Requirements
This topic provides the requirements for the server where Netwrix Auditor will be installed. See the following topics for additional information:
- Supported Data Sources
- Hardware Requirements
- Software Requirements
- Requirements for SQL Server to Store Audit Data
Architecture Overview
Netwrix Auditor provides comprehensive auditing of applications, platforms, and storage systems. The following figure shows the product architecture and component interactions.
![]()
- Netwrix Auditor Server — the central component that handles the collection, transfer, and processing of audit data from the various data sources (audited systems). Netwrix Auditor collects data from sources it doesn't natively support using the RESTful Integration API.
- Netwrix Auditor Client — a component that provides a friendly interface to authorized personnel who can use this console UI to manage product settings, examine alerts, reports, and search results. Other users can obtain audit data by email or with third-party tools — for example, you can provide reports to the management team via the intranet portal. You can install the Client on other hosts using the same installer as the server.
- Data sources — entities that represent the types of audited systems supported by Netwrix Auditor (for example, Active Directory, Exchange Online, NetApp storage system, and so on), or the areas you are interested in (Group Policy, User Activity, and others).
- Long-Term Archive — a file-based storage repository that keeps the audit data collected from all your data sources or imported using Integration API in a compressed format for a long period of time. Default retention period is 120 months.
- Audit databases — these are Microsoft SQL Server databases used as operational storage. Use this type of data storage to browse recent data, run search queries, and generate reports and alerts. Typically, Auditor stores data collected from a specific data source (for example, Exchange Server) in the dedicated Audit database and the long-term archive. So, you can configure as many databases as the data sources you want to process. Default retention period for data stored in the Audit database is 180 days.
NOTE: When auditing Active Directory domains, Exchange servers, expired passwords, and inactive users, the product can encrypt the data it sends using Signing and Sealing. See the following Netwrix knowledge base article for additional information on how to secure Netwrix Auditor: Best Practices for Securing Netwrix Auditor.
Workflow Stages
The general workflow stages are as follows:
-
Authorized administrators prepare IT infrastructure and data sources they are going to audit, as recommended in Netwrix Auditor documentation and industry best practices; they use the Netwrix Auditor Client (management UI) to set up automated data processing.
-
Netwrix Auditor collects audit data from the specified data source (application, server, storage system, and so on).
- To provide a coherent picture of changes that occurred in the audited systems, the product can consolidate data from multiple independent sources (event logs, configuration snapshots, change history records, etc.). Netwrix Auditor Server and Integration API implement this capability.
- See the Integration API topic for additional information on custom data source processing workflow.
-
Netwrix Auditor stores audit data in the Audit databases and the repository (Long-Term Archive) and preserves it there according to the corresponding retention settings.
-
Netwrix Auditor analyzes the incoming audit data and alerts appropriate staff about critical changes, according to the built-in alerts you choose to use and any custom alerts you have created.
-
Authorized users use the Netwrix Auditor Client to view pre-built dashboards, run predefined reports, conduct investigations, and create custom reports based on their searches. Other users obtain the data they need via email or third-party tools.
-
To enable historical data analysis, Netwrix Auditor can extract data from the repository and import it to the Audit database, where it becomes available for search queries and report generation.