diff --git a/docs/accessanalyzer/26.1/install/installer-reference.md b/docs/accessanalyzer/26.1/install/installer-reference.md index b023e7acf7..4e2573fece 100644 --- a/docs/accessanalyzer/26.1/install/installer-reference.md +++ b/docs/accessanalyzer/26.1/install/installer-reference.md @@ -35,7 +35,7 @@ Two environment variable names need care: `--hostname` reads `DSPM_HOSTNAME`, no | `--accept-warnings` | `ACCEPT_WARNINGS` | `false` | Continue past preflight warnings without asking. | | `--assume-yes` | `DSPM_ASSUME_YES` | `false` | Skip the review screen that appears when the configuration file already supplies every required value. | | `--dry-run` | `DRY_RUN` | `false` | Print the planned actions and exit without installing. Needs no TLS files and writes no configuration file. | -| `--log-level` | `LOG_LEVEL` | `info` | Detail written to the log file: `debug`, `info`, `warn`, or `error`. | +| `--log-level` | `LOG_LEVEL` | `info` | Detail the installer writes to the log file: `debug`, `info`, `warn`, or `error`. | | `--log-path` | `LOG_PATH` | `/var/log/dspm-installer.log` | Path to the installer's log file. If you set this explicitly (flag, environment variable, or configuration file) and the path isn't writable or is a symlink, the installer stops with an error instead of falling back to the terminal. | | `--postgres-data-dir` | `POSTGRES_DATA_DIR` | none | Custom directory for the application database's data. | | `--clickhouse-data-dir` | `CLICKHOUSE_DATA_DIR` | none | Custom directory for the analytics store's data. | @@ -146,6 +146,48 @@ When the `antivirus` check finds a product, add these paths to that product's ex The [Requirements](requirements.md) page lists the 18 hosts the `network` check connects to and the CPU, RAM, and disk figures for each size. +## RHEL and CentOS Preparation + +Complete these steps on a Red Hat Enterprise Linux (RHEL) or CentOS server before you run the installer. + +### RHEL 10 + +RHEL 10 splits a kernel module the platform needs into a separate package. Install it first: + +```bash +sudo dnf install -y kernel-modules-extra +``` + +Without it, the `kernel-modules` preflight check can't load `br_netfilter` or `overlay`. + +### Firewalld + +Turn off `firewalld`: + +```bash +systemctl disable firewalld --now +``` + +To keep it enabled instead, add these rules before you install: + +```bash +firewall-cmd --permanent --add-port=6443/tcp +firewall-cmd --permanent --zone=trusted --add-source=10.42.0.0/16 +firewall-cmd --permanent --zone=trusted --add-source=10.43.0.0/16 +firewall-cmd --reload +``` + +These open the platform's internal API port and trust its pod and service networks. Also open the ports that [Requirements](requirements.md#inbound) lists for Access Analyzer itself. + +### Older RHEL and CentOS Releases + +RHEL and CentOS releases before 8.4 ship a version of NetworkManager with a bug that interferes with the platform's networking. Disable `nm-cloud-setup` and reboot before you install: + +```bash +systemctl disable nm-cloud-setup.service nm-cloud-setup.timer +reboot +``` + ## The `wait-for-apps` Command `wait-for-apps` repeats the readiness wait without reinstalling anything. Use it when an install stopped while waiting for the services, or to check whether they're all ready. diff --git a/docs/accessanalyzer/26.1/install/requirements.md b/docs/accessanalyzer/26.1/install/requirements.md index 711d0b6b1b..d9b5e7f9e2 100644 --- a/docs/accessanalyzer/26.1/install/requirements.md +++ b/docs/accessanalyzer/26.1/install/requirements.md @@ -12,7 +12,7 @@ Access Analyzer installs on a single physical or virtual Linux server. | Requirement | Details | |---|---| -| Operating system | Ubuntu. Any Debian-based distribution should work. The installer doesn't check the release version. | +| Operating system | Ubuntu or Red Hat Enterprise Linux (RHEL). Any Debian-based or RPM-based distribution should work. The installer doesn't check the release version. RHEL and CentOS need some [additional preparation](installer-reference.md#rhel-and-centos-preparation). | | Architecture | 64-bit x86 or Arm. | | Access | Root, either directly or through `sudo`. | | Free disk on `/var/lib` | See [size](#size) for storage requirements. Access Analyzer stores its data under `/var/lib`. | @@ -63,7 +63,7 @@ The installer looks for the certificate at `/etc/dspm/tls.crt` and the key at `/ ## License Key -You need a Netwrix license key in the form `XXXX-XXXX-XXXX-XXXX-XXXX-V3`. The key authenticates the installer download, and the installer validates it online during the install, so the server must reach the licensing endpoints listed under [Outbound](#outbound). An expired, suspended, or unknown key stops the install. +You need a Netwrix license key in the form `XXXX-XXXX-XXXX-XXXX-XXXX-V3`. The key authenticates the installer download, and the installer validates it online during the install, so the server must reach the licensing endpoints that [Outbound](#outbound) lists. An expired, suspended, or unknown key stops the install. ## First Administrator diff --git a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md index e2498f0054..77ac35df6f 100644 --- a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md +++ b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md @@ -62,19 +62,19 @@ pattern. - Enable Smart Groups – when you disable this setting, Endpoint Protector converts Smart Groups to regular groups with no entities assigned and removes the Default Group for Computers and the Default Group for Users. -- Enable Default Group for Computers – this will create a default group for computers containing all +- Enable Default Group for Computers – creates a default group for computers containing all computers that aren't part of a Smart Group. :::note -By disabling this setting, you will delete the Default Group for Computers. +Disabling this setting deletes the Default Group for Computers. ::: -- Enable Default Group for Users – this will create a default group for users containing all users +- Enable Default Group for Users – creates a default group for users containing all users that aren't part of a Smart Group. :::note -By disabling this setting, you will delete the Default Group for Users. +Disabling this setting deletes the Default Group for Users. ::: :::note @@ -88,7 +88,7 @@ Smart Group sync job interval: the default configured time is 60 min. You can co Configure the client update settings to optimize update performance by specifying a custom hostname and port. -- Use custom hostname: Enter a custom hostname to tailor the client update URL as needed. +- Use custom hostname: Enter a custom hostname to tailor the client update URL. - Use custom port: Specify a custom port for generating the client update download link, instead of using the default port 443. @@ -119,8 +119,8 @@ Manage the following log settings: - Set the Maximum number of rows in millions to export the Logs Report in .csv format. :::note -By setting the maximum number of rows to 1.0, you will export 1 million logs in the Logs -Report .csv export as one row corresponds with one log. +Setting the maximum number of rows to 1.0 exports 1 million logs in the Logs +Report .csv export, since one row corresponds with one log. ::: @@ -131,8 +131,8 @@ export. structure and display information in Destination details, Email sender, and Email subject columns. :::note -For Endpoint Protector Server versions older than 5.7.0.0, the Reporting V2 setting isn't -enabled by default. +For Endpoint Protector Server versions older than 5.7.0.0, Endpoint Protector doesn't enable +the Reporting V2 setting by default. ::: @@ -150,11 +150,21 @@ You can set a number of reported threats between 100 and 1000. The default is three months. Log rotation runs every five minutes and deletes Device Control, Content Aware Protection, and eDiscovery logs older than the retention period, together with their associated file shadows. For example, setting this option to 6 keeps six months of logs and removes anything - older. Set the value to 0 to disable log rotation. + older. Enter a value between 1 and 360 months. There's no option to turn log rotation off once + it's active — 1 month is the shortest retention period you can configure, and Endpoint Protector + rejects a value of 0. :::warning -Disabling log rotation means Endpoint Protector never removes logs automatically, and the server -continues to consume storage until you intervene. +Endpoint Protector 2608 enables this setting by default. Earlier server versions kept these logs +indefinitely unless an administrator removed them manually or through Audit Log Backup, which can +delete logs from the server as it archives them. The first rotation cycle runs within five minutes +of the server starting, so Endpoint Protector deletes any logs already older than the configured +period at that point — export anything you need to keep before you upgrade. Review this value +as soon as you migrate and configure it to match your organization's retention needs. If you must +retain log data for compliance beyond the configured period, export it regularly through +**Reports and Analysis** > **Export Logs** and store the exports separately — don't rely on +server-side log storage for long-term compliance evidence, since you can't disable log rotation +to keep data on the server indefinitely. ::: @@ -222,21 +232,21 @@ Endpoint Protector automatically modifies the maximum number of reported threat Limit Reporting Content Aware Protection refers to Report Only policies. -- If enabled, the Endpoint Protector client will stop reporting threats for a Report Only policy - after it finds enough threats to conclude it is satisfied. +- When you enable this setting, the Endpoint Protector client stops reporting threats for a Report + Only policy after it finds enough threats to satisfy the policy. The "Content Aware Protection - Ignore Thresholds" toggle refers to Block & Report policies. -- When this toggle is On, scanning doesn't stop at a block verdict, but continues to report further +- When this toggle is On, scanning continues past a block verdict and reports further threats found in a transfer. - To limit the number of reported threats in this case, set the "Maximum number of reported threats" - setting to a value greater than zero. The value you set is only indicative for the number of - reported threats, the actual number reported can be slightly larger. + setting to a value greater than zero. The value you set only indicates the number of + reported threats; the actual number reported can be slightly larger. The ‘Ignore Thresholds’ setting ignores and overrides the ‘Global/Threat Threshold’ values in Content Aware Protection policies when the Boolean logic of the Content Aware Protection policy -contains at least one “AND” operator. A policy will be satisfied when the Boolean logic (see the -following example) is met with one or more matches per identifier. +contains at least one “AND” operator. A policy triggers when one or more matches per identifier +satisfy the Boolean logic (see the following example). Eg. ( E-mail AND SSN US) OR CC Visa @@ -278,20 +288,20 @@ Aware Protection policy. Generally, a Content Aware Protection policy (Block & Report) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in the policy, the scan engine will ignore the ‘Threat Threshold’ setting and continue the scan until -the total threat of 10 is reached, regardless of whether “Limit Reporting” (under DEVICE CONTROL - -Global Settings) is enabled. +it reaches a total of 10 threats, regardless of whether you enable “Limit Reporting” (under DEVICE +CONTROL - Global Settings). Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in -the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under -DEVICE CONTROL - Global Settings) is enabled, the scan continues until the total threat of 10 from -setting ‘Maximum number of reported threats’ under ‘Ignore Thresholds’ is reached. +the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you enable “Limit +Reporting” (under DEVICE CONTROL - Global Settings), the scan continues until it reaches the total +threat of 10 from the ‘Maximum number of reported threats’ setting under ‘Ignore Thresholds’. Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in -the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under -DEVICE CONTROL - Global Settings) is disabled, the scan engine will continue the scan until the -entire file is scanned, but will only report 10 threats, set with ‘Maximum number of reported +the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you disable “Limit +Reporting” (under DEVICE CONTROL - Global Settings), the scan engine will continue until it scans +the entire file, but will only report 10 threats, as set with ‘Maximum number of reported threats’ under ‘Ignore Thresholds’. **Example - Scenario 2** @@ -326,20 +336,20 @@ Protector Server Generally, a Content Aware Protection policy (Block & Report) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in the policy, the scan engine will ignore the ‘Threat Threshold’ setting and continue the scan until -the total threat of 4 from setting ‘Maximum number of reported threats’ is reached, regardless of -whether “Limit Reporting” (under DEVICE CONTROL - Global Settings) is enabled. +it reaches the total threat of 4 from the ‘Maximum number of reported threats’ setting, regardless +of whether you enable “Limit Reporting” (under DEVICE CONTROL - Global Settings). Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in -the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under -DEVICE CONTROL - Global Settings) is enabled, the scan continues until the total threat of 4 from -setting ‘Maximum number of reported threats’ under ‘Ignore Thresholds’ is reached. +the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you enable “Limit +Reporting” (under DEVICE CONTROL - Global Settings), the scan continues until it reaches the total +threat of 4 from the ‘Maximum number of reported threats’ setting under ‘Ignore Thresholds’. Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in -the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under -DEVICE CONTROL - Global Settings) is disabled, the scan engine will continue the scan until the -entire file is scanned, but will only report 4 threats, set with ‘Maximum number of reported threats’ +the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you disable “Limit +Reporting” (under DEVICE CONTROL - Global Settings), the scan engine will continue until it scans +the entire file, but will only report 4 threats, as set with ‘Maximum number of reported threats’ under ‘Ignore Thresholds’. **Example - Scenario 3** @@ -373,14 +383,14 @@ Endpoint Protector Client may report the single threats to Endpoint Protector Se Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied, meaning that all identifiers reach a ‘Threat Threshold’ of at least 1. The scan engine will ignore the ‘Maximum number of reported threats’ under ‘Ignore Thresholds’, when -“Limit Reporting” (under DEVICE CONTROL - Global Settings) is enabled. Reporting stops as soon as +you enable “Limit Reporting” (under DEVICE CONTROL - Global Settings). Reporting stops as soon as the policy is satisfied. Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied, meaning that all identifiers reach a ‘Threat Threshold’ of at least 1. The scan engine will consider the ‘Maximum number of reported threats’ under ‘Ignore Thresholds’, when -“Limit Reporting” (under DEVICE CONTROL - Global Settings) is disabled. Reporting stops when 10 -threats are found. +you disable “Limit Reporting” (under DEVICE CONTROL - Global Settings). Reporting stops when the +scan finds 10 threats. **Example - Scenario 4** @@ -414,8 +424,8 @@ Protector Client may report different 10 threats to Endpoint Protector Server Generally, a Content Aware Protection policy (Block & Report) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and no ‘AND’ operators in the -policy, the scan engine will search until the total threat of 10 from setting ‘Maximum number of -reported threats’ under ‘Ignore Thresholds’ is reached. +policy, the scan engine will search until it reaches the total threat of 10 from the ‘Maximum number +of reported threats’ setting under ‘Ignore Thresholds’. ## Virtual Desktop Clones @@ -486,7 +496,7 @@ Enable the **Active Directory Authentication** setting to import an Active Direc administrators into Endpoint Protector as Super Administrators. :::note -By enabling the Active Directory Authentication, you allow the administrators to use their +Enabling Active Directory Authentication lets administrators use their Active Directory credentials to log into Endpoint Protector. ::: diff --git a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md index bee36dee81..1c81701110 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md @@ -9,7 +9,7 @@ sidebar_position: 13 --- :::note -This article covers on-premises EPP Servers already running the current image-based platform — any version from **2509 through 2604**. If your server is still on a legacy 5.x release (5.7.0.0–5.9.4.2), see [Migrating from a Legacy 5.x Server to 2608](/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x) instead. For the full picture and how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). +This article covers on-premises Endpoint Protector (EPP) Servers already running the current image-based platform — any version from **2509 through 2604**. If your server is still on a legacy 5.x release (5.7.0.0–5.9.4.2), see [Migrating from a Legacy 5.x Server to 2608](/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x) instead. For an overview of how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). ::: ## Overview @@ -20,10 +20,10 @@ Since you're already on the image-based platform, migrating to 2608 doesn't requ | Your Current Version | Recommendation | |---|---| -| 2509, 2510, 2601, 2602, or 2604 | Migrate directly to 2608 — no intermediate version is required | +| 2509, 2510, 2601, 2602, or 2604 | Migrate directly to 2608 — you don't need an intermediate version | :::tip -2608 accepts a direct backup restore from any of 2509, 2510, 2601, 2602, or 2604. It's still good practice to upgrade to 2604 before migrating, since the 2604 → 2608 path is the most thoroughly validated in Netwrix labs. +2608 accepts a direct backup restore from any of 2509, 2510, 2601, 2602, or 2604. It's still good practice to upgrade to 2604 before migrating, since Netwrix labs validate the 2604 → 2608 path most thoroughly. ::: --- @@ -46,7 +46,7 @@ If your current license includes the `php_els` field (used on the 2509–2604 im - Proxmox VE — not officially supported; see the following note :::note -**Proxmox VE** isn't an officially supported hypervisor for Endpoint Protector. Based on customer feedback, Proxmox VE can host the EPP Server image after manually adjusting networking and IP configuration post-deployment. Converting the provided OVF image for use on Proxmox, along with any such adjustments, is entirely the customer's responsibility and falls outside Netwrix support. +**Proxmox VE** isn't an officially supported hypervisor for Endpoint Protector. Based on customer feedback, Proxmox VE can host the EPP Server image after you manually adjust networking and IP configuration post-deployment. Converting the provided OVF image for use on Proxmox, along with any such adjustments, is entirely the customer's responsibility and falls outside Netwrix support. ::: :::warning @@ -82,7 +82,7 @@ The 2608 image adds CrateDB, which may raise the minimum disk, RAM, and CPU base ::: :::tip -If disk space is below 30%, perform database shrinking via **System Maintenance → Audit Log Backups** before proceeding. Exporting old logs to an external SIEM or repository reduces DB size significantly. If not possible, consider expanding the associated disk space. To export logs, see [Audit Log Backup](/docs/endpointprotector/admin/systemmaintenance/overview#audit-log-backup). +If disk space is below 30%, shrink the database via **System Maintenance → Audit Log Backups** before proceeding. Exporting old logs to an external SIEM or repository reduces DB size significantly. If not possible, consider expanding the associated disk space. To export logs, see [Audit Log Backup](/docs/endpointprotector/admin/systemmaintenance/overview#audit-log-backup). ::: ### Maintenance Window Planning @@ -98,7 +98,7 @@ Plan a maintenance window that accounts for the following: These times reflect laboratory test results and may vary in your environment depending on several factors, including hardware assigned to the appliance. **During the upgrade window, you won't have:** -- EPP/EE client communication with the server +- EPP and Enforced Encryption (EE) client communication with the server - Email alerts and SIEM integrations - File Shadow and log generation @@ -214,11 +214,11 @@ Always use the **same IP/FQDN** option. The operational complexity and user impa | High server load | Certificate regeneration for all endpoints creates a burst load spike | :::warning -If using Enforced Encryption and you change the IP/FQDN, every user with an EE-protected drive must decrypt their drive and re-encrypt it after reconnecting to the new server. This can be a major operational disruption in large organizations. Netwrix strongly discourages this. +If you use Enforced Encryption and change the IP/FQDN, every user with an EE-protected drive must decrypt their drive and re-encrypt it after reconnecting to the new server. This can be a major operational disruption in large organizations. Netwrix strongly discourages this. ::: :::warning -If you use SSO (Single Sign-On) and choose a different IP address instead of an FQDN for the new server, reviewing your SSO configuration after the backup is restored is mandatory. SSO response/callback URLs are tied to the server address used at configuration time — changing the IP breaks them. After migration, either manually recreate the SSO configuration with the updated response URL, or open a Netwrix Support case to have it updated on the backend. See [Third-Party Integration Reconfiguration](#third-party-integration-reconfiguration) in Post-Migration Verification. +If you use SSO (Single Sign-On) and choose a different IP address instead of an FQDN for the new server, you must review your SSO configuration after you restore the backup. SSO response/callback URLs are tied to the server address used at configuration time — changing the IP breaks them. After migration, either manually recreate the SSO configuration with the updated response URL, or open a Netwrix Support case to have it updated on the backend. See [Third-Party Integration Reconfiguration](#third-party-integration-reconfiguration) in Post-Migration Verification. ::: ### Deploying the 2608 Base Image @@ -337,7 +337,7 @@ Verify each active module: | Content Aware Protection | Content Aware Protection → Dashboard | | eDiscovery | eDiscovery → Dashboard | | Enforced Encryption | Check that EE-protected drives are accessible | -| Reports & Analytics | Reports and Analytics → relevant sub-service | +| Reports and Analysis | Reports and Analysis → relevant sub-service | | Alerts | Check that configured alerts are firing | :::tip @@ -347,7 +347,7 @@ Generate deliberate test events on a known test machine for each active module. ### eDiscovery Scan Locations Verification :::warning -If an eDiscovery policy with configured **Scan Locations** is restored from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead — with no error reported anywhere. This is a known post-migration issue for any environment using the eDiscovery module. +If you restore an eDiscovery policy with configured **Scan Locations** from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead, without reporting an error anywhere. This is a known post-migration issue for any environment using the eDiscovery module. ::: If you use eDiscovery with Scan Locations configured on any policy, this check is mandatory after restore: @@ -359,13 +359,13 @@ If you use eDiscovery with Scan Locations configured on any policy, this check i ### CAP Policy Verification :::note -In rare cases, a Content Aware Protection (CAP) policy restored from a System Configuration Backup doesn't redistribute correctly and stops triggering, with no error reported. +In rare cases, a Content Aware Protection (CAP) policy restored from a System Configuration Backup doesn't redistribute correctly and stops triggering, without reporting an error. ::: If you use Content Aware Protection, this check is recommended after restore: 1. Test each active CAP policy against a known-blocked transfer to confirm it still triggers. -2. If a policy doesn't trigger, open it, edit and save it — even without changing anything — to redistribute it to endpoints. +2. If a policy doesn't trigger, open it, edit it, and save it — even without changing anything — to redistribute it to endpoints. 3. Re-test to confirm the policy now triggers correctly. ### DPI / CAP Functionality Verification @@ -382,6 +382,33 @@ If using Deep Packet Inspection or Content Aware Protection: 2. Verify that backups are configured and active. 3. Run a test backup and confirm **"Ready to download"** status. +### Log Retention Verification + +:::warning +**This is a behavior change from earlier server versions.** Endpoint Protector 2608 introduces +automatic, age-based log rotation for Device Control, Content Aware Protection, and eDiscovery +logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. +After migration, Endpoint Protector enables this setting by default at three months and +automatically deletes logs older than three months, together with their associated file shadows. +Endpoint Protector deletes logs already older than the configured period on the first rotation +cycle after the server starts, so export anything you want to keep before you migrate. +::: + +After migration, verify: +1. Navigate to **System Configuration → System Settings → Log Settings**. +2. Check the value configured for **Enable Log Rotate After**. +3. Confirm the configured retention period matches your organization's operational and compliance + needs. Adjust the value if three months doesn't match your retention policy. The value is in + months, from 1 to 360 — there's no option to disable log rotation entirely. + +For the full description of this setting, see [Log Settings](/docs/endpointprotector/admin/systemconfiguration/systemsettings#log-settings). + +:::tip +If you need to retain log data for compliance beyond your configured retention period, export it +regularly through **Reports and Analysis** → **Export Logs** and store the exports separately. +Exports also keep the server's log tables smaller, which helps console and report performance. +::: + ### Third-Party Integration Reconfiguration After migration, manually re-import and reconfigure all 3rd-party integrations. While the backup includes configuration data, it doesn't always fully restore credentials and connection secrets, and integration endpoints may require re-registration against the new server. @@ -411,7 +438,7 @@ After reconfiguration, verify each integration is functioning: | AWS / S3 / File Shadows | Generate a file shadow; confirm it reaches the S3 bucket | :::warning -**Mandatory if you used an IP address instead of an FQDN for the new server:** Review your SSO configuration after the backup is restored. The SSO response/callback URL registered against the old server address no longer matches, and SSO logins fail until this is corrected. You have two options: +**Mandatory if you used an IP address instead of an FQDN for the new server:** Review your SSO configuration after you restore the backup. The SSO response/callback URL registered against the old server address no longer matches, and SSO logins fail until you correct it. You have two options: 1. Manually recreate the SSO configuration in **System Configuration → SSO / Single Sign-On** with the updated response/callback URL, and update the corresponding redirect URI in your identity provider. 2. Raise a Netwrix Support case to have the SSO configuration updated on the backend. ::: diff --git a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md index c00f5260c3..52f6ba6ff7 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md @@ -9,7 +9,7 @@ sidebar_position: 12 --- :::note -This article covers on-premises EPP Servers running any version from **5.7.0.0 through 5.9.4.2** (5700, 5710, 5800, 5810, 5820, 5900, 5910, 5920, 5930, 5940, 5941, 5942). If your server is already on the current image-based platform (2509–2604), see [Migrating from the Current Image Platform to 2608](/docs/endpointprotector/install/migrationprocedure/migration-current-image) instead. For the full picture and how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). +This article covers on-premises Endpoint Protector (EPP) Servers running any version from **5.7.0.0 through 5.9.4.2** (5700, 5710, 5800, 5810, 5820, 5900, 5910, 5920, 5930, 5940, 5941, 5942). If your server is already on the current image-based platform (2509–2604), see [Migrating from the Current Image Platform to 2608](/docs/endpointprotector/install/migrationprocedure/migration-current-image) instead. For an overview of how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). ::: ## Overview @@ -55,7 +55,7 @@ If you're unsure whether your license is current, contact Netwrix Support or you - Proxmox VE — not officially supported; see the following note :::note -**Proxmox VE** isn't an officially supported hypervisor for Endpoint Protector. Based on customer feedback, Proxmox VE can host the EPP Server image after manually adjusting networking and IP configuration post-deployment. Converting the provided OVF image for use on Proxmox, along with any such adjustments, is entirely the customer's responsibility and falls outside Netwrix support. +**Proxmox VE** isn't an officially supported hypervisor for Endpoint Protector. Based on customer feedback, Proxmox VE can host the EPP Server image after you manually adjust networking and IP configuration post-deployment. Converting the provided OVF image for use on Proxmox, along with any such adjustments, is entirely the customer's responsibility and falls outside Netwrix support. ::: :::warning @@ -97,7 +97,7 @@ The 2608 image adds CrateDB, which may raise the minimum disk, RAM, and CPU base ::: :::tip -If disk space is below 30%, perform database shrinking via **System Maintenance → Audit Log Backups** before proceeding. Exporting old logs to an external SIEM or repository reduces DB size significantly. If not possible, consider expanding the associated disk space. To export logs, see [Audit Log Backup](/docs/endpointprotector/admin/systemmaintenance/overview#audit-log-backup). +If disk space is below 30%, shrink the database via **System Maintenance → Audit Log Backups** before proceeding. Exporting old logs to an external SIEM or repository reduces DB size significantly. If not possible, consider expanding the associated disk space. To export logs, see [Audit Log Backup](/docs/endpointprotector/admin/systemmaintenance/overview#audit-log-backup). ::: ### Maintenance Window Planning @@ -114,7 +114,7 @@ Plan a maintenance window that accounts for the following: These times reflect laboratory test results and may vary in your environment depending on several factors, including hardware assigned to the appliance. **During the upgrade window, you won't have:** -- EPP/EE client communication with the server +- EPP and Enforced Encryption (EE) client communication with the server - Email alerts and SIEM integrations - File Shadow and log generation @@ -282,7 +282,7 @@ If your 5.9.4.2 backup export is larger than 200 MB, follow these steps: This doesn't change the EPP Server version — it remains 5.9.4.2. ::: -4. If the new export attempt still returns more than 200 MB after successfully importing the offline patch, contact Netwrix Support for assistance with the manual procedure. +4. If the new export attempt still returns more than 200 MB after you successfully import the offline patch, contact Netwrix Support for assistance with the manual procedure. --- @@ -322,11 +322,11 @@ Always use the **same IP/FQDN** option. The operational complexity and user impa | High server load | Certificate regeneration for all endpoints creates a burst load spike | :::warning -If using Enforced Encryption and you change the IP/FQDN, every user with an EE-protected drive must decrypt their drive and re-encrypt it after reconnecting to the new server. This can be a major operational disruption in large organizations. Netwrix strongly discourages this. +If you use Enforced Encryption and change the IP/FQDN, every user with an EE-protected drive must decrypt their drive and re-encrypt it after reconnecting to the new server. This can be a major operational disruption in large organizations. Netwrix strongly discourages this. ::: :::warning -If you use SSO (Single Sign-On) and choose a different IP address instead of an FQDN for the new server, reviewing your SSO configuration after the backup is restored is mandatory. SSO response/callback URLs are tied to the server address used at configuration time — changing the IP breaks them. After migration, either manually recreate the SSO configuration with the updated response URL, or open a Netwrix Support case to have it updated on the backend. See [Third-Party Integration Reconfiguration](#third-party-integration-reconfiguration) in Post-Migration Verification. +If you use SSO (Single Sign-On) and choose a different IP address instead of an FQDN for the new server, you must review your SSO configuration after you restore the backup. SSO response/callback URLs are tied to the server address used at configuration time — changing the IP breaks them. After migration, either manually recreate the SSO configuration with the updated response URL, or open a Netwrix Support case to have it updated on the backend. See [Third-Party Integration Reconfiguration](#third-party-integration-reconfiguration) in Post-Migration Verification. ::: ### Deploying the 2608 Base Image @@ -380,7 +380,7 @@ For air-gapped environments, follow the same procedure using the 2608 cumulative ::: 3. After each patch, refresh the browser and verify the version in **Appliance → Server Information** before applying the next. -4. Once fully patched, confirm the server is stable and all services are running before proceeding to the backup restore. +4. After you fully patch the server, confirm it's stable and all services are running before proceeding to the backup restore. ### Restoring the 5.9.4.2 Backup onto 2608 @@ -474,7 +474,7 @@ Verify each active module: | Content Aware Protection | Content Aware Protection → Dashboard | | eDiscovery | eDiscovery → Dashboard | | Enforced Encryption | Check that EE-protected drives are accessible | -| Reports & Analytics | Reports and Analytics → relevant sub-service | +| Reports and Analysis | Reports and Analysis → relevant sub-service | | Alerts | Check that configured alerts are firing | :::tip @@ -484,7 +484,7 @@ Generate deliberate test events on a known test machine for each active module. ### eDiscovery Scan Locations Verification :::warning -If an eDiscovery policy with configured **Scan Locations** is restored from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead — with no error reported anywhere. This is a known post-migration issue for any environment using the eDiscovery module. +If you restore an eDiscovery policy with configured **Scan Locations** from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead, without reporting an error anywhere. This is a known post-migration issue for any environment using the eDiscovery module. ::: If you use eDiscovery with Scan Locations configured on any policy, this check is mandatory after restore: @@ -496,13 +496,13 @@ If you use eDiscovery with Scan Locations configured on any policy, this check i ### CAP Policy Verification :::note -In rare cases, a Content Aware Protection (CAP) policy restored from a System Configuration Backup doesn't redistribute correctly and stops triggering, with no error reported. +In rare cases, a Content Aware Protection (CAP) policy restored from a System Configuration Backup doesn't redistribute correctly and stops triggering, without reporting an error. ::: If you use Content Aware Protection, this check is recommended after restore: 1. Test each active CAP policy against a known-blocked transfer to confirm it still triggers. -2. If a policy doesn't trigger, open it, edit and save it — even without changing anything — to redistribute it to endpoints. +2. If a policy doesn't trigger, open it, edit it, and save it — even without changing anything — to redistribute it to endpoints. 3. Re-test to confirm the policy now triggers correctly. ### DPI / CAP Functionality Verification @@ -519,6 +519,33 @@ If using Deep Packet Inspection or Content Aware Protection: 2. Verify that backups are configured and active. 3. Run a test backup and confirm **"Ready to download"** status. +### Log Retention Verification + +:::warning +**This is a behavior change from earlier server versions.** Endpoint Protector 2608 introduces +automatic, age-based log rotation for Device Control, Content Aware Protection, and eDiscovery +logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. +After migration, Endpoint Protector enables this setting by default at three months and +automatically deletes logs older than three months, together with their associated file shadows. +Endpoint Protector deletes logs already older than the configured period on the first rotation +cycle after the server starts, so export anything you want to keep before you migrate. +::: + +After migration, verify: +1. Navigate to **System Configuration → System Settings → Log Settings**. +2. Check the value configured for **Enable Log Rotate After**. +3. Confirm the configured retention period matches your organization's operational and compliance + needs. Adjust the value if three months doesn't match your retention policy. The value is in + months, from 1 to 360 — there's no option to disable log rotation entirely. + +For the full description of this setting, see [Log Settings](/docs/endpointprotector/admin/systemconfiguration/systemsettings#log-settings). + +:::tip +If you need to retain log data for compliance beyond your configured retention period, export it +regularly through **Reports and Analysis** → **Export Logs** and store the exports separately. +Exports also keep the server's log tables smaller, which helps console and report performance. +::: + ### Third-Party Integration Reconfiguration After migration, manually re-import and reconfigure all 3rd-party integrations. While the backup includes configuration data, it doesn't always fully restore credentials and connection secrets, and integration endpoints may require re-registration against the new server. @@ -548,7 +575,7 @@ After reconfiguration, verify each integration is functioning: | AWS / S3 / File Shadows | Generate a file shadow; confirm it reaches the S3 bucket | :::warning -**Mandatory if you used an IP address instead of an FQDN for the new server:** Review your SSO configuration after the backup is restored. The SSO response/callback URL registered against the old server address no longer matches, and SSO logins fail until this is corrected. You have two options: +**Mandatory if you used an IP address instead of an FQDN for the new server:** Review your SSO configuration after you restore the backup. The SSO response/callback URL registered against the old server address no longer matches, and SSO logins fail until you correct it. You have two options: 1. Manually recreate the SSO configuration in **System Configuration → SSO / Single Sign-On** with the updated response/callback URL, and update the corresponding redirect URI in your identity provider. 2. Raise a Netwrix Support case to have the SSO configuration updated on the backend. ::: @@ -577,7 +604,7 @@ AD Sync may appear to complete successfully but only import a partial set of use 2. Re-enter tenant ID, client ID, and client secret — the backup doesn't restore these. 3. Verify the redirect URI registered in Azure AD matches the new server address. If the new server uses an IP address instead of an FQDN, either manually recreate the SSO configuration with the updated response/callback URL, or raise a Netwrix Support case to have it updated on the backend. 4. Perform a test SSO login in an incognito window. -5. If SCIM provisioning is broken, re-generate the SCIM token in the EPP console and update it in Entra ID. +5. If SCIM provisioning fails, re-generate the SCIM token in the EPP console and update it in Entra ID. **SIEM / Syslog events not forwarding:** 1. Reconfigure the SIEM destination IP, port, and protocol.