Configuring FS Auditing

If the NAAS Default Configuration Utility has been run, Event Policy Templates for File System (FS) will already be present and should be used for creating more policies. Additional templates for the same service should not be created. If the Default Configuration utility has been run, skip to Step 2.

  1. Create an Event Policy Template for FS.

    1. Select a container > New > Object > naasEventPolicyTemplate

    2. Enter the Service Identifier as NWFS.

    3. Enter the Service Version as 1.0.

    4. Select the applicable data policy types. The applicable data policies are naasUserPolicy, naasSourceMachinePolicy, naasFilePolicy, and naasTargetMachinePolicy.

    5. Select Volume as the Associable Object Type.

    6. To generate the event list, click Read From File > type FSEVENTS.TXT, which is the name of the file containing the list of FS events.

      The FSEVENTS.TXT file is located in the SYS:\AUDIT\NAASEVENTS directory

  2. Create one or more FS Event Policies.

    1. Select a container > New > Object > naasEventPolicy.

    2. Select an existing FS Event Policy Template.

  3. Configure the policies based on the requirements.

  4. Associate the policy to the file volumes that are to be audited. For more details, see Associating an Audit Policy to an Object.

  5. Grant the specific Audit agent Read rights to these policies.

  6. Load the FS Shim from the server console by using the following command:

    Load sys:\system\fsshim

  7. Move on to Starting the Audit Agent.



Previous | Next