Security Manager for Windows

Release Notes

Date Published: May 2011

 
 

 

Security Manager for Windows helps secure your enterprise from internal and external attacks. In real time, the product monitors, analyzes, and consolidates events from log files on monitored Windows computers to detect a variety of occurrences and alert you to them. For example, if Security Manager for Windows detects an unauthorized service running on a monitored Windows computer, Security Manager for Windows can send an alert to the Security Manager Control Center and notify a security team member with the location of the incident.

Security Manager for Windows collects Windows event log entries, allowing you to use archived data to create Forensic Analysis and Trend Analysis reports using the Control Center as well as custom Summary reports using Microsoft SQL Server Reporting Services. The Security Manager for Windows module collects data from the following Windows event logs:

  • Directory Services
  • Security
  • Domain Name Server (DNS)
  • File Replication Service
  • System

This module for the Security Manager product includes several new features. This version also improves usability and resolves several previous issues. Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure our products meet all your needs. You can post feedback in the Security Manager forum on Qmunity, our community Web site that also includes product notifications, blogs, and the Security Manager user group.

This document outlines why you should install this module, lists any installation requirements, and identifies any known issues.

Return to Top

Supported Products

For the latest information about supported software versions and the availability of module updates, visit the Security Manager Supported Products page. If you encounter problems using this module with a later version of your application, contact NetIQ Technical Support.

This release supports the following products:

  • Windows Server 2000
  • Windows Server 2003
  • Windows XP
  • Windows Server 2008
  • Windows Server 2008 Server Core
  • Windows Server 2008 R2
  • Windows Server 2008 Server Core R2
  • Windows Vista
  • Windows 7

Return to Top

Why Install This Module?

Security Manager for Windows monitors, analyzes, and consolidates events from log files on monitored Windows computers to detect a variety of occurrences and alert you to them. The following sections outline the key features and functions provided by this version, as well as issues resolved in this release.

Provides Improved Log Archive Logon Activity Collection

In this release, Security Manager for Windows supports the following new fields in the cross-platform Forensic Analysis report type:

This release also supports the following new Forensic Analysis queries:

  • Windows Logon Activity
  • Windows Authentication Activity
  • WIndows Logon Failures
  • Windows Authentication Failures

Adds "Pre-Authentication Type" Field for Logon Events

In this release, Security Manager for Windows supports the new "Pre-Authentication Type" field for logon events in the cross-platform Forensic Analysis report type. Events 672, 675, 4771, and 4768 now collect pre-authentication field data, which you can display in Forensic Analysis reports. (ENG275867)

Resolves Expired Password Alert Issue

This release resolves an issue where the existing "Logon has failed because password has expired" rule does not correctly generate an alert when a user's password has expired. Security Manager now correctly generates alerts both when a user's password has expired and when a user attempts to log on to a monitored computer using an expired password. (ENG288984)

Filters Noisy Windows Event from Log Archive

This release resolves an issue where the agent unnecessarily sends a large number of Windows Security Log events with the event ID 5156 to the log archive server. Security Manager now filters out events with event ID 5156 when sending data to the log archive. If you want Security Manager to store all Windows Security Log events with this ID, use the Development Console to disable the "Archival Filter Windows Filtering Platform Success Events (5156)" log filter rule. (ENG303236)

Return to Top

System Requirements

The following table lists additional requirements for a Windows agent. For more information about agent requirements, see the Installation Guide for NetIQ Security Manager.

Category Requirement
Processor 1.5 GHz Intel Pentium III or equivalent.
Memory 40 MB minimum. The amount of memory usage varies and depends on the environment, including event rate and other factors.
Operating System All supported Windows agent platforms.
Software
  • Ensure you have Security Manager 6.5, 6.5 Service Pack 1, 6.5.2, or 6.5.3 installed.
  • Ensure you have the latest version of the Security Manager Self-Monitoring module installed. This module is required for optimum functionality of the product.

Return to Top

Installing This Module

Install the module using the Module Installer utility. For more information about installing modules, see the User Guide for NetIQ Security Manager.

You can verify successful installation of the module in the Module Installer. After the installation completes, verify the Status column indicates the module is current and the module version listed in the Installed Version column is the same as the version in the Available Version column.

After you install the module, run the Configuration Wizard to configure logon/logoff monitoring and network port monitoring. For more information about using the Configuration Wizard, see the User Guide for NetIQ Security Manager.

Return to Top

Upgrading This Module

The steps required to upgrade your environment to the latest version of Security Manager for Windows are different depending on what you currently have installed. Select the appropriate upgrade path from the following scenarios.

To upgrade your environment:

  1. If you are upgrading from Intrusion Manager for Windows and do not have Change Guardian for Windows installed, complete the following steps:
    1. Download and install this Security Manager for Windows updated module from Autosync to get the latest supported coverage for Windows.
    2. Move any custom rules from the Intrusion Manager for Windows processing rule groups in the Development Console to a customer-owned processing rule group.
    3. Note
      Ensure you move these custom rules before you perform Step c, or you will lose those customizations.

    4. Obtain the Intrusion Manager for Windows (Legacy) module from NetIQ Technical Support and install it. Installing the Legacy module cleans up the unsupported rules in Security Manager.
  2. If you are upgrading from Intrusion Manager for Windows and have Change Guardian for Windows installed, upgrade Change Guardian for Windows to the latest version and then install the updated Security Manager for Windows module. For information about the latest version of Change Guardian for Windows, see the NetIQ Change Guardian for Windows section of the NetIQ Technical Support Site at www.netiq.com/support.
  3. Note
    NetIQ recommends installing the latest version of Change Guardian for Windows before installing the updated Security Manager for Windows module. If you install the latest version of Change Guardian for Windows after installing Security Manager for Windows, the processing rule groups in Security Manager for Windows will be duplicated in the Change Guardian for Windows processing rule groups. To resolve this issue, reinstall Security Manager for Windows.

  4. If you have Change Guardian for Windows and you have already installed this updated Security Manager for Windows module, upgrade Change Guardian for Windows to the latest version. For information about the latest version of Change Guardian for Windows, see the NetIQ Change Guardian for Windows section of the NetIQ Technical Support Site at www.netiq.com/support.
  5. After you install this module, run the Configuration Wizard to configure the module for logon/logoff and network port monitoring. For more information about using the Configuration Wizard, see the User Guide for NetIQ Security Manager.

Return to Top

Known Issues

NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

Cross-Platform Forensic Analysis Report Type No Longer Uses source.process.name Field

The cross-platform Forensic Analysis report type no longer uses the source.process.name field for logon events. Forensic information for logon events can now be found in the target.process.name field in the forensic template. (ENG302754)

Duplicate Microsoft Sites and Services Rules with CGAD 1.7

If you install Change Guardian for Active Directory version 1.7 and install the latest version of Security Manager for Windows, Security Manager Control Center displays the Microsoft Sites and Services rules in both processing rule groups. To prevent this issue, NetIQ recommends installing the latest versions of both modules. (DOC292551)

Microsoft Sites and Services Alert Views Removed After Installing CGAD 1.7

If you install the latest version of the Security Manager for Windows module and then install Change Guardian for Active Directory version 1.7, the Security Manager Control Center no longer displays alerts and events generated by Microsoft Sites and Services rules in Security Manager for Windows views. To resolve this issue, perform the following steps:

  1. In the Development Console, expand Security Manager Development Console.
  2. Right-click Processing Rule Groups.
  3. Select Restore NetIQ Module.
  4. Click Browse... and navigate to the Security Manager for Windows module.
  5. Under Options, select Merge, and always use the rules defined in the module. Preserve my company's knowledge base comments.
  6. Click Import.

(DOC295327)

Using Spaces with Regular Expressions for Service Accounts

A known issue exists where entering spaces in regular expressions for service accounts in the Configuration Wizard breaks the regular expression. The Security Manager for Windows module supports entering spaces in service account names, but not in regular expressions representing service account names. Security Manager for Windows uses the following rules when monitoring service account logins:

  • A rule that alerts when the service account logs in interactively
  • A rule that alerts when a user that is not in the list of service accounts logs in as a batch job or service
  • A rule that alerts when a user that is not in the list of service accounts logs in via a scheduled task

Using a space in a regular expression can cause these rules to behave opposite of the expected behavior. (ENG273461)

Duplicate Alerts

A known issue exists where Security Manager for Windows raises two alerts for the same event. When any user with a locked-out account attempts to log in, Security Manager for Windows generates an alert. Security Manager for Windows also raises an alert if the built-in administrator account is locked out and attempts to log in. As a result, the module generates two alerts when a locked-out built-in administrator account attempts to log in. (ENG264309)

"Session Name" Field Modified

In this release, the meaning of the "Session Name" field has changed for all logon/logoff events collected by the Security Manager for Windows module. The "Session Name" field now contains the name of the session in which the event occurred, which can be a session or login identifier. (ENG304141)

Return to Top

Contact Information

Our goal is to provide documentation that meets your needs. If you have suggestions for improvements, please email Documentation-Feedback@netiq.com. We value your input and look forward to hearing from you.

For detailed contact information, see the Support Contact Information Web site.

For interactive conversations with your peers and NetIQ experts, become an active member of Qmunity, our community Web site that offers product forums, product notifications, blogs, and product user groups.

Return to Top

Legal Notice

Return to Top