UNSOLVED

FresnoRed

updated

18 years ago

F

FresnoRed

90 Posts

0

3733

May 28th, 2008 07:00

NAS file deletion auditing

I know auditing has been addressed here before, but I've been "asked" to pose the question again. My security group wants to be able to track when files or directories on the NAS were deleted and by whom. We have event viewer implemented on the Data Movers, but that doesn't do what they want and I don't know how either.

Has anyone found a way to do this? Do you know of any links to product that does?

I know, but they (security) doesn't, that this is probably a costly endeavor in terms of response time and money, but I still need to investigate it.

Any words of wisdom would be appreciated.

Thanks,
Harold
County of Fresno
Fresno, CA
  • dynamox

    11 Legend

    20419 Posts

    87439 Points

    1645

    1

    Posted May 28th, 2008 09:00

    we are evaluating these guys right now ..so far so good ..they are EMC partners.

    http://www.varonis.com/products/datadvantage/
  • FresnoRed

    90 Posts

    1645

    0

    Posted May 29th, 2008 08:00

    dynamox,

    Thanks for the reference. Contacted them and we will be doing a webinar. Cost might scare our security people off, but you get what you pay for.

    Thanks again.

    Harold
  • Rainer_EMC

    6 Operator

    8645 Posts

    1645

    0

    Posted May 29th, 2008 13:00

    what wrong with normal CIFS auditing plus a 3rdparty Windows tool to collect and analyze the security.evt ?

    I suggest to contact your local EMC TC and inquire about other possibilieties.

    RSA enVision might be able to help.

    We also just added the CEPA framework for 3rd party quota management, which is currently supported by the NTP and Northern Parklife products.
    I think that framework was also designed to be used by file blocking software, which is quite close to deletion auditing.
  • Rainer_EMC

    6 Operator

    8645 Posts

    1645

    0

    Posted May 29th, 2008 13:00

    by the way they are also in EMC Select so you could order it through EMC if you want
  • dynamox

    11 Legend

    20419 Posts

    87439 Points

    1645

    0

    Posted May 29th, 2008 13:00

    our TC brought them to us in addition with RSA guys. RSA product is nice and all but their appliances are based on event count, in my opinion if you are going to audit CIFS server you will end up paying through the nose, while varonis is per server being monitored.
  • drake2

    44 Posts

    1645

    0

    Posted August 19th, 2008 08:00

    I'm having the same dilemma as Harrold with my security team. I have moved many TBs of data to our Celerra NS42G and six CIFS are all sharing the now 16MB and only security.evt. This gets approx 4hrs of log data which I'm being told isn't acceptable.

    I know VDMs which we haven't been implemented (yet) would allow each CIFS its own security.evt, but what are the rest of you doing for this limitation? I assume most are utlitzing VDMs. Our Celerra came via aquisition and therefore VDMs were never implemented from the start.

    What if anything have the rest of you done in this regard without VDM architecture or 3rd party. Are there any other options? We have the csv exports to work with, but these are quite cumbersome.

    DART 5.5.32.4

    Thanks for any input.
  • Rainer_EMC

    6 Operator

    8645 Posts

    1645

    0

    Posted August 19th, 2008 23:00

    I assume you know you can increase the size of the security.evt file

    Also, converting to VDM's isnt difficult - you just need a couple of minutes of interruption and to work with your EMC TS engineer to establish the procedure.

    Of course the security.evt isnt meant for long-time storage. You should setup a 3rd party tool to export and clear it regularly
  • drake2

    44 Posts

    1645

    0

    Posted August 20th, 2008 13:00

    Rainer thank you. Yes, and as I now realize, you can increase continually once you have moved the security.evt file to its own file system. Just have to make sure to clear your log for it to see this new size designation. There is mention in the "notes" section of primus emc69252. It explains, "once moved an alternate location the is no longer a cap". Amen, I increased mine today to 150MB and now the security team can get approx 36 hours of log data. One of our senior guys then has a Linux script utilizing grep and gawk which import those CSVs to MS excel for them. This is then scheduled for a daily run..

    Ironically I found out as well our security team is currently looking into 3rd party tools.

    Well I'm off to the simulators to play with VDMs.

    Thanks again for assisting a new admin, you guys are great.