I know auditing has been addressed here before, but I've been "asked" to pose the question again. My security group wants to be able to track when files or directories on the NAS were deleted and by whom. We have event viewer implemented on the Data Movers, but that doesn't do what they want and I don't know how either.
Has anyone found a way to do this? Do you know of any links to product that does?
I know, but they (security) doesn't, that this is probably a costly endeavor in terms of response time and money, but I still need to investigate it.
what wrong with normal CIFS auditing plus a 3rdparty Windows tool to collect and analyze the security.evt ?
I suggest to contact your local EMC TC and inquire about other possibilieties.
RSA enVision might be able to help.
We also just added the CEPA framework for 3rd party quota management, which is currently supported by the NTP and Northern Parklife products. I think that framework was also designed to be used by file blocking software, which is quite close to deletion auditing.
our TC brought them to us in addition with RSA guys. RSA product is nice and all but their appliances are based on event count, in my opinion if you are going to audit CIFS server you will end up paying through the nose, while varonis is per server being monitored.
I'm having the same dilemma as Harrold with my security team. I have moved many TBs of data to our Celerra NS42G and six CIFS are all sharing the now 16MB and only security.evt. This gets approx 4hrs of log data which I'm being told isn't acceptable.
I know VDMs which we haven't been implemented (yet) would allow each CIFS its own security.evt, but what are the rest of you doing for this limitation? I assume most are utlitzing VDMs. Our Celerra came via aquisition and therefore VDMs were never implemented from the start.
What if anything have the rest of you done in this regard without VDM architecture or 3rd party. Are there any other options? We have the csv exports to work with, but these are quite cumbersome.
I assume you know you can increase the size of the security.evt file
Also, converting to VDM's isnt difficult - you just need a couple of minutes of interruption and to work with your EMC TS engineer to establish the procedure.
Of course the security.evt isnt meant for long-time storage. You should setup a 3rd party tool to export and clear it regularly
Rainer thank you. Yes, and as I now realize, you can increase continually once you have moved the security.evt file to its own file system. Just have to make sure to clear your log for it to see this new size designation. There is mention in the "notes" section of primus emc69252. It explains, "once moved an alternate location the is no longer a cap". Amen, I increased mine today to 150MB and now the security team can get approx 36 hours of log data. One of our senior guys then has a Linux script utilizing grep and gawk which import those CSVs to MS excel for them. This is then scheduled for a daily run..
Ironically I found out as well our security team is currently looking into 3rd party tools.
Well I'm off to the simulators to play with VDMs.
Thanks again for assisting a new admin, you guys are great.
dynamox
11 Legend
•
20419 Posts
•
87439 Points
1645
1
Posted May 28th, 2008 09:00
http://www.varonis.com/products/datadvantage/