Skip to main content

FS_PermissionChanges Job

The FS_PermissionChanges job is designed to report on permission change activity event information from targeted file servers.

Analysis Tasks for the FS_PermissionChanges Job

View the analysis tasks by navigating to the FileSystem > 5.Activity > Forensics > FS_PermissionChanges > Configure node and select Analysis.

CAUTION: Do not modify or deselect the selected analysis tasks. The analysis tasks are preconfigured for this job.

Analysis Tasks for the FS_PermissionChanges Job

The following analysis tasks are selected by default:

    1. Create Permission Change Events Table – Creates an interim processing table in the database for use by downstream analysis and report generation
    1. Create Permission Changes Table and View – Creates the SA_ENG_PermissionChangesView view accessible under the job’s Results node
    1. Last 30 Days – Creates the SA_FS_PermissionChanges_Last30Days table accessible under the job’s Results node
    1. Trend – Creates the SA_FS_PermissionChanges_TrendOverTime table accessible under the job’s Results node
    1. Create view to notify on - By user, per share, for the past 24 hours – Creates the SA_FS_PermissionChanges_Notification_NOTIFICATION table accessible under the job’s Results node
    1. Raw Details – Creates the SA_FS_PermissionChanges_Details view accessible under the job’s Results node
    1. High risk permission changes – Creates the SA_FS_PermissionChanges_HighRisk table accessible under the job’s Results node
    1. High risk permission changes summary – Creates the SA_FS_PermissionChanges_HighRiskSummary table accessible under the job’s Results node

The Notification analysis task is an optional analysis task which requires configuration before enabling it. The following analysis task is deselected by default:

    1. Alert on Permission Changes – Alerts when permission changes have occurred

In addition to the tables and views created by the analysis tasks, the FS_PermissionChanges job produces the following pre-configured reports:

ReportDescriptionDefault TagsReport Elements
High Risk ChangesThis report highlights successful permission changes performed on a high risk trustee. The line chart shows data for the past 30 days only.GDPR SOX HIPAA PCI-DSS GLBA ITAR FERPA FISMA ISO27001This report is comprised of two elements: - Line Chart– Displays last 30 days of high risk changes - Table – Provides details on high risk changes
Permission ChangesThis report identifies all resources where successful permission changes have occurred. The line chart shows data for the past 30 days only.NoneThis report is comprised of two elements: - Line Chart– Displays last 30 days of permission changes - Table – Provides details on permission changes