From 2fc99697618f32cdb71fafa604ac58f0d3874e50 Mon Sep 17 00:00:00 2001 From: Mihai Rosca Date: Fri, 11 Sep 2026 13:40:43 +0300 Subject: [PATCH 1/9] Document EPP 2608 automatic log rotation as a behavior change System Settings > Log Settings: - Add a warning to Enable Log Rotate After explaining this is new in 2608. Earlier server versions kept Device Control, Content Aware Protection, and eDiscovery logs indefinitely with no automatic deletion; 2608 enables three-month rotation by default on migration. Recommend reviewing the value and using Export Logs to preserve compliance evidence separately. Migration guides (both legacy 5.x and current-image paths): - Add a Log Retention Verification step to Post-Migration Verification, before Audit Log Backup Verification, prompting admins to check and configure Enable Log Rotate After post-migration. Co-Authored-By: Claude Sonnet 5 --- .../systemconfiguration/systemsettings.md | 12 ++++++++++ .../migration-current-image.md | 23 +++++++++++++++++++ .../migrationprocedure/migration-legacy-5x.md | 23 +++++++++++++++++++ 3 files changed, 58 insertions(+) diff --git a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md index e2498f0054..77099c3914 100644 --- a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md +++ b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md @@ -152,6 +152,18 @@ You can set a number of reported threats between 100 and 1000. file shadows. For example, setting this option to 6 keeps six months of logs and removes anything older. Set the value to 0 to disable log rotation. +:::warning +This setting is new starting with Endpoint Protector 2608. Earlier server versions didn't +automatically delete Device Control, Content Aware Protection, or eDiscovery logs based on age — +Endpoint Protector kept logs indefinitely unless an administrator removed them manually or through +Audit Log Backup. After you migrate or upgrade to 2608, this setting is enabled by default at three +months, so Endpoint Protector automatically deletes logs older than three months going forward. +Review this value as soon as you migrate and configure it to match your organization's retention +needs. If you must retain log data for compliance beyond the configured period, export it regularly +through **Reports and Analysis** > **Export Logs** and store the exports separately — don't rely on +server-side log storage for long-term compliance evidence. +::: + :::warning Disabling log rotation means Endpoint Protector never removes logs automatically, and the server continues to consume storage until you intervene. diff --git a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md index bee36dee81..fa19a2a296 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md @@ -422,6 +422,29 @@ AD Sync may appear to complete successfully but only import a partial set of use If an integration fails verification, see [Troubleshooting Failed Integrations](/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x#troubleshooting-failed-integrations). +### Log Retention Verification + +:::warning +**This is a behavior change from earlier server versions.** Endpoint Protector 2608 introduces +automatic, age-based log rotation for Device Control, Content Aware Protection, and eDiscovery +logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. +After migration, this setting is enabled by default at three months — Endpoint Protector +automatically deletes logs older than three months, together with their associated file shadows. +::: + +After migration, verify: +1. Navigate to **System Configuration → System Settings → Log Settings**. +2. Check the value configured for **Enable Log Rotate After**. +3. Confirm the configured retention period matches your organization's operational and compliance + needs. Adjust it if the default of three months is too short. + +:::tip +If you need to retain log data for compliance beyond your configured retention period, export it +regularly through **Reports and Analysis** > **Export Logs** and store the exports separately. +Keeping compliance evidence in exports, rather than relying on indefinite server-side log storage, +also keeps the server's log storage lean and performant. +::: + ### Audit Log Backup Verification :::warning diff --git a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md index c00f5260c3..62b6354e0f 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md @@ -589,6 +589,29 @@ AD Sync may appear to complete successfully but only import a partial set of use 2. Re-enter the S3 bucket name, region, access key, and secret key. 3. Run a test file shadow and confirm the file appears in the bucket. +### Log Retention Verification + +:::warning +**This is a behavior change from earlier server versions.** Endpoint Protector 2608 introduces +automatic, age-based log rotation for Device Control, Content Aware Protection, and eDiscovery +logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. +After migration, this setting is enabled by default at three months — Endpoint Protector +automatically deletes logs older than three months, together with their associated file shadows. +::: + +After migration, verify: +1. Navigate to **System Configuration → System Settings → Log Settings**. +2. Check the value configured for **Enable Log Rotate After**. +3. Confirm the configured retention period matches your organization's operational and compliance + needs. Adjust it if the default of three months is too short. + +:::tip +If you need to retain log data for compliance beyond your configured retention period, export it +regularly through **Reports and Analysis** > **Export Logs** and store the exports separately. +Keeping compliance evidence in exports, rather than relying on indefinite server-side log storage, +also keeps the server's log storage lean and performant. +::: + ### Audit Log Backup Verification :::warning From d43045b2cd6da441c6dddeb49673caa7a847c589 Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Fri, 11 Sep 2026 10:56:29 +0000 Subject: [PATCH 2/9] fix(vale): auto-fix style issues (Vale + Dale) --- .../systemconfiguration/systemsettings.md | 32 +++++++++---------- .../migration-current-image.md | 14 ++++---- .../migrationprocedure/migration-legacy-5x.md | 12 +++---- 3 files changed, 29 insertions(+), 29 deletions(-) diff --git a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md index 77099c3914..609ff0a4a6 100644 --- a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md +++ b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md @@ -62,19 +62,19 @@ pattern. - Enable Smart Groups – when you disable this setting, Endpoint Protector converts Smart Groups to regular groups with no entities assigned and removes the Default Group for Computers and the Default Group for Users. -- Enable Default Group for Computers – this will create a default group for computers containing all +- Enable Default Group for Computers – creates a default group for computers containing all computers that aren't part of a Smart Group. :::note -By disabling this setting, you will delete the Default Group for Computers. +Disabling this setting deletes the Default Group for Computers. ::: -- Enable Default Group for Users – this will create a default group for users containing all users +- Enable Default Group for Users – creates a default group for users containing all users that aren't part of a Smart Group. :::note -By disabling this setting, you will delete the Default Group for Users. +Disabling this setting deletes the Default Group for Users. ::: :::note @@ -119,8 +119,8 @@ Manage the following log settings: - Set the Maximum number of rows in millions to export the Logs Report in .csv format. :::note -By setting the maximum number of rows to 1.0, you will export 1 million logs in the Logs -Report .csv export as one row corresponds with one log. +Setting the maximum number of rows to 1.0 exports 1 million logs in the Logs +Report .csv export, since one row corresponds with one log. ::: @@ -131,8 +131,8 @@ export. structure and display information in Destination details, Email sender, and Email subject columns. :::note -For Endpoint Protector Server versions older than 5.7.0.0, the Reporting V2 setting isn't -enabled by default. +For Endpoint Protector Server versions older than 5.7.0.0, Endpoint Protector doesn't enable +the Reporting V2 setting by default. ::: @@ -156,8 +156,8 @@ You can set a number of reported threats between 100 and 1000. This setting is new starting with Endpoint Protector 2608. Earlier server versions didn't automatically delete Device Control, Content Aware Protection, or eDiscovery logs based on age — Endpoint Protector kept logs indefinitely unless an administrator removed them manually or through -Audit Log Backup. After you migrate or upgrade to 2608, this setting is enabled by default at three -months, so Endpoint Protector automatically deletes logs older than three months going forward. +Audit Log Backup. After you migrate or upgrade to 2608, Endpoint Protector enables this setting by +default at three months and automatically deletes logs older than three months going forward. Review this value as soon as you migrate and configure it to match your organization's retention needs. If you must retain log data for compliance beyond the configured period, export it regularly through **Reports and Analysis** > **Export Logs** and store the exports separately — don't rely on @@ -234,16 +234,16 @@ Endpoint Protector automatically modifies the maximum number of reported threat Limit Reporting Content Aware Protection refers to Report Only policies. -- If enabled, the Endpoint Protector client will stop reporting threats for a Report Only policy - after it finds enough threats to conclude it is satisfied. +- When you enable this setting, the Endpoint Protector client stops reporting threats for a Report + Only policy after it finds enough threats to satisfy the policy. The "Content Aware Protection - Ignore Thresholds" toggle refers to Block & Report policies. -- When this toggle is On, scanning doesn't stop at a block verdict, but continues to report further +- When this toggle is On, scanning continues past a block verdict and reports further threats found in a transfer. - To limit the number of reported threats in this case, set the "Maximum number of reported threats" - setting to a value greater than zero. The value you set is only indicative for the number of - reported threats, the actual number reported can be slightly larger. + setting to a value greater than zero. The value you set only indicates the number of + reported threats; the actual number reported can be slightly larger. The ‘Ignore Thresholds’ setting ignores and overrides the ‘Global/Threat Threshold’ values in Content Aware Protection policies when the Boolean logic of the Content Aware Protection policy @@ -498,7 +498,7 @@ Enable the **Active Directory Authentication** setting to import an Active Direc administrators into Endpoint Protector as Super Administrators. :::note -By enabling the Active Directory Authentication, you allow the administrators to use their +Enabling Active Directory Authentication lets administrators use their Active Directory credentials to log into Endpoint Protector. ::: diff --git a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md index fa19a2a296..5c2168b8c9 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md @@ -9,7 +9,7 @@ sidebar_position: 13 --- :::note -This article covers on-premises EPP Servers already running the current image-based platform — any version from **2509 through 2604**. If your server is still on a legacy 5.x release (5.7.0.0–5.9.4.2), see [Migrating from a Legacy 5.x Server to 2608](/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x) instead. For the full picture and how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). +This article covers on-premises EPP Servers already running the current image-based platform — any version from **2509 through 2604**. If your server is still on a legacy 5.x release (5.7.0.0–5.9.4.2), see [Migrating from a Legacy 5.x Server to 2608](/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x) instead. For an overview of how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). ::: ## Overview @@ -20,7 +20,7 @@ Since you're already on the image-based platform, migrating to 2608 doesn't requ | Your Current Version | Recommendation | |---|---| -| 2509, 2510, 2601, 2602, or 2604 | Migrate directly to 2608 — no intermediate version is required | +| 2509, 2510, 2601, 2602, or 2604 | Migrate directly to 2608 — you don't need an intermediate version | :::tip 2608 accepts a direct backup restore from any of 2509, 2510, 2601, 2602, or 2604. It's still good practice to upgrade to 2604 before migrating, since the 2604 → 2608 path is the most thoroughly validated in Netwrix labs. @@ -218,7 +218,7 @@ If using Enforced Encryption and you change the IP/FQDN, every user with an EE-p ::: :::warning -If you use SSO (Single Sign-On) and choose a different IP address instead of an FQDN for the new server, reviewing your SSO configuration after the backup is restored is mandatory. SSO response/callback URLs are tied to the server address used at configuration time — changing the IP breaks them. After migration, either manually recreate the SSO configuration with the updated response URL, or open a Netwrix Support case to have it updated on the backend. See [Third-Party Integration Reconfiguration](#third-party-integration-reconfiguration) in Post-Migration Verification. +If you use SSO (Single Sign-On) and choose a different IP address instead of an FQDN for the new server, you must review your SSO configuration after you restore the backup. SSO response/callback URLs are tied to the server address used at configuration time — changing the IP breaks them. After migration, either manually recreate the SSO configuration with the updated response URL, or open a Netwrix Support case to have it updated on the backend. See [Third-Party Integration Reconfiguration](#third-party-integration-reconfiguration) in Post-Migration Verification. ::: ### Deploying the 2608 Base Image @@ -347,7 +347,7 @@ Generate deliberate test events on a known test machine for each active module. ### eDiscovery Scan Locations Verification :::warning -If an eDiscovery policy with configured **Scan Locations** is restored from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead — with no error reported anywhere. This is a known post-migration issue for any environment using the eDiscovery module. +If you restore an eDiscovery policy with configured **Scan Locations** from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead — with no error reported anywhere. This is a known post-migration issue for any environment using the eDiscovery module. ::: If you use eDiscovery with Scan Locations configured on any policy, this check is mandatory after restore: @@ -365,7 +365,7 @@ In rare cases, a Content Aware Protection (CAP) policy restored from a System Co If you use Content Aware Protection, this check is recommended after restore: 1. Test each active CAP policy against a known-blocked transfer to confirm it still triggers. -2. If a policy doesn't trigger, open it, edit and save it — even without changing anything — to redistribute it to endpoints. +2. If a policy doesn't trigger, open it, edit it, and save it — even without changing anything — to redistribute it to endpoints. 3. Re-test to confirm the policy now triggers correctly. ### DPI / CAP Functionality Verification @@ -411,7 +411,7 @@ After reconfiguration, verify each integration is functioning: | AWS / S3 / File Shadows | Generate a file shadow; confirm it reaches the S3 bucket | :::warning -**Mandatory if you used an IP address instead of an FQDN for the new server:** Review your SSO configuration after the backup is restored. The SSO response/callback URL registered against the old server address no longer matches, and SSO logins fail until this is corrected. You have two options: +**Mandatory if you used an IP address instead of an FQDN for the new server:** Review your SSO configuration after you restore the backup. The SSO response/callback URL registered against the old server address no longer matches, and SSO logins fail until you correct it. You have two options: 1. Manually recreate the SSO configuration in **System Configuration → SSO / Single Sign-On** with the updated response/callback URL, and update the corresponding redirect URI in your identity provider. 2. Raise a Netwrix Support case to have the SSO configuration updated on the backend. ::: @@ -428,7 +428,7 @@ If an integration fails verification, see [Troubleshooting Failed Integrations]( **This is a behavior change from earlier server versions.** Endpoint Protector 2608 introduces automatic, age-based log rotation for Device Control, Content Aware Protection, and eDiscovery logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. -After migration, this setting is enabled by default at three months — Endpoint Protector +After migration, Endpoint Protector enables this setting by default at three months and automatically deletes logs older than three months, together with their associated file shadows. ::: diff --git a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md index 62b6354e0f..4c2adc371f 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md @@ -9,7 +9,7 @@ sidebar_position: 12 --- :::note -This article covers on-premises EPP Servers running any version from **5.7.0.0 through 5.9.4.2** (5700, 5710, 5800, 5810, 5820, 5900, 5910, 5920, 5930, 5940, 5941, 5942). If your server is already on the current image-based platform (2509–2604), see [Migrating from the Current Image Platform to 2608](/docs/endpointprotector/install/migrationprocedure/migration-current-image) instead. For the full picture and how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). +This article covers on-premises EPP Servers running any version from **5.7.0.0 through 5.9.4.2** (5700, 5710, 5800, 5810, 5820, 5900, 5910, 5920, 5930, 5940, 5941, 5942). If your server is already on the current image-based platform (2509–2604), see [Migrating from the Current Image Platform to 2608](/docs/endpointprotector/install/migrationprocedure/migration-current-image) instead. For an overview of how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). ::: ## Overview @@ -326,7 +326,7 @@ If using Enforced Encryption and you change the IP/FQDN, every user with an EE-p ::: :::warning -If you use SSO (Single Sign-On) and choose a different IP address instead of an FQDN for the new server, reviewing your SSO configuration after the backup is restored is mandatory. SSO response/callback URLs are tied to the server address used at configuration time — changing the IP breaks them. After migration, either manually recreate the SSO configuration with the updated response URL, or open a Netwrix Support case to have it updated on the backend. See [Third-Party Integration Reconfiguration](#third-party-integration-reconfiguration) in Post-Migration Verification. +If you use SSO (Single Sign-On) and choose a different IP address instead of an FQDN for the new server, you must review your SSO configuration after you restore the backup. SSO response/callback URLs are tied to the server address used at configuration time — changing the IP breaks them. After migration, either manually recreate the SSO configuration with the updated response URL, or open a Netwrix Support case to have it updated on the backend. See [Third-Party Integration Reconfiguration](#third-party-integration-reconfiguration) in Post-Migration Verification. ::: ### Deploying the 2608 Base Image @@ -484,7 +484,7 @@ Generate deliberate test events on a known test machine for each active module. ### eDiscovery Scan Locations Verification :::warning -If an eDiscovery policy with configured **Scan Locations** is restored from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead — with no error reported anywhere. This is a known post-migration issue for any environment using the eDiscovery module. +If you restore an eDiscovery policy with configured **Scan Locations** from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead — with no error reported anywhere. This is a known post-migration issue for any environment using the eDiscovery module. ::: If you use eDiscovery with Scan Locations configured on any policy, this check is mandatory after restore: @@ -502,7 +502,7 @@ In rare cases, a Content Aware Protection (CAP) policy restored from a System Co If you use Content Aware Protection, this check is recommended after restore: 1. Test each active CAP policy against a known-blocked transfer to confirm it still triggers. -2. If a policy doesn't trigger, open it, edit and save it — even without changing anything — to redistribute it to endpoints. +2. If a policy doesn't trigger, open it, edit it, and save it — even without changing anything — to redistribute it to endpoints. 3. Re-test to confirm the policy now triggers correctly. ### DPI / CAP Functionality Verification @@ -548,7 +548,7 @@ After reconfiguration, verify each integration is functioning: | AWS / S3 / File Shadows | Generate a file shadow; confirm it reaches the S3 bucket | :::warning -**Mandatory if you used an IP address instead of an FQDN for the new server:** Review your SSO configuration after the backup is restored. The SSO response/callback URL registered against the old server address no longer matches, and SSO logins fail until this is corrected. You have two options: +**Mandatory if you used an IP address instead of an FQDN for the new server:** Review your SSO configuration after you restore the backup. The SSO response/callback URL registered against the old server address no longer matches, and SSO logins fail until you correct it. You have two options: 1. Manually recreate the SSO configuration in **System Configuration → SSO / Single Sign-On** with the updated response/callback URL, and update the corresponding redirect URI in your identity provider. 2. Raise a Netwrix Support case to have the SSO configuration updated on the backend. ::: @@ -595,7 +595,7 @@ AD Sync may appear to complete successfully but only import a partial set of use **This is a behavior change from earlier server versions.** Endpoint Protector 2608 introduces automatic, age-based log rotation for Device Control, Content Aware Protection, and eDiscovery logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. -After migration, this setting is enabled by default at three months — Endpoint Protector +After migration, Endpoint Protector enables this setting by default at three months and automatically deletes logs older than three months, together with their associated file shadows. ::: From 2cc49320d37bdb893b8bce8779d0f899ed9b0c92 Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Fri, 11 Sep 2026 11:00:30 +0000 Subject: [PATCH 3/9] docs: apply fixes from PR review - Merge the two stacked log rotation warnings in System Settings into one, open with the behavior change, explain the Audit Log Backup side effect, and state that logs already past the retention period are deleted on the first rotation cycle within five minutes of startup - Move Log Retention Verification ahead of Third-Party Integration Reconfiguration in both migration guides so it's reached before rotation runs - Add the first-rotation-cycle warning, the units and disable value, and a link to the Log Settings reference in both migration guides - Replace the vague export rationale with the performance benefit - Use the arrow separator consistently in the migration guides and reconcile the menu name to Reports and Analysis Co-Authored-By: Claude --- .../systemconfiguration/systemsettings.md | 25 ++++----- .../migration-current-image.md | 52 ++++++++++--------- .../migrationprocedure/migration-legacy-5x.md | 52 ++++++++++--------- 3 files changed, 67 insertions(+), 62 deletions(-) diff --git a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md index 609ff0a4a6..119d440fd1 100644 --- a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md +++ b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md @@ -153,20 +153,17 @@ You can set a number of reported threats between 100 and 1000. older. Set the value to 0 to disable log rotation. :::warning -This setting is new starting with Endpoint Protector 2608. Earlier server versions didn't -automatically delete Device Control, Content Aware Protection, or eDiscovery logs based on age — -Endpoint Protector kept logs indefinitely unless an administrator removed them manually or through -Audit Log Backup. After you migrate or upgrade to 2608, Endpoint Protector enables this setting by -default at three months and automatically deletes logs older than three months going forward. -Review this value as soon as you migrate and configure it to match your organization's retention -needs. If you must retain log data for compliance beyond the configured period, export it regularly -through **Reports and Analysis** > **Export Logs** and store the exports separately — don't rely on -server-side log storage for long-term compliance evidence. -::: - -:::warning -Disabling log rotation means Endpoint Protector never removes logs automatically, and the server -continues to consume storage until you intervene. +Endpoint Protector 2608 enables this setting by default. Earlier server versions kept these logs +indefinitely unless an administrator removed them manually or through Audit Log Backup, which +archives logs off the server and clears them from the database. The first rotation cycle runs +within five minutes of the server starting, so any logs already older than the configured period +are deleted at that point — export anything you need to keep before you upgrade. Review this value +as soon as you migrate and configure it to match your organization's retention needs. If you must +retain log data for compliance beyond the configured period, export it regularly through +**Reports and Analysis** > **Export Logs** and store the exports separately — don't rely on +server-side log storage for long-term compliance evidence. Disabling log rotation means Endpoint +Protector never removes logs automatically, and the server continues to consume storage until you +intervene. ::: diff --git a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md index 5c2168b8c9..9751127eb6 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md @@ -337,7 +337,7 @@ Verify each active module: | Content Aware Protection | Content Aware Protection → Dashboard | | eDiscovery | eDiscovery → Dashboard | | Enforced Encryption | Check that EE-protected drives are accessible | -| Reports & Analytics | Reports and Analytics → relevant sub-service | +| Reports and Analysis | Reports and Analysis → relevant sub-service | | Alerts | Check that configured alerts are firing | :::tip @@ -382,6 +382,33 @@ If using Deep Packet Inspection or Content Aware Protection: 2. Verify that backups are configured and active. 3. Run a test backup and confirm **"Ready to download"** status. +### Log Retention Verification + +:::warning +**This is a behavior change from earlier server versions.** Endpoint Protector 2608 introduces +automatic, age-based log rotation for Device Control, Content Aware Protection, and eDiscovery +logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. +After migration, Endpoint Protector enables this setting by default at three months and +automatically deletes logs older than three months, together with their associated file shadows. +Logs already older than the configured period are deleted on the first rotation cycle after the +server starts. +::: + +After migration, verify: +1. Navigate to **System Configuration → System Settings → Log Settings**. +2. Check the value configured for **Enable Log Rotate After**. +3. Confirm the configured retention period matches your organization's operational and compliance + needs. Adjust the value if three months doesn't match your retention policy. The value is in + months; set it to 0 to disable log rotation entirely. + +For the full description of this setting, see [Log Settings](/docs/endpointprotector/admin/systemconfiguration/systemsettings#log-settings). + +:::tip +If you need to retain log data for compliance beyond your configured retention period, export it +regularly through **Reports and Analysis** → **Export Logs** and store the exports separately. +Exports also keep the server's log tables smaller, which helps console and report performance. +::: + ### Third-Party Integration Reconfiguration After migration, manually re-import and reconfigure all 3rd-party integrations. While the backup includes configuration data, it doesn't always fully restore credentials and connection secrets, and integration endpoints may require re-registration against the new server. @@ -422,29 +449,6 @@ AD Sync may appear to complete successfully but only import a partial set of use If an integration fails verification, see [Troubleshooting Failed Integrations](/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x#troubleshooting-failed-integrations). -### Log Retention Verification - -:::warning -**This is a behavior change from earlier server versions.** Endpoint Protector 2608 introduces -automatic, age-based log rotation for Device Control, Content Aware Protection, and eDiscovery -logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. -After migration, Endpoint Protector enables this setting by default at three months and -automatically deletes logs older than three months, together with their associated file shadows. -::: - -After migration, verify: -1. Navigate to **System Configuration → System Settings → Log Settings**. -2. Check the value configured for **Enable Log Rotate After**. -3. Confirm the configured retention period matches your organization's operational and compliance - needs. Adjust it if the default of three months is too short. - -:::tip -If you need to retain log data for compliance beyond your configured retention period, export it -regularly through **Reports and Analysis** > **Export Logs** and store the exports separately. -Keeping compliance evidence in exports, rather than relying on indefinite server-side log storage, -also keeps the server's log storage lean and performant. -::: - ### Audit Log Backup Verification :::warning diff --git a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md index 4c2adc371f..1d520e109a 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md @@ -474,7 +474,7 @@ Verify each active module: | Content Aware Protection | Content Aware Protection → Dashboard | | eDiscovery | eDiscovery → Dashboard | | Enforced Encryption | Check that EE-protected drives are accessible | -| Reports & Analytics | Reports and Analytics → relevant sub-service | +| Reports and Analysis | Reports and Analysis → relevant sub-service | | Alerts | Check that configured alerts are firing | :::tip @@ -519,6 +519,33 @@ If using Deep Packet Inspection or Content Aware Protection: 2. Verify that backups are configured and active. 3. Run a test backup and confirm **"Ready to download"** status. +### Log Retention Verification + +:::warning +**This is a behavior change from earlier server versions.** Endpoint Protector 2608 introduces +automatic, age-based log rotation for Device Control, Content Aware Protection, and eDiscovery +logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. +After migration, Endpoint Protector enables this setting by default at three months and +automatically deletes logs older than three months, together with their associated file shadows. +Logs already older than the configured period are deleted on the first rotation cycle after the +server starts. +::: + +After migration, verify: +1. Navigate to **System Configuration → System Settings → Log Settings**. +2. Check the value configured for **Enable Log Rotate After**. +3. Confirm the configured retention period matches your organization's operational and compliance + needs. Adjust the value if three months doesn't match your retention policy. The value is in + months; set it to 0 to disable log rotation entirely. + +For the full description of this setting, see [Log Settings](/docs/endpointprotector/admin/systemconfiguration/systemsettings#log-settings). + +:::tip +If you need to retain log data for compliance beyond your configured retention period, export it +regularly through **Reports and Analysis** → **Export Logs** and store the exports separately. +Exports also keep the server's log tables smaller, which helps console and report performance. +::: + ### Third-Party Integration Reconfiguration After migration, manually re-import and reconfigure all 3rd-party integrations. While the backup includes configuration data, it doesn't always fully restore credentials and connection secrets, and integration endpoints may require re-registration against the new server. @@ -589,29 +616,6 @@ AD Sync may appear to complete successfully but only import a partial set of use 2. Re-enter the S3 bucket name, region, access key, and secret key. 3. Run a test file shadow and confirm the file appears in the bucket. -### Log Retention Verification - -:::warning -**This is a behavior change from earlier server versions.** Endpoint Protector 2608 introduces -automatic, age-based log rotation for Device Control, Content Aware Protection, and eDiscovery -logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. -After migration, Endpoint Protector enables this setting by default at three months and -automatically deletes logs older than three months, together with their associated file shadows. -::: - -After migration, verify: -1. Navigate to **System Configuration → System Settings → Log Settings**. -2. Check the value configured for **Enable Log Rotate After**. -3. Confirm the configured retention period matches your organization's operational and compliance - needs. Adjust it if the default of three months is too short. - -:::tip -If you need to retain log data for compliance beyond your configured retention period, export it -regularly through **Reports and Analysis** > **Export Logs** and store the exports separately. -Keeping compliance evidence in exports, rather than relying on indefinite server-side log storage, -also keeps the server's log storage lean and performant. -::: - ### Audit Log Backup Verification :::warning From ac927d2bf8cd02ad2216c14b90a426a79f0f360e Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Fri, 11 Sep 2026 11:01:59 +0000 Subject: [PATCH 4/9] docs: correct Audit Log Backup behavior and use active voice in rotation warnings - Audit Log Backup deletion is an option, not automatic: System Maintenance documents a per-job choice of whether to keep or delete logs from the server, so 'archives logs off the server and clears them from the database' overstates it - Make the first-rotation-cycle sentence active per the Netwrix voice rules, and restore the actionable 'export before you migrate' guidance in both guides Co-Authored-By: Claude --- .../admin/systemconfiguration/systemsettings.md | 8 ++++---- .../install/migrationprocedure/migration-current-image.md | 4 ++-- .../install/migrationprocedure/migration-legacy-5x.md | 4 ++-- 3 files changed, 8 insertions(+), 8 deletions(-) diff --git a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md index 119d440fd1..740db69937 100644 --- a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md +++ b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md @@ -154,10 +154,10 @@ You can set a number of reported threats between 100 and 1000. :::warning Endpoint Protector 2608 enables this setting by default. Earlier server versions kept these logs -indefinitely unless an administrator removed them manually or through Audit Log Backup, which -archives logs off the server and clears them from the database. The first rotation cycle runs -within five minutes of the server starting, so any logs already older than the configured period -are deleted at that point — export anything you need to keep before you upgrade. Review this value +indefinitely unless an administrator removed them manually or through Audit Log Backup, which can +delete logs from the server as it archives them. The first rotation cycle runs within five minutes +of the server starting, so Endpoint Protector deletes any logs already older than the configured +period at that point — export anything you need to keep before you upgrade. Review this value as soon as you migrate and configure it to match your organization's retention needs. If you must retain log data for compliance beyond the configured period, export it regularly through **Reports and Analysis** > **Export Logs** and store the exports separately — don't rely on diff --git a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md index 9751127eb6..dff0b40618 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md @@ -390,8 +390,8 @@ automatic, age-based log rotation for Device Control, Content Aware Protection, logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. After migration, Endpoint Protector enables this setting by default at three months and automatically deletes logs older than three months, together with their associated file shadows. -Logs already older than the configured period are deleted on the first rotation cycle after the -server starts. +Endpoint Protector deletes logs already older than the configured period on the first rotation +cycle after the server starts, so export anything you want to keep before you migrate. ::: After migration, verify: diff --git a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md index 1d520e109a..aa3e393127 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md @@ -527,8 +527,8 @@ automatic, age-based log rotation for Device Control, Content Aware Protection, logs. Earlier versions kept these logs indefinitely unless an administrator deleted them manually. After migration, Endpoint Protector enables this setting by default at three months and automatically deletes logs older than three months, together with their associated file shadows. -Logs already older than the configured period are deleted on the first rotation cycle after the -server starts. +Endpoint Protector deletes logs already older than the configured period on the first rotation +cycle after the server starts, so export anything you want to keep before you migrate. ::: After migration, verify: From 1c26b2737ac8dcb8319c87a873bbb65afb33cccc Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Fri, 11 Sep 2026 11:12:00 +0000 Subject: [PATCH 5/9] fix(vale): auto-fix style issues (Vale + Dale) --- .../admin/systemconfiguration/systemsettings.md | 4 ++-- .../migrationprocedure/migration-current-image.md | 6 +++--- .../install/migrationprocedure/migration-legacy-5x.md | 10 +++++----- 3 files changed, 10 insertions(+), 10 deletions(-) diff --git a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md index 740db69937..57feef9d78 100644 --- a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md +++ b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md @@ -244,8 +244,8 @@ The "Content Aware Protection - Ignore Thresholds" toggle refers to Block & Repo The ‘Ignore Thresholds’ setting ignores and overrides the ‘Global/Threat Threshold’ values in Content Aware Protection policies when the Boolean logic of the Content Aware Protection policy -contains at least one “AND” operator. A policy will be satisfied when the Boolean logic (see the -following example) is met with one or more matches per identifier. +contains at least one “AND” operator. A policy triggers when one or more matches per identifier +satisfy the Boolean logic (see the following example). Eg. ( E-mail AND SSN US) OR CC Visa diff --git a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md index dff0b40618..2bf669292f 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md @@ -9,7 +9,7 @@ sidebar_position: 13 --- :::note -This article covers on-premises EPP Servers already running the current image-based platform — any version from **2509 through 2604**. If your server is still on a legacy 5.x release (5.7.0.0–5.9.4.2), see [Migrating from a Legacy 5.x Server to 2608](/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x) instead. For an overview of how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). +This article covers on-premises Endpoint Protector (EPP) Servers already running the current image-based platform — any version from **2509 through 2604**. If your server is still on a legacy 5.x release (5.7.0.0–5.9.4.2), see [Migrating from a Legacy 5.x Server to 2608](/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x) instead. For an overview of how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). ::: ## Overview @@ -98,7 +98,7 @@ Plan a maintenance window that accounts for the following: These times reflect laboratory test results and may vary in your environment depending on several factors, including hardware assigned to the appliance. **During the upgrade window, you won't have:** -- EPP/EE client communication with the server +- EPP and Enforced Encryption (EE) client communication with the server - Email alerts and SIEM integrations - File Shadow and log generation @@ -214,7 +214,7 @@ Always use the **same IP/FQDN** option. The operational complexity and user impa | High server load | Certificate regeneration for all endpoints creates a burst load spike | :::warning -If using Enforced Encryption and you change the IP/FQDN, every user with an EE-protected drive must decrypt their drive and re-encrypt it after reconnecting to the new server. This can be a major operational disruption in large organizations. Netwrix strongly discourages this. +If you use Enforced Encryption and change the IP/FQDN, every user with an EE-protected drive must decrypt their drive and re-encrypt it after reconnecting to the new server. This can be a major operational disruption in large organizations. Netwrix strongly discourages this. ::: :::warning diff --git a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md index aa3e393127..2cae33f256 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md @@ -9,7 +9,7 @@ sidebar_position: 12 --- :::note -This article covers on-premises EPP Servers running any version from **5.7.0.0 through 5.9.4.2** (5700, 5710, 5800, 5810, 5820, 5900, 5910, 5920, 5930, 5940, 5941, 5942). If your server is already on the current image-based platform (2509–2604), see [Migrating from the Current Image Platform to 2608](/docs/endpointprotector/install/migrationprocedure/migration-current-image) instead. For an overview of how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). +This article covers on-premises Endpoint Protector (EPP) Servers running any version from **5.7.0.0 through 5.9.4.2** (5700, 5710, 5800, 5810, 5820, 5900, 5910, 5920, 5930, 5940, 5941, 5942). If your server is already on the current image-based platform (2509–2604), see [Migrating from the Current Image Platform to 2608](/docs/endpointprotector/install/migrationprocedure/migration-current-image) instead. For an overview of how this fits together, start at the [EPP Server Migration & Upgrade Guide](/docs/endpointprotector/install/migrationprocedure/migrationguide). ::: ## Overview @@ -114,7 +114,7 @@ Plan a maintenance window that accounts for the following: These times reflect laboratory test results and may vary in your environment depending on several factors, including hardware assigned to the appliance. **During the upgrade window, you won't have:** -- EPP/EE client communication with the server +- EPP and Enforced Encryption (EE) client communication with the server - Email alerts and SIEM integrations - File Shadow and log generation @@ -282,7 +282,7 @@ If your 5.9.4.2 backup export is larger than 200 MB, follow these steps: This doesn't change the EPP Server version — it remains 5.9.4.2. ::: -4. If the new export attempt still returns more than 200 MB after successfully importing the offline patch, contact Netwrix Support for assistance with the manual procedure. +4. If the new export attempt still returns more than 200 MB after you successfully import the offline patch, contact Netwrix Support for assistance with the manual procedure. --- @@ -322,7 +322,7 @@ Always use the **same IP/FQDN** option. The operational complexity and user impa | High server load | Certificate regeneration for all endpoints creates a burst load spike | :::warning -If using Enforced Encryption and you change the IP/FQDN, every user with an EE-protected drive must decrypt their drive and re-encrypt it after reconnecting to the new server. This can be a major operational disruption in large organizations. Netwrix strongly discourages this. +If you use Enforced Encryption and change the IP/FQDN, every user with an EE-protected drive must decrypt their drive and re-encrypt it after reconnecting to the new server. This can be a major operational disruption in large organizations. Netwrix strongly discourages this. ::: :::warning @@ -380,7 +380,7 @@ For air-gapped environments, follow the same procedure using the 2608 cumulative ::: 3. After each patch, refresh the browser and verify the version in **Appliance → Server Information** before applying the next. -4. Once fully patched, confirm the server is stable and all services are running before proceeding to the backup restore. +4. Once the server is fully patched, confirm it's stable and all services are running before proceeding to the backup restore. ### Restoring the 5.9.4.2 Backup onto 2608 From d70f04d01b5dd7ad4d1d69b83b3a9f0cc5f30e90 Mon Sep 17 00:00:00 2001 From: Mihai Rosca Date: Fri, 11 Sep 2026 14:46:43 +0300 Subject: [PATCH 6/9] Fix incorrect claim that Enable Log Rotate After can be set to 0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Flagged by Flaviu: the setting can't actually be set to 0. Confirmed in code (configure/actions.class.php) that the save handler requires 1-360; PHP's empty(0) check means 0 is silently rejected with no error shown, so there's no supported way to fully disable log rotation once Communication V2/CrateDB is active — 1 month is the minimum. Corrects the same false claim in three places: the Log Settings bullet and warning in systemsettings.md, and the identical Log Retention Verification step duplicated across both migration guides. Co-Authored-By: Claude Sonnet 5 --- .../admin/systemconfiguration/systemsettings.md | 9 +++++---- .../migrationprocedure/migration-current-image.md | 2 +- .../install/migrationprocedure/migration-legacy-5x.md | 2 +- 3 files changed, 7 insertions(+), 6 deletions(-) diff --git a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md index 57feef9d78..71d66f98ab 100644 --- a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md +++ b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md @@ -150,7 +150,9 @@ You can set a number of reported threats between 100 and 1000. The default is three months. Log rotation runs every five minutes and deletes Device Control, Content Aware Protection, and eDiscovery logs older than the retention period, together with their associated file shadows. For example, setting this option to 6 keeps six months of logs and removes anything - older. Set the value to 0 to disable log rotation. + older. Enter a value between 1 and 360 months. There's no option to turn log rotation off once + it's active — 1 month is the shortest retention period you can configure, and Endpoint Protector + rejects a value of 0. :::warning Endpoint Protector 2608 enables this setting by default. Earlier server versions kept these logs @@ -161,9 +163,8 @@ period at that point — export anything you need to keep before you upgrade. Re as soon as you migrate and configure it to match your organization's retention needs. If you must retain log data for compliance beyond the configured period, export it regularly through **Reports and Analysis** > **Export Logs** and store the exports separately — don't rely on -server-side log storage for long-term compliance evidence. Disabling log rotation means Endpoint -Protector never removes logs automatically, and the server continues to consume storage until you -intervene. +server-side log storage for long-term compliance evidence, since you can't disable log rotation +to keep data on the server indefinitely. ::: diff --git a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md index 2bf669292f..1110d911ac 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md @@ -399,7 +399,7 @@ After migration, verify: 2. Check the value configured for **Enable Log Rotate After**. 3. Confirm the configured retention period matches your organization's operational and compliance needs. Adjust the value if three months doesn't match your retention policy. The value is in - months; set it to 0 to disable log rotation entirely. + months, from 1 to 360 — there's no option to disable log rotation entirely. For the full description of this setting, see [Log Settings](/docs/endpointprotector/admin/systemconfiguration/systemsettings#log-settings). diff --git a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md index 2cae33f256..b71ac995cd 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md @@ -536,7 +536,7 @@ After migration, verify: 2. Check the value configured for **Enable Log Rotate After**. 3. Confirm the configured retention period matches your organization's operational and compliance needs. Adjust the value if three months doesn't match your retention policy. The value is in - months; set it to 0 to disable log rotation entirely. + months, from 1 to 360 — there's no option to disable log rotation entirely. For the full description of this setting, see [Log Settings](/docs/endpointprotector/admin/systemconfiguration/systemsettings#log-settings). From 236647945d49e8b4d35e58228948e60532b56c98 Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Fri, 11 Sep 2026 11:54:34 +0000 Subject: [PATCH 7/9] fix(vale): auto-fix style issues (Vale + Dale) --- .../systemconfiguration/systemsettings.md | 44 +++++++++---------- .../migration-current-image.md | 10 ++--- .../migrationprocedure/migration-legacy-5x.md | 12 ++--- 3 files changed, 33 insertions(+), 33 deletions(-) diff --git a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md index 71d66f98ab..77ac35df6f 100644 --- a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md +++ b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md @@ -88,7 +88,7 @@ Smart Group sync job interval: the default configured time is 60 min. You can co Configure the client update settings to optimize update performance by specifying a custom hostname and port. -- Use custom hostname: Enter a custom hostname to tailor the client update URL as needed. +- Use custom hostname: Enter a custom hostname to tailor the client update URL. - Use custom port: Specify a custom port for generating the client update download link, instead of using the default port 443. @@ -288,20 +288,20 @@ Aware Protection policy. Generally, a Content Aware Protection policy (Block & Report) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in the policy, the scan engine will ignore the ‘Threat Threshold’ setting and continue the scan until -the total threat of 10 is reached, regardless of whether “Limit Reporting” (under DEVICE CONTROL - -Global Settings) is enabled. +it reaches a total of 10 threats, regardless of whether you enable “Limit Reporting” (under DEVICE +CONTROL - Global Settings). Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in -the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under -DEVICE CONTROL - Global Settings) is enabled, the scan continues until the total threat of 10 from -setting ‘Maximum number of reported threats’ under ‘Ignore Thresholds’ is reached. +the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you enable “Limit +Reporting” (under DEVICE CONTROL - Global Settings), the scan continues until it reaches the total +threat of 10 from the ‘Maximum number of reported threats’ setting under ‘Ignore Thresholds’. Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in -the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under -DEVICE CONTROL - Global Settings) is disabled, the scan engine will continue the scan until the -entire file is scanned, but will only report 10 threats, set with ‘Maximum number of reported +the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you disable “Limit +Reporting” (under DEVICE CONTROL - Global Settings), the scan engine will continue until it scans +the entire file, but will only report 10 threats, as set with ‘Maximum number of reported threats’ under ‘Ignore Thresholds’. **Example - Scenario 2** @@ -336,20 +336,20 @@ Protector Server Generally, a Content Aware Protection policy (Block & Report) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in the policy, the scan engine will ignore the ‘Threat Threshold’ setting and continue the scan until -the total threat of 4 from setting ‘Maximum number of reported threats’ is reached, regardless of -whether “Limit Reporting” (under DEVICE CONTROL - Global Settings) is enabled. +it reaches the total threat of 4 from the ‘Maximum number of reported threats’ setting, regardless +of whether you enable “Limit Reporting” (under DEVICE CONTROL - Global Settings). Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in -the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under -DEVICE CONTROL - Global Settings) is enabled, the scan continues until the total threat of 4 from -setting ‘Maximum number of reported threats’ under ‘Ignore Thresholds’ is reached. +the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you enable “Limit +Reporting” (under DEVICE CONTROL - Global Settings), the scan continues until it reaches the total +threat of 4 from the ‘Maximum number of reported threats’ setting under ‘Ignore Thresholds’. Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in -the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under -DEVICE CONTROL - Global Settings) is disabled, the scan engine will continue the scan until the -entire file is scanned, but will only report 4 threats, set with ‘Maximum number of reported threats’ +the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you disable “Limit +Reporting” (under DEVICE CONTROL - Global Settings), the scan engine will continue until it scans +the entire file, but will only report 4 threats, as set with ‘Maximum number of reported threats’ under ‘Ignore Thresholds’. **Example - Scenario 3** @@ -383,14 +383,14 @@ Endpoint Protector Client may report the single threats to Endpoint Protector Se Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied, meaning that all identifiers reach a ‘Threat Threshold’ of at least 1. The scan engine will ignore the ‘Maximum number of reported threats’ under ‘Ignore Thresholds’, when -“Limit Reporting” (under DEVICE CONTROL - Global Settings) is enabled. Reporting stops as soon as +you enable “Limit Reporting” (under DEVICE CONTROL - Global Settings). Reporting stops as soon as the policy is satisfied. Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied, meaning that all identifiers reach a ‘Threat Threshold’ of at least 1. The scan engine will consider the ‘Maximum number of reported threats’ under ‘Ignore Thresholds’, when -“Limit Reporting” (under DEVICE CONTROL - Global Settings) is disabled. Reporting stops when 10 -threats are found. +you disable “Limit Reporting” (under DEVICE CONTROL - Global Settings). Reporting stops when the +scan finds 10 threats. **Example - Scenario 4** @@ -424,8 +424,8 @@ Protector Client may report different 10 threats to Endpoint Protector Server Generally, a Content Aware Protection policy (Block & Report) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and no ‘AND’ operators in the -policy, the scan engine will search until the total threat of 10 from setting ‘Maximum number of -reported threats’ under ‘Ignore Thresholds’ is reached. +policy, the scan engine will search until it reaches the total threat of 10 from the ‘Maximum number +of reported threats’ setting under ‘Ignore Thresholds’. ## Virtual Desktop Clones diff --git a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md index 1110d911ac..1c81701110 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md @@ -23,7 +23,7 @@ Since you're already on the image-based platform, migrating to 2608 doesn't requ | 2509, 2510, 2601, 2602, or 2604 | Migrate directly to 2608 — you don't need an intermediate version | :::tip -2608 accepts a direct backup restore from any of 2509, 2510, 2601, 2602, or 2604. It's still good practice to upgrade to 2604 before migrating, since the 2604 → 2608 path is the most thoroughly validated in Netwrix labs. +2608 accepts a direct backup restore from any of 2509, 2510, 2601, 2602, or 2604. It's still good practice to upgrade to 2604 before migrating, since Netwrix labs validate the 2604 → 2608 path most thoroughly. ::: --- @@ -46,7 +46,7 @@ If your current license includes the `php_els` field (used on the 2509–2604 im - Proxmox VE — not officially supported; see the following note :::note -**Proxmox VE** isn't an officially supported hypervisor for Endpoint Protector. Based on customer feedback, Proxmox VE can host the EPP Server image after manually adjusting networking and IP configuration post-deployment. Converting the provided OVF image for use on Proxmox, along with any such adjustments, is entirely the customer's responsibility and falls outside Netwrix support. +**Proxmox VE** isn't an officially supported hypervisor for Endpoint Protector. Based on customer feedback, Proxmox VE can host the EPP Server image after you manually adjust networking and IP configuration post-deployment. Converting the provided OVF image for use on Proxmox, along with any such adjustments, is entirely the customer's responsibility and falls outside Netwrix support. ::: :::warning @@ -82,7 +82,7 @@ The 2608 image adds CrateDB, which may raise the minimum disk, RAM, and CPU base ::: :::tip -If disk space is below 30%, perform database shrinking via **System Maintenance → Audit Log Backups** before proceeding. Exporting old logs to an external SIEM or repository reduces DB size significantly. If not possible, consider expanding the associated disk space. To export logs, see [Audit Log Backup](/docs/endpointprotector/admin/systemmaintenance/overview#audit-log-backup). +If disk space is below 30%, shrink the database via **System Maintenance → Audit Log Backups** before proceeding. Exporting old logs to an external SIEM or repository reduces DB size significantly. If not possible, consider expanding the associated disk space. To export logs, see [Audit Log Backup](/docs/endpointprotector/admin/systemmaintenance/overview#audit-log-backup). ::: ### Maintenance Window Planning @@ -347,7 +347,7 @@ Generate deliberate test events on a known test machine for each active module. ### eDiscovery Scan Locations Verification :::warning -If you restore an eDiscovery policy with configured **Scan Locations** from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead — with no error reported anywhere. This is a known post-migration issue for any environment using the eDiscovery module. +If you restore an eDiscovery policy with configured **Scan Locations** from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead, without reporting an error anywhere. This is a known post-migration issue for any environment using the eDiscovery module. ::: If you use eDiscovery with Scan Locations configured on any policy, this check is mandatory after restore: @@ -359,7 +359,7 @@ If you use eDiscovery with Scan Locations configured on any policy, this check i ### CAP Policy Verification :::note -In rare cases, a Content Aware Protection (CAP) policy restored from a System Configuration Backup doesn't redistribute correctly and stops triggering, with no error reported. +In rare cases, a Content Aware Protection (CAP) policy restored from a System Configuration Backup doesn't redistribute correctly and stops triggering, without reporting an error. ::: If you use Content Aware Protection, this check is recommended after restore: diff --git a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md index b71ac995cd..52f6ba6ff7 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md @@ -55,7 +55,7 @@ If you're unsure whether your license is current, contact Netwrix Support or you - Proxmox VE — not officially supported; see the following note :::note -**Proxmox VE** isn't an officially supported hypervisor for Endpoint Protector. Based on customer feedback, Proxmox VE can host the EPP Server image after manually adjusting networking and IP configuration post-deployment. Converting the provided OVF image for use on Proxmox, along with any such adjustments, is entirely the customer's responsibility and falls outside Netwrix support. +**Proxmox VE** isn't an officially supported hypervisor for Endpoint Protector. Based on customer feedback, Proxmox VE can host the EPP Server image after you manually adjust networking and IP configuration post-deployment. Converting the provided OVF image for use on Proxmox, along with any such adjustments, is entirely the customer's responsibility and falls outside Netwrix support. ::: :::warning @@ -97,7 +97,7 @@ The 2608 image adds CrateDB, which may raise the minimum disk, RAM, and CPU base ::: :::tip -If disk space is below 30%, perform database shrinking via **System Maintenance → Audit Log Backups** before proceeding. Exporting old logs to an external SIEM or repository reduces DB size significantly. If not possible, consider expanding the associated disk space. To export logs, see [Audit Log Backup](/docs/endpointprotector/admin/systemmaintenance/overview#audit-log-backup). +If disk space is below 30%, shrink the database via **System Maintenance → Audit Log Backups** before proceeding. Exporting old logs to an external SIEM or repository reduces DB size significantly. If not possible, consider expanding the associated disk space. To export logs, see [Audit Log Backup](/docs/endpointprotector/admin/systemmaintenance/overview#audit-log-backup). ::: ### Maintenance Window Planning @@ -380,7 +380,7 @@ For air-gapped environments, follow the same procedure using the 2608 cumulative ::: 3. After each patch, refresh the browser and verify the version in **Appliance → Server Information** before applying the next. -4. Once the server is fully patched, confirm it's stable and all services are running before proceeding to the backup restore. +4. After you fully patch the server, confirm it's stable and all services are running before proceeding to the backup restore. ### Restoring the 5.9.4.2 Backup onto 2608 @@ -484,7 +484,7 @@ Generate deliberate test events on a known test machine for each active module. ### eDiscovery Scan Locations Verification :::warning -If you restore an eDiscovery policy with configured **Scan Locations** from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead — with no error reported anywhere. This is a known post-migration issue for any environment using the eDiscovery module. +If you restore an eDiscovery policy with configured **Scan Locations** from a System Configuration Backup, EPP ignores the Scan Locations and runs a full disk scan instead, without reporting an error anywhere. This is a known post-migration issue for any environment using the eDiscovery module. ::: If you use eDiscovery with Scan Locations configured on any policy, this check is mandatory after restore: @@ -496,7 +496,7 @@ If you use eDiscovery with Scan Locations configured on any policy, this check i ### CAP Policy Verification :::note -In rare cases, a Content Aware Protection (CAP) policy restored from a System Configuration Backup doesn't redistribute correctly and stops triggering, with no error reported. +In rare cases, a Content Aware Protection (CAP) policy restored from a System Configuration Backup doesn't redistribute correctly and stops triggering, without reporting an error. ::: If you use Content Aware Protection, this check is recommended after restore: @@ -604,7 +604,7 @@ AD Sync may appear to complete successfully but only import a partial set of use 2. Re-enter tenant ID, client ID, and client secret — the backup doesn't restore these. 3. Verify the redirect URI registered in Azure AD matches the new server address. If the new server uses an IP address instead of an FQDN, either manually recreate the SSO configuration with the updated response/callback URL, or raise a Netwrix Support case to have it updated on the backend. 4. Perform a test SSO login in an incognito window. -5. If SCIM provisioning is broken, re-generate the SCIM token in the EPP console and update it in Entra ID. +5. If SCIM provisioning fails, re-generate the SCIM token in the EPP console and update it in Entra ID. **SIEM / Syslog events not forwarding:** 1. Reconfigure the SIEM destination IP, port, and protocol. From d32371b27c5882fa864ba1578bbf4325fe699f84 Mon Sep 17 00:00:00 2001 From: thobed <10742470+thobed@users.noreply.github.com> Date: Fri, 11 Sep 2026 09:47:45 -0400 Subject: [PATCH 8/9] Document RHEL and CentOS installer prep steps Add a RHEL and CentOS Preparation section covering the kernel-modules-extra package RHEL 10 needs, firewalld rules (or disabling it), and the NetworkManager/nm-cloud-setup bug on RHEL/CentOS releases before 8.4. Sourced from https://docs.k3s.io/installation/requirements#operating-systems, scoped to what applies to Access Analyzer's single-node install. Update requirements.md's OS row to mention RHEL/RPM-based support and link to the new section, since it previously implied only Debian-based distributions were supported. --- .../26.1/install/installer-reference.md | 42 +++++++++++++++++++ .../26.1/install/requirements.md | 2 +- 2 files changed, 43 insertions(+), 1 deletion(-) diff --git a/docs/accessanalyzer/26.1/install/installer-reference.md b/docs/accessanalyzer/26.1/install/installer-reference.md index b023e7acf7..7a7ce60a53 100644 --- a/docs/accessanalyzer/26.1/install/installer-reference.md +++ b/docs/accessanalyzer/26.1/install/installer-reference.md @@ -146,6 +146,48 @@ When the `antivirus` check finds a product, add these paths to that product's ex The [Requirements](requirements.md) page lists the 18 hosts the `network` check connects to and the CPU, RAM, and disk figures for each size. +## RHEL and CentOS Preparation + +Complete these steps on a Red Hat Enterprise Linux (RHEL) or CentOS server before you run the installer. + +### RHEL 10 + +RHEL 10 splits a kernel module the platform needs into a separate package. Install it first: + +```bash +sudo dnf install -y kernel-modules-extra +``` + +Without it, the `kernel-modules` preflight check can't load `br_netfilter` or `overlay`. + +### Firewalld + +Turn off `firewalld`: + +```bash +systemctl disable firewalld --now +``` + +To keep it enabled instead, add these rules before you install: + +```bash +firewall-cmd --permanent --add-port=6443/tcp +firewall-cmd --permanent --zone=trusted --add-source=10.42.0.0/16 +firewall-cmd --permanent --zone=trusted --add-source=10.43.0.0/16 +firewall-cmd --reload +``` + +These open the platform's internal API port and trust its pod and service networks. Also open the ports that [Requirements](requirements.md#inbound) lists for Access Analyzer itself. + +### Older RHEL and CentOS Releases + +RHEL and CentOS releases before 8.4 ship a version of NetworkManager with a bug that interferes with the platform's networking. Disable `nm-cloud-setup` and reboot before you install: + +```bash +systemctl disable nm-cloud-setup.service nm-cloud-setup.timer +reboot +``` + ## The `wait-for-apps` Command `wait-for-apps` repeats the readiness wait without reinstalling anything. Use it when an install stopped while waiting for the services, or to check whether they're all ready. diff --git a/docs/accessanalyzer/26.1/install/requirements.md b/docs/accessanalyzer/26.1/install/requirements.md index 711d0b6b1b..1ce1f4803f 100644 --- a/docs/accessanalyzer/26.1/install/requirements.md +++ b/docs/accessanalyzer/26.1/install/requirements.md @@ -12,7 +12,7 @@ Access Analyzer installs on a single physical or virtual Linux server. | Requirement | Details | |---|---| -| Operating system | Ubuntu. Any Debian-based distribution should work. The installer doesn't check the release version. | +| Operating system | Ubuntu or Red Hat Enterprise Linux (RHEL). Any Debian-based or RPM-based distribution should work. The installer doesn't check the release version. RHEL and CentOS need some [additional preparation](installer-reference.md#rhel-and-centos-preparation). | | Architecture | 64-bit x86 or Arm. | | Access | Root, either directly or through `sudo`. | | Free disk on `/var/lib` | See [size](#size) for storage requirements. Access Analyzer stores its data under `/var/lib`. | From 0fe69ebede9ae11fa1ce2d16b2ba0228cc3a443a Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Fri, 11 Sep 2026 13:51:51 +0000 Subject: [PATCH 9/9] fix(vale): auto-fix style issues (Vale + Dale) --- docs/accessanalyzer/26.1/install/installer-reference.md | 2 +- docs/accessanalyzer/26.1/install/requirements.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/accessanalyzer/26.1/install/installer-reference.md b/docs/accessanalyzer/26.1/install/installer-reference.md index 7a7ce60a53..4e2573fece 100644 --- a/docs/accessanalyzer/26.1/install/installer-reference.md +++ b/docs/accessanalyzer/26.1/install/installer-reference.md @@ -35,7 +35,7 @@ Two environment variable names need care: `--hostname` reads `DSPM_HOSTNAME`, no | `--accept-warnings` | `ACCEPT_WARNINGS` | `false` | Continue past preflight warnings without asking. | | `--assume-yes` | `DSPM_ASSUME_YES` | `false` | Skip the review screen that appears when the configuration file already supplies every required value. | | `--dry-run` | `DRY_RUN` | `false` | Print the planned actions and exit without installing. Needs no TLS files and writes no configuration file. | -| `--log-level` | `LOG_LEVEL` | `info` | Detail written to the log file: `debug`, `info`, `warn`, or `error`. | +| `--log-level` | `LOG_LEVEL` | `info` | Detail the installer writes to the log file: `debug`, `info`, `warn`, or `error`. | | `--log-path` | `LOG_PATH` | `/var/log/dspm-installer.log` | Path to the installer's log file. If you set this explicitly (flag, environment variable, or configuration file) and the path isn't writable or is a symlink, the installer stops with an error instead of falling back to the terminal. | | `--postgres-data-dir` | `POSTGRES_DATA_DIR` | none | Custom directory for the application database's data. | | `--clickhouse-data-dir` | `CLICKHOUSE_DATA_DIR` | none | Custom directory for the analytics store's data. | diff --git a/docs/accessanalyzer/26.1/install/requirements.md b/docs/accessanalyzer/26.1/install/requirements.md index 1ce1f4803f..d9b5e7f9e2 100644 --- a/docs/accessanalyzer/26.1/install/requirements.md +++ b/docs/accessanalyzer/26.1/install/requirements.md @@ -63,7 +63,7 @@ The installer looks for the certificate at `/etc/dspm/tls.crt` and the key at `/ ## License Key -You need a Netwrix license key in the form `XXXX-XXXX-XXXX-XXXX-XXXX-V3`. The key authenticates the installer download, and the installer validates it online during the install, so the server must reach the licensing endpoints listed under [Outbound](#outbound). An expired, suspended, or unknown key stops the install. +You need a Netwrix license key in the form `XXXX-XXXX-XXXX-XXXX-XXXX-V3`. The key authenticates the installer download, and the installer validates it online during the install, so the server must reach the licensing endpoints that [Outbound](#outbound) lists. An expired, suspended, or unknown key stops the install. ## First Administrator