Loading...
此版本发布于2023-07-15

用户操作手册 - 中文

充分了解 SKYAUDIT 产品的每一步操作,让您操作无障碍

邮件日志
内部威胁分析

用户活动分析
信息资产审计
The version was published on 2023-07-15

USER MANUAL - EN

Let you fully understand every operation of SKYAUDIT, Operational accessibility

Mail Log
Insider Threat Analysis
User Activity Analysis
Information Asset Audit
2023-07-15にリリースされました

ユーザーマニュアル - 日本語

SKYAUDITの各ステップを十分に理解し、バリアなしで操作できます

メールログ
内部脅威分析
ユーザー活動分析
情報資産監査
此版本发布于2023-07-15

管理员操作手册 - 中文

让管理员清楚每一个操作细节,轻松上手,快速操作

ESA的升级和迁移
数据库备份管理
终端审计管理
日志警告管理
版本配置
This version was released on July 15, 2023

Installation package

Support downloading multiple versions of installation packages

中文版
EN Version
日本語版
This version was released on July 15, 2023

Product White Paper

Detailed description of SKYAUDIT's functions, usage methods, and market positioning information

V5.0
V4.3

FAQ

“Disk Drive” is a storage device of the USB removable disk class.

Robert Fox
What kind of listening storage device does “Disk Drive” belong to in the Content column of the console storage device log?

Select the group corresponding to the client, click Group Configuration->General Log Settings to set the file upload interval, and set it to the required upload interval, if there are a large number of screenshots, it is not recommended to set a very short interval, which will cause pressure on the server.

Robert Fox
How to set the client log file upload interval?

The client has the status of "Started" or "Starting", "Started" indicates that the client is in the status of the startup log function successfully, "Waiting" means that the server is waiting for the client's response, and "Starting" indicates that the agent is starting a function or fails to start a function.

Robert Fox
What is the meaning of the status of each function on the client and when is it triggered?

You cannot view the image information of related logs in the ESA Portal/Console.

Robert Fox
What happens if a user manually deletes archived screenshots from a file server?

You cannot view the image information of related logs in the ESA Portal/Console.

Robert Fox
When an ESA database is backed up, will old data be deleted? Will there be any changes to the online database file size?

Old data is backed up to the offline database, the internal data size of the database is reduced, and the file size of the online database is not reduced unless the user manually shrinks the database. When new data is inserted, unused space inside the database is taken, so there is no need to manually shrink the database.

Robert Fox
When an ESA database is backed up, will old data be deleted? Will there be any changes to the online database file size?

Elapsed time and CPU usage time are measured in seconds.

Robert Fox
What are the units of elapsed time and CPU usage time in application logs?

ISMSWebDAVUser's password is not allowed to be changed.

Robert Fox
Can users change the password of ISMSWebDAVUser?

The ESA Portal/Console is not available for the operation as it will affect the logs of the client in question.

Robert Fox
Can I delete a client under an inactive client?

The amount of logs depends on the configuration, for example, the daily log volume of 1,000 clients is about 0.4 Gbit/s. The screen recording file size depends on the screen recording interval and resolution set (about 10K~200K per image).

Robert Fox
How many logs are generated per 1,000 clients after all audit logs are enabled?

There is no effect on the functionality of the product. If you automatically obtain an IP address, you can query the user by user name and machine name.

Robert Fox
When users are mobile in different factories, the IP address is automatically obtained, whether it has an impact on product functions and whether it has an impact on the audit. How to ensure that policies are unified and users are accurately identified during audits?

ESA provides warning emails based on keyword logs. The above requirement requires regular statistics of a certain phenomenon. It is suggested that users can realize the above requirement by using the built-in mail and analysis function of SQLServer.

Robert Fox
Is it possible to realize automatic alarm: after customizing the rules of file leakage (such as more than XX copies or more than XXMB size or more than XX times of external operations), if any employee violates the rules, the system will automatically record the logs and alert the administrator?

When the contents of the DiskDrive Type column of the ESADiskDriveLog table are equal to the ID in the EnumDiskDriverType table, the storage type is the content type mapped to that ID.

Robert Fox
How do I distinguish the storage type between the data types in the DiskDrive Type column in the ESADiskDriveLog table?

The newly installed ESA agent is automatically registered every 10 minutes, and if a license is available, it can be used after successful registration.

Robert Fox
If the license points are exhausted and some of the ESAAgents that have occupied the license are released, can the newly installed ESAAgent client still be used?

By default, the log retention period is 30 days, and if new logs are generated after 30 days, the logs older than 30 days will be deleted.

Robert Fox
What is the default value for log retention time for client group configuration?

It may be related to the password security policy of the user environment, you can try to adjust the security policy appropriately or temporarily disable the policy before installing.

Robert Fox
What Is the Reason for the Failure to Create ISMSWebDavUser When I Install ESA Server?

UpdateTime is UTC and ServerTime is the time zone standard time.

Robert Fox
What Are the Time Zones for ServerTime and UpdateTime of Logs?

By default, Exe Plolle and Kemud Exe. Even if Felix Log's listening process is not set, Exproller. Ex and Kemud. Felix Logge of Ex.

Robert Fox
What processes does the Ilijax Logg system listen to by default?

Because it involves screenshot operations, the screenshot upload time of web page access logs is processed according to the rules of screenshot logs. The same goes for screenshots of the clipboard log.

Robert Fox
Why is the screenshot file of the web page access log not packaged even when it is time to upload?
Top