Adding a Palo Alto Device as a Proxied Device
Shows how to add a Palo Alto firewall as a proxied device in Netwrix Change Tracker. Covers SSH credential prerequisites, prompt regex configuration, and the login script directives current Gen 7 agents require.
Adding or Replacing Compliance Report Templates
Use this article when you have replaced or edited a configuration or compliance report template and need to upload it to Netwrix Change Tracker. It covers uploading templates, overwriting defaults, and assigning templates to device groups.
Understanding the Agent Installation Files
Describes the files stored in the Netwrix Change Tracker Gen 7 NetCore agent installation path, including Events.db, Config.xml, Rolling-log.txt, and HubDetails.xml.
Antivirus Exclusions
Antivirus and endpoint detection and response (EDR) exclusions required for Netwrix Change Tracker agents and Hub to avoid performance degradation.
APM Monitoring Objects
Recommended services, processes, paths, and log locations to monitor with application performance monitoring (APM) tools for Netwrix Change Tracker's Gen7 Hub server and agents.
Applying a Compliance Template to a Group
Step-by-step instructions to apply a compliance template to a group in Netwrix Change Tracker for automated reporting.
Using Baseline Data Beyond Change Detection
Explains additional uses for baseline data in Netwrix Change Tracker beyond individual file change detection, including retaining full configuration records for network devices and firewalls, and points to the Baseline Center documentation for building and running a Baseline Policy.
Configuring Recursive File Content Monitoring
Shows how to enable recursive file content monitoring by editing the Change Tracker web server configuration and applying the filter to a configuration template in Netwrix Change Tracker.
Configuring FAST
Configuring File Approved Safe Technology (FAST) in Netwrix Change Tracker by creating a Planned Change rule set with a FAST Match rule.
Creating a Custom Tracked Attributes Filter
Shows how to create a custom tracked attributes filter within a Netwrix Change Tracker configuration template when no default filter matches your requirements.
Disabling 2FA for the Default Administrator
Describes how to disable two-factor authentication (2FA) for the default administrator user in Netwrix Change Tracker so one-time codes are written to the server log for Allowed Commands.
Excluding Information from Process Output Tracking (Agentless)
Shows how to exclude or edit lines from process output tracking on agentless devices using the ExcludeMatchesWithComment login script directive, so that always-changing values such as uptime do not generate change events.
Exporting Events to CSV, PDF, or XLSX
Exporting events from the Netwrix Change Tracker Events page to CSV, PDF, or XLSX format.
Express Agent Database and Log Location
Use the ConfigPath switch in expressAgent.ini to change the Express Agent database and log files location on Netwrix Change Tracker.
FAST Cloud Proxy Settings
If you use a proxy on your Netwrix Change Tracker Server and FAST Cloud does not work, configure the proxy for IIS processes by adding a system environment variable. This article shows the exact steps to set the ALL_PROXY variable.
FileAccessed Events
Explains why you are receiving File Access ("fileaccessed") events in Netwrix Change Tracker, what they indicate, and how to enable or disable them via policy templates.
In-Transit and At-Rest Data Encryption
Supported TLS versions for in-transit encryption and MongoDB at-rest encryption options for Netwrix Change Tracker.
Increasing File Content Max for Extension
Instructions to increase the File Content Max for extension setting on the Netwrix Change Tracker agent when file contents are not tracked because a file exceeds the configured size limit.
Increasing File Hash Max for Extension
Instructions to increase the File Hash Max for extension setting on the Netwrix Change Tracker agent when a file hash is not calculated because a file exceeds the configured size limit.
Monitoring Oracle Databases
How to configure Netwrix Change Tracker to monitor Oracle databases. This article covers required connection details, creating database credentials, proxy device setup, running test compliance reports, and common Oracle error troubleshooting.
Network Ports for Change Tracker
Describes which network ports to open to allow Netwrix Change Tracker agents and servers to communicate, including ports for agentless monitoring and network device configuration.
Preventing Default Group Recreation
Preventing Netwrix Change Tracker from recreating default OS groups after deletion by adding the CreateDefaultGroups configuration item.
Re-Registering a Deleted Device
Re-registering a device that was previously deleted from Netwrix Change Tracker using the Agents and Devices settings page.
Resetting the Default Admin Password
Instructions to reset the default admin password on Netwrix Change Tracker when the reset API is accessible only from the localhost on the Hub server.
Resubmitting Unplanned Changes
Using the Planned Change Wizard to create a planned change schedule and resubmit unplanned events in bulk in Netwrix Change Tracker.
Retrieving Baseline Events After Restart
Configuring Netwrix Change Tracker to retrieve baseline events (file lists and hashes) after an agent or server restarts.
Setting Up SIEM Integration
Configuring syslog integration to forward Netwrix Change Tracker events to a Security Information and Event Management (SIEM) solution.
Special Characters in Passwords
Supported special characters for Netwrix Change Tracker user and agent passwords, and how to configure local password requirements.
Enabling Account Lockout for Failed Login Attempts
Shows how to configure Netwrix Change Tracker to lock a user account after repeated failed login attempts, by setting lockoutenabled to true in appsettings.json. This overrides the previous IP-blocking behavior, which is no longer used.
Turning Off Bulk Email Notifications
Shows how to configure Netwrix Change Tracker to send a separate real-time email notification for each change, instead of compiling multiple changes into a single email.
Uninstalling the Agent via PowerShell
Uninstalling the Netwrix Change Tracker agent using the silent uninstaller executable via PowerShell for both NetCore and non-NetCore installations.
Updating Agents from the Console
Comprehensive guide for updating Netwrix Change Tracker agents from the Hub console, including download instructions, upload procedures, deployment scheduling, phased rollout strategies, testing recommendations, and troubleshooting.
Upload Compliance/Tracking Template
This article shows how to upload a compliance/tracking template to Netwrix Change Tracker using the Settings > Policy Templates page, with step-by-step instructions.