Skip to main content

User Activity

note

Read and complete the instructions in the following topics before configuring your monitoring plan:

  • Protocols and Ports Required – To ensure successful data collection and activity monitoring configure necessary protocols and ports for inbound and outbound connections
  • Data Collecting Account – Configure data collecting accounts as required to audit your IT systems
  • User Activity – Configure data source as required to be monitored

Complete the following fields:

OptionDescription
General
Monitor this data source and collect activity dataEnable monitoring of the selected data source and configure Auditor to collect and store audit data.
Notify users about activity monitoringYou can enable the message that appears when a user logs in and specify the message text.
Record video of user activity within sessions
  • If disabled, the product collects only user session events (regardless of whether the user is idle or not).
  • If enabled, the product will both collect user session events and record video of user activity.
By default, this option is disabled.
Video Recording
Adjust video qualityFor these settings to become effective, enable video recording on the General tab. Optimize video file by adjusting the following:
  • File size and video quality
  • Save video in grayscale
  • CPU load and Video smoothness
Adjust video durationFor these settings to become effective, enable video recording on the General tab. Limit video file length by adjusting the following:
  • Recording lasts for <...> minutes—Video recording stops after the selected time period.
  • User has been idle for <...> minutes—Video recording stops if the product considers a user inactive during the selected time period.
If the Record video of user activity within sessions option is enabled, the User Sessions report shows active time calculated without including user idle period. Mind that Windows considers a computer idle if there has not been user interaction via the mouse or keyboard for a given time and if the hard drives and processors have been idle more than 90% of that time.
  • Free disk space is less than <...> MB—Video recording stops when the selected disk space limit is reached.
  • Consider user activity — Select one of the following:
    • Stop if user has been idle for <...> minutes. Select if you want the product to stop video recording for a user after the specified time period.
    • Continue video recording regardless of the user idle state. When selected, Netwrix Auditor continues video recording for idle users.
Set a retention period to clear stale videosWhen the selected retention period is over, Netwrix Auditor deletes your video recordings.
Users
Specify users to track their activitySelect the users whose activity you want to record. You can select All users or create a list of Specific users or user groups. You can also add certain users to the Exceptions list.
Applications
Specify applications you want to trackSelect the applications that you want to monitor. You can select All applications or create a list of Specific applications. You can also add certain applications to the Exceptions list.
Monitored ComputersFor a newly created monitoring plan for User Activity, the list of monitored computers is empty. Add items to your monitoring plan and wait until Netwrix Auditor retrieves all computers within these items. See Add Items for Monitoring for more information. The list contains computer name, its current status and last activity time.

Review your data source settings and click Add to go back to your plan. The newly created data source will appear in the Data source list. As a next step, click Add item to specify an object for monitoring. See the Add Items for Monitoring topic for additional information.

How to Include/Exclude Applications

To create a list of applications to include in or exclude from monitoring, provide the following:

  • Title — application title as shown on top of the application window, for example, MonthlyReport.docx - Word.

    • You can also find the title in the "What" column of related Netwrix Auditor reports and search results, for example, in the User Sessions report.
  • Description — as shown in the Description column on the Details tab of Windows Task Manager.

    • Using Description can help to filter out several components of a single application — for example, all executables having TeamViewer 14 description belong to the same app.

To create a list of inclusions / exclusions for applications:

Step 1 – Click Add on the right of the list.

Step 2 – Enter application title and description you have identified.

The product supports wildcards (*?) and applies them as follows:

  • * - Notepad (the "Title" filter) will exclude all Notepad windows.
  • colo?r * (the "Title" filter) will exclude all application window titles containing "color" or "colour".
note

Same logic applies to the inclusion rules.

Example

To exclude the Notepad application window with "Document1" open, add the following filter values:

  • In the Title filter enter "Document1.txt - Notepad":

    uavr_source_example_1

  • In the Description filter, enter the corresponding value, here it will be "Notepad".

uavr_source_example_2_thumb_0_0

Computer

For evaluation purposes, Netwrix recommends selecting Computer as an item for a monitoring plan. After you configure the product to collect data from the specified items, it applies audit settings (including Core and Compression services installation) to all computers within AD Container or IP Range.

Complete the following fields:

OptionDescription
General
Specify a computerProvide a server name by entering its FQDN, NETBIOS, or IPv4 address. You can click Browse to select a computer from the list of computers in your network.
Specify the account for collecting dataSelect the account you want to use to collect data for this item. If you want to use a specific account (other than the one you specified during monitoring plan creation), select account type you want to use and enter credentials. The following choices are available: - User/password. The account must have the same permissions and access rights as the default account used for data collection. See the Data Collecting Account topic for additional information. - Group Managed Service Account (gMSA). You should specify only the account name in the domain\account$ format. See the Use Group Managed Service Account (gMSA) topic for additional information.

IP Range

Complete the following fields:

OptionDescription
General
Specify IP rangeSpecify an IP range for the audited computers. To exclude computers from within the specified range, click Exclude. Enter the IP subrange you want to exclude, and click Add.
Specify the account for collecting dataSelect the account the same way as for the Computer item.

AD Container

Complete the following fields:

OptionDescription
General
Specify AD containerSpecify a whole AD domain, OU, or container. Click Browse to select from the list of containers in your network. You can also:
  • Select a particular computer type to audit within the chosen AD container: Domain controllers, Servers (excluding domain controllers), or Workstations.
  • Click Exclude to specify AD domains, OUs, and containers you don't want to audit. In the Exclude Containers dialog, click Add and specify an object. The list of containers doesn't include child domains of trusted domains.
Use other options (Computer, IP range) to specify the target computers.
Specify the account for collecting dataSelect the account the same way as for the Computer item.