SearchInform FileAuditor Ensures Analysis of Windows Security Log, Active Directory Logs and NetApp LOG
20.12.2023

From now on the system performs audit of operations and access rights in SAN without agent.

FileAuditor, the DCAP system by SearchInform from now on ensures audit of access rights and operations on files in network storages, which don’t have the agent implemented. Agent is the system’s component, which is deployed locally and ensures control in places. The system analysis Windows Logs, where the data on users’ actions on files is kept; it also analysis Active Directory logs, containing data on changes done to users’ access rights.

Previously, analysis of file operations  was available only in case the agent was deployed, network analysis was performed only for files in storages. Integration enables to quickly get data on operations on the network level. Data from AD helps to obtain the full picture be revealing cases of, for example: temporary change of users’ access rights by system administrator; adding a user to the privileged group; illicit access rights blockings.

“Let me point the importance of the new changes. First of all, functional difference between agent and server-based model of scanning storages is eliminated. Analysis of files, their categorization, tagging, change of access rights – all these functions are now available both in case agent is installed and without its installation. Secondly, we extend the list of storages supported”. – told Sergio Bertoni, the Leading Analyst at SearchInform.

The fine-tuning enables to control SANs with atypical file systems or in cases, when it’s for some reason is uncomfortable or impossible to deploy the agent. For example, in case it’s required to analyze some detached network folder (there’s no need to analyze all the storage). Agentless scanning saves resources. FileAuditor works with the NetApp the same way. Previously, it was impossible to perform audit of the NetApp.  In addition to the abovementioned functionality, the solution also supports FTP, SMB, DFS, NFS, NTFS; can be integrated with the whole line of Huawei OceanStore and Dorado, what makes the solution universal tool for ensuring control of file storages in any infrastructure.

Subscribe to get helpful articles and white papers. We discuss industry trends and give advice on how to deal with data leaks and cyberincidents.