403 IP Address Blocked
This article provides a resolution for the "Hub connection failed" error due to an IP address being blocked after multiple login failures.
This article provides a resolution for the "Hub connection failed" error due to an IP address being blocked after multiple login failures.
Shows how to add a Palo Alto firewall as a proxied device in Netwrix Change Tracker. Covers SSH credential prerequisites, prompt regex configuration, and the login script directives current Gen 7 agents require.
Antivirus and endpoint detection and response (EDR) exclusions required for Netwrix Change Tracker agents and Hub to avoid performance degradation.
Use this article when you have replaced or edited a configuration or compliance report template and need to upload it to Netwrix Change Tracker. It covers uploading templates, overwriting defaults, and assigning templates to device groups.
Step-by-step instructions to apply a compliance template to a group in Netwrix Change Tracker for automated reporting.
How to back up, restore, or move your MongoDB database used by Netwrix Change Tracker, including copying required files and troubleshooting the "Key not valid in specified state" error.
This article addresses the error related to the certificate thumbprint mismatch in the Netwrix Agent and provides a resolution to ensure proper reporting to the Hub Server.
Resolving an issue where the Netwrix Change Tracker agent cannot start on RHEL 8 or 9 due to default cryptographic policy changes, by applying a custom subpolicy.
Describes what information to collect and provide to Netwrix Support when reporting an issue with Netwrix Change Tracker, including general details, Agent and ITSM module attachments, and Hub Server attachments.
Step-by-step instructions to reset the MongoDB admin account password when authentication is enabled and the admin password is lost. Requires access to the server hosting MongoDB.
If compliance reports in Netwrix Change Tracker show Status as Processing with a percentage that never reaches 100%, an IIS request-filtering tool such as UrlScan may be blocking the Transfer-Encoding header. This article explains the cause and the fix.
Explains how to resolve the "Hub location details have not been specified" error when an agent cannot find HubDetails.xml, including running the connection script and manually editing HubDetails.xml.
Configuring File Approved Safe Technology (FAST) in Netwrix Change Tracker by creating a Planned Change rule set with a FAST Match rule.
Supported TLS versions for in-transit encryption and MongoDB at-rest encryption options for Netwrix Change Tracker.
Shows how to enable recursive file content monitoring by editing the Change Tracker web server configuration and applying the filter to a configuration template in Netwrix Change Tracker.
If Netwrix Change Tracker events reports contain ErrorEvent entries labeled "Corrupt", multiple conflicting agent configuration files may be present on affected devices. This article explains how to identify affected agents and perform an agent reset to resolve the issue.
Shows how to create a custom tracked attributes filter within a Netwrix Change Tracker configuration template when no default filter matches your requirements.
Use the UI indicators and provided scripts to determine whether the default agent account password is in use on the Netwrix Change Tracker Hub. Includes PowerShell and Bash scripts for versions prior to 7.7.4 and guidance for versions 7.7.4 and later.
Describes which network ports to open to allow Netwrix Change Tracker agents and servers to communicate, including ports for agentless monitoring and network device configuration.
Describes how to disable two-factor authentication (2FA) for the default administrator user in Netwrix Change Tracker so one-time codes are written to the server log for Allowed Commands.
This article explains the purpose of `core.*` files in Gen 7 Agent servers and whether they can be safely deleted to free up disk space.
Shows how to configure Netwrix Change Tracker to lock a user account after repeated failed login attempts, by setting lockoutenabled to true in appsettings.json. This overrides the previous IP-blocking behavior, which is no longer used.
Shows how to enable baseline events on monitored folders in Netwrix Change Tracker and explains what baseline events are and how they appear on the hub.
Resolving Error 503 when the Netwrix Change Tracker login screen is unavailable due to the web application pool not running or incorrect application pool identity credentials.
Fixes a 404 error when accessing the Netwrix Change Tracker API Metadata page by enabling the plugins.metadataenabled key in appSettings.config.
When an agent with the same name as an already registered agent attempts to connect to Netwrix Change Tracker, the hub can return a 500 error indicating the requested agent name is in use. This article explains how to resolve the error on Windows and RHEL/CentOS by restoring the correct agent ID and editing HubDetails.xml.
When you run the Netwrix ChangeTracker Gen7 Agent NetCore installer and test the Hub connection, you may receive a WinHttp.WinHttpRequest error stating the connection was terminated abnormally. Install Microsoft's Easy Fix update to enable TLS 1.1/TLS 1.2 for WinHTTP to resolve the issue.
Resolving the "Error, the requested event counts summary size cannot be smaller than the system event count window size" message in Netwrix Change Tracker by correcting the EventStatsUnitSeconds configuration value.
Shows how to exclude or edit lines from process output tracking on agentless devices using the ExcludeMatchesWithComment login script directive, so that always-changing values such as uptime do not generate change events.
Shows how to export or back up individual MongoDB collections used by Netwrix Change Tracker. Includes commands to view collections and use mongodump for exporting collections.
Exporting events from the Netwrix Change Tracker Events page to CSV, PDF, or XLSX format.
Resolving the "file is being used by another process" error when running a report in Netwrix Change Tracker, typically caused by antivirus or EDR solutions locking the report file.
Shows how to resolve the "Check Log for Details" message by verifying and reinstalling the NNTInfo driver and explains kernel buffer limitations that can cause intermittent loss of "who made the change" information.
Use the ConfigPath switch in expressAgent.ini to change the Express Agent database and log files location on Netwrix Change Tracker.
If you use a proxy on your Netwrix Change Tracker Server and FAST Cloud does not work, configure the proxy for IIS processes by adding a system environment variable. This article shows the exact steps to set the ALL_PROXY variable.
Shows how to run an events report that includes Created Planned Changes, Approved Changes, and the user who performed these actions in Netwrix Change Tracker.
This article shows how to upload a compliance/tracking template to Netwrix Change Tracker using the Settings > Policy Templates page, with step-by-step instructions.
Resolves HTTP/HTTPS Error 500.19 caused by a duplicate X-Frame-Options collection entry in web.config after upgrading Netwrix Change Tracker from an older version.
Instructions to increase the File Content Max for extension setting on the Netwrix Change Tracker agent when file contents are not tracked because a file exceeds the configured size limit.
Instructions to increase the File Hash Max for extension setting on the Netwrix Change Tracker agent when a file hash is not calculated because a file exceeds the configured size limit.
Resolves a MongoDB connection timeout for the Netwrix Change Tracker Hub by increasing the IIS pool size and MongoDB connection timeout in appsettings.Production.json.
Shows how to troubleshoot a MongoDump failure caused by a Windows socket buffer issue and links to Microsoft guidance for resolution.
Explains how to resolve MongoDB "out of memory" errors by configuring Windows virtual memory (page file) to System managed so the Netwrix Change Tracker database and Hub Server can function properly.
Provides steps to repair a corrupted MongoDB database that causes the MongoDB service to stop repeatedly for Netwrix Change Tracker.
How to configure Netwrix Change Tracker to monitor Oracle databases. This article covers required connection details, creating database credentials, proxy device setup, running test compliance reports, and common Oracle error troubleshooting.
Instructions to migrate a MongoDB database used by Netwrix Change Tracker from a Linux Hub server to a Windows Hub server, including exporting on Linux, restoring on Windows, and resolving the "Key not valid in specified state" error.
Resolves a "Permission denied" error when running the NNT_FILEHASH_LINUX_X64 binary on agentless Linux devices monitored by Netwrix Change Tracker.
Explains why old or duplicate events appear as new in syslogs and shows how to remove pending notifications from MongoDB to prevent re-reporting of outdated events in Netwrix Change Tracker.
Resolving the "Number of pages in the report will exceed 250" error in Netwrix Change Tracker by increasing the MaxPagesInReport configuration setting.
Preventing Netwrix Change Tracker from recreating default OS groups after deletion by adding the CreateDefaultGroups configuration item.
Re-registering a device that was previously deleted from Netwrix Change Tracker using the Agents and Devices settings page.
Explaining what Redis QFork.dat files are, where they are stored for Netwrix Change Tracker, and when it is safe to delete them to recover disk space.
Instructions to reset the default admin password on Netwrix Change Tracker when the reset API is accessible only from the localhost on the Hub server.
Using the Planned Change Wizard to create a planned change schedule and resubmit unplanned events in bulk in Netwrix Change Tracker.
Configuring Netwrix Change Tracker to retrieve baseline events (file lists and hashes) after an agent or server restarts.
This article explains how to resolve the "AgentTaskRunner - task execution failed for task 11 - TrackerPollTask-Baseline-processtracker-88" error in the Rolling Log by adjusting the policy template in Netwrix Change Tracker.
Explains the cause and resolution for a Rolling-Log error where AgentTaskRunner fails due to a mismatched path-match type in a policy template in Netwrix Change Tracker.
Explains the "FileContentTrackerDataCollectorLocal - couldn't locate File entry" rolling-log message in Netwrix Change Tracker, when it is safe to ignore, and how to troubleshoot if the file should exist.
Explains the "Hub Offline, connection retries exhausted" rolling-log error for Netwrix Change Tracker agents and how to troubleshoot connectivity between the agent and the Netwrix Server.
Shows how to fix the Rolling-Log error "HubDetails - Crypto error. Has the agent process account changed since the password data was entered?" by repairing the HubDetails.xml file used by the Netwrix Change Tracker agent.
Explains the Rolling-Log error where ItemStoragePipeline cannot collect a file's SHA256 hash because the file is missing, and provides guidance and troubleshooting steps for Netwrix Change Tracker.
Explains the RegistryTrackerDataCollector error that indicates the Netwrix Change Tracker agent cannot access a registry key, why the error appears, and how to troubleshoot or safely ignore it.
Configuring syslog integration to forward Netwrix Change Tracker events to a Security Information and Event Management (SIEM) solution.
Resolving "System Error" messages when running event queries with text search in Netwrix Change Tracker by switching to regex search and increasing query timeouts.
Shows how to configure Netwrix Change Tracker to send a separate real-time email notification for each change, instead of compiling multiple changes into a single email.
Resolving the "System Error / An unknown error occurred" message when uploading agent updates in Netwrix Change Tracker by increasing the IIS maxAllowedContentLength value.
Describes the files stored in the Netwrix Change Tracker Gen 7 NetCore agent installation path, including Events.db, Config.xml, Rolling-log.txt, and HubDetails.xml.
Uninstalling the Netwrix Change Tracker agent using the silent uninstaller executable via PowerShell for both NetCore and non-NetCore installations.
Comprehensive guide for updating Netwrix Change Tracker agents from the Hub console, including download instructions, upload procedures, deployment scheduling, phased rollout strategies, testing recommendations, and troubleshooting.
Explains additional uses for baseline data in Netwrix Change Tracker beyond individual file change detection, including retaining full configuration records for network devices and firewalls, and points to the Baseline Center documentation for building and running a Baseline Policy.
Supported special characters for Netwrix Change Tracker user and agent passwords, and how to configure local password requirements.
Recommended services, processes, paths, and log locations to monitor with application performance monitoring (APM) tools for Netwrix Change Tracker's Gen7 Hub server and agents.
Explains why you are receiving File Access ("fileaccessed") events in Netwrix Change Tracker, what they indicate, and how to enable or disable them via policy templates.