Get a single, correlated view of all SharePoint, SharePoint Online and OneDrive for Business activity whether on-prem or in the cloud.
Store audit data in one centralized and secure database, providing separation of duties (SoD) between SharePoint admins and security staff.
Track changes to SharePoint server configurations and security changes involving users, permissions, farms, servers, lists and more.
Track user and administrator activity with detailed information for change events, plus original and current values for all changes.
Narrow searches from multiple SharePoint sources by event type, user account and more, enabling administrators to pinpoint the source of issues.
Send critical change and pattern alerts to email and mobile devices to prompt immediate action, even while you're not on site.
Enrich SIEM solutions including Sentinel, Splunk, ArcSight, QRadar or any platform supporting Syslog by integrating Change Auditor’s detailed activity logs.
Provides preconfigured and customizable reports that satisfy auditor requests so that administrators can get back to their regular jobs quickly.
View, highlight and filter change events and discover their relation to other security events in chronological order across your Microsoft environment for better forensic analysis and security incident response.
Correlate disparate IT data from numerous systems and devices into IT Security Search, an interactive search engine for fast security incident response and forensic analysis. Include user entitlements and activity, event trends, suspicious patterns and more with rich visualizations and event timelines.
Provide instant, one-click access to all information on the change you're viewing and all related events, such as what other changes came from specific users and workstations, eliminating additional guesswork and unknown security concerns.
Remove auditing limitations and capture change information using this NetApp monitoring tool – without the need for system-provided audit logs, resulting in faster results and significant savings of storage resources.
There are specific system requirements for the Change Auditor coordinator (server-side), Change Auditor client (client-side), Change Auditor agent (server-side), and the Change Auditor workstation and web client (optional components). For a full list of system requirements and required permissions for all components and target systems that can be audited by Change Auditor please refer to the Change Auditor Installation Guide.
The Change Auditor coordinator is responsible for fulfilling client and agent requests and for generating alerts.
Quad core Intel® Core™ i7 equivalent or better
Minimum: 8 GB RAM or better
Recommended: 32 GB RAM or better
SQL databases supported up to the following versions:
NOTE: Performance may vary depending on network configuration, topology, and Azure SQL Managed Instance configuration.
NOTE: Change Auditor supports SQL AlwaysOn Availability Groups, SQL Clusters, and databases that have row and page compression applied.
Installation platforms (x64) supported up to the following versions:
NOTE: Microsoft Windows Data Access Components (MDAC) must be enabled. (MDAC is part of the operating system and enabled by default.)
For the best performance, Quest strongly recommends:
NOTE: Microsoft ODBC Driver 17 for SQL Server is required when the Change Auditor database resides on Azure SQL Managed Instance and Azure Active Directory authentication is selected.
NOTE: Do NOT pre-allocate a fixed size for the Change Auditor database.
In addition, the following software/configuration is required:
Additional Account Coordinator minimum permissions required, please see Change Auditor Installation Guide .