diff --git a/docs/accessanalyzer/26.1/install/requirements.md b/docs/accessanalyzer/26.1/install/requirements.md index 7b5413a2e9..38d418333d 100644 --- a/docs/accessanalyzer/26.1/install/requirements.md +++ b/docs/accessanalyzer/26.1/install/requirements.md @@ -4,11 +4,11 @@ description: Server sizing, hostname, network ports, TLS certificate, license ke sidebar_position: 1 --- -Gather everything on this page before you run the installer. The installer runs a preflight check on the server first and stops if the server doesn't meet the hard requirements, so a few minutes here saves a failed installation later. +Gather everything on this page before you run the installer. The installer runs a preflight check first and stops if the server doesn't meet the hard requirements, so a few minutes here saves a failed installation later. ## Server -Access Analyzer installs on a single Linux server, physical or virtual. +Access Analyzer installs on a single physical or virtual Linux server. | Requirement | Details | |---|---| @@ -30,7 +30,7 @@ You pick a size when you install. The size sets the CPU and RAM the installer re | large | 24 | 96 GB | 3,000 GB | Up to about 800 million objects and 25,000 to 100,000 identities. | | enterprise | 32 | 128 GB | 8,000 GB | Up to about 3 billion objects and more than 100,000 identities. | -CPU cores and RAM are hard minimums: the installer's preflight check fails below them, and the install doesn't proceed. The check allows a 5% tolerance on RAM and disk, so a virtual machine provisioned at exactly the stated figure passes even though the guest sees slightly less. +CPU cores and RAM are hard minimums: the installer's preflight check fails below them, and the install doesn't proceed. The check allows a 5% tolerance on RAM and disk, so a virtual machine you provision at exactly the stated figure passes even though the guest sees slightly less. Disk is a recommendation. A server with less free space than the size recommends still installs and runs, but the preflight check warns that the disk is too small for the data that size is designed to hold. The 40 GB floor is different: below that, the preflight check fails. @@ -81,10 +81,11 @@ Open these ports on the server's firewall. | 80 | TCP | Users' browsers | Redirects HTTP requests to HTTPS. | | 4504 | TCP | Netwrix Activity Monitor | Receives activity data. Open it only if you use [Netwrix Activity Monitor](../integrations/netwrix-activity-monitor.md). | | 6443 | TCP | Agent hosts | Lets [agents](../agents/index.md) connect back to the server. Open it only to the hosts you deploy agents on. | +| 9000, 8123 | TCP | External query tools | Direct access to the analytics store. Open them only if you [open the analytics store's ports](../integrations/external-clickhouse-access.md). | ### Outbound -The installer downloads everything it needs during the install, and the running product keeps a small number of outbound connections afterwards. Allow TCP 443 from the server to each of these hosts. The preflight check tests every one of them: it fails if a name doesn't resolve in DNS and warns if a connection times out or is refused. +The installer downloads everything it needs during the install, and the running product keeps a few outbound connections afterwards. Allow TCP 443 from the server to each of these hosts. The preflight check tests every one of them: it fails if a name doesn't resolve in DNS and warns if a connection times out or the host refuses it. | Host | Purpose | |---|---| diff --git a/docs/accessanalyzer/26.1/integrations/external-clickhouse-access.md b/docs/accessanalyzer/26.1/integrations/external-clickhouse-access.md new file mode 100644 index 0000000000..012978e857 --- /dev/null +++ b/docs/accessanalyzer/26.1/integrations/external-clickhouse-access.md @@ -0,0 +1,144 @@ +--- +title: External analytics store access +description: Open the Access Analyzer analytics store (ClickHouse) ports so an external tool, such as a business intelligence (BI) platform, can query it directly. +sidebar_position: 2 +--- + +Access Analyzer keeps scan results in an analytics store, a ClickHouse database that backs the dashboards and reports. By default it accepts connections only from inside the Access Analyzer server. To query it from an external tool, such as a business intelligence (BI) platform, open its ports with the `dspmctl` command on the server. + +Opening access exposes two ports: + +| Port | Protocol | Purpose | +|---|---|---| +| 9000 | TCP | ClickHouse native protocol. | +| 8123 | TCP | ClickHouse HTTP interface. | + +Access Analyzer never exposes the metrics port. External queries run on the same analytics store that serves scan ingestion and the reports, so heavy external load competes with the product. + +:::warning +These ports are unencrypted. Credentials and query results cross the network in clear text. Restrict access to a trusted network, or put a TLS-terminating proxy in front of the ports. +::: + +## Prerequisites + +- **Server access.** Shell access to the Access Analyzer server with `sudo` rights. `dspmctl` needs `sudo`, the same as the installer. +- **Network path.** The external tool must reach the server on the ports you open. Open them inbound on the server's firewall and on anything between the two hosts. + +## Choose an access type + +Access Analyzer's bundled k3s cluster includes ServiceLB, its built-in load balancer. Use `LoadBalancer` with a list of allowed client address ranges in Classless Inter-Domain Routing (CIDR) notation. ServiceLB binds ports 9000 and 8123 on the server, so those ports must be free. + +`NodePort` has no access control in Access Analyzer, so restrict it with the server's firewall. Use it only if you disabled ServiceLB or ports 9000 and 8123 are already in use. + +A list of allowed address ranges works only with `LoadBalancer`. Setting it with `NodePort` fails. + +## Open the ports + +`dspmctl set-helm-param` turns automated sync off for the application. The last step turns it back on. + +1. On the Access Analyzer server, set the access parameters. For `LoadBalancer`, restricting access to one address range: + + ```bash + sudo dspmctl set-helm-param netwrix \ + config.clickhouse.externalAccess.enabled=true \ + config.clickhouse.externalAccess.type=LoadBalancer \ + 'config.clickhouse.externalAccess.loadBalancerSourceRanges[0]=' + ``` + + Add `[1]`, `[2]`, and so on for more ranges. For `NodePort`: + + ```bash + sudo dspmctl set-helm-param netwrix \ + config.clickhouse.externalAccess.enabled=true \ + config.clickhouse.externalAccess.type=NodePort \ + config.clickhouse.externalAccess.nodePorts.native=30900 \ + config.clickhouse.externalAccess.nodePorts.http=30823 + ``` + + Choose ports from 30000 through 32767, or omit the `nodePorts` lines to have Kubernetes assign them. + +2. Apply the change: + + ```bash + sudo dspmctl sync netwrix + ``` + +3. Turn automated sync back on: + + ```bash + sudo dspmctl enable-auto netwrix + ``` + +4. Open the chosen ports on the server's firewall. + +## Get the credentials + +Opening access creates a dedicated analytics store user, `access_analyzer_external`, with a generated password. The user has read-only access to the `access_analyzer` and `access_analyzer_sample` databases, with the same per-query memory limits as the user Access Analyzer's own reports use. It can run at most four queries at once, and its total memory across them is capped. Clients can't override these limits. + +Give external tools only this user. Don't share the analytics store's administrator credentials: the exposed port reaches the administrator like any other user, so its password is the only thing protecting it. + +1. On the Access Analyzer server, print the password: + + ```bash + sudo dspmctl get-secret clickhouse-external-secret password + ``` + + Omit `password` to print the username and password together. Print one key at a time when you capture the value in a variable, because the two-key form adds a carriage return. + +2. In the external tool, connect with the username `access_analyzer_external`, this password, and the `access_analyzer` database. + +## Verify access + +1. On the server, list the assigned ports and address: + + ```bash + kubectl get svc clickhouse-external -n access-analyzer + ``` + +2. From the external host, check the HTTP port. With `LoadBalancer` that is `8123`. With `NodePort`, use the assigned node port from the `PORT(S)` column: + + ```bash + curl http://:/ping + ``` + + A working connection returns `Ok.`. + +## Limitations + +- With `LoadBalancer`, Kubernetes still opens a port on every node. On a cluster with routable node addresses, a client can reach the database through that port and bypass the allowed address ranges. Close it by turning off node-port allocation: + + ```bash + sudo dspmctl set-helm-param netwrix config.clickhouse.externalAccess.allocateLoadBalancerNodePorts=false + ``` + +- Access Analyzer runs one analytics store. With `NodePort`, connections reach it through any node in the cluster. To change how the cluster routes traffic, set `config.clickhouse.externalAccess.externalTrafficPolicy` to `Cluster` or `Local`. + +## Rotate the password + +Access Analyzer creates the password once and resets the `access_analyzer_external` user's password from it on every sync. A password changed inside the analytics store is overwritten at the next sync, so rotate through the stored secret: + +```bash +kubectl delete secret clickhouse-external-secret -n access-analyzer +sudo dspmctl sync netwrix +sudo dspmctl enable-auto netwrix +``` + +The sync generates a new password. Print it with `dspmctl get-secret`. + +## Close access + +1. Turn the ports off. This also stops `dspmctl get-secret` from reading the password, but it doesn't delete the password or the `access_analyzer_external` user, and turning access on again reuses the old password: + + ```bash + sudo dspmctl set-helm-param netwrix config.clickhouse.externalAccess.enabled=false + sudo dspmctl sync netwrix + sudo dspmctl enable-auto netwrix + ``` + +2. Delete the stored password so the next time you turn access on it generates a new one: + + ```bash + kubectl delete secret clickhouse-external-secret -n access-analyzer + ``` + +3. Remove the firewall rules you added. diff --git a/docs/accessanalyzer/26.1/integrations/index.md b/docs/accessanalyzer/26.1/integrations/index.md index 1aa353969d..29c79b24c1 100644 --- a/docs/accessanalyzer/26.1/integrations/index.md +++ b/docs/accessanalyzer/26.1/integrations/index.md @@ -6,3 +6,5 @@ description: How Netwrix Activity Monitor connects to Access Analyzer and what i Access Analyzer integrates with [Netwrix Activity Monitor](netwrix-activity-monitor.md). Activity Monitor sends Access Analyzer the activity it records on file servers, SharePoint Online, and Microsoft 365 Copilot. You enroll an Activity Monitor agent with Access Analyzer using a short-lived enrollment token; after that the agent connects without it. The agent streams its events to the Access Analyzer server over TLS on port 4504. Scans tell you what data exists and who can reach it. Activity tells you who used that access, what they did, and when. With the integration in place, the **Activity** tab of the [Data security dashboard](../dashboards-reports/dashboards/data-security.md) breaks events down by type, data source, and user, and charts activity over time. The Activity Investigation report and the **Activity** tab of the Share Audit report in [Data reports](../dashboards-reports/reports/data.md) draw on the file server events from the same feed. All three stay empty until you enroll an agent and it starts sending data. + +You can also open the analytics store's ports so an external tool, such as a business intelligence (BI) platform, can query it directly. See [External analytics store access](external-clickhouse-access.md).