- LANGuardian
LANGuardian features, architecture, and licensing. - Solutions
See what you can do with LANGuardian. - Downloads
Free trial software, videos, documentation, and more. - Customers
See what our customers are doing with LANGuardian. - Partners
With the optional Identity module enabled, LANGuardian integrates with a Microsoft Windows environment to access additional information that it incorporates into reports, trends, and dashboards. The Identity module provides LANGuardian with:
LANGuardian includes this information in the reports, trends, and dashboards that it creates, making them more readable and more useful for troubleshooting and monitoring activity on your network.
Integrating LANGuardian with Windows is a two-part process:
When you complete this process, LANGuardian reports will include details from your Windows domain controller.
Integrating LANGuardian with Active Directory requires use of an account in the Active Directory domain. You specify the account credentials in the Configuration Wizard when you first install LANGuardian, which uses the credentials to authenticate itself when querying the domain.
LANGuardian never makes changes to the information stored in Active Directory. All queries that it submits to the domain controller are read-only. LANGuardian uses the SMB (System Message Block) protocol to query the domain controller.
We recommend that you create a dedicated account to associate your LANGuardian instance with Active Directory. If you do this, ensure that the account has the following rights: Deny logon locally and Manage auditing and security log. The account does not require Administrator privileges.
To configure your Windows server to work with LANGuardian, you must create a LANGuardian-specific account on the Windows domain, give the account the required permissions, and enable event log auditing.
Follow these steps to create a LANGuardian account in the Windows domain:
Make sure the User must change password at next logon checkbox is left unchecked.
Follow these steps to configure the appropriate security on the LANGuardian Windows account:
Double-click each policy name to display its Properties dialog box.
In a Windows server, the event log records details of all system and user activity (events). There are many different types of event, and you can configure the Windows server to record only the events that are of interest. If you record logon events, LANGuardian can include details of user logons in its reports, trends, and dashboards.
Follow these steps to enable event log auditing:
In a default Windows Server installation, the maximum event log size is set to 512 KB. We recommend increasing the size of the security log to 20 MB.
Follow these steps to set the maximum event log size:
| If the domain controller is running... | The event ID is... |
|---|---|
| Windows Server 2008 R2 | 4624 (Logon Event) |
| Windows Server 2008 | 4624 (Logon Event) |
| Windows Server 2003 | 540 (Logon Event) 672 (Account Logon Event) |
| Windows 2000 Server | 672 (Account Logon Event) |
LANGuardian uses a Windows domain account to authenticate itself and query the server for user information and login activity. The domain account must have the necessary privileges to access the Active Directory global catalog and Windows event logs.
LANGuardian has an auto-discover facility that identifies every domain controller (DC) in a domain. To enumerate the DCs, it directs an LDAP query to a seed server, which returns a list of all DCs in the domain. LANGuardian then queries each DC to request its version.
From the list of DCs, select the ones you want LANGuardian to know about. LANGuardian will save the details in its configuration database and query them periodically for up-to-date information. We recommend that you add all DCs unless you are sure they do not authenticate users. If a DC authenticates users and LANGuardian does not know about it, the information you see in LANGuardian graphs and reports might be incomplete.
Follow these steps to connect LANGuardian with Active Directory:
Enter the following details:
Notes:
LANGuardian maintains a database of Active Directory user and group membership information, which it incorporates into the reports and graphs that it creates. To keep this database up-to-date, LANGuardian issues LDAP queries against the domain at regular intervals. You can configure LANGuardian to execute these queries hourly, daily, weekly, monthly, or never.
To configure the interval:
As well as scheduling regular updates, you can update the directory information at any time by clicking the Update button.
LANGuardian periodically reads the Security event log of all DCs that are configured in its database, and it extracts details of all Logon and Account Logon events. The details it extracts are as follows:
LANGuardian stores this information in its database and incorporates it in reports and graphs. For example, you can see who was the last user to log on to each client system in the domain, who opened or deleted a specific file, or when a specific user logged on to or logged of a client machine.
Please contact us if you need help installing or configuring NetFort LANGuardian. You can avail of free no-obligation technical support by contacting our helpdesk on support@netfort.com. See also the NetFort discussion forum for technical tips and usage information.