Skip to main content

Exchange Registry Keys

Review the basic registry keys that you may need to configure for monitoring Exchange with Netwrix Auditor. Navigate to Start → Run and type "regedit".

Registry key (REG_DWORD type)Description / Value
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Netwrix Auditor\AD Change Reporter
CleanAutoBackupLogsDefines the retention period for the security log backups: - 0—Auditor never deletes backups from domain controllers - [X]—Auditor deletes backups after [X] hours
IgnoreAuditCheckResultErrorDefines whether to display audit check errors in the Activity Summary footer: - 0—Display errors - 1—Don't display errors
IgnoreRootDCErrorsDefines whether to display audit check errors for the root domain (when Auditor collects data from a child domain) in the Activity Summary footer: - 0—Display errors - 1—Don't display errors
MonitorModifiedAndRevertedBackDefines whether the Activity Summary must display the attributes whose values changed and then reverted between data collections: - 0—The Activity Summary doesn't display these attributes - 1—The Activity Summary displays these attributes as "modified and reverted back"
ProcessBackupLogsDefines whether to process security log backups: - 0—No - 1—Yes Even if this key is set to "0", Auditor doesn't delete the security log backups regardless of the value of the CleanAutoBackupLogs key.
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Netwrix Auditor\AD Change Reporter<monitoring plan name>
CollectLogsMaxThreadsDefines the number of Domain Controllers to simultaneously start log collection on.
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Netwrix Auditor\Management Console\Database settings
overwrite_datasourceDefines whether to overwrite the database connection settings (stored in the reports data source) if they differ from the SQL server settings specified when configuring the monitoring plan: - 0—No - 1—Yes
SqlOperationTimeoutDefines the timeout for executing SQL queries such as data selection, insertion, or deletion (in seconds).
timeoutDefines the Audit Database connection timeout (in seconds).