Main Navigation Section

Change Auditor for Windows File Servers

Windows file auditing software tracks, reports and alerts on vital changes. Your Microsoft Windows file servers contain critical and sensitive information. But, it’s difficult to audit file access to specific documents, resulting in violations of information security policies and misuse of access rights. Issues can result in costly service disruptions and crippling network downtime. To avoid these problems, you need to be notified — in real time — of critical changes to your Windows file servers. Change Auditor for Windows File Servers makes that possible.

Change Auditor for Windows File Servers is the Windows file auditing software you need to drive the security and control of Windows file servers by tracking all key file access and folder changes in real time. You will instantly know the “who, what, when, where and originating workstation” details, and get the original and current values for fast troubleshooting. Control and audit changes to Microsoft Windows file servers efficiently and cost-effectively.

Key Benefits

Centralized auditing

Monitor and audit all file server changes from multiple servers and locations all from one single console.

At-a-glance display

Track user and admin activity with original and current values for change events using this Windows file auditing software.

Share auditing

Ensure admins have access to shared files by capturing change events in real time.

Object protection

Protect against changes to critical files and folders from being modified or accidentally deleted.

Real-time alerts on the move

Send critical change and pattern alerts to email and mobile devices to prompt immediate action, even while you're not on site.

SIEM integration

Enrich SIEM solutions including Sentinel, Splunk, ArcSight, QRadar or any platform supporting Syslog by integrating Change Auditor’s detailed activity logs.

Auditor-ready reporting

Generate comprehensive best practices reports for regulatory compliance mandates such as GDPR, SOX, PCI-DSS, HIPAA, FISMA, GLBA and more.

Features

Related searches

Provide instant, one-click access to all information on the change you're viewing and all related events, such as what other changes came from specific users and workstations, eliminating additional guesswork and unknown security concerns.

Superior auditing engine

Remove auditing limitations and captures change information without the need for Windows-provided audit logs, resulting in faster results and significant savings of storage resources.

Security timelines

View, highlight and filter change events and discover their relation to other security events in chronological order across your Windows environment for better forensic analysis and security incident response.

Improved security insights

Correlate disparate IT data from numerous systems and devices into IT Security Search, an interactive search engine for fast security incident response and forensic analysis. This Windows file server auditing solution includes user entitlements and activity, event trends, suspicious patterns and more with rich visualizations and event timelines.

North Central Texas Council of Government

If high-severity events occur, Change Auditor alerts us by email, so we can can determine whether the change was made properly through our change management process or is a malicious act by a hacker.

Brett Ogletree Information Security Officer, North Central Texas Council of Government

AFV Beltrame Group

With Change Auditor, we achieved our goal of gaining complete and centralized visibility of security audit operations across the entire Group — including not just our on-premises Windows file servers and domain controllers but also our Office 365 services, such as mail, SharePoint Online and OneDrive for Business

Mirco Destro CIO and IT Manager, AFV Beltrame Group

    Stevie Awards 2018 People’s Choice winner

    In the 2018 Stevie Award’s People Choice awards, Change Auditor was voted best software and also won a Silver Stevie for best new product of 2018.

    Specifications

    There are specific system requirements for the Change Auditor coordinator (server-side), Change Auditor client (client-side), Change Auditor agent (server-side), and the Change Auditor workstation and web client (optional components). For a full list of system requirements and required permissions for all components and target systems that can be audited by Change Auditor please refer to the Change Auditor Installation Guide.

    The Change Auditor coordinator is responsible for fulfilling client and agent requests and for generating alerts.

    Processor

    Quad core Intel® Core™ i7 equivalent or better

    Memory

    Minimum: 8 GB RAM or better

    Recommended: 32 GB RAM or better

    SQL Server

    SQL databases supported up to the following versions:

    • Microsoft SQL Server 2022
    • Microsoft SQL Server 2016 SP3
    • Microsoft SQL Server 2017
    • Microsoft SQL Server 2019
    • Azure SQL Managed Instance (PaaS) with SQL authentication or Azure Active Directory authentication

    NOTE: Performance may vary depending on network configuration, topology, and Azure SQL Managed Instance configuration.

    NOTE: Change Auditor supports SQL AlwaysOn Availability Groups, SQL Clusters, and databases that have row and page compression applied.

    Operating system

    Installation platforms (x64) supported up to the following versions:

    • Windows Server 2016
    • Windows Server 2019
    • Windows Server 2022

    NOTE: Microsoft Windows Data Access Components (MDAC) must be enabled. (MDAC is part of the operating system and enabled by default.)

    Coordinator software and configuration

    For the best performance, Quest strongly recommends:

    • Install the Change Auditor coordinator on a dedicated member server.
    • The Change Auditor database should be configured on a separate, dedicated SQL server instance.

    NOTE: Microsoft ODBC Driver 17 for SQL Server is required when the Change Auditor database resides on Azure SQL Managed Instance and Azure Active Directory authentication is selected.

    NOTE: Do NOT pre-allocate a fixed size for the Change Auditor database.

    In addition, the following software/configuration is required:

    • The coordinator must have LDAP and GC connectivity to all domain controllers in the local domain and the forest root domain.
    • x64 version of Microsoft’s .NET Framework 4.8
    • x64 version of Microsoft XML Parser (MSXML) 6.0
    • x64 version of Microsoft SQLXML 4.0
    Coordinator footprint
    • Estimated hard disk space used: 1 GB.
    • Coordinator RAM usage is highly dependent on the environment, number of agent connections, and event volume.
    • Estimated database size will vary depending on the number of agents deployed and audited events captured.

    Additional Account Coordinator minimum permissions required, please see Change Auditor Installation Guide .

    Get started now

    Improve Windows File Server security and compliance auditing.

    Support and Services

    Product Support

    Self-service tools will help you to install, configure and troubleshoot your product.

    Support Offerings

    Find the right level of support to accommodate the unique needs of your organization.

    Professional Services

    Search from a wide range of available service offerings delivered onsite or remote to best suit your needs.

    Education Services

    Training courses delivered through online web-based, on-site or virtual instructor-led.