5.8 Configuring Windows Monitoring

On a Windows environment, Change Guardian monitors the following:

  • File integrity

  • File shares

  • File systems

  • Local users and groups

  • Processes

  • Registry

  • Removable media

NOTE:Change Guardian supports monitoring removable media events only on USB flash drives. To monitor external hard disk drive (HDD), create a file system monitoring policy on the mounted drive.

5.8.1 Implementation Checklist

The following table provides an overview of the tasks required for Change Guardian to start monitoring Windows events:

Task

See

Complete the prerequisites

Prerequisites

Add a license key

Adding a License Key

Configure Change Guardian for monitoring

Creating Windows Policies

Assigning Policies and Policy Sets

Triage events.

You can triage events in the Change Guardian dashboard and the Administration Console.

NOTE:Change Guardian supports monitoring removable media events only on USB flash drives and Windows platform. To monitor external hard disk drive (HDD), create a file system monitoring policy on the mounted drive.

5.8.2 Prerequisites

Ensure that you have completed the following:

5.8.3 Creating Windows Policies

You can create policies to monitor changes to the following:

  • File integrity

  • File shares

  • File systems

  • Local users and groups

  • Processes

  • Registry

  • Removable media

NOTE:To enable the Registry Browser in Change Guardian, you must set the repositoryEnabled flag (under HKLM\Software\Wow6432Node\NetIQ\ChangeGuardianAgent\repositoryEnabled) to 1, and then restart the agent.

If you do not manually set the flag to 1, when you use the Registry Browser, you will receive a Could not connect to Windows Data Source error.

For information about creating policies, see Creating Change Guardian Policies.

After creating policies, you can assign them to assets. For information about assigning policies, see Working with Policies.