Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
44 changes: 43 additions & 1 deletion docs/accessanalyzer/26.1/install/installer-reference.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ Two environment variable names need care: `--hostname` reads `DSPM_HOSTNAME`, no
| `--accept-warnings` | `ACCEPT_WARNINGS` | `false` | Continue past preflight warnings without asking. |
| `--assume-yes` | `DSPM_ASSUME_YES` | `false` | Skip the review screen that appears when the configuration file already supplies every required value. |
| `--dry-run` | `DRY_RUN` | `false` | Print the planned actions and exit without installing. Needs no TLS files and writes no configuration file. |
| `--log-level` | `LOG_LEVEL` | `info` | Detail written to the log file: `debug`, `info`, `warn`, or `error`. |
| `--log-level` | `LOG_LEVEL` | `info` | Detail the installer writes to the log file: `debug`, `info`, `warn`, or `error`. |
| `--log-path` | `LOG_PATH` | `/var/log/dspm-installer.log` | Path to the installer's log file. If you set this explicitly (flag, environment variable, or configuration file) and the path isn't writable or is a symlink, the installer stops with an error instead of falling back to the terminal. |
| `--postgres-data-dir` | `POSTGRES_DATA_DIR` | none | Custom directory for the application database's data. |
| `--clickhouse-data-dir` | `CLICKHOUSE_DATA_DIR` | none | Custom directory for the analytics store's data. |
Expand Down Expand Up @@ -146,6 +146,48 @@ When the `antivirus` check finds a product, add these paths to that product's ex

The [Requirements](requirements.md) page lists the 18 hosts the `network` check connects to and the CPU, RAM, and disk figures for each size.

## RHEL and CentOS Preparation

Complete these steps on a Red Hat Enterprise Linux (RHEL) or CentOS server before you run the installer.

### RHEL 10

RHEL 10 splits a kernel module the platform needs into a separate package. Install it first:

```bash
sudo dnf install -y kernel-modules-extra
```

Without it, the `kernel-modules` preflight check can't load `br_netfilter` or `overlay`.

### Firewalld

Turn off `firewalld`:

```bash
systemctl disable firewalld --now
```

To keep it enabled instead, add these rules before you install:

```bash
firewall-cmd --permanent --add-port=6443/tcp
firewall-cmd --permanent --zone=trusted --add-source=10.42.0.0/16
firewall-cmd --permanent --zone=trusted --add-source=10.43.0.0/16
firewall-cmd --reload
```

These open the platform's internal API port and trust its pod and service networks. Also open the ports that [Requirements](requirements.md#inbound) lists for Access Analyzer itself.

### Older RHEL and CentOS Releases

RHEL and CentOS releases before 8.4 ship a version of NetworkManager with a bug that interferes with the platform's networking. Disable `nm-cloud-setup` and reboot before you install:

```bash
systemctl disable nm-cloud-setup.service nm-cloud-setup.timer
reboot
```

## The `wait-for-apps` Command

`wait-for-apps` repeats the readiness wait without reinstalling anything. Use it when an install stopped while waiting for the services, or to check whether they're all ready.
Expand Down
4 changes: 2 additions & 2 deletions docs/accessanalyzer/26.1/install/requirements.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ Access Analyzer installs on a single physical or virtual Linux server.

| Requirement | Details |
|---|---|
| Operating system | Ubuntu. Any Debian-based distribution should work. The installer doesn't check the release version. |
| Operating system | Ubuntu or Red Hat Enterprise Linux (RHEL). Any Debian-based or RPM-based distribution should work. The installer doesn't check the release version. RHEL and CentOS need some [additional preparation](installer-reference.md#rhel-and-centos-preparation). |
| Architecture | 64-bit x86 or Arm. |
| Access | Root, either directly or through `sudo`. |
| Free disk on `/var/lib` | See [size](#size) for storage requirements. Access Analyzer stores its data under `/var/lib`. |
Expand Down Expand Up @@ -63,7 +63,7 @@ The installer looks for the certificate at `/etc/dspm/tls.crt` and the key at `/

## License Key

You need a Netwrix license key in the form `XXXX-XXXX-XXXX-XXXX-XXXX-V3`. The key authenticates the installer download, and the installer validates it online during the install, so the server must reach the licensing endpoints listed under [Outbound](#outbound). An expired, suspended, or unknown key stops the install.
You need a Netwrix license key in the form `XXXX-XXXX-XXXX-XXXX-XXXX-V3`. The key authenticates the installer download, and the installer validates it online during the install, so the server must reach the licensing endpoints that [Outbound](#outbound) lists. An expired, suspended, or unknown key stops the install.

## First Administrator

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -62,19 +62,19 @@ pattern.
- Enable Smart Groups – when you disable this setting, Endpoint Protector converts Smart Groups to
regular groups with no entities assigned and removes the Default Group for Computers and the
Default Group for Users.
- Enable Default Group for Computers – this will create a default group for computers containing all
- Enable Default Group for Computers – creates a default group for computers containing all
computers that aren't part of a Smart Group.

:::note
By disabling this setting, you will delete the Default Group for Computers.
Disabling this setting deletes the Default Group for Computers.
:::


- Enable Default Group for Users – this will create a default group for users containing all users
- Enable Default Group for Users – creates a default group for users containing all users
that aren't part of a Smart Group.

:::note
By disabling this setting, you will delete the Default Group for Users.
Disabling this setting deletes the Default Group for Users.
:::

:::note
Expand All @@ -88,7 +88,7 @@ Smart Group sync job interval: the default configured time is 60 min. You can co
Configure the client update settings to optimize update performance by specifying a custom hostname
and port.

- Use custom hostname: Enter a custom hostname to tailor the client update URL as needed.
- Use custom hostname: Enter a custom hostname to tailor the client update URL.
- Use custom port: Specify a custom port for generating the client update download link, instead of
using the default port 443.

Expand Down Expand Up @@ -119,8 +119,8 @@ Manage the following log settings:
- Set the Maximum number of rows in millions to export the Logs Report in .csv format.

:::note
By setting the maximum number of rows to 1.0, you will export 1 million logs in the Logs
Report .csv export as one row corresponds with one log.
Setting the maximum number of rows to 1.0 exports 1 million logs in the Logs
Report .csv export, since one row corresponds with one log.
:::


Expand All @@ -131,8 +131,8 @@ export.
structure and display information in Destination details, Email sender, and Email subject columns.

:::note
For Endpoint Protector Server versions older than 5.7.0.0, the Reporting V2 setting isn't
enabled by default.
For Endpoint Protector Server versions older than 5.7.0.0, Endpoint Protector doesn't enable
the Reporting V2 setting by default.
:::


Expand All @@ -150,11 +150,21 @@ You can set a number of reported threats between 100 and 1000.
The default is three months. Log rotation runs every five minutes and deletes Device Control, Content Aware
Protection, and eDiscovery logs older than the retention period, together with their associated
file shadows. For example, setting this option to 6 keeps six months of logs and removes anything
older. Set the value to 0 to disable log rotation.
older. Enter a value between 1 and 360 months. There's no option to turn log rotation off once
it's active — 1 month is the shortest retention period you can configure, and Endpoint Protector
rejects a value of 0.

:::warning
Disabling log rotation means Endpoint Protector never removes logs automatically, and the server
continues to consume storage until you intervene.
Endpoint Protector 2608 enables this setting by default. Earlier server versions kept these logs
indefinitely unless an administrator removed them manually or through Audit Log Backup, which can
delete logs from the server as it archives them. The first rotation cycle runs within five minutes
of the server starting, so Endpoint Protector deletes any logs already older than the configured
period at that point — export anything you need to keep before you upgrade. Review this value
as soon as you migrate and configure it to match your organization's retention needs. If you must
retain log data for compliance beyond the configured period, export it regularly through
**Reports and Analysis** > **Export Logs** and store the exports separately — don't rely on
server-side log storage for long-term compliance evidence, since you can't disable log rotation
to keep data on the server indefinitely.
:::


Expand Down Expand Up @@ -222,21 +232,21 @@ Endpoint Protector automatically modifies the maximum number of reported threat

Limit Reporting Content Aware Protection refers to Report Only policies.

- If enabled, the Endpoint Protector client will stop reporting threats for a Report Only policy
after it finds enough threats to conclude it is satisfied.
- When you enable this setting, the Endpoint Protector client stops reporting threats for a Report
Only policy after it finds enough threats to satisfy the policy.

The "Content Aware Protection - Ignore Thresholds" toggle refers to Block & Report policies.

- When this toggle is On, scanning doesn't stop at a block verdict, but continues to report further
- When this toggle is On, scanning continues past a block verdict and reports further
threats found in a transfer.
- To limit the number of reported threats in this case, set the "Maximum number of reported threats"
setting to a value greater than zero. The value you set is only indicative for the number of
reported threats, the actual number reported can be slightly larger.
setting to a value greater than zero. The value you set only indicates the number of
reported threats; the actual number reported can be slightly larger.

The ‘Ignore Thresholds’ setting ignores and overrides the ‘Global/Threat Threshold’ values in
Content Aware Protection policies when the Boolean logic of the Content Aware Protection policy
contains at least one “AND” operator. A policy will be satisfied when the Boolean logic (see the
following example) is met with one or more matches per identifier.
contains at least one “AND” operator. A policy triggers when one or more matches per identifier
satisfy the Boolean logic (see the following example).

Eg. ( E-mail AND SSN US) OR CC Visa

Expand Down Expand Up @@ -278,20 +288,20 @@ Aware Protection policy.
Generally, a Content Aware Protection policy (Block & Report) will trigger when the Boolean logic of
the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in
the policy, the scan engine will ignore the ‘Threat Threshold’ setting and continue the scan until
the total threat of 10 is reached, regardless of whether “Limit Reporting” (under DEVICE CONTROL -
Global Settings) is enabled.
it reaches a total of 10 threats, regardless of whether you enable “Limit Reporting” (under DEVICE
CONTROL - Global Settings).

Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of
the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in
the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under
DEVICE CONTROL - Global Settings) is enabled, the scan continues until the total threat of 10 from
setting ‘Maximum number of reported threats’ under ‘Ignore Thresholds’ is reached.
the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you enable “Limit
Reporting” (under DEVICE CONTROL - Global Settings), the scan continues until it reaches the total
threat of 10 from the ‘Maximum number of reported threats’ setting under ‘Ignore Thresholds’.

Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of
the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in
the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under
DEVICE CONTROL - Global Settings) is disabled, the scan engine will continue the scan until the
entire file is scanned, but will only report 10 threats, set with ‘Maximum number of reported
the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you disable “Limit
Reporting” (under DEVICE CONTROL - Global Settings), the scan engine will continue until it scans
the entire file, but will only report 10 threats, as set with ‘Maximum number of reported
threats’ under ‘Ignore Thresholds’.

**Example - Scenario 2**
Expand Down Expand Up @@ -326,20 +336,20 @@ Protector Server
Generally, a Content Aware Protection policy (Block & Report) will trigger when the Boolean logic of
the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in
the policy, the scan engine will ignore the ‘Threat Threshold’ setting and continue the scan until
the total threat of 4 from setting ‘Maximum number of reported threats’ is reached, regardless of
whether “Limit Reporting” (under DEVICE CONTROL - Global Settings) is enabled.
it reaches the total threat of 4 from the ‘Maximum number of reported threats’ setting, regardless
of whether you enable “Limit Reporting” (under DEVICE CONTROL - Global Settings).

Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of
the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in
the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under
DEVICE CONTROL - Global Settings) is enabled, the scan continues until the total threat of 4 from
setting ‘Maximum number of reported threats’ under ‘Ignore Thresholds’ is reached.
the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you enable “Limit
Reporting” (under DEVICE CONTROL - Global Settings), the scan continues until it reaches the total
threat of 4 from the ‘Maximum number of reported threats’ setting under ‘Ignore Thresholds’.

Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of
the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in
the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If “Limit Reporting” (under
DEVICE CONTROL - Global Settings) is disabled, the scan engine will continue the scan until the
entire file is scanned, but will only report 4 threats, set with ‘Maximum number of reported threats’
the policy, the scan engine will ignore the ‘Threat Threshold’ setting. If you disable “Limit
Reporting” (under DEVICE CONTROL - Global Settings), the scan engine will continue until it scans
the entire file, but will only report 4 threats, as set with ‘Maximum number of reported threats’
under ‘Ignore Thresholds’.

**Example - Scenario 3**
Expand Down Expand Up @@ -373,14 +383,14 @@ Endpoint Protector Client may report the single threats to Endpoint Protector Se
Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of
the policy is satisfied, meaning that all identifiers reach a ‘Threat Threshold’ of at least 1. The
scan engine will ignore the ‘Maximum number of reported threats’ under ‘Ignore Thresholds’, when
“Limit Reporting” (under DEVICE CONTROL - Global Settings) is enabled. Reporting stops as soon as
you enable “Limit Reporting” (under DEVICE CONTROL - Global Settings). Reporting stops as soon as
the policy is satisfied.

Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of
the policy is satisfied, meaning that all identifiers reach a ‘Threat Threshold’ of at least 1. The
scan engine will consider the ‘Maximum number of reported threats’ under ‘Ignore Thresholds’, when
“Limit Reporting” (under DEVICE CONTROL - Global Settings) is disabled. Reporting stops when 10
threats are found.
you disable “Limit Reporting” (under DEVICE CONTROL - Global Settings). Reporting stops when the
scan finds 10 threats.

**Example - Scenario 4**

Expand Down Expand Up @@ -414,8 +424,8 @@ Protector Client may report different 10 threats to Endpoint Protector Server

Generally, a Content Aware Protection policy (Block & Report) will trigger when the Boolean logic of
the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and no ‘AND’ operators in the
policy, the scan engine will search until the total threat of 10 from setting ‘Maximum number of
reported threats’ under ‘Ignore Thresholds’ is reached.
policy, the scan engine will search until it reaches the total threat of 10 from the ‘Maximum number
of reported threats’ setting under ‘Ignore Thresholds’.

## Virtual Desktop Clones

Expand Down Expand Up @@ -486,7 +496,7 @@ Enable the **Active Directory Authentication** setting to import an Active Direc
administrators into Endpoint Protector as Super Administrators.

:::note
By enabling the Active Directory Authentication, you allow the administrators to use their
Enabling Active Directory Authentication lets administrators use their
Active Directory credentials to log into Endpoint Protector.
:::

Expand Down
Loading