VMware
Netwrix Auditor relies on native logs for collecting audit data. Therefore, successful change and access auditing requires a certain configuration of native audit settings in the audited environment and on the Auditor console computer. Configuring your IT infrastructure may also include enabling certain built-in Windows services, etc. You must configure auditing properly to ensure audit data integrity. Otherwise, your change reports may contain warnings, errors, or incomplete audit data.
CAUTION: Exclude the folder associated with Netwrix Auditor from antivirus scanning. See the Antivirus Exclusions for Netwrix Auditor knowledge base article for additional information.
You can automatically configure your IT infrastructure for monitoring through a monitoring plan. You don't need to configure anything manually.
Review a full list of object types and attributes Netwrix Auditor can collect on a VMware server (standalone host or vCenter server).
| Object type | Attributes |
|---|---|
| Virtual Machine |
|
| Authorization Manager |
|
| Cluster Resource |
|
| Computer Resource |
|
| Datacenter |
|
| Data Store |
|
| Distributed Port Group |
|
| Distributed Switch |
|
| Folder |
|
| Host System |
|
| Resource Pool |
|
| VirtualApp |
|
Users and groups
Starting with version 10.5, Netwrix Auditor for VMware collects data on VMware users and groups.
Auditing users and groups requires vCenter 6.5 or later.
Netwrix Auditor monitors the following objects:
-
vCenter Single Sign-On (SSO) Users. The product collects data from vCenter.
-
Localos users. For these users, the product collects data from ESXi and vCenter.
noteNetwrix Auditor reports the Who value as "Not Applicable" for localos users if it collected the data from the entire vCenter.
-
VMware groups. The product collects data from vCenter.
| Object type | Actions | Attributes |
|---|---|---|
| SSO User |
|
|
| Localos user |
|
|
| Group |
|
|
Netwrix Auditor may report on several changes with who reported as system due to the native VMware audit peculiarities. To exclude these changes from reports, see the VMware Monitoring Scope topic.
Considerations and Limitations
The following considerations refer to VMware infrastructure monitoring with Netwrix Auditor:
- Netwrix Auditor reports a VM moved from one resource pool to another (within the same VMware host) as Modified.
- If you specified an ESXi host as a monitored item in the corresponding monitoring plan, but created a virtual machine using the vCenter Server (not this ESXi host) management facilities, Netwrix Auditor doesn't collect information about this VM creation. To work around this, specify the vCenter Server as a monitored item in the monitoring plan.
- For ESXi host permission changes, the "What" field in the Activity Records (and, therefore, reports and search results) will report \root.
- Netwrix Auditor doesn't collect data on the Failed Logon event for incorrect logon attempts through VMware vCenter Single Sign-On.
- Netwrix Auditor also doesn't collect data on the logon attempts performed using SSH.
- For a custom role creation event, Netwrix Auditor reports the initiator as System.