Home » Get the Log Data » How to configure File Integrity Monitoring

How to get the changes to files and folders monitored


File Integrity monitoring helps you to monitor any changes such as addition, deletion or modification in your Windows system files and folders.

You can generate and schedule reports that gives you precise integrity details. You can also trigger an alert upon any changes in the files/folders, by setting up an alert profile

Requisites for file monitoring

  • The Windows machine, whose files/folders are to be monitored, must be added as a host (Windows) in EventLog Analyzer server

  • An agent should be installed in that particular machine

    • Note: An agent installed in a particular machine can monitor only the files and folders of that machine

Configuring File Integrity Monitoring

To configure File Integrity Monitoring, go to

  • Home tab > File Monitoring > Monitoring List > Actions: Add or
  • Settings tab > Configurations: File Monitoring > Add

    Configuration for FIM

     

  1. If you want to monitor the files/folders in a location that is same across various hosts, then you can save the location as a template and assign it to a number of hosts

  2. In the 'Assign host' field, you can either select the host from the auto-complete list or type the host name whose files/folders are to be monitored. You can select/enter multiple hosts only if the files/folders are in the same location across all the hosts

  3. In 'Location(s) File(s)' field, type the location (absolute path) of the files/folders which are need to be monitored. Alternatively you can also import a text file that contains the location

To import the text file click on 'Import' link

    Importing Locations - FIM

    1. Browse and select the text file, that contains the location of the files/ folders that are to be monitored

    2. Click on Import button to import the text file
  1. 'Exclude' field provides you an option to exclude certain sub-folders (contained in the folder specified above), from monitoring. Specify the location of the sub-folder in this field to exclude it from monitoring

  2. Save the configuration by clicking on 'Save Monitoring' button

  3. If you want to monitor the check sum changes in the files, then select the Checksum checkbox. The check sum changes will only be monitored for those files that are added, after enabling this feature

 

Note:
  • If an agent is already installed in the host for which you want to monitor the files, file monitoring will be enabled in the agent. For versions prior to 8050, if you were already using an agent for log collection, it will be uninstalled and 8050 version agent will be installed
  • If agent is not installed in the host for which you want to monitor the files, agent will be installed and file monitoring will be enabled in the agent

 

Caution:
Monitoring checksum is a CPU, memory intensive activity

 

File Integrity Monitoring Dashboard

Once you have configured hosts for monitoring,upon clicking File Integrity Monitoring from the Home page,you will have the File Integrity Monitoring dashboard

FIM Dashboard

  1. The overview graph displays the overall changes happened to the files and folders added for monitoring

  2. The tabular section of the dashboard, displays host wise changes in the files/folders, that are added for monitoring

    FIM-Add alert

With +Add Alert option,you can trigger an alert upon any changes to the files and folders that  are being added for monitoring

Generating and Scheduling Reports for File Monitoring

To view the file monitoring report, click on a host that has the files/folders for which you need the report for. This will open up the File monitoring Report page

FIM- Reports Dashboard

  • The reports page provides you the changes that has happened to the file/folder that you have added for monitoring

  • FIM Reports page provides you with Initial Details of the file/folder and the Current Details of the file/folder and the changes that had occurred. This helps you to perform Baseline Integrity monitoring. The files/folders are matched with the baseline to detect the changes during the integrity scan

You can also schedule the FIM report as follows,

FIM - Report Scheduling

  1. Select the File/folde for which you want to schedule the report,from the left pane

  2. Click on +Schedule button. This will open up the Add New Reports Page

In the Add New Reports page,

FIM-Report Schedule

  1. Provide the name for your FIM report

  2. You can schedule the report only once or at  regular intervals. To schedule the report for one time, choose Only once option. For scheduling the report at regular intervals, you can choose from  Hourly/Daily/Weekly/Monthly options

Scheduling Report for one time

If you choose to schedule the report only for a time, then

FIM-Report scheduling

  1. Specify the date at which the report is to be generated

  2. Select the time range from the predefined list, for which the report is to be generated

  3. Choose one of the report formats

  4. If you want to redistribute the report through email, check  'Email To' option and specify the email address in the corresponding field. You can enter multiple email ids separated by a comma. Ensure that you have already configured the email server. If not, click on the Configure your Mail Server here link to configure or reconfigure it

  5. Mention the message/notes that you want to specify along with the email in 'Add Notes' field

Click on Finish to generate and schedule the report

Scheduling the Report periodically

If you choose to schedule the report periodically, you can do it by scheduling the Report on Hourly/Daily/Weekly/Monthly basis

Scheduling on Monthly basis

FIM-Report scheduling-Monthly basis

  1. Select the date and time at which the report is to be generated every month

  2. Specify the time range for which the report is to be generated. For this scheduling on monthly basis you'll have Previous Month and Last 30 days options to choose from

  3. If you want to generate the report only for weekdays, check the Generate Report only for weekdays option

Scheduling on Weekly basis

FIM-Report Scheduling

  1. Select the day and time at which the report is to be generated every week

  2. Specify the time range for which the report is to be generated. You'll have Previous week and Last 7 days options to choose from

  3. Make use of the Time Filter option to select the time range for which the report is to be generated. You can select either Working Hours or Non - Working Hour time range.You can also define the Custom Time range for which the report will be generated

Note:

You can change the Working and Non working hour timing range with the Settings option

Scheduling on Daily basis

FIM-Report Scheduling

Specify the time (in hours) at which the report is to be generated daily

Choose the time range from the predefined  list for which the report will be generated. You'll have Previous Day and Last 24 hours options to choose from

Make use of the Time Filter to select the Working hours/Non Working hours/Custom time range

If you want this report generation only on weekdays, enable Run on Weekdays option

Scheduling on Hourly basis

FIM-Reports Scheduling

Specify the time at which the report is to be generated. With this option, the report will be generated exactly after an hour of the specified time

Choose the time range for which the report is to be generated, from the predefined list

After choosing either Hourly/Daily/Weekly/Monthly basis for report scheduling,

FIM-Report Scheduling

Choose one of the report formats

If you want to redistribute the report through email, check the 'Email To' option and specify the email address in the corresponding field. You can enter multiple email ids separated by a comma. Ensure that you have already configured the email server. If not, click on the Configure your Mail Server here link to configure it

Specify the message/notes that you want to specify along with the email in 'Add Notes' field

Click on Finish to generate and schedule the report

Setting up an alert for File Integrity Monitoring

With EventLog Analyzer, you can trigger an alert for any changes occurring to the files/folders  that are being monitored

    FIM-Alert

  1. Provide a unique name for your alert profile

  2. Choose the criticality level from High, Medium and Low for the alert profile

  3. File Integrity monitoring alert could be set up only for the host for which file integrity monitoring has been configured. Only those hosts will be available for selection, in the 'Select Host/Group' field. You can select the Windows host group as such to have the alert for all the hosts added for monitoring. Alternatively, you can also select individual hosts as per your requirement

  4. You can trigger the alert for any creation, deletion, modification or rename in the files/folders added for monitoring. The Location(s) field, narrows down your alerting criteria. Instead of generating alerts for changes in the entire file/folder,you can specify the alert to be triggered for changes in any sub-files/ sub-folders by specifying their location in this field

Note:

When you have set up the alert for multiple host, ensure that the location of the file/folder you specified exists and is same for all the hosts

  1. The triggered alert can be notified by Email, SMS. You can also remediate the alert condition by running a script using Run Program option.Before setting up the alert notification, you need to configure the Email and SMS settings

Click on the Add Alert Profile button for saving the alert profile

 

 
Copyright © 2013, ZOHO Corp. All Rights Reserved.
ManageEngine