Skip to main content

Group Policy Registry Keys

Review the basic registry keys that you may need to configure for monitoring Group Policy with Netwrix Auditor. Navigate to Start → Run and type "regedit".

Registry key (REG_DWORD type)Description / Value
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Netwrix Auditor\AD Change Reporter
CleanAutoBackupLogsDefines the retention period for the security log backups: - 0—Never delete backups from domain controllers - [X]—Delete backups after [X] hours
GPOBackupDefines whether to backup GPOs during data collection: - 0—No - 1—Yes
GPOBackupDaysDefines the backup frequency: - 0—Backup always - X—Once in X days GPOBackup must be set to "1".
IgnoreAuditCheckResultErrorDefines whether to display audit check errors in the Activity Summary footer: - 0—Display errors - 1—Don't display errors
IgnoreRootDCErrorsDefines whether to display audit check errors for the root domain (when Netwrix Auditor collects data from a child domain) in the Activity Summary footer: - 0—Display errors - 1—Don't display errors
ProcessBackupLogsDefines whether to process security log backups: - 0—No - 1—Yes Even if this key is set to "0", Netwrix Auditor doesn't delete the security log backups regardless of the value of the CleanAutoBackupLogs key.
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Netwrix Auditor\AD Change Reporter<monitoring plan name>
CollectLogsMaxThreadsDefines the number of Domain Controllers to simultaneously start log collection on.
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Netwrix Auditor\ AD Change Reporter<monitoring plan name>\Database settings
SessionImportDaysDefines the frequency of a full snapshot upload: - X—Once in X days
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Netwrix Auditor\Management Console\Database settings
overwrite_datasourceDefines whether to overwrite the database connection settings (stored in the reports data source) if they differ from the SQL server settings specified when configuring the monitoring plan: - 0—No - 1—Yes
SqlOperationTimeoutDefines the timeout for executing SQL queries such as data selection, insertion, or deletion (in seconds).
timeoutDefines the Audit Database connection timeout (in seconds).