User Activity
Read and complete the instructions in the following topics before configuring your monitoring plan:
- Protocols and Ports Required – To ensure successful data collection and activity monitoring configure necessary protocols and ports for inbound and outbound connections
- Data Collecting Account – Configure data collecting accounts as required to audit your IT systems
- User Activity – Configure data source as required to be monitored
Complete the following fields:
| Option | Description |
|---|---|
| General | |
| Monitor this data source and collect activity data | Enable monitoring of the selected data source and configure Auditor to collect and store audit data. |
| Notify users about activity monitoring | You can enable the message that appears when a user logs in and specify the message text. |
| Record video of user activity within sessions |
|
| Video Recording | |
| Adjust video quality | For these settings to become effective, enable video recording on the General tab. Optimize video file by adjusting the following:
|
| Adjust video duration | For these settings to become effective, enable video recording on the General tab. Limit video file length by adjusting the following:
|
| Set a retention period to clear stale videos | When the selected retention period is over, Netwrix Auditor deletes your video recordings. |
| Users | |
| Specify users to track their activity | Select the users whose activity you want to record. You can select All users or create a list of Specific users or user groups. You can also add certain users to the Exceptions list. |
| Applications | |
| Specify applications you want to track | Select the applications that you want to monitor. You can select All applications or create a list of Specific applications. You can also add certain applications to the Exceptions list. |
| Monitored Computers | For a newly created monitoring plan for User Activity, the list of monitored computers is empty. Add items to your monitoring plan and wait until Netwrix Auditor retrieves all computers within these items. See Add Items for Monitoring for more information. The list contains computer name, its current status and last activity time. |
Review your data source settings and click Add to go back to your plan. The newly created data source will appear in the Data source list. As a next step, click Add item to specify an object for monitoring. See the Add Items for Monitoring topic for additional information.
How to Include/Exclude Applications
To create a list of applications to include in or exclude from monitoring, provide the following:
-
Title — application title as shown on top of the application window, for example, MonthlyReport.docx - Word.
- You can also find the title in the "What" column of related Netwrix Auditor reports and search results, for example, in the User Sessions report.
-
Description — as shown in the Description column on the Details tab of Windows Task Manager.
- Using Description can help to filter out several components of a single application — for example, all executables having TeamViewer 14 description belong to the same app.
To create a list of inclusions / exclusions for applications:
Step 1 – Click Add on the right of the list.
Step 2 – Enter application title and description you have identified.
The product supports wildcards (*?) and applies them as follows:
- * - Notepad (the "Title" filter) will exclude all Notepad windows.
- colo?r * (the "Title" filter) will exclude all application window titles containing "color" or "colour".
Same logic applies to the inclusion rules.
Example
To exclude the Notepad application window with "Document1" open, add the following filter values:
-
In the Title filter enter "Document1.txt - Notepad":
-
In the Description filter, enter the corresponding value, here it will be "Notepad".
![]()
Computer
For evaluation purposes, Netwrix recommends selecting Computer as an item for a monitoring plan. After you configure the product to collect data from the specified items, it applies audit settings (including Core and Compression services installation) to all computers within AD Container or IP Range.
Complete the following fields:
| Option | Description |
|---|---|
| General | |
| Specify a computer | Provide a server name by entering its FQDN, NETBIOS, or IPv4 address. You can click Browse to select a computer from the list of computers in your network. |
| Specify the account for collecting data | Select the account you want to use to collect data for this item. If you want to use a specific account (other than the one you specified during monitoring plan creation), select account type you want to use and enter credentials. The following choices are available: - User/password. The account must have the same permissions and access rights as the default account used for data collection. See the Data Collecting Account topic for additional information. - Group Managed Service Account (gMSA). You should specify only the account name in the domain\account$ format. See the Use Group Managed Service Account (gMSA) topic for additional information. |
IP Range
Complete the following fields:
| Option | Description |
|---|---|
| General | |
| Specify IP range | Specify an IP range for the audited computers. To exclude computers from within the specified range, click Exclude. Enter the IP subrange you want to exclude, and click Add. |
| Specify the account for collecting data | Select the account the same way as for the Computer item. |
AD Container
Complete the following fields:
| Option | Description |
|---|---|
| General | |
| Specify AD container | Specify a whole AD domain, OU, or container. Click Browse to select from the list of containers in your network. You can also:
|
| Specify the account for collecting data | Select the account the same way as for the Computer item. |