_sharepoint_serveron-premise_errors.md index caece417a3..cec7929210 100644 --- a/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/troubleshoot_sharepoint_serveron-premise_errors.md +++ b/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/troubleshoot_sharepoint_serveron-premise_errors.md @@ -21,7 +21,7 @@ This is a reference list of articles on troubleshooting errors in SharePoint Ser ### Related Articles -- [SharePoint Core Service Deployment Failed](/docs/kb/auditor/sharepoint-core-service-deployment-failed.md) +- [SharePoint Core Service Deployment Failed](/docs/kb/auditor/configuration-and-setup/sharepoint-and-teams-auditing/sharepoint-core-service-deployment-failed.md) - [Timeout Expired Error on SharePoint Core Service D](/docs/kb/auditor/timeout-expired-error-on-sharepoint-core-service-deployment.md) - [Event ID 1204 in Health Log](/docs/kb/auditor/event-id-1204-in-health-log.md) - [Event ID 1205 in Health Log](/docs/kb/auditor/event-id-1205-in-health-log.md) @@ -56,4 +56,6 @@ This is a reference list of articles on troubleshooting errors in SharePoint Ser - [Event ID 1286 in Health Log](/docs/kb/auditor/event-id-1286-in-health-log.md) - [Event ID 1287 in Health Log](/docs/kb/auditor/event-id-1287-in-health-log.md) - [Event ID 1288 in Health Log](/docs/kb/auditor/event-id-1288-in-health-log.md) -- [Event ID 1289 in Health Log](/docs/kb/auditor/event-id-1289-in-health-log.md) \ No newline at end of file +- [Event ID 1289 in Health Log](/docs/kb/auditor/event-id-1289-in-health-log.md) + + diff --git a/docs/kb/auditor/configuration-and-setup/sql-server-auditing/cannot-generate-sspi-context-error-in-sql-server-monitoring-plan.md b/docs/kb/auditor/configuration-and-setup/sql-server-auditing/cannot-generate-sspi-context-error-in-sql-server-monitoring-plan.md index f181d99de4..7cfffcc8ed 100644 --- a/docs/kb/auditor/configuration-and-setup/sql-server-auditing/cannot-generate-sspi-context-error-in-sql-server-monitoring-plan.md +++ b/docs/kb/auditor/configuration-and-setup/sql-server-auditing/cannot-generate-sspi-context-error-in-sql-server-monitoring-plan.md @@ -98,7 +98,7 @@ If you are unable to resolve the issue with SPN registration, and if your scenar ### Cause #3 – Different TLS Protocol Versions -Allow the operating systems to select the protocol for incoming and outgoing communication on both your Netwrix Auditor and SQL servers. For more information, see Client and Server Cannot Communicate, Because They Do Not Possess a Common Algorithm: [Client and Server Cannot Communicate, Because They Do Not Possess a Common Algorithm](/docs/kb/auditor/client-and-server-cannot-communicate-because-they-do-not-possess-a-common-algorithm.md) +Allow the operating systems to select the protocol for incoming and outgoing communication on both your Netwrix Auditor and SQL servers. For more information, see Client and Server Cannot Communicate, Because They Do Not Possess a Common Algorithm: [Client and Server Cannot Communicate, Because They Do Not Possess a Common Algorithm](/docs/kb/auditor/troubleshooting-and-errors/data-collection-errors/client-and-server-cannot-communicate-because-they-do-not-possess-a-common-algorithm.md) ### Cause #4 – SQL and Netwrix Auditor Servers Time Difference @@ -109,5 +109,8 @@ Synchronize the time on both SQL and Netwrix Auditor servers to eliminate clock - [SQL Server Ports](https://docs.netwrix.com/docs/auditor/10_8/configuration/sqlserver/ports) - Cannot Generate SSPI Context – Fix the Error with Kerberos Configuration Manager · Microsoft: https://learn.microsoft.com/en-US/troubleshoot/sql/database-engine/connect/cannot-generate-sspi-context-error#fix-the-error-with-kerberos-configuration-manager-recommended - Register Service Principal Name for Kerberos Connections – Automatic SPN Registration · Microsoft: https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/register-a-service-principal-name-for-kerberos-connections?view=sql-server-ver16#Auto -- [Client and Server Cannot Communicate, Because They Do Not Possess a Common Algorithm](/docs/kb/auditor/client-and-server-cannot-communicate-because-they-do-not-possess-a-common-algorithm.md) +- [Client and Server Cannot Communicate, Because They Do Not Possess a Common Algorithm](/docs/kb/auditor/troubleshooting-and-errors/data-collection-errors/client-and-server-cannot-communicate-because-they-do-not-possess-a-common-algorithm.md) - [Clock Skew Is Too Great](/docs/kb/auditor/clock-skew-is-too-great.md) + + + diff --git a/docs/kb/auditor/configuration-and-setup/sql-server-auditing/connection-string-is-not-valid-in-sql-server-monitoring-plan.md b/docs/kb/auditor/configuration-and-setup/sql-server-auditing/connection-string-is-not-valid-in-sql-server-monitoring-plan.md index a2bcf33aaf..23df2f6462 100644 --- a/docs/kb/auditor/configuration-and-setup/sql-server-auditing/connection-string-is-not-valid-in-sql-server-monitoring-plan.md +++ b/docs/kb/auditor/configuration-and-setup/sql-server-auditing/connection-string-is-not-valid-in-sql-server-monitoring-plan.md @@ -53,10 +53,12 @@ Review the affected item in your SQL Server monitoring plan: 4. Review the instance name specified: - For a default SQL instance name (`MSSQLSERVER`), only specify the server FQDN or NetBIOS name. See the example for a reference. - ![Default instance example](images/ka04u000000wvzg_0EM4u000008pVor.png) + ![Default instance example](../../../images/ka04u000000wvzg_0EM4u000008pVor.png) - For a named SQL instance, specify `FQDN\Instance_name`. - ![Named instance example](images/ka04u000000wvzg_0EM4u000008pVow.png) + ![Named instance example](../../../images/ka04u000000wvzg_0EM4u000008pVow.png) 5. Once the changes are introduced, click **Save & Close**. + + diff --git a/docs/kb/auditor/configuration-and-setup/sql-server-auditing/could-not-find-stored-procedure-getallproperties.md b/docs/kb/auditor/configuration-and-setup/sql-server-auditing/could-not-find-stored-procedure-getallproperties.md index 8b2fffaee6..96462e554f 100644 --- a/docs/kb/auditor/configuration-and-setup/sql-server-auditing/could-not-find-stored-procedure-getallproperties.md +++ b/docs/kb/auditor/configuration-and-setup/sql-server-auditing/could-not-find-stored-procedure-getallproperties.md @@ -46,6 +46,9 @@ The ReportServer database is corrupted and has to be rebuilt. 1. Once you've opened SSMS, unfold the **Databases** folder in the **Object Explorer** pane on the left. 2. Right-click each (`ReportServer` and `ReportServerTemp`) database and select **Delete**. 3. Before confirming the deletion, make sure to check the **Close existing connections** checkbox. -3. Once the databases are deleted, regenerate the `ReportServer` database. Refer to the following article for additional information: [Deploying the Report Server Database](/docs/kb/auditor/deploying-the-report-server-database.md) +3. Once the databases are deleted, regenerate the `ReportServer` database. Refer to the following article for additional information: [Deploying the Report Server Database](/docs/kb/auditor/system-administration/database-management/deploying-the-report-server-database.md) 4. After you've configured the `ReportServer` database, grant the roles to the SSRS service account the roles required. Refer to the following article for additional information: [Configure SSRS Account](https://docs.netwrix.com/docs/auditor/10_8/requirements/sqlserverreportingservice#configure-ssrs-account) 5. Restart **Netwrix Auditor Archive Service** and **Netwrix Auditor Management Service** via **Services**. + + + diff --git a/docs/kb/auditor/configuration-and-setup/sql-server-auditing/error-check-your-sql-server-settings-in-audit-database-settings.md b/docs/kb/auditor/configuration-and-setup/sql-server-auditing/error-check-your-sql-server-settings-in-audit-database-settings.md index d39ac777c2..06a86e7053 100644 --- a/docs/kb/auditor/configuration-and-setup/sql-server-auditing/error-check-your-sql-server-settings-in-audit-database-settings.md +++ b/docs/kb/auditor/configuration-and-setup/sql-server-auditing/error-check-your-sql-server-settings-in-audit-database-settings.md @@ -56,7 +56,7 @@ Refer to the list of possible causes for the error: 2. Configure your SQL Server instance to allow remote connections. Learn more in [Configure remote access (server configuration option) — Use SQL Server Management Studio ⸱ Microsoft 🧩](https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/configure-the-remote-access-server-configuration-option?view=sql-server-ver16#SSMSProcedure). 3. Enable the TCP/IP protocol in the SQL Server—refer to the following article for additional information: Enable TCP/IP Protocol in SQL Server. -> **NOTE:** Alternatively, review the TCP port used for SQL Server communication—learn more in [Configure SQL Server to listen on a specific TCP port — Assign a TCP/IP port number to the SQL Server Database Engine ⸱ Microsoft 🧩](https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/configure-a-server-to-listen-on-a-specific-tcp-port?view=sql-server-ver15#assign-a-tcpip-port-number-to-the-sql-server-database-engine). For additional information on setting a custom TCP port in Netwrix Auditor, refer to the following article: [Specify Custom SQL Server Port for Netwrix Auditor Audit Database](/docs/kb/auditor/specify-custom-sql-server-port-for-netwrix-auditor-audit-database.md). +> **NOTE:** Alternatively, review the TCP port used for SQL Server communication—learn more in [Configure SQL Server to listen on a specific TCP port — Assign a TCP/IP port number to the SQL Server Database Engine ⸱ Microsoft 🧩](https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/configure-a-server-to-listen-on-a-specific-tcp-port?view=sql-server-ver15#assign-a-tcpip-port-number-to-the-sql-server-database-engine). For additional information on setting a custom TCP port in Netwrix Auditor, refer to the following article: [Specify Custom SQL Server Port for Netwrix Auditor Audit Database](/docs/kb/auditor/configuration-and-setup/sql-server-auditing/specify-custom-sql-server-port-for-netwrix-auditor-audit-database.md). ## Related Articles @@ -64,4 +64,7 @@ Refer to the list of possible causes for the error: - [Configure remote access (server configuration option) — Use SQL Server Management Studio ⸱ Microsoft 🧩](https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/configure-the-remote-access-server-configuration-option?view=sql-server-ver16#SSMSProcedure) - Enable TCP/IP Protocol in SQL Server - [Configure SQL Server to listen on a specific TCP port — Assign a TCP/IP port number to the SQL Server Database Engine ⸱ Microsoft 🧩](https://learn.microsoft.com/en-us/sql/database-engine/configure-windows/configure-a-server-to-listen-on-a-specific-tcp-port?view=sql-server-ver15#assign-a-tcpip-port-number-to-the-sql-server-database-engine) -- [Specify Custom SQL Server Port for Netwrix Auditor Audit Database](/docs/kb/auditor/specify-custom-sql-server-port-for-netwrix-auditor-audit-database.md) +- [Specify Custom SQL Server Port for Netwrix Auditor Audit Database](/docs/kb/auditor/configuration-and-setup/sql-server-auditing/specify-custom-sql-server-port-for-netwrix-auditor-audit-database.md) + + +