# SIEM, Event Log Monitoring & Server Monitoring > EventSentry offers affordable SIEM functionality, rock-solid server monitoring, event log monitoring with AD changes and cyber security tracking. This file provides a curated overview of 1024 key pages on https://www.eventsentry.com to help LLMs understand and navigate the site content. When referencing content from this site, please cite https://www.eventsentry.com as the source and link to the specific page URL. ## Home - [SIEM, Event Log Monitoring & Server Monitoring](https://www.eventsentry.com/): EventSentry offers affordable SIEM functionality, rock-solid server monitoring, event log monitoring with AD changes and cyber security tracking. ## Pages - [Validate your IT infrastructure with EventSentry | EventSentry](https://www.eventsentry.com/validationscripts): EventSentry's include out-of-the-box security checks to ensure that your network infrastructure includes a strong baseline. - [EventSentry v6.0 | New Features | EventSentry](https://www.eventsentry.com/6.0): EventSentry v6.0 is now available with powerful security features, local inventory, compromised password, threat scoring, sysmon management, plus expanded reporting capabilities - [SysAdmin Tools Changelog | EventSentry](https://www.eventsentry.com/sysadmintools-changelog): EventSentry SysAdmin Tools Changelog with details on new features and bugfixes for each release. - [Windows Event Log Monitoring and Centralized Database Consolidation | EventSentry](https://www.eventsentry.com/features): Real-Time Event log and SIEM monitoring is the core monitoring component of EventSentry, and features one of most sophisticated filtering engines on the market. - [Ransomware Detection and Mitigation : Real-time Alerts and Dashboards | EventSentry](https://www.eventsentry.com/ransomware): EventSentry can detect Ransomware and similar attacks in real time - whether it’s at the reconnaissance, exploitation, persistence, propagation or execution stage. - [EventSentry for Healthcare Organizations | EventSentry](https://www.eventsentry.com/healthcare): Protect senstive data access in your environment. Meet your compliance requirements with easy to use dashboards and real-time alerts. - [Why Monitor Active Directory Changes? | EventSentry](https://www.eventsentry.com/active-directory-changes): Windows Active Directory (AD) change monitoring is critical for security and required by many compliance requirements - [SysAdmin Tools | EventSentry](https://www.eventsentry.com/sysadmintools): The EventSentry SysAdmin Tools is a set of command-line and graphical utilities designed to help network administrators with their daily administrative tasks. - [Windows Workstation Monitoring | EventSentry](https://www.eventsentry.com/workstation-monitoring): Many attacks start on workstations, so having full visibility can be crucial. EventSentry increases the security of your network when you monitor workstations. - [Windows Account Lockouts : Real-time Alerts and Dashboards | EventSentry](https://www.eventsentry.com/account-lockouts): Using EventSentry you can immediately know when users are locked out on your network - [EventSentry for IT Security Monitoring | EventSentry](https://www.eventsentry.com/it-security): Protect senstive data access in your environment. Meet your compliance requirements with easy to use dashboards and real-time alerts. - [Windows Server Monitoring | EventSentry](https://www.eventsentry.com/server-monitoring): EventSentry's server monitoring capabilities take a 360 view on the log, network and overall performance of the servers, both on-premise and in the cloud - [EventSentry for Schools, Education | EventSentry](https://www.eventsentry.com/education): Protect senstive data access in your environment. Meet your compliance requirements with easy to use dashboards and real-time alerts. - [Knowledge Base | EventSentry](https://www.eventsentry.com/howto): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Knowledge Base | EventSentry](https://www.eventsentry.com/sales-faq): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [EventSentry for Government | EventSentry](https://www.eventsentry.com/government): Full visibility to senstive data access in your environment. Meet your compliance requirements with easy to use dashboards and real-time alerts. - [EventSentry for Finance and Banking | EventSentry](https://www.eventsentry.com/finance-banking): EventSentry v4.2 is now available with enhanced ransomware detection, software version checking, plus expanded Syslog formats - [CMMC Compliance Software for Defense Contractors | EventSentry](https://www.eventsentry.com/what-is-cmmc-compliance): EventSentry helps organizations meet CMMC compliance with continuous monitoring event and confirm STIG security controls. - [What is NetFlow? | EventSentry](https://www.eventsentry.com/what-is-netflow): NetFlow is a network protocol developed by Cisco Systems that collects network data for network performance, traffic patterns, and security threats. - [Security Orchestration, Automation, and Response (SOAR) Software | EventSentry](https://www.eventsentry.com/soar): Learn how on-premise SIEM solutions can help automate, orchestrate, and streamline security operations for faster threat detection and response. - [Pricing | EventSentry](https://www.eventsentry.com/pricing): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [On-premise SIEM solution | EventSentry](https://www.eventsentry.com/on-premise-siem): Discover the benefits of on-premise SIEM solutions, including control over data, customization, scalability, performance, and integration. - [Demonstrate PCI DSS Compliance with auditing | EventSentry](https://www.eventsentry.com/pci-dss-compliance-software): EventSentry helps organizations demonstrate PCI-DSS with continuous monitoring audit log events and confirm STIG security controls. - [Controlled Unclassified Information (CUI) Software | EventSentry](https://www.eventsentry.com/cui-data): Secure your Controlled Unclassified Information (CUI) with our monitoring software. Get real-time insights into access controls and safeguard sensitive data from unauthorized access. Request a free ... - [What is File Integrity Monitoring? | EventSentry](https://www.eventsentry.com/what-is-file-integrity-monitoring): Secure your Controlled Unclassified Information (CUI) with our monitoring software. Get real-time insights into access controls and safeguard sensitive data from unauthorized access. Request a free ... - [Event Log Consolidation | EventSentry](https://www.eventsentry.com/event-log-consolidation): EventSentry helps organizations meet CMMC with continuous monitoring event and confirm STIG security controls. - [Switch to the most affordable, fully functional SIEM on the market](https://www.eventsentry.com/switch): Make the switch to EventSentry. We offer competitive discounts and friendly licensing. - [Full vs Light | EventSentry](https://www.eventsentry.com/downloads): Detailed comparison between EventSentry and EventSentry Light - [About Us | EventSentry](https://www.eventsentry.com/about): Founded in 2002, EventSentry is developed in direct response to requests and feedback from Systems Administrators 'in the field.' - [Solutions | EventSentry](https://www.eventsentry.com/solutions): Learn how EventSentry provides robust server, log, network & application monitoring. Learn how EventSentry solutions can - [Benefits of Consolidating to SIEM | EventSentry](https://www.eventsentry.com/benefits-of-consolidation): EventSentry v5.0 is now available with enhanced ransomware detection, software version checking, plus expanded Syslog formats - [Event Log Monitoring with real-time alerts, dashboards and consolidated search | EventSentry](https://www.eventsentry.com/event-log-monitoring): EventSentry helps organizations consolidate and monitoring their event logs. Identify Account Lockouts, security group changes, and rogue software installations. - [Admin Assistant | EventSentry](https://www.eventsentry.com/adminassistant): Admin Assistant lets you query or update a variety of Windows settings and services across any number of servers and/or workstations, without the need to create a script or perform the actions manua... - [Compliance Validator | EventSentry](https://www.eventsentry.com/compliance-validator): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [PingSentry - Monitor the uptime of your websites | EventSentry](https://www.eventsentry.com/pingsentry): PingSentry is a web service that monitors the availability of your websites or public hostnames over ping or custom TCP ports ## About - [Testimonial | EventSentry](https://www.eventsentry.com/about/testimonials): EventSentry customer testimonials. More uses than a Swiss Army Knife! - [Reviews & Awards | EventSentry](https://www.eventsentry.com/about/in-the-press): EventSentry Reviews, Awards and Press coverage. Voted WindowSecurity.com Readers' Choice Award Winner - Event Log Monitoring - [Our Customers | EventSentry](https://www.eventsentry.com/about/our-customers): A few EventSentry customers along with a case study Forging More Uptime - [Our SysAdmin Promise | EventSentry](https://www.eventsentry.com/about/our-sysadmin-promise): EventSentry is built with our SysAdmin Promise in mind - [Case Studies | EventSentry](https://www.eventsentry.com/about/case-studies): EventSentry customer testimonials. More uses than a Swiss Army Knife! - [Live Demo | EventSentry](https://www.eventsentry.com/about/livedemo): EventSentry Live Demo illustrating our Dashboards, Compliance Tracking and System Health ## Blog - [Xming Terminal Vt100](https://www.eventsentry.com/blog/xming_terminal_vt100.html) - [Aa Firefox Netframeworkassistant Registry](https://www.eventsentry.com/blog/aa_FireFox_NetFrameworkAssistant_Registry.html) - [Xming Desktop](https://www.eventsentry.com/blog/xming_desktop.html) - [From PowerShell to p@W3RH311 – Detecting and Preventing PowerShell Attacks](https://www.eventsentry.com/blog/2018/01/powershell-pw3rh311-detecting-preventing-powershell-attacks.html) - [A SNMP-enabled temperature + humidity sensor for under $110](https://www.eventsentry.com/blog/2022/02/a-snmp-enabled-temperature-humidity-sensor-for-under-110.html) - [From PowerShell to P0W3rH3LL - Auditing PowerShell](https://www.eventsentry.com/blog/2018/01/powershell-p0wrh11-securing-powershell.html): Securing PowerShell - Mitigate PowerShell Attacks - [UNICODE - ONE code to rule them all](https://www.eventsentry.com/blog/2010/04/unicode-one-code-to-rule-the.html) - [CryptoLocker Defense for Sysadmins (Part 1/3)](https://www.eventsentry.com/blog/2013/12/cryptolocker-defense-for-sysadmins.html): Explains how sysadmins can actively defend against CryptoLocker using the EventSentry Light monitoring suite - [Trapping CryptoLocker/CryptoWall with Honey (Part 2/3)](https://www.eventsentry.com/blog/2015/11/trapping-cryptolockercryptowall-with-honey.html) - [Why complex passwords may be less secure than you think](https://www.eventsentry.com/blog/2011/08/why-complex-passwords-can-be-i.html) - [Agent vs Agentless: Why you should monitor (event) logs with an agent-based log monitoring solution](https://www.eventsentry.com/blog/2017/03/agent-vs-agentless-why-you-should-monitor-event-logs-with-an-agent-based-log-monitoring-solution.html) - [Remote Support with VNC - The Easy & Secure Way!](https://www.eventsentry.com/blog/2017/02/remote-support-with-vnc-the-easy-secure-way.html) - [Creating your very own event message DLL](https://www.eventsentry.com/blog/2010/11/creating-your-very-own-event-m.html) - [EventSentry v3.4: New Security Features, Software Version Checker, Better Performance & more!](https://www.eventsentry.com/blog/2017/11/eventsentry-v3-4-new-security-features-software-version-checker-better-performance-more.html) - [How to make the Windows Software RAID log to the event log](https://www.eventsentry.com/blog/2012/02/how-to-make-the-windows-softwa.html) - [An alternative to email alerts. Part 1: Using Trello to manage EventSentry's alerts](https://www.eventsentry.com/blog/2014/10/an-alternative-to-email-alerts-part-1-using-trello-to-manage-eventsentrys-alerts.html) - [Do not trust thee RAID alone](https://www.eventsentry.com/blog/2011/02/do-not-trust-thee-raid.html) - [RDProtector: Automatically blocking malicious IPs from RDP with EventSentry](https://www.eventsentry.com/blog/2019/07/rdprotector-automatically-blocking-malicious-ips-from-rdp-with-eventsentry.html) - [Predict the Future! A universal approach to detecting malicious PowerShell activity ](https://www.eventsentry.com/blog/2023/12/predict-the-future-a-universal-approach-to-detecting-malicious-powershell-activity.html) - [Auditing DNS Server Changes on Windows 2012 R2 and later with EventSentry](https://www.eventsentry.com/blog/2017/10/auditing-dns-server-changes-on-windows-2012-r2-and-later-with-eventsentry.html) - [Defeating Ransomware with EventSentry & Auditing (Part 3/3)](https://www.eventsentry.com/blog/2016/03/defeating-ransomware-with-eventsentry-auditing.html) - [Detecting Web Server Scans in Real-Time](https://www.eventsentry.com/blog/2016/11/detecting-web-server-scans-in-real-time.html) - [Covid-19: The importance of data & how it relates to Network Security](https://www.eventsentry.com/blog/2020/03/how-covid19-relates-to-network-security.html) - [NTFS Alternate Data Streams: Hiding data in plain sight since 1993](https://www.eventsentry.com/blog/2008/07/ntfs-alternate-data-streams-hi.html) - [Curiosity Kills the Cat](https://www.eventsentry.com/blog/2010/07/curiousity-kills-the-cat.html) - [Firefox .NET Framework Assistant Paranoia](https://www.eventsentry.com/blog/2009/06/firefox-net-framework-assistan.html) - [Event Log Message Files (The description for Event ID ... cannot be found)](https://www.eventsentry.com/blog/2008/04/event-log-message-files-the-de.html) - [How to REALLY monitor SMTP, POP3 and IMAP on Exchange 2003](https://www.eventsentry.com/blog/2010/02/how-to-really-monitor-smtp-pop.html) - [Mobile Alerts: Pushing EventSentry alerts directly to your mobile devices with Prowl and NMA](https://www.eventsentry.com/blog/2013/08/pushing-alerts-directly-to-your-mobile-device-with-prowl-and-nma.html): How to create effective mobile alerts by pushing network monitoring and system monitoring alerts from EventSentry to an Apple or Android mobile device - [EventSentry v6: Azure Logs, HEC, Sigma, Log Signing & More](https://www.eventsentry.com/blog/2026/01/eventsentry-v6-azure-logs-hec-sigma-log-signing-more.html) - [Get your KIX on route 66 - Powerful (login) scripts made easy with KiXtart](https://www.eventsentry.com/blog/2009/09/get-your-kix-on-route-66-pow.html) - [Finding a crashing TAPI driver and re-organizing svchost.exe](https://www.eventsentry.com/blog/2009/03/troubleshooting-svchostexe.html) - [Are disconnected RDP sessions ticking time bombs in your network?](https://www.eventsentry.com/blog/2022/04/are-disconnected-rdp-sessions-ticking-time-bombs-in-your-network.html) - [EventSentry v3.3 Part 1: NetFlow, Easier Deployment & Laptop Monitoring](https://www.eventsentry.com/blog/2016/12/eventsentry-v3-3-part-1-netflow-easier-deployment-laptop-monitoring.html) - [Defeating Ransomware with EventSentry - Remediation](https://www.eventsentry.com/blog/2016/09/defeating-ransomware-with-eventsentry-remediation.html) - [3-2-1-Go! EventSentry 3.2.1 is out!](https://www.eventsentry.com/blog/2016/02/3-2-1-eventsentry-3-2-1-is-out.html) - [Wish Sandwich - 5 (free) tools we wish Windows had](https://www.eventsentry.com/blog/2009/08/wish-sandwich-5-tools-we-wis.html) - [Automatically restarting services or processes based on resource usage](https://www.eventsentry.com/blog/2016/02/automatically-restarting-memory-hungry-services.html) - [Managing Windows Services & Service Credentials](https://www.eventsentry.com/blog/2014/09/managing-services-service-credentials.html) - [How to dynamically toggle your Wireless adapter with EventSentry](https://www.eventsentry.com/blog/2012/01/how-to-dynamically-toggle-your.html) - [EventSentry v3.5 Released: Windows Process Monitoring to the Max, Registry Tracking, Tags & More](https://www.eventsentry.com/blog/2018/07/eventsentry-v3-5-released-windows-process-monitoring-max-registry-tracking-tags.html) - [Securing Exchange Server OWA & ActiveSync - Proactive Security with EventSentry](https://www.eventsentry.com/blog/2017/12/securing-exchange-server-owa-activesync-proactive-security-with-eventsentry.html) - [Group Policy Software Deployment: Targeting the right computers with WMI filters](https://www.eventsentry.com/blog/2009/10/useful-wmi-queries-to-filter-g.html) - [Announcing EventSentry v2.91](https://www.eventsentry.com/blog/2009/11/announcing-eventsentry-v291.html) - [EventSentry v5.2: Processes, Security & Inventory](https://www.eventsentry.com/blog/2025/03/eventsentry-v5-2-processes-security-inventory.html) - [The Network Monitoring Focus of the EventSentry SysAdmin Tools](https://www.eventsentry.com/blog/2014/06/the-network-monitoring-focus-of-the-eventsentry-sysadmin-tools.html) - [Running Linux applications on Windows - over the network with Xming](https://www.eventsentry.com/blog/2009/04/running-linux-applications-on.html) - [Cleaning up Disk Space and automatic fragmentation reports via email](https://www.eventsentry.com/blog/2009/02/cleaning-up-disk-space-defragm.html) - [Auditing DNS Server Changes on Windows 2008/2008R2/2012 with EventSentry](https://www.eventsentry.com/blog/2017/11/auditing-dns-server-changes-on-windows-20082008r22012-with-eventsentry.html) - [EventSentry v4.0 - Introducing ADMonitor](https://www.eventsentry.com/blog/2019/03/eventsentry-v4-0-introducing-admonitor.html) - [EventSentry v5.1: Anomaly Detection / Permission Inventory / Training Courses & More!](https://www.eventsentry.com/blog/2023/11/eventsentry-v5-1-anomaly-detection-permission-inventory-training-courses-more.html) - [It's Not Black Magic: Malware & Ransomware in Plain English](https://www.eventsentry.com/blog/2024/02/its-not-black-magic-malware-ransomware-in-plain-english.html) - [EventSentry v2.93.1 - Part 2](https://www.eventsentry.com/blog/2012/07/eventsentry-v2931-part-2.html) - [EventSentry v4.1](https://www.eventsentry.com/blog/2019/12/eventsentry-v4-1.html) - [Revealing Suspicious VPN Activity with Anomaly Detection](https://www.eventsentry.com/blog/2024/01/revealing-suspicious-vpn-activity-with-anomaly-detection.html) - [EventSentry v2.90: Event Log Monitoring Changes](https://www.eventsentry.com/blog/2008/11/eventsentry-v290-event-log-mon.html) - [Top Events You Should Always Audit & Monitor](https://www.eventsentry.com/blog/2021/05/top-events-you-should-always-audit-monitor.html) - [EventSentry v3.3 Part 2: Event annotation, Filter Chaining, RegEx and more](https://www.eventsentry.com/blog/2016/12/eventsentry-v3-3-part-2-event-annotation-filter-chaining-regex-and-more.html) - [Operational Event 567? Maybe sometimes.](https://www.eventsentry.com/blog/2008/03/operational-event-567-maybe-so.html) - [How the EventSentry SysAdmin Tools Focus on File System Maintenance](https://www.eventsentry.com/blog/2014/08/how-the-eventsentry-sysadmin-tools-focus-on-file-system-maintenance.html) - [Validating your IT environment, discovering browser extensions & more with EventSentry v4.2](https://www.eventsentry.com/blog/2020/10/validating-your-it-environment-discovering-browser-extensions-more-with-eventsentry-v4-2.html) - [Tracking Objects with 560 and 562 Object Access events](https://www.eventsentry.com/blog/2008/03/tracking-objects-with-560-and.html) - [How to identify long-running processes](https://www.eventsentry.com/blog/2015/01/how-to-identify-long-running-processes.html) - [Vista Event Log Changes](https://www.eventsentry.com/blog/2007/12/vista-event-log-changes.html) - [The “Check” Monitoring Utilities of the EventSentry SysAdmin Tools](https://www.eventsentry.com/blog/2014/05/the-check-monitoring-utilities-of-the-eventsentry-sysadmin-tools.html) - [Monitoring Windows Updates](https://www.eventsentry.com/blog/2013/02/monitoring-windows-updates.html) - [Mr. Fix It: Reviving a relative's computer](https://www.eventsentry.com/blog/2008/08/fixing-a-relatives-computer.html) - [Your favorite tools and utilities always available everywhere (almost)](https://www.eventsentry.com/blog/2008/09/keeping-your-tools-handy.html) - [Can the EventSentry Agents cause the same outage & disruption like the CrowdStrike Falcon sensor did?](https://www.eventsentry.com/blog/2024/07/can-the-eventsentry-agents-cause-the-same-outage-disruption-like-the-crowdstrike-falcon-sensor-did.html) - [EventSentry v2.92 + iPhone App](https://www.eventsentry.com/blog/2011/06/eventsentry-iphone-app-new-v29.html) - [EventSentry v2.93.1 - Part 1](https://www.eventsentry.com/blog/2012/06/eventsentry-v2931-part-1.html) - [Reliable SMS Alerting with the SMSEagle](https://www.eventsentry.com/blog/2015/02/reliable-sms-alerting-with-the-smseagle.html) - [EventSentry v2.90: Compliance Tracking for SOX, PCI, GLBA, HIPAA, FISMA, COBIT, ...](https://www.eventsentry.com/blog/2008/12/eventsentry-v290-compliance-tr.html) - [Perfect hardware for a TV-based dashboard](https://www.eventsentry.com/blog/2016/06/perfect-hardware-for-a-tv-based-dashboard.html) - [Auditing Changes to Microsoft SQL Server Database Tables](https://www.eventsentry.com/blog/2009/05/auditing-changes-to-mssql-data.html) - [Server Virtualization: Physical to Virtual Migration](https://www.eventsentry.com/blog/2008/02/server-virtualization-physical.html) - [Announcing AutoAdministrator v2.0](https://www.eventsentry.com/blog/2009/01/announcing-autoadministrator-v.html) - [The Essential Security Tools of the EventSentry SysAdmin Tools](https://www.eventsentry.com/blog/2014/04/the-essential-security-tools-of-the-eventsentry-sysadmin-tools.html) - [Automatically shutting down workstations](https://www.eventsentry.com/blog/2007/11/automatically-shutting-down-wo.html) - [Automatically Restarting a Failed Windows Process](https://www.eventsentry.com/blog/2014/01/automatically-restarting-a-process.html) - [A Better & Faster Ping](https://www.eventsentry.com/blog/2012/06/a-better-faster-ping.html) - [Event 4964: Special Groups Feature for Vista + Windows 2008 Entrepreneurs](https://www.eventsentry.com/blog/2008/05/event-4964-special-groups-feat.html) - [Who Is In My Server Room?](https://www.eventsentry.com/blog/2007/11/who-is-in-my-server-room.html) - [Plink - or - Issuing SSH Commands on Demand](https://www.eventsentry.com/blog/2007/12/plink-or-issuing-ssh-command-o.html) - [Vista/Win2k8 Event Log Changes #2: .evtx Format](https://www.eventsentry.com/blog/2007/12/vistawin2k8-event-log-changes.html) - [EventSentry 5.1.1.104: Security, Security, Security!](https://www.eventsentry.com/blog/2024/05/eventsentry-5-1-1-104-security-security-security.html) - [Mr. Robot, Mimikatz and Lateral Movement](https://www.eventsentry.com/blog/2017/12/mr-robot-mimikatz-and-lateral-movement.html) - [The tale of the dying capacitors](https://www.eventsentry.com/blog/2008/01/troubleshooting-can-be-frustra.html) - [Additional Notes on EventSentry Update v3.2.1.30](https://www.eventsentry.com/blog/2016/04/additional-notes-on-eventsentry-update-v3-2-1-30.html) - [Setting Service permissions with subinacl.exe](https://www.eventsentry.com/blog/2007/11/setting-service-permissions-wi.html) - [Capturing Network Traffic anytime](https://www.eventsentry.com/blog/2025/01/capturing-network-traffic-anytime.html) - [The Life of the Sysadmin: A Patch Tuesday Story](https://www.eventsentry.com/blog/2023/01/the-life-of-the-sysadmin-a-patch-tuesday-story.html) - [Applying Patches and Updates with Group Policy](https://www.eventsentry.com/blog/2008/06/push-out-updates-with-group-po.html) - [Monitoring Transaction Log Files for PCI compliance](https://www.eventsentry.com/blog/2022/10/monitoring-transaction-log-files-for-pci-compliance.html) - [EventSentry Light Supercharged](https://www.eventsentry.com/blog/2013/06/eventsentry-light-supercharged.html) - [An alternative to email alerts. Part 2: Integrating EventSentry with Slack](https://www.eventsentry.com/blog/2015/10/an-alternative-to-email-alerts-part-2-integrating-eventsentry-with-slack.html) - [EventSentry SysAdmin Tools: New SNMP query utility "snmptool](https://www.eventsentry.com/blog/2015/12/eventsentry-sysadmin-tools-new-snmp-query-utility-snmptool.html) - [NTToolkit Update with three more utilities: CheckDB, CheckURL and NTPClient](https://www.eventsentry.com/blog/2008/05/new-version-of-our-free-nttool.html) - [Announcing EventSentry Light v2.93.1](https://www.eventsentry.com/blog/2012/09/eventsentry-light-v2931.html) - [Showing Server Uptime with uptime.exe](https://www.eventsentry.com/blog/2008/04/showing-server-uptime-with-upt.html) - [EventSentry Mobile v1.3 for iOS Available!](https://www.eventsentry.com/blog/2014/01/eventsentry-mobile-v1-3-for-ios-available.html): The new version of the EventSentry Mobile app is optimized for iOS 7 and includes a networking tool dialog to ping hosts and perform DNS and GEO IP lookups - [Discovering vulnerable Log4J libraries on your network with EventSentry](https://www.eventsentry.com/blog/2021/12/discovering-vulnerable-log4j-libraries-on-your-network-with-eventsentry.html) - [EventSentry SysAdmin Tools: Digital Signature Verification with checksum.exe](https://www.eventsentry.com/blog/2018/03/eventsentry-sysadmin-tools-digital-signature-verification-checksum-exe.html) - [EventSentry Mobile Updates for iOS & Android](https://www.eventsentry.com/blog/2013/03/eventsentry-mobile-updates-for.html) - [AutoAdministrator: Chapter 3](https://www.eventsentry.com/blog/2017/06/autoadministrator-chapter-3.html) - [EventSentry on GitHub: PowerShell module, templates and more!](https://www.eventsentry.com/blog/2021/06/eventsentry-on-github-powershell-module-templates-and-more.html) - [Inauguration](https://www.eventsentry.com/blog/2007/11/inauguration.html) - [Gateway IP Monitor Update with DynDNS update feature](https://www.eventsentry.com/blog/2008/06/gateway-ip-monitor-update-with.html) - [1983: Coleco Adam](https://www.eventsentry.com/blog/2008/02/1983-coleco-adam.html) ## Documentation - [EventSentry Help v6.0](https://www.eventsentry.com/documentation/help/html/hmftsearch.htm) - [EventSentry Best Practices](https://www.eventsentry.com/documentation/bestpractices/html/hmftsearch.htm) - [EventSentry Overview](https://www.eventsentry.com/documentation/overview/html/hmftsearch.htm) - [Threat Detection with EventSentry](https://www.eventsentry.com/documentation/threatdetection/HTML/hmftsearch.html) - [Threat Detection with EventSentry](https://www.eventsentry.com/documentation/threatdetection/HTML/hmkwindex.html) - [EventSentry Overview](https://www.eventsentry.com/documentation/overview/html/hmkwindex.htm) - [EventSentry Best Practices](https://www.eventsentry.com/documentation/bestpractices/html/hmkwindex.htm) - [EventSentry Help v6.0](https://www.eventsentry.com/documentation/help/html/hmkwindex.htm) - [Threat Detection with EventSentry](https://www.eventsentry.com/documentation/threatdetection/HTML/hmcontent.html) - [EventSentry Help v6.0](https://www.eventsentry.com/documentation/help/html/hmcontent.htm) - [EventSentry Overview](https://www.eventsentry.com/documentation/overview/html/hmcontent.htm) - [EventSentry Best Practices](https://www.eventsentry.com/documentation/bestpractices/html/hmcontent.htm) - [EventSentry Help v6.0](https://www.eventsentry.com/documentation/help/6_0_1/de/html/hmftsearch.htm) - [EventSentry Help v6.0](https://www.eventsentry.com/documentation/help/6_0_1/de/html/hmkwindex.htm) - [EventSentry Help v6.0](https://www.eventsentry.com/documentation/help/6_0_1/de/html/hmcontent.htm) ## Downloads - [Release History | EventSentry](https://www.eventsentry.com/downloads/version-history): Detailed list of new features and bugfixes in each release of EventSentry - [Release History | EventSentry](https://www.eventsentry.com/downloads/release-history): Detailed list of new features and bugfixes in each release of EventSentry - [Trial Request | EventSentry](https://www.eventsentry.com/downloads/trial): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Create Certificate | EventSentry](https://www.eventsentry.com/downloads/create-cert): Create self signed certificate for SSL encryption for use with EventSentry - [Download EventSentry Light : Select Edition | EventSentry](https://www.eventsentry.com/downloads/select-edition): Detailed comparison between an EventSentry trial and EventSentry Light - [EventSentry Home Lab License | EventSentry](https://www.eventsentry.com/downloads/homelab): Request our EventSentry Home Lab license - [Latest Patch | EventSentry](https://www.eventsentry.com/downloads/latest-patch): Detailed list of updates and fix included in the latest build of EventSentry ## Features - [System Health Monitoring | EventSentry](https://www.eventsentry.com/features/system-health-monitoring): EventSentry monitors all critical aspects of your servers to ensure that potential issues are detected as soon as possible. System health monitoring includes Disk Space, Services, Performance, Sched... - [Network Monitoring with Ping, TCP, Arp, Syslog, SNMP & NetFlow | EventSentry](https://www.eventsentry.com/features/network-monitoring): Provides unparalleled insight into your network by correlating a number of powerful monitoring components, including ICMP & TCP checks, active & passive SNMP, NetFlow & sFlow traffic analysis, ARP m... - [Software, Patch & Hardware Inventory | EventSentry](https://www.eventsentry.com/features/inventory): EventSentry can monitor all (registered) installed software and patches on a server and/or workstation and generate an alert when an application is installed or uninstalled. A hardware inventory col... - [Windows Event Log Monitoring and Centralized Database Consolidation | EventSentry](https://www.eventsentry.com/features/event-log-monitoring): Real-Time Event log and SIEM monitoring is the core monitoring component of EventSentry, and features one of most sophisticated filtering engines on the market. - [Application Monitoring | EventSentry](https://www.eventsentry.com/features/application-monitoring): EventSentry's features include a variety of functionality for monitoring traditional as well as web-based applications. - [Notifications & Remediation | EventSentry](https://www.eventsentry.com/features/notifications): EventSentry currently supports 16 different types of notifications to support alerts, remediation and integration. - [Package Management with easy Remote Update Features | EventSentry](https://www.eventsentry.com/features/management): The EventSentry management application was designed to make monitoring as easy as possible while offering great flexibility at the same time. EventSentry features an intuitive MMC-like management ap... - [Performance Monitoring | EventSentry](https://www.eventsentry.com/features/performance-monitoring): Performance monitoring lets you monitor your servers' system and application performance to detect immediate performance issues and analyze performance trends over time. - [Event Log Compliance for PCI-DSS, Sarbanes Oxley, HIPAA, SB1386, GLBA, CJIS, FISMA | EventSentry](https://www.eventsentry.com/features/compliance): EventSentry's event log compliance can help you meet many government regulations, such as NIST 800-171, ISO 27001:2013 and PCI-DSS. EventSentry offers compliance tracking features, real-time event l... - [Why Monitor? | EventSentry](https://www.eventsentry.com/features/why-monitor) - [Why Monitor With EventSentry? | EventSentry](https://www.eventsentry.com/features/why-eventsentry): How EventSentry differentiates itself from the competition - [Event Log Consolidation to MSSQL, PostgreSQL, MySQL and Oracle databases | EventSentry](https://www.eventsentry.com/features/log-consolidation): Leveraging event log consolidation in EventSentry provides a wealth of information from your network. Correlate events, visualize patterns and identify performance bottlenecks in an easy to search r... - [File Integrity Monitoring Software | EventSentry](https://www.eventsentry.com/features/file-monitoring): File monitoring software allows you to be notified and track changes to critical system and user files. File integrity monitoring detects when files and checksums are added, deleted or changed. For ... - [Log File Monitoring Solution | EventSentry](https://www.eventsentry.com/features/log-file-monitoring): Monitors Azure logs, structured log files (IIS, DHCP, DNS, ..) and simple log files - [ADMonitor | EventSentry](https://www.eventsentry.com/features/admonitor): EventSentry offers native Active Directory and Group Policy change monitoring - [Disk Space Monitoring | EventSentry](https://www.eventsentry.com/features/diskspace-monitoring): EventSentry monitors any fixed disk drive, mount point and/or folder, finds the 250 largest files and can both generate alerts as well as collect historical information in the EventSentry database. - [Process Monitoring | EventSentry](https://www.eventsentry.com/features/process-monitoring): EventSentry provides one of the most detailed, extensive and robust process analysis capabilities the scale across the entire enterprise. - [Service, Process and Application Monitoring | EventSentry](https://www.eventsentry.com/features/service-monitoring): With Service Monitoring you can monitor all Windows services, drivers and processes easily. You can be alerted when a service or application are unavailable, when a service is added to the system or... - [Web Reporting | EventSentry](https://www.eventsentry.com/features/reporting): EventSentry's web-based event log reporting provides a wealth of reporting options. Reporting options include overview / status pages, event log reporting, search pages for archived data as well as ... - [Account Management Tracking | EventSentry](https://www.eventsentry.com/features/compliance-account-management): Tracks all changes to user and group accounts on domain controllers as well as member servers and workstations. In domain environments, the creation, deletion and modification of computer accounts i... - [Process Tracking | EventSentry](https://www.eventsentry.com/features/compliance-processes): Process Tracking monitors application / process usage on workstations and servers, which is useful for troubleshooting as well as later analysis, e.g. in high-security environments. - [NTP Synchronization and Verification | EventSentry](https://www.eventsentry.com/features/ntp-monitoring): The Network Time Protocol (NTP) allows the synchronization of computer clocks between computers, including computers located in different time zones. Having all computers in a network such as Active... - [File Access Tracking | EventSentry](https://www.eventsentry.com/features/compliance-file-access): File Access Tracking collects all successful file access activity that is logged by the Operating System when auditing on a directory and/or file is enabled. - [Compliance Tracking: Console & Network Logon Tracking | EventSentry](https://www.eventsentry.com/features/compliance-logons): Logon Tracking keeps track of both network logons (success and failure) as well console and remote desktop logon sessions on your network. The collected information can be queried through the web re... - [Policy Change Tracking | EventSentry](https://www.eventsentry.com/features/compliance-policy-change): Tracks a variety of policy changes, such as audit policy changes, user rights changes and more. - [Environment Monitoring | EventSentry](https://www.eventsentry.com/features/environment-monitoring): EventSentry offers a full range of environment monitoring sensors to notify you of environment problems like defective air conditioning, intrusion attempts, water leaks and more. - [Full Feature List | EventSentry](https://www.eventsentry.com/features/full-feature-list): EventSentry is the proactive, real-time monitoring solution that watches over your servers, workstations and network devices to ensure maximum availability and that also helps with SOX, HIPAA and ot... - [Print Tracking | EventSentry](https://www.eventsentry.com/features/compliance-print): Tracks all printed documents in the EventSentry database, and allows for per-page cost to be associated with a print queue. - [Permission Inventory | EventSentry](https://www.eventsentry.com/features/compliance-permission): Searchable inventory of all NTFS permissions ## Kb - [Can I detect Ransomware by monitoring if a new file extension has been](https://www.eventsentry.com/kb/528-can-i-detect-ransomware-by-monitoring-if-a-new-file-extension-has-been-detected-on-my-network): Since Ransomware often manifests itself by creating (encrypted) files with new file extensions, detecting never-before seen file extensions can be an effective w - [How do I use the Service Monitoring feature? | EventSentry](https://www.eventsentry.com/kb/490-how-do-i-use-the-service-monitoring-feature): EventSentry's service monitoring feature allows you to be notified when a service changes its status, or when a service and/or driver are added or removed.Sy - [How do I migrate / move my EventSentry installation and PostgreSQL | EventSentry](https://www.eventsentry.com/kb/496-how-do-i-migrate-move-my-eventsentry-installation-and-postgresql-database-to-a-new-server): To move EventSentry and Web Reports:1) Export your current EventSentry settings from the Management Console toolbar by clicking Home ) Export. Then transfe - [How can I list files that weren't modified in the last X days? | EventSentry](https://www.eventsentry.com/kb/454-how-can-i-list-files-that-weren-t-modified-in-the-last-x-days): Utilizing a PowerShell script that outputs files not accessed or modified in a certain number days, EventSentry can then import the structured output from a temp - [Can EventSentry help me detect cryptolocker and take action when | EventSentry](https://www.eventsentry.com/kb/279-can-eventsentry-help-me-detect-cryptolocker-and-take-action-when-cryptolocker-starts-infecting-a-network-share): Yes. There are four components necessary to configure in order to detect CryptoLocker or other Ransomware software and send an alert or cut off access to the ne - [Sending an email reminder when users have been logged into a server for](https://www.eventsentry.com/kb/465-sending-an-email-reminder-when-users-have-been-logged-into-a-server-for-a-certain-amount-of-time): EventSentry has the ability to email a user or users when they have been logged into a server for a set time limit. For example, a server or group of servers, ha - [How can I automatically block a potentially malicious IP address on a | EventSentry](https://www.eventsentry.com/kb/402-how-can-i-automatically-block-a-potentially-malicious-ip-address-on-a-pfsense-firewall): ) Requires: EventSentry NetFlow license, pfSense 2.4 or later, psexec, kitty_portableStarting with EventSentry v4.0.3, EventSentry can log events when a poten - [Auditing SQL Server with EventSentry | EventSentry](https://www.eventsentry.com/kb/413-auditing-sql-server-with-eventsentry): ) Requires: SQL Server 2016 (13.x) SP1 or newer (all editions)Starting with SQL Server 2016 (13.x) SP1 or newer, auditing can be enabled on all editions (not j - [How to correctly add a SNMP-capable device to EventSentry? | EventSentry](https://www.eventsentry.com/kb/451-how-to-correctly-add-a-snmp-capable-device-to-eventsentry): EventSentry can retrieve various device information such as disk space & performance metrics via SNMP. This guide shows how to correctly configure and add a devi - [How to install, auto-update and deploy Sysmon automatically using | EventSentry](https://www.eventsentry.com/kb/437-how-to-install-auto-update-and-deploy-sysmon-automatically-using-eventsentry-s-application-scheduler): The System Monitor service & driver ("Sysmon" for short) logs various events - mostly in respon - [Monitoring file checksum changes on Linux hosts | EventSentry](https://www.eventsentry.com/kb/476-monitoring-file-checksum-changes-on-linux-hosts): File integrity on Linux hosts can be monitored by integrating the Samhain tool and EventSentry.Note: This guide was created with Debian/Ubuntu in mind, the - [Detecting Emotet malware with Emocheck and EventSentry | EventSentry](https://www.eventsentry.com/kb/414-detecting-emotet-malware-with-emocheck-and-eventsentry): Emotet (https://en.wikipedia.org/wiki/Emotet) is dangerous malware that has been infecting networks since 2016, causing serious damage to organizations. The team - [How to monitor data in a SQL database | EventSentry](https://www.eventsentry.com/kb/527-how-to-monitor-data-in-a-sql-database): EventSentry provides the ability to monitor an custom table or custom database. This article will walkthrough monitoring the results of any SQL query from a Post - [How do I configure Web Reports to use HTTPS with an SSL / TLS | EventSentry](https://www.eventsentry.com/kb/371-how-do-i-configure-web-reports-to-use-https-with-an-ssl-tls-wildcard-certificate): Note: These instructions are only for EventSentry 3.4 and newer. For older versions, please see (knowledge base - [How do I automatically restart services or processes based on resource](https://www.eventsentry.com/kb/448-how-do-i-automatically-restart-services-or-processes-based-on-resource-usage): EventSentry can be configured to restart services based on their resource usage. For example, when a service uses more than the specified amount of memory, handl - [Multi-Tenant Setup of EventSentry for MSPs using multiple databases | EventSentry](https://www.eventsentry.com/kb/475-multi-tenant-setup-of-eventsentry-for-msps-using-multiple-databases): This HowTo illustrates how to configure EventSentry to support multiple tenants (customers), utilizing a single installation with multiple databases: Single E - [How do I trigger an action if a file is added/deleted from a directory?](https://www.eventsentry.com/kb/432-how-do-i-trigger-an-action-if-a-file-is-added-deleted-from-a-directory): There are several scenarios where you may want to monitor when files are added or deleted from a directory, and when this happens, trigger a particular action. I - [How can I optimize the performance of the built-in EventSentry | EventSentry](https://www.eventsentry.com/kb/232-how-can-i-optimize-the-performance-of-the-built-in-eventsentry-postgresql-database): The built-in EventSentry database ships with a basic configuration which is tuned for wide compatibility instead of speed. If you are collecting a lot of data, i - [How to setup Azure / Microsoft 365 audit logs in EventSentry using | EventSentry](https://www.eventsentry.com/kb/520-how-to-setup-azure-microsoft-365-audit-logs-in-eventsentry-using-delimited-log-file-monitoring): EventSentry v6 UpdatePlease note that EventSentry v6 and later includes native support for downloading and monitoring Azure-based logs as well as built-in log f - [Get notified when a certificate of a remote web site is about to expire](https://www.eventsentry.com/kb/431-get-notified-when-a-certificate-of-a-remote-web-site-is-about-to-expire-using-sysadmin-tools): You can be notified when a remote web site certificate is about to expire using checkurl.exe from EventSentry SysAdmin Tools.For that we are going to:1. Insta - [Monitoring and viewing COVID19 stats in the EventSentry Dashboard | EventSentry](https://www.eventsentry.com/kb/416-monitoring-and-viewing-covid19-stats-in-the-eventsentry-dashboard): Note: This article AND script have been updated on 3/25/2020 to use a more accurate data source - please update your script. Countries must now be specified by - [How do I capture data for the Compliance pages in the Web Reports? | EventSentry](https://www.eventsentry.com/kb/310-how-do-i-capture-data-for-the-compliance-pages-in-the-web-reports): Preparing to track:First, consider which Compliance data types you need to capture, and ensure that your audit settings in Windows are properly configure - [How do I install and configure the HWg-STE Ethernet temperature / | EventSentry](https://www.eventsentry.com/kb/453-how-do-i-install-and-configure-the-hwg-ste-ethernet-temperature-humidity-sensor): This guide explains how to deploy the HWg-STE Ethernet temperature / humidity sensor in your server room or office.Note: Please see the links below if you hav - [Automatically monitoring Microsoft Office Documents for threats | EventSentry](https://www.eventsentry.com/kb/474-automatically-monitoring-microsoft-office-documents-for-threats): EventSentry can integrate with Decalage's oletools to scan Microsoft Office files on your hosts for threats. This is us - [What are the supported upgrade paths? | EventSentry](https://www.eventsentry.com/kb/312-what-are-the-supported-upgrade-paths): Please follow the steps below prior to upgrading any EventSentry installation:1. Save a copy of your current settings. Home ) Export (3.0 and up) or File ) Ex - [How do I use content filters to match specific event log text? | EventSentry](https://www.eventsentry.com/kb/487-how-do-i-use-content-filters-to-match-specific-event-log-text): The initial install of EventSentry includes several default packages that match common scenarios our customers face. For example, when an error is detected on a - [How do I configure Logon/Logoff tracking? | EventSentry](https://www.eventsentry.com/kb/489-how-do-i-configure-logon-logoff-tracking): Getting StartedLogon Tracking allows you to track console logons as well as a variety of network logons, both failed and successful. This feature can be fo - [How can I create an include or exclude filter straight from the event | EventSentry](https://www.eventsentry.com/kb/485-how-can-i-create-an-include-or-exclude-filter-straight-from-the-event-log-viewer): An include or exclude event log filter can be created from any event log using the built-in Event Log Viewer in the EventSentry management console. This is a qui - [How do I troubleshoot agent-collector connectivity issues? | EventSentry](https://www.eventsentry.com/kb/307-how-do-i-troubleshoot-agent-collector-connectivity-issues): If you go into the Windows event viewer on your EventSentry server, select the Application log, and look for event 117, 118, 119, 122, or 123 from Eve - [How do I configure authentication to monitor or manage the agents that](https://www.eventsentry.com/kb/283-how-do-i-configure-authentication-to-monitor-or-manage-the-agents-that-are-in-a-separate-windows-domain-or-workgroup): 1) Make sure the "EventSentry Heartbeat Monitor" service on your management console computer is configured to run under an account that has administrator rights - [How can I install Heartbeat agent on different computer/machine? | EventSentry](https://www.eventsentry.com/kb/479-how-can-i-install-heartbeat-agent-on-different-computer-machine): How can I install the Heartbeat agent on a separate computer/machine? EventSentry's Heartbeat agent can be installed on a different computer/machine separate f - [What are the Microsoft SQL server database growth requirements for | EventSentry](https://www.eventsentry.com/kb/311-what-are-the-microsoft-sql-server-database-growth-requirements-for-upgrading-to-2-93-or-newer): The database upgrade can consume a large amount of disk space for Microsoft SQL databases. You would need to look up the size of the ESEventLogMain table (in SQ - [Receiving alerts for domains that are about to expire | EventSentry](https://www.eventsentry.com/kb/505-receiving-alerts-for-domains-that-are-about-to-expire): You can get an alert when a domain is about to expire (in 30 days) by using the WhoisXMLAPI. Creating API key Create a user a - [How can I optimize my Microsoft SQL Server (MSSQL) database? | EventSentry](https://www.eventsentry.com/kb/35-how-can-i-optimize-my-microsoft-sql-server-mssql-database): You can optimize the performance of a new database by setting the initial database size to a large number, for example 2Gb.You can also set the new or existing - [How do I reclaim disk space (after purging data) by shrinking the | EventSentry](https://www.eventsentry.com/kb/241-how-do-i-reclaim-disk-space-after-purging-data-by-shrinking-the-built-in-postgresql-database): If, after purging data from your EventSentry database, you still have enough disk space (approximately 1.5x the database size is needed) available on the driv - [How to deploy the agent via MSI to an external host? | EventSentry](https://www.eventsentry.com/kb/423-how-to-deploy-the-agent-via-msi-to-an-external-host): If you are unable to deploy the agent to a remote host via the management console, then the EventSentry Management Console can generate a MSI file that can be us - [How do I reset the users in the built in EventSentry database? | EventSentry](https://www.eventsentry.com/kb/227-how-do-i-reset-the-users-in-the-built-in-eventsentry-database): Method A: If you know the "postgres" user password, you can use the pgAdmin utility:1A. Open pgAdmin by opening the Windows Start Menu to EventSentry -) pg - [Detecting and automatically recovering from bypassing Windows logons | EventSentry](https://www.eventsentry.com/kb/433-detecting-and-automatically-recovering-from-bypassing-windows-logons-with-utilman-exe): Utilman.exe is the utility program that is launched when the "Ease of Access" button on the login screen is clicked. At the time of writing, it is still vulnerab - [How do I enable UTC support, and what are the implications? | EventSentry](https://www.eventsentry.com/kb/240-how-do-i-enable-utc-support-and-what-are-the-implications): Starting with v3.0, UTC support is automatically enabled in EventSentry for new installations and affects all time stamps viewed through the web reports. - [How do I setup Let's Encrypt with the Web Reports? | EventSentry](https://www.eventsentry.com/kb/421-how-do-i-setup-let-s-encrypt-with-the-web-reports): Let's Encrypt is a free, automated, and open certificate authority brought to you by the nonprofit (Internet Security Research Group) - [Integrating the EventSentry tray app "EventSentray" with OTRS Ticket | EventSentry](https://www.eventsentry.com/kb/435-integrating-the-eventsentry-tray-app-eventsentray-with-otrs-ticket-system-via-email): OTRS is another popular IT helpdesk ticket system. Starting with version 4.2, EventSentry includes the tray icon feature which - [How do I configure a filter timer? | EventSentry](https://www.eventsentry.com/kb/488-how-do-i-configure-a-filter-timer): Filter Timers give you the ability to ignore events if they are followed by a specific second event within a set time period. For example, you probably want to b - [How do I configure an Event Log Filter Threshold? | EventSentry](https://www.eventsentry.com/kb/482-how-do-i-configure-an-event-log-filter-threshold): A standard EventSentry event log filter will forward the configured event to the configured action every time the event occurs. Alternatively, a filter thresho - [How to setup DoD PKI authentication via Common Access Card (CAC) in the](https://www.eventsentry.com/kb/438-how-to-setup-dod-pki-authentication-via-common-access-card-cac-in-the-web-reports): Step 1: Prepare the CertificateOpen a command prompt as an administrator and navigate to the following folder (depends on where you installed EventSent - [How do I enable the collector service? | EventSentry](https://www.eventsentry.com/kb/295-how-do-i-enable-the-collector-service): The EventSentry collector has numerous advantages compared with agents connecting directly to the EventSentry database and is recommended for most installations: - [After upgrading to EventSentry v3.3 or later, how do I utilize the new](https://www.eventsentry.com/kb/332-after-upgrading-to-eventsentry-v3-3-or-later-how-do-i-utilize-the-new-postgresql-v9-6-database): If you are not utilizing the built-in PostgreSQL database then you can ignore this article.EventSentry v3.3 includes a new version 9.6 of the built-in PostgreS - [A vulnerability scanner detected that the EventSentry collector is | EventSentry](https://www.eventsentry.com/kb/513-a-vulnerability-scanner-detected-that-the-eventsentry-collector-is-using-a-weak-cipher-how-can-i-resolve-this): When you scan the collector with a vulnerability scanner, it will list all ciphers that are currently supported by the Windows OS. However, the only cipher that - [Can I migrate my existing data (mssql, mysql, oracle) to the new | EventSentry](https://www.eventsentry.com/kb/224-can-i-migrate-my-existing-data-mssql-mysql-oracle-to-the-new-built-in-eventsentry-database): It is not currently possible to migrate data from your existing Microsoft SQL Server, MySQL or Oracle database to the built-in EventSentry PostgreSQL database. - [How to detect TCP port scans initiated from a windows host | EventSentry](https://www.eventsentry.com/kb/508-how-to-detect-tcp-port-scans-initiated-from-a-windows-host): A port scan that is initiated from a monitored host can be detect by monitoring (Windows Filtering Platform event id 5156)(https://system32.eventsentry.com/secur - [How is the network utilization calculated? How accurate is it? | EventSentry](https://www.eventsentry.com/kb/284-how-is-the-network-utilization-calculated-how-accurate-is-it): EventSentry includes the Network Utilization (sometimes labeled Network Bandwidth) performance object which is located under "Packages - System He - [Why is the agent status listed as Frozen or Idle or Disconnected? | EventSentry](https://www.eventsentry.com/kb/343-why-is-the-agent-status-listed-as-frozen-or-idle-or-disconnected): In EventSentry 3.3 series and newer, there are multiple ways to check the agent status, and they are performed in this order:Read collector connection - [Integrating the EventSentry tray app "EventSentray" with Spiceworks | EventSentry](https://www.eventsentry.com/kb/434-integrating-the-eventsentry-tray-app-eventsentray-with-spiceworks-help-desk-via-email): Spiceworks Help Desk is a popular IT helpdesk ticket system. Starting with version 4.2 EventSentry suppor - [Monitoring Azure Logs | EventSentry](https://www.eventsentry.com/kb/537-monitoring-azure-logs): Monitoring and consolidating cloud-based logs from Azure requires the following configuration steps. Please note that new EventSentry v6.x installations do not r - [How can I recreate the default internal PostgreSQL database? | EventSentry](https://www.eventsentry.com/kb/519-how-can-i-recreate-the-default-internal-postgresql-database): If you experience data corruption, data loss, or accidentally delete files from the internal Postgres database, this guide will walk you through the steps to reg - [How can I detect insider threats with EventSentry? | EventSentry](https://www.eventsentry.com/kb/510-how-can-i-detect-insider-threats-with-eventsentry): EventSentry has a dashboard you can import into Web Reports that is designed to help detect insider threats. To install it, first download it from this link: (re - [How to enable API access to Microsoft Entra ID (AzureAD)? | EventSentry](https://www.eventsentry.com/kb/518-how-to-enable-api-access-to-microsoft-entra-id-azuread): This guide provides step-by-step instructions to enable audit log access in Microsoft Entra ID, formerly Azure Active Directory (AzureAD).--- Prerequisites - [How can I discover all vulnerable Log4J libraries on my network? | EventSentry](https://www.eventsentry.com/kb/463-how-can-i-discover-all-vulnerable-log4j-libraries-on-my-network): EventSentry includes the validation script (Threat-Intel: Log4j Remote Code Execution)(https://www.eventsentry.com/validationscripts/guid/a01ac7ca-b4f4-44e2-badd - [How do I configure a basic Event Log Filter? | EventSentry](https://www.eventsentry.com/kb/481-how-do-i-configure-a-basic-event-log-filter): Filters are an essential part of EventSentry which allow you to configure a set of actions to activate whenever an event occurs. For example, you can setup a fil - [How to Monitor Mass File Deletions with EventSentry | EventSentry](https://www.eventsentry.com/kb/543-how-to-monitor-mass-file-deletions-with-eventsentry): Prerequisites:Before configuring EventSentry, ensure your Windows environment is prepared to track file operations:1. Advanced Audit Policy: "Audit File Sy - [Monitoring process CPU usage on Linux hosts | EventSentry](https://www.eventsentry.com/kb/473-monitoring-process-cpu-usage-on-linux-hosts): While overall performance and CPU statistics from non-Windows hosts can easily be obtained via SNMP, getting the CPU usage of each process requires a few additio - [Even though I configured EventSentry correctly, I am not receiving | EventSentry](https://www.eventsentry.com/kb/61-even-though-i-configured-eventsentry-correctly-i-am-not-receiving-emails-from-the-agent-s): There are a number of reasons why you might not be receiving emails from the remote machines running the EventSentry agents. Please check each step below to reso - [How can I populate the Virtual Machines inventory from my VMWare ESXi | EventSentry](https://www.eventsentry.com/kb/269-how-can-i-populate-the-virtual-machines-inventory-from-my-vmware-esxi-hosts): EventSentry requires that SNMP is enabled on the VMWare ESXi hosts in order to pull the virtual machine inventory. IMPORTANT: You must enable SNMP on the - [If I change the database user passwords (eventsentry_svc, | EventSentry](https://www.eventsentry.com/kb/374-if-i-change-the-database-user-passwords-eventsentry_svc-eventsentry_web-where-do-i-need-to-update-the-passwords-in-my-eventsentry-instance): For the eventsentryweb account:In the web reports menu, click Settings and choose Profiles, and type the new eventsentryweb password in the settings an - [How can I be alerted if Microsoft Windows Firewall policies change | EventSentry](https://www.eventsentry.com/kb/429-how-can-i-be-alerted-if-microsoft-windows-firewall-policies-change-and-or-firewall-is-disabled): Windows Firewall policy changes, like new program exceptions, enabling/disabling/deleting policies can be monitored and detected with EventSentry, along to detec - [Can I use my own certificate for the collector instead of the | EventSentry](https://www.eventsentry.com/kb/328-can-i-use-my-own-certificate-for-the-collector-instead-of-the-self-signed-certificate): Yes, however, if you change the certificate used for the Collector, your agents will refuse to connect to the Collector once the certificate has changed. This w - [What are the exact permission requirements for the ADMonitor service | EventSentry](https://www.eventsentry.com/kb/390-what-are-the-exact-permission-requirements-for-the-admonitor-service-account-eventsentryadmonitor): Under most circumstances, the EventSentry Configuration Assistant (which is launched after every installation and/or upgrade) automatically creates the EventSe - [How can I integrate EventSentry with Telegram Messenger? | EventSentry](https://www.eventsentry.com/kb/428-how-can-i-integrate-eventsentry-with-telegram-messenger): Telegram Messenger integration can be accomplished with the HTTP action. Configuring Telegram MessengerCreating a BOTTelegram implements a "bot" s - [How does ADMonitor determine if a user is an admin? | EventSentry](https://www.eventsentry.com/kb/412-how-does-admonitor-determine-if-a-user-is-an-admin): EventSentry ADMonitor utilizes the adminCount attribute that is associated with AD user accounts to determine whether a user has administrative permissions. - [How do I verify that health or performance monitoring will work via | EventSentry](https://www.eventsentry.com/kb/380-how-do-i-verify-that-health-or-performance-monitoring-will-work-via-snmp-on-my-monitored-device): Your device must support SNMP-get, sometimes referred to as SNMP polling, and must be able to accept incoming connections on UDP port 161. If your device has it - [How do I get notified if a Synology diskstation has a software update | EventSentry](https://www.eventsentry.com/kb/425-how-do-i-get-notified-if-a-synology-diskstation-has-a-software-update-available): Synology diskstations offer a SNMP counter that can be monitored with EventSentry to alert if a system update is available. This information can be obtained by m - [How do I make the built-in Postgres database record non-Latin text | EventSentry](https://www.eventsentry.com/kb/333-how-do-i-make-the-built-in-postgres-database-record-non-latin-text-such-as-japanese-chinese-hebrew-etc-successfully): Option A: If you have not completed the Configuration Assistant when installing EventSentry for the first time:1A) Use the Microsoft documentation to loc - [Why do we receive a handshake error (0xffffffff) when checking for | EventSentry](https://www.eventsentry.com/kb/337-why-do-we-receive-a-handshake-error-0xffffffff-when-checking-for-updates-in-the-management-console): The full error is: "Server disconnected before handshake completion. (0xffffffff). There was an error downloading the latest version information from the https: - [How to get notified if a user copies a file to a removable drive (e.g.](https://www.eventsentry.com/kb/410-how-to-get-notified-if-a-user-copies-a-file-to-a-removable-drive-e-g-usb-memory-stick): Starting with Windows 10 and Windows Server 2016 you can generate audit events whenever files are written to a removable drive by enabling auditing for the Rem - [Can I monitor hosts running Windows NT 4? | EventSentry](https://www.eventsentry.com/kb/276-can-i-monitor-hosts-running-windows-nt-4): Windows NT 4.0 is supported until version 2.90, and starting with EventSentry v2.91, Windows NT 4.0 is no longer a supported platform. If you need to monitor a c - [Are there any EventSentry files that I might need to whitelist in my | EventSentry](https://www.eventsentry.com/kb/369-are-there-any-eventsentry-files-that-i-might-need-to-whitelist-in-my-antivirus-antimalware-software): Yes, depending on how aggressive your Antivirus/Antimalware software is, you may be unable to deploy the agent or push an updated configuration without whitelist - [Disabling Windows Remote Management (WinRM) / Mass deployment over | EventSentry](https://www.eventsentry.com/kb/436-disabling-windows-remote-management-winrm-mass-deployment-over-network-using-admin-assistant): This guide illustrates how to completely disable WinRM and how to deploy it over the network using the free tool (EventSentry Admin Assistant)(https://www.events - [Can I configure EventSentry to send event log alerts to Microsoft | EventSentry](https://www.eventsentry.com/kb/504-can-i-configure-eventsentry-to-send-event-log-alerts-to-microsoft-teams): EventSentry can send alerts to Microsoft Teams by using an HTTP action to integrate with an incoming webhook. First, you will need to configure a webhook in the - [The heartbeat monitor is reporting "Access is denied" when monitoring | EventSentry](https://www.eventsentry.com/kb/41-the-heartbeat-monitor-is-reporting-access-is-denied-when-monitoring-the-agent-status-of-a-remote-computer): This happens when the user account the heartbeat service is running under does not have privileges to query the EventSentry service status on the remote host(s). - [How do I migrate data from the legacy v9.1 built-in PostgreSQL database](https://www.eventsentry.com/kb/330-how-do-i-migrate-data-from-the-legacy-v9-1-built-in-postgresql-database-to-the-newer-v9-6-postgresql-database): Follow the steps outlined below in order to migrate all data from the legacy v9.1 built-in PostgreSQL database to the newer v9.6 PostgreSQL database.Prerequ - [How can I be notified if a user logs in outside of business hours? | EventSentry](https://www.eventsentry.com/kb/511-how-can-i-be-notified-if-a-user-logs-in-outside-of-business-hours): Windows logs security event id 4624 whenever a user logs on to a machine. Using the Hour/Day settings in - [How to quickly patch CVE-2020-0796 | EventSentry](https://www.eventsentry.com/kb/415-how-to-quickly-patch-cve-2020-0796): Recent CVE advisory CVE-2020-0796 explains a remote code execution vulnerability that exists in t - [Your agents receive event ID 907 (The certificate provided by the | EventSentry](https://www.eventsentry.com/kb/308-your-agents-receive-event-id-907-the-certificate-provided-by-the-collector-does-not-match-the-locally-cached-certificate): This can happen if you reset your collector certificate without pushing the new configuration within 1 week, or by migrating the EventSentry server to a new mach - [Monitoring and alerting on the runtime duration of processes | EventSentry](https://www.eventsentry.com/kb/502-monitoring-and-alerting-on-the-runtime-duration-of-processes): Monitoring and alerting on the runtime duration of processesThis guide demonstrates how to set up EventSentry to trigger an alert when a process runs longer th - [Which version of TLS does EventSentry use between the collector and its](https://www.eventsentry.com/kb/335-which-version-of-tls-does-eventsentry-use-between-the-collector-and-its-agents): Since EventSentry utilizes the TLS capabilities of the OS, the version of TLS being used between the collector and the agents depends both on the version of Wind - [How do I use the Variable function? | EventSentry](https://www.eventsentry.com/kb/486-how-do-i-use-the-variable-function): In EventSentry, Variables allow you to dynamically assign values to groups or hosts. This allows you to create more flexible configurations when objects such - [How can I be notified if a web site inside IIS is stopped? | EventSentry](https://www.eventsentry.com/kb/209-how-can-i-be-notified-if-a-web-site-inside-iis-is-stopped): You can launch the following VBScript through the application scheduler (e.g. every 1 minute) to be notified when a web site (or other component, e.g. SMTP) in I - [The Security \[2\] Attack Surface Dashboard | EventSentry](https://www.eventsentry.com/kb/515-the-security-2-attack-surface-dashboard): The Attack Surface dashboard utilized various validation scripts to ensure the monitored hosts meet basic security and best practices guidelines. To make it easi - [Does EventSentry work with SQL Server 2005 Express? What do I need to | EventSentry](https://www.eventsentry.com/kb/95-does-eventsentry-work-with-sql-server-2005-express-what-do-i-need-to-do-to-make-eventsentry-work-with-sql-server-2005-express): EventSentry definitely works with SQL Server 2005 Express, however some special steps need to be taken to make EventSentry work with SQL Server 2005 Express. Mos - [How can I receive an alert when battery level is low? | EventSentry](https://www.eventsentry.com/kb/419-how-can-i-receive-an-alert-when-battery-level-is-low): The "Software/Hardware Inventory" system health package can monitor battery levels both on laptops and directly attached UPS devices. Alerts generated by this - [How do I setup Certify the Web to manage the certificate used by the | EventSentry](https://www.eventsentry.com/kb/522-how-do-i-setup-certify-the-web-to-manage-the-certificate-used-by-the-web-reports): Certify The Web provides a way to easily manage, install and auto-renew free SSL/TLS certificates from (letsencrypt.org)(https://le - [Integrating the EventSentry tray app "EventSentray" with Zendesk | EventSentry](https://www.eventsentry.com/kb/439-integrating-the-eventsentry-tray-app-eventsentray-with-zendesk): Zendesk is a popular customer service ticket system. Starting with version 4.2, EventSentry supports the tray icon feature that allow - [How do I trigger an email alert from an incoming Syslog message? | EventSentry](https://www.eventsentry.com/kb/399-how-do-i-trigger-an-email-alert-from-an-incoming-syslog-message): Forwarding Syslog messages as email alerts is a three-step process assuming that Syslog messages are already successfully received in EventSentry: Enable Sysl - [What performance impact does EventSentry have on a monitored computer | EventSentry](https://www.eventsentry.com/kb/47-what-performance-impact-does-eventsentry-have-on-a-monitored-computer-e-g-cpu-memory-etc): Generally speaking EventSentry does not have a significant performance impact on a computer. EventSentry was developed in C++ with the goal of being invisible in - [Can I install the network services on a remote host with EventSentry | EventSentry](https://www.eventsentry.com/kb/306-can-i-install-the-network-services-on-a-remote-host-with-eventsentry-3-2-3-3-or-3-4): EventSentry 3.5 to 4.2 use different installation files for the network services, please see knowledge base article 384.Ev - [How do I customize the email subject or body of an alert? | EventSentry](https://www.eventsentry.com/kb/409-how-do-i-customize-the-email-subject-or-body-of-an-alert): Event log alerts can often by cryptic and difficult to understand, especially when alerts need to be interpreted by non-technical staff. EventSentry makes it eas - [Is the EventSentry agent cluster-aware? Can the EventSentry agent be | EventSentry](https://www.eventsentry.com/kb/98-is-the-eventsentry-agent-cluster-aware-can-the-eventsentry-agent-be-installed-on-computers-in-windows-cluster): Yes, you can install the EventSentry service on cluster nodes by defining the EventSentry service as a cluster resource (service).Please follow the instruction - [How can I automate the installation (silent install) of the EventSentry](https://www.eventsentry.com/kb/352-how-can-i-automate-the-installation-silent-install-of-the-eventsentry-agent-for-example-when-automatically-setting-up-rolling-out-servers-or-workstations-how-can-i-manually-install-the-eventsentry-agent): The easiest option is to generate an MSI file that contains the agent and your settings.In the EventSentry console, use the toolbar to click Groups ) Age - [How do I reconfigure EventSentry and store all future data in the new | EventSentry](https://www.eventsentry.com/kb/331-how-do-i-reconfigure-eventsentry-and-store-all-future-data-in-the-new-v9-6-postgresql-database-instance): Follow the steps below to reconfigure EventSentry to store all future data in the new PostgreSQL v9.6 database and retain all existing data inside the legacy Pos - [How can I integrate STIX threat feeds into EventSentry's Threat Intel | EventSentry](https://www.eventsentry.com/kb/442-how-can-i-integrate-stix-threat-feeds-into-eventsentry-s-threat-intel-feature): Starting with version 4.2.3, EventSentry supports custom threat feeds (black lists - [How do I set up the database purge from Web Reports? | EventSentry](https://www.eventsentry.com/kb/523-how-do-i-set-up-the-database-purge-from-web-reports): Starting in EventSentry 5.1, a new way to purge your database is available in Web Reports. This purge job runs more efficiently on large databases and is recomme - [After migrating my MSSQL to another why am I receiving logon errors | EventSentry](https://www.eventsentry.com/kb/149-after-migrating-my-mssql-to-another-why-am-i-receiving-logon-errors-from-the-eventsentry_web-account): You may encounter one of the following errors:OdbcExpandError: (28000)(Microsoft)(SQL Native Client)(SQL Server)Login failed for user 'eventsentry_svc'. (1845 - [Heartbeat Monitoring reports "Access is denied" for the status of | EventSentry](https://www.eventsentry.com/kb/216-heartbeat-monitoring-reports-access-is-denied-for-the-status-of-remote-eventsentry-agents-even-though-authentication-is-set): When configuring authentication in the heartbeat agent, it is important that you are logged in with the same user account under which the "EventSentry Heartbeat - [Automating EventSentry administrative tasks with PowerShell | EventSentry](https://www.eventsentry.com/kb/450-automating-eventsentry-administrative-tasks-with-powershell): A small number of EventSentry tasks can be automated with the EventSentry PowerShell module that can be downloaded from our github (here)(https://github.com/even - [When trying to view the web reports using Oracle I always get the | EventSentry](https://www.eventsentry.com/kb/82-when-trying-to-view-the-web-reports-using-oracle-i-always-get-the-following-error-specified-driver-could-not-be-loaded-due-to-system-error-5-oracle-in-orahome92010): System error 5 translates to "Access Denied", and you are getting this error because the NTFS permissions in the Oracle installation directory are setup incorrec - [How do I install the USB to serial port driver in order to use the | EventSentry](https://www.eventsentry.com/kb/213-how-do-i-install-the-usb-to-serial-port-driver-in-order-to-use-the-usb-only-temperature-humidity-sensor): In order to use the USB-only temperature or humidity environment sensor, the Virtual COM port (VCP) drivers need to be installed on the host on which the sensor - [How do I change the maximum scan time for SNMP performance monitoring?](https://www.eventsentry.com/kb/495-how-do-i-change-the-maximum-scan-time-for-snmp-performance-monitoring): The maximum scan time is a setting in the Heartbeat service that determines how long the service will scan a device for SNMP-get data and wait for a response. If - [How can I only be alerted if a host remains offline for more than X | EventSentry](https://www.eventsentry.com/kb/424-how-can-i-only-be-alerted-if-a-host-remains-offline-for-more-than-x-minutes): EventSentry has a unique timer-filter feature that can suppress unnecessary alerts if the error condition only lasts for a (configurable) short period of time. T - [The agent status is listed as "UNKNOWN" with error "Unable to find or | EventSentry](https://www.eventsentry.com/kb/273-the-agent-status-is-listed-as-unknown-with-error-unable-to-find-or-decrypt-stored-authentication-credentials): When configuring authentication in the heartbeat agent, it is important that you are logged in with the same user account under which the "EventSentry Heartbeat - [When trying to use the web reports on IIS running on a 64-bit (x64) | EventSentry](https://www.eventsentry.com/kb/122-when-trying-to-use-the-web-reports-on-iis-running-on-a-64-bit-x64-edition-of-windows-2003-or-2008-i-get-the-following-error-provider-is-not-specified-and-there-is-no-designated-default-provider-how-can-i-fix-this): Windows 2003In order to host the web reports on a 64bit machine you will need to use a connection string to access the database and switch IIS to run i - [Can I install the network services on a remote host with EventSentry | EventSentry](https://www.eventsentry.com/kb/384-can-i-install-the-network-services-on-a-remote-host-with-eventsentry-3-5): EventSentry 3.4 and older use different installation files for the network services; please see knowledge base article 306 - [How do I configure the Port Mapping feature to populate the Switch | EventSentry](https://www.eventsentry.com/kb/309-how-do-i-configure-the-port-mapping-feature-to-populate-the-switch-inventory-data): 1) Your switch must be present in your EventSentry configuration, in a Network Device group2) Clicking Check Status ) Go in the console toolbar must display th - [Can I allow non-administrators to manage my EventSentry configuration?](https://www.eventsentry.com/kb/262-can-i-allow-non-administrators-to-manage-my-eventsentry-configuration): Yes.The preferred method for managing agent configurations is through the collector, which can automatically deploy the EventSentry configuration as well as ag - [How can I get notified if an unsigned executable is launched? | EventSentry](https://www.eventsentry.com/kb/507-how-can-i-get-notified-if-an-unsigned-executable-is-launched): By monitoring 4688 events from the security event log and filtering on the process file size, EventSentry can notify you if an unsigned executable (a file withou - [How do I migrate data from the legacy v9.6 built-in PostgreSQL database](https://www.eventsentry.com/kb/469-how-do-i-migrate-data-from-the-legacy-v9-6-built-in-postgresql-database-to-the-newer-v14-x-postgresql-database): The default and recommended database upgrade path when upgrading to EventSentry v5 is to access existing data from the v9.6 database through a separate profile i - [How can I get notified if an executable that is larger than a certain | EventSentry](https://www.eventsentry.com/kb/506-how-can-i-get-notified-if-an-executable-that-is-larger-than-a-certain-size-is-launched): By monitoring 4688 events from the security event log and filtering on the process file size, EventSentry can notify you if a large (or small) executable was lau - [How can I monitor network bandwidth & jitter using Performance | EventSentry](https://www.eventsentry.com/kb/411-how-can-i-monitor-network-bandwidth-jitter-using-performance-monitoring): We can monitor bandwidth, jitter, latency and packet loss using performance monitoring by monitoring the output of an executable. The command line CLI can be fou - [Can I get alerted about expiring certificates in EventSentry? | EventSentry](https://www.eventsentry.com/kb/339-can-i-get-alerted-about-expiring-certificates-in-eventsentry): You can utilize a short PowerShell script to get a list of all certificates that expire within a certain number of days. This script can then be executed on a re - [Detecting whether a process is running for more than X seconds/minutes](https://www.eventsentry.com/kb/394-detecting-whether-a-process-is-running-for-more-than-x-seconds-minutes-using-performance-monitoring): (video 2)- Create a ‘System Health’ package labeled ‘Performance Processes’- Click this package and then in the toolbar, the click 'Add' down-down on the righ - [Can I receive an alert when a drive in a Windows 2008 software RAID | EventSentry](https://www.eventsentry.com/kb/211-can-i-receive-an-alert-when-a-drive-in-a-windows-2008-software-raid-fails): Unlike Windows Server 2003, Windows Server 2008 does not log an alert to the event log when a drive in a software raid fails. To work around this limitation, sch - [I am updating from EventSentry v2.43 to the latest version which has a](https://www.eventsentry.com/kb/37-i-am-updating-from-eventsentry-v2-43-to-the-latest-version-which-has-a-new-database-layout-what-do-i-need-to-do-to-update-our-database): Starting with version 2.50, EventSentry uses a new database layout. Depending on your circumstances you can either choose to start over with a new database, whil - [How do I install a patch? | EventSentry](https://www.eventsentry.com/kb/58-how-do-i-install-a-patch): NOTE: Patches can only be applied to the same version the patch was designed for. For example, a patch for version 2.90 cannot be applied to a 2.81 instal - [Can I install the network services on a remote host with EventSentry | EventSentry](https://www.eventsentry.com/kb/470-can-i-install-the-network-services-on-a-remote-host-with-eventsentry-5-0): EventSentry 3.4 and older use different installation files for the network services; please see knowledge base article 306. - [I cannot install or update EventSentry on some or all remote computers](https://www.eventsentry.com/kb/51-i-cannot-install-or-update-eventsentry-on-some-or-all-remote-computers-using-remote-update-some-of-the-error-messages-reported-are-access-denied-remote-procedure-call-rpc-failed): EventSentry uses Windows RPC calls to update remote agents, and remote update forwards all error messages reported by Windows when a remote update fails.EventS - [When monitoring the EventSentry service on remote computers, a 560 | EventSentry](https://www.eventsentry.com/kb/72-when-monitoring-the-eventsentry-service-on-remote-computers-a-560-audit-failure-event-in-the-security-log-is-logged-during-every-heartbeat-interval): The OS will usually log an Audit Failure similar to the one shown below when a process (e.g. the heartbeat monitoring agent) tries to read the service status:O - [How can I purge the EventSentry database to remove old data, or data | EventSentry](https://www.eventsentry.com/kb/183-how-can-i-purge-the-eventsentry-database-to-remove-old-data-or-data-that-is-not-of-interest): You can remove data from the EventSentry database in two ways: Through the web reports with the maintenance wizard, or through the command-line utility esdbpur - [How do I send Syslog messages from CentOS/Redhat to EventSentry? | EventSentry](https://www.eventsentry.com/kb/500-how-do-i-send-syslog-messages-from-centos-redhat-to-eventsentry): To send syslog messages from a CentOS machine to your EventSentry syslog daemon, you can use the default syslog service on CentOS/Redhat, ryslog. Here's a step-b - [How to configure EventSentry to detect threats like APTs, Mimikatz, | EventSentry](https://www.eventsentry.com/kb/447-how-to-configure-eventsentry-to-detect-threats-like-apts-mimikatz-malicious-traffic-and-others-with-sysmon): Sysmon is a free driver-based utility that supplements Windows's built-in audit capabilities. C - [Detecting Process Anomalies | EventSentry](https://www.eventsentry.com/kb/544-detecting-process-anomalies): EventSentry can detect process anomalies with its (anomaly detection feature)(https://www.eventsentry.com/documentation/help/html/configpackagesfiltersanomaly.ht - [I am not seeing Syslog messages in EventSentry, even though the | EventSentry](https://www.eventsentry.com/kb/229-i-am-not-seeing-syslog-messages-in-eventsentry-even-though-the-eventsentry-network-services-service-is-configured-and-running): Please perform the following troubleshooting steps if incoming Syslog messages and/or SNMP traps are not showing up in the application event log and/or EventSent - [Can I detect credit card numbers in log files or event log messages? | EventSentry](https://www.eventsentry.com/kb/242-can-i-detect-credit-card-numbers-in-log-files-or-event-log-messages): Yes, using the Regular Expression match type of - [How do I back up the built in EventSentry database? | EventSentry](https://www.eventsentry.com/kb/235-how-do-i-back-up-the-built-in-eventsentry-database): If you are using the built in EventSentry database, you can back it up using the "pg_dump.exe" utility. This is located by default in the EventSentry\postgresql1 - [Our EventSentry database is growing very quickly and we would like to | EventSentry](https://www.eventsentry.com/kb/76-our-eventsentry-database-is-growing-very-quickly-and-we-would-like-to-know-which-tables-which-features-are-using-up-the-majority-of-the-disk-space): Please see the instructions below to see how much space a feature is using:Microsoft SQL Server:Run the following command in SQL Query Analyzer to see - [Can I use EventSentry to deploy a kill file or vaccine for stopping | EventSentry](https://www.eventsentry.com/kb/354-can-i-use-eventsentry-to-deploy-a-kill-file-or-vaccine-for-stopping-ransomware-viruses-such-as-petya-notpetya): Yes, this is only takes a few minutes to configure.Use the EventSentry console toolbar and click Tools ) Embedded Scripts Make a new script a - [Can I configure the agent to run under a non-privileged account, | EventSentry](https://www.eventsentry.com/kb/184-can-i-configure-the-agent-to-run-under-a-non-privileged-account-instead-of-the-default-localsystem): By default, the EventSentry agent runs under the LocalSystem account, which has unrestricted access to Operating System resources, which ensures that all compone - [How to monitor AppLocker events | EventSentry](https://www.eventsentry.com/kb/478-how-to-monitor-applocker-events): What is AppLocker?Introduced in Windows 7 Enterprise Edition, AppLocker provides a mechanism within Windows to whitelist / blacklist known applications, publis - [The Heartbeat Agent is running under the LocalSystem account. | EventSentry](https://www.eventsentry.com/kb/135-the-heartbeat-agent-is-running-under-the-localsystem-account): It is not recommended to run the Heartbeat Agent under the LocalSystem account if you are monitoring the status of the EventSentry service (agent) on remote comp - [How can I extend my trial version? | EventSentry](https://www.eventsentry.com/kb/93-how-can-i-extend-my-trial-version): You can extend your existing trial version without loosing any settings and without having to interrupt the monitoring process.You have two options for extendi - [How to get notified of Group Policy Changes by email | EventSentry](https://www.eventsentry.com/kb/512-how-to-get-notified-of-group-policy-changes-by-email): Changes to group policies are detected by ADMonitor and recorded in the EventSentry database. As such, both a report and a job in the web reports need to be setu - [Is it possible to use load-balancing with multiple Collector hosts? | EventSentry](https://www.eventsentry.com/kb/342-is-it-possible-to-use-load-balancing-with-multiple-collector-hosts): It is not possible to automatically load-balance with multiple Collector hosts, but you can manually distribute the load by allocating certain groups or specific - [How to detect whether a process is running for more than X | EventSentry](https://www.eventsentry.com/kb/393-how-to-detect-whether-a-process-is-running-for-more-than-x-seconds-minutes): (video 1)--- Create event log package labeled "Long Running Process" Create an include filter in that package labeled “Process Creation”:textAction: D - [We receive the following error when trying to consolidate information | EventSentry](https://www.eventsentry.com/kb/113-we-receive-the-following-error-when-trying-to-consolidate-information-to-the-database-login-failed-for-user-eventsentry_svc-the-user-is-not-associated-with-a-trusted-sql-server-connection): There are usually two causes for the above error:1. The SQL Server does not have SQL Authentication turned on. A trusted SQL Server connection implies t - [How can I be alerted when a specific process starts? | EventSentry](https://www.eventsentry.com/kb/457-how-can-i-be-alerted-when-a-specific-process-starts): Windows generates an event ID 4688 in the Windows Security Event Log when a process gets launched. In Eve - [I am upgrading from v2.93 to v3.0. How do I enable SNMP performance | EventSentry](https://www.eventsentry.com/kb/251-i-am-upgrading-from-v2-93-to-v3-0-how-do-i-enable-snmp-performance-monitoring): Starting with version 3.0, performance counters can now also be configured to retrieve information via SNMP. With new installations, the "Performance System" s - [Running the EventSentry Management Console remotely via RemoteApp | EventSentry](https://www.eventsentry.com/kb/536-running-the-eventsentry-management-console-remotely-via-remoteapp): Since the EventSentry Management Console needs to be launched on the host where EventSentry was installed, managing EventSentry usually requires that users login - [How do I reinstall ADMonitor? | EventSentry](https://www.eventsentry.com/kb/521-how-do-i-reinstall-admonitor): In rare cases the internal database for the ADMonitor component may to be reset. If support directs you to do so, you can follow these steps to reinstall ADMonit - [EventSentry is unable to access certain resources located on different](https://www.eventsentry.com/kb/18-eventsentry-is-unable-to-access-certain-resources-located-on-different-computers-when-using-the-file-action-html-csv-ascii-or-when-performing-event-log-backups): You will need to take additional configuration steps when configuring EventSentry to access resources located on different computer.By default, the EventSentry - [Can I install the network services on a remote host with EventSentry | EventSentry](https://www.eventsentry.com/kb/275-can-i-install-the-network-services-on-a-remote-host-with-eventsentry-3-0-or-3-1-if-so-how): EventSentry 3.2 and newer use a different installation method for the network services, please see knowledge base article 306.To install the network services o - [Can I use EventSentry to deploy a kill file or vaccine for stopping | EventSentry](https://www.eventsentry.com/kb/368-can-i-use-eventsentry-to-deploy-a-kill-file-or-vaccine-for-stopping-ransomware-viruses-such-as-bad-rabbit): Yes, this is only takes a few minutes to configure.Use the EventSentry console toolbar and click Tools ) Embedded Scripts Make a new script a - [How can I be notified if a file has not been updated in a certain time?](https://www.eventsentry.com/kb/208-how-can-i-be-notified-if-a-file-has-not-been-updated-in-a-certain-time): You can launch the following VBScript through the application scheduler (e.g. every 1 minute) to be notified when a file has not been updated in X seconds.N - [When trying to test an email (smtp) notification, I always get an error](https://www.eventsentry.com/kb/155-when-trying-to-test-an-email-smtp-notification-i-always-get-an-error-that-tells-me-that-the-server-is-unable-to-relay-550-5-7-1-unable-to-relay-for-externaluser-hotmail-com-how-can-i-fix-this): If the email recipient you configured in the EventSentry action is outside of your email organization then the host attempting to to send the email must be allow - [How can I automate the installation (silent install) of the EventSentry](https://www.eventsentry.com/kb/99-how-can-i-automate-the-installation-silent-install-of-the-eventsentry-agent-for-example-when-automatically-setting-up-rolling-out-servers-or-workstations-how-can-i-manually-install-the-eventsentry-agent): Note: This article only applies to EventSentry v3.1 and earlier. See KB 297 for an updated version of this KB aricle.In order to function correctly the - [The Security \[3\] Critical Changes & Activity Dashboard | EventSentry](https://www.eventsentry.com/kb/516-the-security-3-critical-changes-activity-dashboard): The Critical Changes & Activity dashboard utilized a variety of EventSentry features to identify & review changes made to the network infrastructure and Active D - [Is there a default retention period? | EventSentry](https://www.eventsentry.com/kb/325-is-there-a-default-retention-period): NOTE: Starting in EventSentry 5.1, the default way to purge your database is from Web Reports. Please see KB 523 for in - [Why I am unable to install the EventSentry agent on a remote computer | EventSentry](https://www.eventsentry.com/kb/64-why-i-am-unable-to-install-the-eventsentry-agent-on-a-remote-computer-prior-to-v2-6): I am unable to install the EventSentry agent on a remote computer. I either get the error "Unable to start service (timeout)" from within the management applicat - [How to get an email alert if a user attempts to log on more than X | EventSentry](https://www.eventsentry.com/kb/407-how-to-get-an-email-alert-if-a-user-attempts-to-log-on-more-than-x-times-with-a-wrong-password): The easiest way to get notified in real-time whenever a user attempts to log on more than X times with a wrong password is by forwarding “Microsoft-Windows-Secur - [How do I send Syslog messages from Ubuntu to EventSentry? | EventSentry](https://www.eventsentry.com/kb/260-how-do-i-send-syslog-messages-from-ubuntu-to-eventsentry): The Syslog daemon (rsyslog) on Ubuntu is configured through the /etc/rsyslog.conf configuration file. Follow the steps below to send all Syslog messages f - [Why do I get an error about the "eventsentrysvcin.reg" file when | EventSentry](https://www.eventsentry.com/kb/326-why-do-i-get-an-error-about-the-eventsentry_svc_in-reg-file-when-pushing-the-configuration): You may receive the following error:batchUnable to prepare configuration file.Unable to open file (C:\Program Files (x86)\EventSentry\eventsentrysvcin.r - [The agent is using a large amount of CPU, is there anything I should | EventSentry](https://www.eventsentry.com/kb/304-the-agent-is-using-a-large-amount-of-cpu-is-there-anything-i-should-check): Please ensure that you do not have Registry Auditing enabled for the following registry path:HKEYLOCALMACHINE\SOFTWARE\netikus.net\EventSentry\bootscan - [On Windows 2000, the agent will not start, or I have to start the | EventSentry](https://www.eventsentry.com/kb/197-on-windows-2000-the-agent-will-not-start-or-i-have-to-start-the-service-manually): Due to an issue with the rasctrs.dll, which enables performance counters for the Remote Access service, the EventSentry service (v2.92 only) will n - [We plan on monitoring X servers with EventSentry, how big can we expect](https://www.eventsentry.com/kb/107-we-plan-on-monitoring-x-servers-with-eventsentry-how-big-can-we-expect-the-database-size-to-become-grow-for-x-servers): The anticipated database size depends on many factors, not just the number of hosts that are being monitored. In order to predict the future database size you wi - [What ports do I need to open to install or update an agent on a remote](https://www.eventsentry.com/kb/25-what-ports-do-i-need-to-open-to-install-or-update-an-agent-on-a-remote-computer-that-is-behind-a-firewall-or-router): EventSentry uses the standard Windows ports used for RPC/SMB File sharing to install/deploy, update, and manage the agent. To enable this feature to work with a - [Can I monitor a user's clipboard and detect / erase malicious content | EventSentry](https://www.eventsentry.com/kb/529-can-i-monitor-a-user-s-clipboard-and-detect-erase-malicious-content-from-the-clipboard): Yes, the tray utility EventSentray can be configured to monitor all text that is copied to a user's clipboard. This can prevent certain attacks that can tric - [The Heartbeat Status or Management Console report "the network path was](https://www.eventsentry.com/kb/302-the-heartbeat-status-or-management-console-report-the-network-path-was-not-found-or-the-rpc-server-is-unavailable): Both the Heartbeat agent and the Management Console attempt to connect to the service control manager running on a remote host in order to query the status of, o - [Is it possible to autoupdate or schedule remote configuration | EventSentry](https://www.eventsentry.com/kb/323-is-it-possible-to-autoupdate-or-schedule-remote-configuration-deployments): Yes, EventSentry includes a Remote Update (eventsentry_upd.exe) command line utility that will allow you to automate the remote update process. You can schedule - [How can I trigger an alert for specific text from a (log) file | EventSentry](https://www.eventsentry.com/kb/420-how-can-i-trigger-an-alert-for-specific-text-from-a-log-file): With the "EventSentry Log File Monitoring" feature you can be alerted via email if specific text gets written to a file. In this HowTo, we will use the default - [I am updating my database server to a newer version and I need to move](https://www.eventsentry.com/kb/200-i-am-updating-my-database-server-to-a-newer-version-and-i-need-to-move-my-eventsentry-database-from-my-old-database-server-to-the-new-one): If you need to relocate you would have to install SQL on your new system and to move your database, you would have to detach it from your old system (to do this - [Monitoring & Maintaining EventSentry Integrity | EventSentry](https://www.eventsentry.com/kb/535-monitoring-maintaining-eventsentry-integrity): This article explains how to monitor and maintain the integrity of an EventSentry installation.ServicesAll EventSentry service names (both the service key nam - [Receiving alerts for expired/expiring certificates | EventSentry](https://www.eventsentry.com/kb/395-receiving-alerts-for-expired-expiring-certificates): (video 3) Under 'Home ) Scripts ) User (Embedded)' click 'New' and then label this, 'expiring_certs.ps1' and in the 'Script Content' box add:powe - [How do I monitor failed logins on VMWare ESXi Hosts? | EventSentry](https://www.eventsentry.com/kb/462-how-do-i-monitor-failed-logins-on-vmware-esxi-hosts): Failed login attempts on VMWare ESXi hosts can be monitored via Syslog and the EventSentry Network Services Syslog daemon.First, the VMWare ESXi Host must be c - [The Security \[1\] Foundation Dashboard | EventSentry](https://www.eventsentry.com/kb/514-the-security-1-foundation-dashboard): The Security Foundation dashboard identifies audit insufficiently configured Windows audit settings from all monitored hosts. Properly configured audit settings - [Command output including non-Ascii characters are incorrectly displayed](https://www.eventsentry.com/kb/452-command-output-including-non-ascii-characters-are-incorrectly-displayed-in-application-scheduler): When utilizing the application scheduler on some Non-English versions of Windows, commands that output non-ascii characters (e.g. Umlaut in German) may cause the - [How do I send Syslog messages from macOS to EventSentry? | EventSentry](https://www.eventsentry.com/kb/449-how-do-i-send-syslog-messages-from-macos-to-eventsentry): The Syslog daemon (syslog) on macOS is configured through the /etc/syslog.conf configuration file. Follow the steps below to send all Syslog messages from an mac - [Custom Logon Failure dashboard tile using Event ID 4625 | EventSentry](https://www.eventsentry.com/kb/464-custom-logon-failure-dashboard-tile-using-event-id-4625): The EventSentry dashboard includes the generic "Search" tile, which can be used to display data from any page in the web reports, e.g. event log data. The Search - [Why am I unable to start the EventSentry Service and the EventSentry | EventSentry](https://www.eventsentry.com/kb/48-why-am-i-unable-to-start-the-eventsentry-service-and-the-eventsentry-management-console-on-windows-2003-sp1): On my Windows Server 2003 with service pack 1 (SP1) I am unable to start the EventSentry Service (Agent), and the EventSentry management console also won't load. - [How do I customize NTP (network time protocol) monitoring alerts? | EventSentry](https://www.eventsentry.com/kb/360-how-do-i-customize-ntp-network-time-protocol-monitoring-alerts): Open the management console Navigate to Packages -) System Health In the ribbon, click on the arrow below "Filter" and select "Network - [How do I run a script or query using PgAdmin? | EventSentry](https://www.eventsentry.com/kb/313-how-do-i-run-a-script-or-query-using-pgadmin): If our support department has requested that you run a script or query using PgAdmin, here are the steps:1) Right-click PgAdmin and run as an administrator (S - [The agent can't connect to the collector and logs event ID 905. What | EventSentry](https://www.eventsentry.com/kb/348-the-agent-can-t-connect-to-the-collector-and-logs-event-id-905-what-does-the-error-in-event-905-mean): There are several different errors that can occur.Timeout (301) or Connection Timed Out (10060)Please ensure that the agent can resolve the coll - [How can I manually remove all EventSentry agents, including the | EventSentry](https://www.eventsentry.com/kb/63-how-can-i-manually-remove-all-eventsentry-agents-including-the-associated-configuration-from-a-computer): Please follow the steps below to remove the EventSentry agent from a computer: In the Windows Start menu, open the Control Panel to "Add/Remove Programs" or - [The server running the management console is no longer available (e.g.](https://www.eventsentry.com/kb/55-the-server-running-the-management-console-is-no-longer-available-e-g-it-was-re-installed-how-can-i-restore-the-configuration-from-one-of-the-agents): In order to transfer the EventSentry configuration from a remote computer to the computer running the management application do the following:1) Log in - [Can I use my own certificate for the Network Services instead of the | EventSentry](https://www.eventsentry.com/kb/501-can-i-use-my-own-certificate-for-the-network-services-instead-of-the-default-self-signed-certificate): Yes, a self-signed certificate can be substituted for the certificate that is automatically generated by the Network Services when you enable Syslog TLS. You wil - [Can I get notified when an IIS web site is stopped (and/or started) on](https://www.eventsentry.com/kb/305-can-i-get-notified-when-an-iis-web-site-is-stopped-and-or-started-on-windows-2008-or-later): Yes, to get notified when an IIS site is stopped or started, follow the steps below: In the Windows event viewer, navigate to the Microsoft-Windows-IIS-Config - [I am using IIS, but when trying to view the web reports I always get a](https://www.eventsentry.com/kb/29-i-am-using-iis-but-when-trying-to-view-the-web-reports-i-always-get-a-http-error-404-file-or-directory-not-found-even-though-i-know-for-sure-that-the-page-does-exist): If you have verified that the page(s) you are trying to access does indeed exist, then this error is being displayed because the ASP component is missing in your - [I can see Syslog and/or SNMP packets sent to my machine with a packet | EventSentry](https://www.eventsentry.com/kb/261-i-can-see-syslog-and-or-snmp-packets-sent-to-my-machine-with-a-packet-sniffer-but-eventsentry-is-not-logging-the-packets-to-the-event-log-or-database): A packet sniffer like Microsoft Network Monitor, IPMon+ or Wireshark see network packets before they are analyzed by Windows and the Windows Firewall. As such it - [Can I configure the EventSentry Heartbeat Monitor service to run under](https://www.eventsentry.com/kb/105-can-i-configure-the-eventsentry-heartbeat-monitor-service-to-run-under-the-network-service-built-in-account-to-increase-security): Yes, you can configure the EventSentry Heartbeat Monitor service to run under the NETWORK SERVICE account for increased security. Follow the steps - [Why am I receiving ODBC/Database connection using Microsoft SQL Server](https://www.eventsentry.com/kb/117-why-am-i-receiving-odbc-database-connection-using-microsoft-sql-server-2000-2005): I get the following errors when testing our ODBC/Database connection using Microsoft SQL Server 2000/2005, the errors are also logged to the Application event lo - [How do I enable SNMP on a CentOS Linux host so that I can monitor | EventSentry](https://www.eventsentry.com/kb/282-how-do-i-enable-snmp-on-a-centos-linux-host-so-that-i-can-monitor-system-metrics-cpu-memory-diskspace-with-eventsentry): Run the following commands in the terminal:Update all packages: sudo yum check-update Install SNMP: yum -y install net-snmp(/li - [ASP support is not enabled on this installation of IIS. If you plan on](https://www.eventsentry.com/kb/143-asp-support-is-not-enabled-on-this-installation-of-iis-if-you-plan-on-hosting-the-eventsentry-web-reports-on-this-machine-then-asp-support-needs-to-be-enabled): To enable ASP support on IIS (ASP support is disabled by default), follow the steps below:IIS 6 Go to Start - Settings - Control Panel Open ( - [How can I be notified when an Exchange Server 2007/2010 mailbox is | EventSentry](https://www.eventsentry.com/kb/214-how-can-i-be-notified-when-an-exchange-server-2007-2010-mailbox-is-created-removed): There are a few prerequisites to setup in order to get notified when an Exchange mailbox is created or removed. The instructions below are for Exchange Server 20 - [I enabled the heartbeat option on the management console. How can I | EventSentry](https://www.eventsentry.com/kb/156-i-enabled-the-heartbeat-option-on-the-management-console-how-can-i-configure-the-subject-of-the-alert-in-order-to-have-the-name-of-the-computer-that-went-down-and-not-the-one-that-does-the-monitoring): The subject of EventSentry emails is highly customizable using standard variables (e.g. $HOSTNAME) as well as insertion string variables ($STR1, $STR2, ...).Si - [Can I be notified when a directory contains more than a configurable | EventSentry](https://www.eventsentry.com/kb/206-can-i-be-notified-when-a-directory-contains-more-than-a-configurable-number-of-files): You can launch the following VBScript through the application scheduler (e.g. every 1 minute) to be notified when the number of files in a given folder exceeds a - [Is there a way to import multiple (event) log files with a script? | EventSentry](https://www.eventsentry.com/kb/387-is-there-a-way-to-import-multiple-event-log-files-with-a-script): Yes, EventSentry comes with a log file import utility which can be operated manually (double-click it and navigate the interface) or from the command line. The - [How do I troubleshoot a System DNS that is not writing to the database?](https://www.eventsentry.com/kb/24-how-do-i-troubleshoot-a-system-dns-that-is-not-writing-to-the-database): I am trying to use the ODBC notification with a Microsoft SQL Server (MSSQL) and I have setup a system DSN. When I click the TEST button in the ODBC target of th - [How do I adjust file (integrity) monitoring alerts? | EventSentry](https://www.eventsentry.com/kb/359-how-do-i-adjust-file-integrity-monitoring-alerts): File monitoring (aka as File Integrity Monitoring, FIM) monitors directories to detect changes to files as well as files being added and removed from directories - [I am using the Event Log Backup feature to backup (or backup and clear)](https://www.eventsentry.com/kb/21-i-am-using-the-event-log-backup-feature-to-backup-or-backup-and-clear-the-event-logs-to-a-central-network-location-but-the-event-logs-are-not-being-backed-up-instead-an-access-denied-error-occurs): This is usually a permissions issue. When backing up the logs the EventSentry agent is running under the LocalSystem account by default, and you might have to ta - [What is the difference between a Full License and a Network Device | EventSentry](https://www.eventsentry.com/kb/267-what-is-the-difference-between-a-full-license-and-a-network-device-license): In a nutshell, full licenses are intended to be used for Windows(R) servers and workstations, whereas network device licenses are intended to be used for Non-Win - [Can EventSentry send a SMS (text message) alert? | EventSentry](https://www.eventsentry.com/kb/301-can-eventsentry-send-a-sms-text-message-alert): EventSentry can send alerts via SMS in two different ways:1. Email GatewaysMost mobile (cell) phone providers offer an email to cell phone gateway, whe - [How to Exclude a Service from Monitoring in EventSentry | EventSentry](https://www.eventsentry.com/kb/356-how-to-exclude-a-service-from-monitoring-in-eventsentry): You can configure EventSentry to ignore specific services to prevent unnecessary alerts. Please note that excluding a service via the System Health settings will - [I'm receiving the following error: Could not acquire security | EventSentry](https://www.eventsentry.com/kb/336-i-m-receiving-the-following-error-could-not-acquire-security-credentials-error-0x80090331-what-can-i-do): I'm receiving the following error from the collector: Event ID: 905 Source: EventSentry Category: Collector Client The EventSentry agent is una - [Removing the built-in EventSentry PostgreSQL v9.6 Database after | EventSentry](https://www.eventsentry.com/kb/467-removing-the-built-in-eventsentry-postgresql-v9-6-database-after-migrating-to-v14-2): After successfully migrating to the newer PostgreSQL v14.2 database that is available in EventSentry v5.0 and later, the legacy v9.6 built-in database can be rem - [How to monitor/detect PrintNightmare CVE-2021-1675 / CVE-2021-34527 | EventSentry](https://www.eventsentry.com/kb/458-how-to-monitor-detect-printnightmare-cve-2021-1675-cve-2021-34527-utilizing-the-windows-event-log-and-sysmon): Sysmon is a free driver-based utility that supplements Windows's built-in audit capabilities. C - [I no longer use Postgres for EventSentry. How do I remove the Postgres](https://www.eventsentry.com/kb/270-i-no-longer-use-postgres-for-eventsentry-how-do-i-remove-the-postgres-driver-from-my-computers): Removing or uninstalling the Postgres driver should only be done if you have no other applications that use Postgres on your computers. If you are certain that - [How to monitor performance metrics (CPU and memory utilization) on | EventSentry](https://www.eventsentry.com/kb/441-how-to-monitor-performance-metrics-cpu-and-memory-utilization-on-vmware-esxi-hosts): Since VMWare ESXi hosts report CPU and memory utilization differently than other Linux or Unix-based hosts, the generic Performance System package cannot be used - [You are unable to store authentication credentials due to a delegation](https://www.eventsentry.com/kb/286-you-are-unable-to-store-authentication-credentials-due-to-a-delegation-error): If you attempt to store authentication credentials in the EventSentry Management Console and receive the following error:The requested operation cannot be c - [How do I enable SNMP on an Ubuntu Linux host so that I can monitor | EventSentry](https://www.eventsentry.com/kb/281-how-do-i-enable-snmp-on-an-ubuntu-linux-host-so-that-i-can-monitor-system-metrics-cpu-memory-diskspace-with-eventsentry): Run the following commands in the terminal:Update package list: sudo apt update Install SNMP: sudo apt install snmpd - [After installing the EventSentry agent on computers when I try to start](https://www.eventsentry.com/kb/118-after-installing-the-eventsentry-agent-on-computers-when-i-try-to-start-the-eventsentry-service-agent-i-receive-the-error-the-system-license-has-expired-your-logon-request-is-denied): This message is displayed when the EventSentry agent does not have a valid license installed, it does not necessarily mean that a trial license has expired.Fir - [How do I move the built-in EventSentry PostgreSQL database? | EventSentry](https://www.eventsentry.com/kb/247-how-do-i-move-the-built-in-eventsentry-postgresql-database): First we recommend you make a backup of the database in case you have any issues and need to re-install:(a href="https://www.eventsentry.com/kb/235" target="b - [How can I exclude a specific disk on one or more hosts from generating](https://www.eventsentry.com/kb/362-how-can-i-exclude-a-specific-disk-on-one-or-more-hosts-from-generating-disk-space-alerts): If you are getting diskspace alerts about a specific drive that is expected to have little or no disk space available (such as the destination for a backup), the - [Is EventSentry affected by the Heartbleed vulnerability? | EventSentry](https://www.eventsentry.com/kb/256-is-eventsentry-affected-by-the-heartbleed-vulnerability): By default, EventSentry is not affected by the Heartbleed unless SSL is enabled on the built-in PostgreSQL database.See below for a list of all EventSentry com - [Print Tracking in the Web Reports shows either "Print Document" or an | EventSentry](https://www.eventsentry.com/kb/491-print-tracking-in-the-web-reports-shows-either-print-document-or-an-incorrect-document-name): Following a recent security update to Microsoft Windows (Desktop and Server), some computers do not log the name of the printed document to the Microsoft-Windo - [One of my servers is behind a firewall/router or in a DMZ, what ports | EventSentry](https://www.eventsentry.com/kb/40-one-of-my-servers-is-behind-a-firewall-router-or-in-a-dmz-what-ports-need-to-be-open-so-that-eventsentry-can-notify-the-configured-actions): This depends on the notifications used. Below you can find a list of the standard ports used for the support notifications in EventSentry. Deploy, Manage, or - [When Non-Administrators try to view the web reports, or after upgrading](https://www.eventsentry.com/kb/52-when-non-administrators-try-to-view-the-web-reports-or-after-upgrading-to-the-latest-version-we-get-the-following-error-msxml3-dll-error-80070005-access-is-denied): Starting with version 2.70, the EventSentry web reports need the XML files which are located in the installation directory of EventSentry to work correctly. Fo - [How can I detect web application attacks with EventSentry? | EventSentry](https://www.eventsentry.com/kb/443-how-can-i-detect-web-application-attacks-with-eventsentry): Starting with EventSentry v4.2.3, web attacks can be detected with a set of regular expression rules that can be applied to any monitored log file, including IIS - [Can I restrict the EventSentryADMonitor account's Domain Admin | EventSentry](https://www.eventsentry.com/kb/444-can-i-restrict-the-eventsentryadmonitor-account-s-domain-admin-permissions): For additional security you can restrict the EventSentryADMonitor account to only be allowed to be used on the EventSentry server and domain controllers, and - [When trying to run a PowerShell script from EventSentry, the script | EventSentry](https://www.eventsentry.com/kb/198-when-trying-to-run-a-powershell-script-from-eventsentry-the-script-hangs-and-never-exits): Due to a bug in powershell.exe (see additional links), any PowerShell script launched by EventSentry's application scheduler or process action will never termina - [Heartbeat alerts contain the text "\[10022\] invalid argument" even | EventSentry](https://www.eventsentry.com/kb/427-heartbeat-alerts-contain-the-text-10022-invalid-argument-even-though-the-remote-host-port-is-up-how-do-i-resolve-this): If you receive an error message similar to the one shown below(img 323)then we recommend that you first restart the EventSentry Heartbeat Service to see if t - [How can I be notified if a single file exceeds a certain file size? | EventSentry](https://www.eventsentry.com/kb/207-how-can-i-be-notified-if-a-single-file-exceeds-a-certain-file-size): You can launch the following VBScript through the application scheduler (e.g. every 1 minute) to be notified when the size of a file exceeds a configurable limit - [When trying to view the web reports in a Non-US language (e.g. Korean,](https://www.eventsentry.com/kb/111-when-trying-to-view-the-web-reports-in-a-non-us-language-e-g-korean-japanese-chinese-etc-then-some-characters-don-t-show-up-correctly-in-the-web-reports-this-problem-only-occurs-on-microsoft-sql-server-not-with-mysql): This usually happens when the locale / character set of the host where IIS is installed differs from that of the language being recorded in the Microsoft SQL Ser - [What information should I send to NETIKUS.NET during a beta test? | EventSentry](https://www.eventsentry.com/kb/291-what-information-should-i-send-to-netikus-net-during-a-beta-test): The purpose of our public beta programs is to identify errors and bugs in EventSentry prior to the official release as well as gather feedback about the new vers - [When running a search you get the following error: Active Server Pages,](https://www.eventsentry.com/kb/45-when-running-a-search-you-get-the-following-error-active-server-pages-asp-0113-0x80004005-the-maximum-amount-of-time-for-a-script-to-execute-was-exceeded): By default IIS will throw this error when an ASP page does not return within 90 seconds. For simple searches in the web reports, this should not be an issue. How - [Is there a package for EventSentry which includes the events listed in](https://www.eventsentry.com/kb/338-is-there-a-package-for-eventsentry-which-includes-the-events-listed-in-the-document-spotting-the-adversary-with-windows-event-log-monitoring): The National Security Agency (NSA) and the Central Security Service (CSS) published the document "Spotting the Adversary with Windows Event Log Monitoring" which - [How do I display the host or device names of a Syslog sender, instead | EventSentry](https://www.eventsentry.com/kb/292-how-do-i-display-the-host-or-device-names-of-a-syslog-sender-instead-of-its-ip-address): On the EventSentry server, use the command prompt to run:nslookup 192.168.1.1(replace "192.168.1.1" with the IP address of a Syslog-sending device or server) - [Can I customize the email subject of SNORT alerts received via Syslog?](https://www.eventsentry.com/kb/349-can-i-customize-the-email-subject-of-snort-alerts-received-via-syslog): Yes, by using the regular expression and subject override feature in event log filters the email subject can show select properties from Snort alerts.A typical - [How can I configure my SQL Server 2000 or 2005 to use SQL | EventSentry](https://www.eventsentry.com/kb/114-how-can-i-configure-my-sql-server-2000-or-2005-to-use-sql-authentication-in-addition-to-windows-authentication): It is highly recommended that you use SQL Authentication when consolidating events and other information to a SQL Server database.Microsoft SQL Serve - [Can I monitor the RAID status, fan status, and so forth of Dell and HP](https://www.eventsentry.com/kb/345-can-i-monitor-the-raid-status-fan-status-and-so-forth-of-dell-and-hp-servers): Yes, as long as the necessary WMI interface (Dell OpenManage, HP Insight WBEM) is installed in the operating system, the EventSentry agent can detect and monitor - [How do I ensure that my Web Reports successfully convert from 32-bit to](https://www.eventsentry.com/kb/370-how-do-i-ensure-that-my-web-reports-successfully-convert-from-32-bit-to-64-bit-in-eventsentry-3-4): If you used the default install destination (C:\Program Files (x86)\EventSentry\WebReports) you don't have to do anything and your settings should successfully b - [The "Test" button is unsuccessful in Environment Monitoring. How can I](https://www.eventsentry.com/kb/293-the-test-button-is-unsuccessful-in-environment-monitoring-how-can-i-verify-that-the-sensor-is-functioning): First, you would need to verify which COM port the sensor is attached to. In this example, we will use COM3, but you would want to specify the COM port that you - [Agent Deployment / Installation Prerequisites | EventSentry](https://www.eventsentry.com/kb/538-agent-deployment-installation-prerequisites): When deploying agents with the management console (and not via MSI), the user running the management console needs to meet the following prerequisites on each re - [When viewing the web reports with Internet Explorer (IE), one or more | EventSentry](https://www.eventsentry.com/kb/27-when-viewing-the-web-reports-with-internet-explorer-ie-one-or-more-pages-do-not-display-but-instead-return-a-500-internal-server-error-or-an-error-occurred-on-the-server-when-processing-the-url): To find out why a page is not loading you will need to reconfigure Internet Explorer to show advanced error messages: Open Internet Explorer Click Tools -) - [One or more database action is configured to use a System DSN instead | EventSentry](https://www.eventsentry.com/kb/137-one-or-more-database-action-is-configured-to-use-a-system-dsn-instead-of-a-connection-string): You can configure EventSentry to connect to database servers either by using an ODBC connection string (recommended) or by using an ODBC System DSN.System DSN' - [How can I find out which message file is used by a particular source | EventSentry](https://www.eventsentry.com/kb/65-how-can-i-find-out-which-message-file-is-used-by-a-particular-source-logging-to-the-event-log): Every application that is logging to the event log ussage has what is called a message file associated with it. Message files are used to translate event ids and - [How can I restrict or extend access to the web reports? | EventSentry](https://www.eventsentry.com/kb/67-how-can-i-restrict-or-extend-access-to-the-web-reports): Access to the web reports can be restricted or extended by changing the NTFS permissions of the actual ASP files, by default located in \Program Files\EventSentr - [Monitoring Docker containers | EventSentry](https://www.eventsentry.com/kb/472-monitoring-docker-containers): The CPU and memory utilization of each container as well as the number of docker containers currently running can be monitored using EventSentry's performance mo - [When testing the temperature/humidity sensor I get an "Access is | EventSentry](https://www.eventsentry.com/kb/84-when-testing-the-temperature-humidity-sensor-i-get-an-access-is-denied-error-temperature-monitoring-seems-to-work-for-a-while-but-at-some-points-stops-working-until-i-reboot-the-server): If EventSentry reports "Access Denied" when trying to read data from the temperature and/or humidity environment sensor, then this usually means that another app - [Why do I receive error MySQL error 1045 (access denied for user | EventSentry](https://www.eventsentry.com/kb/365-why-do-i-receive-error-mysql-error-1045-access-denied-for-user-root-servername): The default MySQL permissions do not allow remote connections when using the "root" account, but the "root" account is needed to create, modify, or upgrade your - [Can a run the EventSentry Collector Service as a non-privileged account](https://www.eventsentry.com/kb/290-can-a-run-the-eventsentry-collector-service-as-a-non-privileged-account-like-network-service): Yes. However, if you change the service account used for the Collector, you will not be able to re-use the existing certificate, as a new one must be created wh - [How can I restart a server on a regular basis, say every Sunday | EventSentry](https://www.eventsentry.com/kb/406-how-can-i-restart-a-server-on-a-regular-basis-say-every-sunday-morning): The easiest way to accomplish this is by using the EventSentry application scheduler & the Windows "(Shutdown.exe)(https://docs.microsoft.com/en-us/windows-serve - [How to get an email when a specific service/driver starts or stops? | EventSentry](https://www.eventsentry.com/kb/405-how-to-get-an-email-when-a-specific-service-driver-starts-or-stops): The easiest way to get notified in real-time whenever specific service/driver starts or stops is by forwarding “EventSentry” event 10100 or 10150. This particula - [Can I monitor databases (e.g. SQL Server, Oracle, etc.) with | EventSentry](https://www.eventsentry.com/kb/120-can-i-monitor-databases-e-g-sql-server-oracle-etc-with-eventsentry): Yes, you can monitor most databases with EventSentry, depending on how well the database interacts with the following components of the Operating System: Even - [What is proration? | EventSentry](https://www.eventsentry.com/kb/329-what-is-proration): SummaryProration is a line item which is automatically added to quotes and invoices when additional EventSentry licenses are added to an existing set of - [How do I configure a Maintenance Plan for my database? | EventSentry](https://www.eventsentry.com/kb/220-how-do-i-configure-a-maintenance-plan-for-my-database): When using Microsoft SQL Server with EventSentry, we recommend setting up a Maintenance Plan to continually check integrity, reduce index fragmentation and perio - [Can I create a PowerShell embedded script? | EventSentry](https://www.eventsentry.com/kb/324-can-i-create-a-powershell-embedded-script): Yes!Navigate to Tools ) Embedded scripts within the EventSentry management console. The "Manage Embedded Scripts" window then open and from there you can click - [How do I adjust scheduled tasks monitoring alerts? | EventSentry](https://www.eventsentry.com/kb/361-how-do-i-adjust-scheduled-tasks-monitoring-alerts): EventSentry monitors all scheduled tasks on a system by default and will generate an alert when a scheduled task is added, removed or changed.Open the - [How can I get notified when a server or workstation reboot? | EventSentry](https://www.eventsentry.com/kb/401-how-can-i-get-notified-when-a-server-or-workstation-reboot): The easiest way to get notified in real-time whenever a Windows-based system boots is by forwarding "Event Log" event 6009. This event is logged to the System ev - [Is it possible to monitor both the System32 & Syswow64 directories? | EventSentry](https://www.eventsentry.com/kb/243-is-it-possible-to-monitor-both-the-system32-syswow64-directories): Yes, it is possible to monitor both of these directories on a 64-bit machine with the "Disable folder redirection on 64-bit systems (Wow64)" option in File Monit - [Can I monitor Cisco devices (e.g. switches and routers) with | EventSentry](https://www.eventsentry.com/kb/199-can-i-monitor-cisco-devices-e-g-switches-and-routers-with-eventsentry): Yes, you can monitor Cisco devices, as well as network devices from other vendors, in a variety of ways with EventSentry.SNMP Alerts (Traps)You can con - [Some of the default performance counters which ship with EventSentry do](https://www.eventsentry.com/kb/236-some-of-the-default-performance-counters-which-ship-with-eventsentry-do-not-work-on-our-systems-which-are-in-german): EventSentry ships with a variety of default packages, all of which are optimized for systems installed in English. Efforts are underway to support other language - [How do I exclude service status change alerts for the aelookupsvc? | EventSentry](https://www.eventsentry.com/kb/300-how-do-i-exclude-service-status-change-alerts-for-the-aelookupsvc): The quickest way to exclude unwanted service status change events, such as the aelookupsvc, is to added them to the list of excluded services:I - [Microsoft introduced additional "Operational" event logs with Vista and](https://www.eventsentry.com/kb/163-microsoft-introduced-additional-operational-event-logs-with-vista-and-windows-server-2008-that-appear-in-the-applications-and-services-logs-section-of-the-event-viewer-can-i-monitor-these-operational-event-logs-with-eventsentry-and-if-so-how): Most of the event logs contained under the "Microsoft" folder in the "Applications and Services Logs" section of the Event Viewer can be monitored using the "Cus - [I deleted a significant amount of data from my MSSQL database, but | EventSentry](https://www.eventsentry.com/kb/151-i-deleted-a-significant-amount-of-data-from-my-mssql-database-but-space-used-by-the-database-remains-high-and-i-am-unable-to-free-up-disk-space-i-am-also-unable-to-shrink-the-database-transaction-log-file): If the recovery model is set to "Full", then Microsoft SQL Server will record transactions, including removed data, in the transaction log for recovery purposes. - [Can I change the size of the network services debug log file? | EventSentry](https://www.eventsentry.com/kb/353-can-i-change-the-size-of-the-network-services-debug-log-file): Starting with version 3.3.1.84, the maximum size of the debug log file located in %SYSTEMROOT%\system32\eventsentry\logs can be adjusted with the debug - [I changed the language in the web reports to an Asian language (e.g. | EventSentry](https://www.eventsentry.com/kb/112-i-changed-the-language-in-the-web-reports-to-an-asian-language-e-g-korean-japanese-but-the-characters-don-t-show-up-correctly-the-event-log-messages-are-but-the-fields-themselves-are-garbled): The most likely cause for this is an incorrect character set encoding in the XML file. Version 2.72d and earlierTo resolve this problem, open the We - [EventSentry Debug Log Files. | EventSentry](https://www.eventsentry.com/kb/83-eventsentry-debug-log-files): EventSentry writes debug information to log files to help troubleshoot configuration and software issues. To prevent disk space issues, all log files are capped - [How do I resolve the error "Group Policy Management not installed" on | EventSentry](https://www.eventsentry.com/kb/392-how-do-i-resolve-the-error-group-policy-management-not-installed-on-the-admonitor-dialog): Group Policy Management is required by the EventSentry ADMonitor Service to detect Group Policy changes and needs to be installed on the machine that is running - [Can the EventSentry agent be installed inside a Windows Docker | EventSentry](https://www.eventsentry.com/kb/471-can-the-eventsentry-agent-be-installed-inside-a-windows-docker-container): Yes, the EventSentry agent can be installed inside a Docker container running either Windows Server or Windows Server Core (Nano server is NOT supported).Follo - [Why are events not formatted correctly, even though they show up | EventSentry](https://www.eventsentry.com/kb/159-why-are-events-not-formatted-correctly-even-though-they-show-up-correctly-with-the-built-in-windows-event-viewer): Some events that are processed by EventSentry are not formatted correctly, even though they show up correctly with the built-in Windows Event Viewer. This seems - [I setup an ODBC target, but only the local machine is writing correctly](https://www.eventsentry.com/kb/11-i-setup-an-odbc-target-but-only-the-local-machine-is-writing-correctly-to-the-database-the-other-computers-where-eventsentry-is-installed-have-the-correct-configuration-but-are-not-writing-to-the-database): When using ODBC targets you will need to make sure that: The System DSN referenced in the ODBC target is present on all computers writing to the database. Thi - [Why do I get "SNMP v3 Authentication Error" when doing Check Status? | EventSentry](https://www.eventsentry.com/kb/379-why-do-i-get-snmp-v3-authentication-error-when-doing-check-status): If you use EventSentry 3.4 and have a build number older than 68, this error can indicate that either the SNMP check failed due to a blocked port (UDP port 161 i - [Can I change the size of the EventSentry Agent's debug log file? | EventSentry](https://www.eventsentry.com/kb/234-can-i-change-the-size-of-the-eventsentry-agent-s-debug-log-file): Starting with version 2.93.1.37, the maximum size of the debug log file located in %SYSTEMROOT%\system32\eventsentry\logs can be adjusted with the "debuglevel_ma - [My LDAPS integration for Linux Web Reports fails due to certificate | EventSentry](https://www.eventsentry.com/kb/363-my-ldaps-integration-for-linux-web-reports-fails-due-to-certificate-errors-how-do-i-fix-this): 1) Obtain the specified LDAP server's certificate:https://ldapwiki.com/wiki/Obtain%20a%20Certificate%20from%20Server*Note, please save it as "X.509 Certificate - [How are the username and password for database targets stored in the | EventSentry](https://www.eventsentry.com/kb/86-how-are-the-username-and-password-for-database-targets-stored-in-the-registry-is-this-information-stored-in-clear-text-or-encrypted): All ODBC connection information, including the Connection String Username Passwordare stored in clear text in the registry. However, the following prec - [How do I get notified when a new user is created in Active Directory? | EventSentry](https://www.eventsentry.com/kb/403-how-do-i-get-notified-when-a-new-user-is-created-in-active-directory): The easiest way to get notified in real-time whenever a user is created in Active Directory is by forwarding “Microsoft-Windows-Security-Auditing” event (4720)(h - [How can I upgrade the network services to 64-bit? | EventSentry](https://www.eventsentry.com/kb/327-how-can-i-upgrade-the-network-services-to-64-bit): Starting with version 3.2 of EventSentry, the network services component (service) is available as both a 32-bit and 64-bit executable. New installations will au - [I have been instructed to get a crash dump to debug a crashing agent. | EventSentry](https://www.eventsentry.com/kb/257-i-have-been-instructed-to-get-a-crash-dump-to-debug-a-crashing-agent-how-can-get-a-crash-dump): To get a crash dump, the following steps will have to be followed as per this Microsoft Article on the machine with the crashing program: (a href="https://msdn.m - [On Microsoft SQL Server, can I run database purge jobs with a user | EventSentry](https://www.eventsentry.com/kb/195-on-microsoft-sql-server-can-i-run-database-purge-jobs-with-a-user-other-than-the-built-in-sa-or-administrator-account): Yes, you do not need to run database purge jobs with an administrative account. For SQL Server 2005 and later, please follow the steps below to create an account - [I can't view the .chm help file of EventSentry - all I see is "Action | EventSentry](https://www.eventsentry.com/kb/53-i-can-t-view-the-chm-help-file-of-eventsentry-all-i-see-is-action-cancelled-when-i-click-on-the-topics): When you open a CHM file from a UNC path or from a network drive even if the network drive is mapped to a drive letter, the HTML Help viewer opens and instead of - [Can I change the size of the EventSentry Collector debug log file(s)? | EventSentry](https://www.eventsentry.com/kb/388-can-i-change-the-size-of-the-eventsentry-collector-debug-log-file-s): The maximum size of the debug log file for the collector service can be adjusted with the debuglevelmaxsize registry value. This DWORD value specifies the - [Unable to connect to one or more database actions. | EventSentry](https://www.eventsentry.com/kb/147-unable-to-connect-to-one-or-more-database-actions): The support utility was not able to connect to one of the configured database actions, which usually indicates a connectivity problem between the host where the - [Do I need to change or modify anything when including the EventSentry | EventSentry](https://www.eventsentry.com/kb/367-do-i-need-to-change-or-modify-anything-when-including-the-eventsentry-agent-in-a-deployment-image-or-template): Yes, it is very important to remove the unique agent identifier to prevent connection failures when using the Collector component. To remove the identifier:1) - [When trying to install an EventSentry agent on a remote machine you get](https://www.eventsentry.com/kb/71-when-trying-to-install-an-eventsentry-agent-on-a-remote-machine-you-get-the-following-error-error-7056-the-system-license-has-expired-your-logon-request-is-denied): This error appears when the EventSentry license information, which is stored in the registry, has not been transferred correctly to the remote host.Please perf - [Which database uses more bandwidth, and how much bandwidth (network | EventSentry](https://www.eventsentry.com/kb/80-which-database-uses-more-bandwidth-and-how-much-bandwidth-network-traffic-does-event-log-consolidation-use): We have compared network traffic used between Microsoft SQL Server and MySQL in a scenario where one event log entry is logged to a database. In this scenario Ev - [Is it possible to trigger a script or command based on the IP address | EventSentry](https://www.eventsentry.com/kb/377-is-it-possible-to-trigger-a-script-or-command-based-on-the-ip-address-value-in-an-event): Yes, in fact we have a (tutor - [Does EventSentry support multiple tenants (multi-tenancy)? | EventSentry](https://www.eventsentry.com/kb/266-does-eventsentry-support-multiple-tenants-multi-tenancy): Yes, the EventSentry web reports support multi-tenancy through access control and profiles.Access ControlBy enabling access control through the "Accoun - [How to set the Agent service Debug Level to High and send logs to | EventSentry](https://www.eventsentry.com/kb/60-how-to-set-the-agent-service-debug-level-to-high-and-send-logs-to-eventsentry-support): 1. Set Debug Level: In the EventSentry Management Console, navigate to Services and set the debug level to High. Setting the debug level to High has little t - [When installing EventSentry or launching the database wizard, I get an](https://www.eventsentry.com/kb/381-when-installing-eventsentry-or-launching-the-database-wizard-i-get-an-error-about-api-ms-win-crt-runtime-l1-1-0-and-it-crashes): This is caused by a missing Windows update. If Windows has not been recently updated, or if you've been installing nothing but Security-Only updates and Securit - [The "installdir" registry value is either missing or pointing to an | EventSentry](https://www.eventsentry.com/kb/140-the-installdir-registry-value-is-either-missing-or-pointing-to-an-invalid-directory): The EventSentry registry contains the "installdir" value that stores the physical location where EventSentry is installed with the setup program, C:\Program F - [How can I get an alert if a VMWare VM on an ESXi host is reverted to a](https://www.eventsentry.com/kb/408-how-can-i-get-an-alert-if-a-vmware-vm-on-an-esxi-host-is-reverted-to-a-snapshot): In a production environment it can be important to know if and when a VM is reverted to a snapshot. If the VMWare ESXi host is (configured to send Syslog message - [After upgrading EventSentry, the uptime calculation page does not work](https://www.eventsentry.com/kb/59-after-upgrading-eventsentry-the-uptime-calculation-page-does-not-work-properly-and-some-or-all-hosts-are-missing): To resolve this problem you will need to stop the EventSentry Heartbeat agent and delete the temporary file used by the service. Please follow the instructions b - [Do I need a database to run EventSentry? | EventSentry](https://www.eventsentry.com/kb/157-do-i-need-a-database-to-run-eventsentry): While a database is not strictly required to run EventSentry (it will install & run just fine without), it is recommended for most scenarios.If you want to tak - [Which types of sensor combinations are available with the HWg-STE2 LITE](https://www.eventsentry.com/kb/525-which-types-of-sensor-combinations-are-available-with-the-hwg-ste2-lite-monitor): The HWg-STE2 LITE has one RJ-11 connector and ships with a single temperature sensor out of the box. Monitoring something other than temperature requires that th - [I created a process action that is visible on the desktop, but the | EventSentry](https://www.eventsentry.com/kb/160-i-created-a-process-action-that-is-visible-on-the-desktop-but-the-application-doesn-t-display-properly-the-window-is-there-but-the-content-of-the-window-can-t-be-seen-even-if-i-move-the-frame): This problem usually only occurs under the following circumstances:- You are launching an application with a user interface from EventSentry (e.g. notepad) - n - [How can I restrict access to the management application from | EventSentry](https://www.eventsentry.com/kb/66-how-can-i-restrict-access-to-the-management-application-from-unauthorized-users): Access to the EventSentry configuration is automatically restricted to members of the local Administrators group, or Domain Admins group on domain controllers. M - [Why are we receiveing error "ConnectionOpen (gethostbyname()())" when | EventSentry](https://www.eventsentry.com/kb/94-why-are-we-receiveing-error-connectionopen-gethostbyname-when-connecting-to-sql-server): When the EventSentry database is located in a SQL Server instance, then you can point to the instance by using the TCP port number instead of using the instance - [What are the default accounts used for each EventSentry service? | EventSentry](https://www.eventsentry.com/kb/376-what-are-the-default-accounts-used-for-each-eventsentry-service): | Service | Account || -------- | -------- || EventSentry (agent) | LocalSystem account | | EventSentry Collector | LocalSystem account | | Event - [Events seem to be processed multiple times, instead of just once. For | EventSentry](https://www.eventsentry.com/kb/16-events-seem-to-be-processed-multiple-times-instead-of-just-once-for-example-events-show-up-twice-in-emails-or-are-written-multiple-times-to-the-database-why): Filters are processed sequentially, one-by-one, by the EventSentry agent. If an event matches multiple filters, then every filter matching the event will send th - [The EventSentry registry key cannot be accessed by the currently | EventSentry](https://www.eventsentry.com/kb/136-the-eventsentry-registry-key-cannot-be-accessed-by-the-currently-logged-on-user): EventSentry secures the registry key where the EventSentry configuration is stored (HKLM\Software\netikus.net\EventSentry) by removing the following built - [Can I monitor both the active and passive node in a cluster with | EventSentry](https://www.eventsentry.com/kb/130-can-i-monitor-both-the-active-and-passive-node-in-a-cluster-with-eventsentry-without-receiving-duplicate-notifications-from-events-in-the-event-logs): If you do not want to setup the EventSentry service as a cluster resource, then you can also reconfigure the cluster to disable the replication of event logs. Yo - [When installing EventSentry with the heartbeat monitor option I get the](https://www.eventsentry.com/kb/69-when-installing-eventsentry-with-the-heartbeat-monitor-option-i-get-the-following-error-message-no-mapping-between-account-names-and-security-id-s-was-done): This error message is displayed when the setup routine cannot find the username that you specified for the heartbeat agent. There are two ways to solve this prob - [Can I monitor website content with EventSentry? | EventSentry](https://www.eventsentry.com/kb/319-can-i-monitor-website-content-with-eventsentry): Yes, NETIKUS.NET provides a free tool called CheckURL that may be sch - [When searching for events using the web reports, I sometimes or always](https://www.eventsentry.com/kb/96-when-searching-for-events-using-the-web-reports-i-sometimes-or-always-get-the-following-error-message-microsoft-odbc-sql-server-driver-timeout-expired): The web reports have a limit on how long a database query may take before it is interrupted. You can increase this limit through the profile editor however. Navi - [The EventSentry agent is not installed or stopped. | EventSentry](https://www.eventsentry.com/kb/134-the-eventsentry-agent-is-not-installed-or-stopped): EventSentry requires the EventSentry agent to installed on running on all machines that you need to monitor. If the agent is not installed or stopped, no monitor - [Why is the "Performed By" column in ADMonitor reports empty? | EventSentry](https://www.eventsentry.com/kb/503-why-is-the-performed-by-column-in-admonitor-reports-empty): While ADMonitor itself does not rely on Windows auditing to detect actual changes made in Active Directory, it does require access to the event log of a domain c - [When to use a non-embedded script vs embedded script? | EventSentry](https://www.eventsentry.com/kb/398-when-to-use-a-non-embedded-script-vs-embedded-script): For any "Process" action or "Application Scheduler" object in EventSentry, you can use a non-embedded script by providing the full path to the script file, i.e., - [I see duplicate entries in the computer drop-down box in the web | EventSentry](https://www.eventsentry.com/kb/217-i-see-duplicate-entries-in-the-computer-drop-down-box-in-the-web-reports-for-computer-names-which-exceed-15-characters-why): On hosts where the computer name exceeds the NetBIOS maximum of 15 characters, some events may be logged to the event log with the truncated NetBIOS-compatible n - [I installed EventSentry on a 64-bit version of Windows and when trying](https://www.eventsentry.com/kb/89-i-installed-eventsentry-on-a-64-bit-version-of-windows-and-when-trying-to-access-the-web-reports-i-get-the-following-error-provider-is-not-specified-and-there-is-no-designated-default-provider-i-would-like-to-use-the-microsoft-access-database): Microsoft has not yet provided 64-bit drivers for Microsoft Access, and at this point does not seem to have any plans of doing so.While the EventSentry agent i - [How do I configure a recurring event log filter? | EventSentry](https://www.eventsentry.com/kb/483-how-do-i-configure-a-recurring-event-log-filter): A Recurring Event filter is useful in situations where you would like to take an action when an event does not occur. A common use case for this is a suc - [I keep getting a warning message in the system event log (event id 1047](https://www.eventsentry.com/kb/90-i-keep-getting-a-warning-message-in-the-system-event-log-event-id-1047-with-event-source-w3svc-stating-that-the-application-eventsentry-belonging-to-site-1-has-an-apppoolid-set-but-the-property-is-empty-therefore-the-application-will-be-ignored): This is a warning message only and can usually be ignored and is due to a misconfigured virtual directory. The following steps should resolve the problem: Ope - [How do I schedule a (daily) report for network logons? | EventSentry](https://www.eventsentry.com/kb/404-how-do-i-schedule-a-daily-report-for-network-logons): You can schedule an daily network logon tracking report in the web reports which includes all authentications to domain controllers by users. This report is av - [What are the advantages of the collector service? | EventSentry](https://www.eventsentry.com/kb/296-what-are-the-advantages-of-the-collector-service): Utilizing the collector service offers the following advantages:Communication between the collector and the agents can automatically be encrypted - [Many tables in my built-in (PostgreSQL) EventSentry database have | EventSentry](https://www.eventsentry.com/kb/298-many-tables-in-my-built-in-postgresql-eventsentry-database-have-duplicate-constraints-how-can-i-delete-them): Due to a bug in the EventSentry configuration assistant, the EventSentry database (PostgreSQL only) may create duplicate constraints when updating a PostgreSQL d - [I'm trying to apply a license key to EventSentry v3.1 or later, but the](https://www.eventsentry.com/kb/280-i-m-trying-to-apply-a-license-key-to-eventsentry-v3-1-or-later-but-the-management-console-does-not-accept-the-key-and-states-that-it-is-invalid): A new licensing engine was introduced in EventSentry v3.1, and license keys issued for EventSentry v3.0 or earlier (those license keys are usually 56 characters - [How can I get an alert when a VIB package is installed on an ESXi host?](https://www.eventsentry.com/kb/477-how-can-i-get-an-alert-when-a-vib-package-is-installed-on-an-esxi-host): In a production environment it can be important to know when a VIB package is installed on an ESXI host. If the VMWare ESXi host is (configured to send Syslog m - [Can you assign email (SMTP) notification actions to system health | EventSentry](https://www.eventsentry.com/kb/110-can-you-assign-email-smtp-notification-actions-to-system-health-packages): No, you cannot assign email notification targets to system health packages. Only ODBC (database) notifications can be directly linked to a system health package. - [Can I use environment sensors if only the EventSentry agent is | EventSentry](https://www.eventsentry.com/kb/226-can-i-use-environment-sensors-if-only-the-eventsentry-agent-is-installed): Yes, only the EventSentry agent is required to monitor temperature, humidity, water and/or smoke. The management console is needed to configure these sensors how - [How can I have EventSentry display disk defrag information? | EventSentry](https://www.eventsentry.com/kb/189-how-can-i-have-eventsentry-display-disk-defrag-information): By using the 'Embedded Scripts' feature and the 'Application Scheduler' feature you can create a script that will write the disk defrag information to your local - [BCA/CJDN Compliance \[MNJIS-5002\] | EventSentry](https://www.eventsentry.com/kb/509-bca-cjdn-compliance-mnjis-5002): EventSentry can help users be compliant with MNJIS-5002 and help secure CJI (criminal justice information). The BCA package contains a number of event log ru - [How do I modify the number of days events are retained in the database?](https://www.eventsentry.com/kb/289-how-do-i-modify-the-number-of-days-events-are-retained-in-the-database): NOTE: Starting in EventSentry 5.1, the default way to purge your database is from Web Reports. Please see KB 523 for in - [When I try to test the Email action I get the following error: "Unable](https://www.eventsentry.com/kb/17-when-i-try-to-test-the-email-action-i-get-the-following-error-unable-to-establish-a-tcp-connection-i-can-ping-the-smtp-server-by-hostname-and-ip-address-i-am-not-getting-any-emails): Some anti-virus software products (e.g. McAfee starting with version 8.x) block and/or intercept outgoing connections to port 25. This will interfere with the Ev - [How do I configure a summary event log filter? | EventSentry](https://www.eventsentry.com/kb/484-how-do-i-configure-a-summary-event-log-filter): A summary event log filter allows for events to be collected over a period of time rather than sending you an alert or performing an action immediately. You - [How can I get an alert when a VMWare VM snapshot on an ESXi host is | EventSentry](https://www.eventsentry.com/kb/460-how-can-i-get-an-alert-when-a-vmware-vm-snapshot-on-an-esxi-host-is-created-or-deleted): In a production environment it can be important to know if and when a snapshots of a VM are added to deleted. If the VMWare ESXi host is configured to send Syslo - [How to set the default page or url in the web reports | EventSentry](https://www.eventsentry.com/kb/499-how-to-set-the-default-page-or-url-in-the-web-reports): Each user account has the ability to set the default page, and subsequently a default search, in the web reports under their user account. Configuring the def - [When trying to view the web reports on an Oracle database, I always get](https://www.eventsentry.com/kb/81-when-trying-to-view-the-web-reports-on-an-oracle-database-i-always-get-the-following-error-ora-00942-table-or-view-does-not-exist): You are getting this error because the table prefix for Oracle (EVENTSENTRY.) was not configured through the profile editor. When accessing resources in Oracle, - [Can I use the Environment Sensors with a virtual machine? | EventSentry](https://www.eventsentry.com/kb/287-can-i-use-the-environment-sensors-with-a-virtual-machine): You can use the USB-based Environment Sensors with a virtual machine by redirecting the USB port from the Virtual Machine Host computer to the Virtual Machine Gu - [How do I push/install the heartbeat monitoring agent out to the remote](https://www.eventsentry.com/kb/39-how-do-i-push-install-the-heartbeat-monitoring-agent-out-to-the-remote-computers): The heartbeat monitoring agent is designed to be installed only on a small number of hosts, usually one.It is not necessary and recommended to install the hear - [Can I use EventSentry with the MSDE version of MS SQL Server? | EventSentry](https://www.eventsentry.com/kb/68-can-i-use-eventsentry-with-the-msde-version-of-ms-sql-server): Yes, you can use EventSentry with MSDE, however we do not recommend it as it provides limited administration capabilities and requires you to do many configurati - [Check Agent Status shows "Unable to get service status: -1" | EventSentry](https://www.eventsentry.com/kb/315-check-agent-status-shows-unable-to-get-service-status-1): This is caused by a permission issue. Either the account which is being used to run the EventSentry console, or the account configured for Set Authentication on - [How can I manually reset the 'adminCount' attribute in Active | EventSentry](https://www.eventsentry.com/kb/417-how-can-i-manually-reset-the-admincount-attribute-in-active-directory): EventSentry ADMonitor uses the 'adminCount' attribute to determine whether a user is an administrator. However, since this attribute is not reset by Windows - [The Web Reports have been slow to load pages and search data. How can I](https://www.eventsentry.com/kb/6-the-web-reports-have-been-slow-to-load-pages-and-search-data-how-can-i-improve-the-performance-of-web-reports): If you use the built-in (Postgres) database, you may need to optimize it: https://www.eventsentry.com/kb/232If you use Microsoft SQL as your database, you may n - [How can I find out which port my EventSentry database is listening on?](https://www.eventsentry.com/kb/115-how-can-i-find-out-which-port-my-eventsentry-database-is-listening-on): Microsoft SQL Server 2000 Open Enterprise Manager and locate the server name / instance name under the SQL Server Group container. Right-click - [When viewing certain pages on the web reports, I get the error | EventSentry](https://www.eventsentry.com/kb/106-when-viewing-certain-pages-on-the-web-reports-i-get-the-error-permission-denied-eventsentry-eventsentry_db_inc-asp-some-information-shows-but-it-always-ends-before-the-ipaddress-column): This is due to EventSentry not being able to execute the nslookup.exe process on the server which is needed to resolve host names to IP addresses.You ca - [Is Windows Vista supported? | EventSentry](https://www.eventsentry.com/kb/128-is-windows-vista-supported): Starting with the latest build of EventSentry 2.72, you can monitor Windows Vista machines with the EventSentry agent.Microsoft introduced a new interface to t - [How to schedule a PowerShell script | EventSentry](https://www.eventsentry.com/kb/396-how-to-schedule-a-powershell-script): * In the management console, under 'Tools ) Embedded Scripts' click 'New' and give the script a descriptive name, e.g. 'script_name.ps1' and in the 'Script Conte - [Even though I am monitoring services, I am sometimes not being notified](https://www.eventsentry.com/kb/109-even-though-i-am-monitoring-services-i-am-sometimes-not-being-notified-when-a-service-is-restarted-i-did-make-sure-that-the-service-is-not-excluded): EventSentry monitors the service status of all services at pre-defined intervals, every 20 seconds by default. If a particular service restarts itself within 20 - [Packages that are assigned to a group or globally are working, but | EventSentry](https://www.eventsentry.com/kb/154-packages-that-are-assigned-to-a-group-or-globally-are-working-but-packages-that-are-assigned-to-individual-computers-are-not-i-am-managing-my-computers-using-fqdn-names): When packages that are assigned to individual computers do not work, then please make sure that the computers in question are part of an AD domain.If the compu - [Windows Server 2003 R2 creates a new event log called DFS | EventSentry](https://www.eventsentry.com/kb/116-windows-server-2003-r2-creates-a-new-event-log-called-b-dfs-replication-b-if-dfs-replication-is-installed-how-can-i-monitor-this-event-log-with-eventsentry): You can monitor this event log through the Custom Event Log monitoring feature of EventSentry.Simply click the Custom Event Logs tab on an existi - [How many computers can I monitor with the trial version? | EventSentry](https://www.eventsentry.com/kb/22-how-many-computers-can-i-monitor-with-the-trial-version): After you have requested a trial version of EventSentry you should have received an email that will show you on how many computers you can install EventSentry. I - [I am getting various runtime errors while trying to install or upgrade](https://www.eventsentry.com/kb/49-i-am-getting-various-runtime-errors-while-trying-to-install-or-upgrade-eventsentry): In order to troubleshoot installation issues we need to get the log file of the installation. Starting with version 2.60 EventSentry will now log the installatio - [Why am I unable to see the System DSN I just created? | EventSentry](https://www.eventsentry.com/kb/150-why-am-i-unable-to-see-the-system-dsn-i-just-created): The "Data Sources (ODBC)" application, by default, creates System DSN names that are created in the 64bit part of the Windows registry, and as such are only visi - [The computer where the EventSentry Management Console is installed does](https://www.eventsentry.com/kb/146-the-computer-where-the-eventsentry-management-console-is-installed-does-not-have-an-internet-connection-how-can-i-still-download-new-packages-and-or-be-notified-if-new-packages-are-available): You can download the package file from our website from a computer that does have an Internet connection and then copy the package file to the computer where the - [When trying to upgrade EventSentry to the latest version I get the | EventSentry](https://www.eventsentry.com/kb/79-when-trying-to-upgrade-eventsentry-to-the-latest-version-i-get-the-following-or-similar-error-the-upgrade-cannot-be-performed-due-to-a-missing-program-or-wrong-version): This error occurs when you try to upgrade an older version of EventSentry using a patch from a newer version. For example, you cannot use a patch for EventSent - [I am getting started with EventSentry. Is there training available? | EventSentry](https://www.eventsentry.com/kb/321-i-am-getting-started-with-eventsentry-is-there-training-available): Yes. we offer on-site as well as remote training and consulting services for a separate fee. Training covers services which exceed the scope of EventSentry suppo - [The Windows Firewall logs 861 events pertaining to the | EventSentry](https://www.eventsentry.com/kb/148-the-windows-firewall-logs-861-events-pertaining-to-the-eventsentry_svc-exe-every-time-the-service-starts-and-throughout-its-runtime-the-events-usually-mention-udp-ports-in-the-1000-4000-range-why-is-eventsentry-listening-on-udp-ports): The EventSentry service uses Microsoft's LDAP library to resolve GUIDs from Active Directory at startup and during runtime. The port number will vary on differen - [How to run PowerShell scripts either through the application scheduler](https://www.eventsentry.com/kb/397-how-to-run-powershell-scripts-either-through-the-application-scheduler-or-actions): In order to launch PowerShell scripts from EventSentry you will need to verify/change the execution policy and supply the -inputformat none parameter to p - [One or more database actions point to a MySQL database, but no MySQL | EventSentry](https://www.eventsentry.com/kb/138-one-or-more-database-actions-point-to-a-mysql-database-but-no-mysql-database-driver-is-installed-on-this-system): EventSentry currently uses ODBC to communicate with the available database servers, including MySQL. As such, an ODBC driver for the selected database type needs - [Can I monitor devices using SNMP? | EventSentry](https://www.eventsentry.com/kb/191-can-i-monitor-devices-using-snmp): Starting with version 2.92, EventSentry can receive SNMP traps with the "EventSentry Network Services" service. This service includes a Syslog as well as Snmp - [When running a query on the search page on IIS 6.0 and later I get the](https://www.eventsentry.com/kb/30-when-running-a-query-on-the-search-page-on-iis-6-0-and-later-i-get-the-following-error-response-buffer-limit-exceeded-how-can-i-increase-the-buffer-without-narrowing-my-search): The buffer can be increased by changing the AspBufferingLimit setting in Metabase.xml to a larger size. The default value is 4194304, which is about 4 MB.(b - [How can I remove the EventSentry agent from a (remote) server? | EventSentry](https://www.eventsentry.com/kb/46-how-can-i-remove-the-eventsentry-agent-from-a-remote-server): You can remove the EventSentry agent from a remote machine with remote update. Please follow the these steps to remove the agent: Right-click the "Computers - [To which IP addresses, URLs and ports does the host where EventSentry | EventSentry](https://www.eventsentry.com/kb/455-to-which-ip-addresses-urls-and-ports-does-the-host-where-eventsentry-is-installed-need-access-to): The EventSentry management console and services (excluding the agent) need access to the following:| Application | Process | URLs / IPs | Purpose || -------- - [How do I manually remove the EventSentry evaluation key? | EventSentry](https://www.eventsentry.com/kb/75-how-do-i-manually-remove-the-eventsentry-evaluation-key): Please follow these steps to remove the trial license manually:1. Close the EventSentry Management Application2. Open the registry editor regedit.exe3. Navig - [When trying to use the web reports with Oracle I am getting the | EventSentry](https://www.eventsentry.com/kb/85-when-trying-to-use-the-web-reports-with-oracle-i-am-getting-the-following-error-oracle-odbc-ora-ora-12638-credential-retrieval-failed-you-may-also-get-this-error-in-the-odbc-target-dialog-or-in-the-debug-log-file): In order to solve this problem you need to change the SQLNET.AUTHENTICATION_SERVICES parameter in the sqlnet.ora file.The sqlnet.ora file is usually loc - [Can two users change filters, targets, etc. at the same time in the | EventSentry](https://www.eventsentry.com/kb/78-can-two-users-change-filters-targets-etc-at-the-same-time-in-the-eventsentry-management-console-without-causing-a-conflict): The EventSentry management console is unfortunately not multi-user capable, as such you cannot modify the configuration on the same machine from differnet user a - [Can I make changes to the EventSentry configuration in the registry? Do](https://www.eventsentry.com/kb/103-can-i-make-changes-to-the-eventsentry-configuration-in-the-registry-do-i-have-to-restart-the-agent-after-i-made-configuration-changes): Yes, you can make changes directly to the registry, but always make a configuration backup before you make any changes to the registry. Please also note that edi - [Logon tracking sometimes does not show in the event log when a user or](https://www.eventsentry.com/kb/74-logon-tracking-sometimes-does-not-show-in-the-event-log-when-a-user-or-computer-has-logged-off-even-though-i-know-the-user-is-not-logged-in-anymore): Microsoft Windows 2000 and earlier have a problem where the logoff events with event ID 538 (which are intercepted by EventSentry) are sometimes not logged to th - [I installed EventSentry on a Windows NT4 machine and I get the | EventSentry](https://www.eventsentry.com/kb/91-i-installed-eventsentry-on-a-windows-nt4-machine-and-i-get-the-following-error-message-when-i-open-the-eventsentry-management-application-the-dynamic-link-library-pdh-dll-could-not-be-found-in-the-specified-path-is-windows-nt-4-0-supported): Windows NT4 is still supported, but you are getting this error message because the required dynamic link library pdh.dll is not installed on your Windows - [Can I monitor Subversion from CollabNet with EventSentry? | EventSentry](https://www.eventsentry.com/kb/341-can-i-monitor-subversion-from-collabnet-with-eventsentry): Yes, you can monitor several aspects of Subversion with EventSentry. We will assume that SVN is installed in C:\CSVN, and that the repositories are installed in - [I setup a few filters and notifications, and installed the agent on my](https://www.eventsentry.com/kb/10-i-setup-a-few-filters-and-notifications-and-installed-the-agent-on-my-servers-but-i-am-only-getting-emails-from-the-local-machine-where-the-management-console-is-installed-not-from-the-other-servers): After making configuration changes on your management workstation, you will need to use the "Update Configuration" feature of remote update to push the updated c - [The heartbeat monitoring agent will either not start, or stop (crash) | EventSentry](https://www.eventsentry.com/kb/57-the-heartbeat-monitoring-agent-will-either-not-start-or-stop-crash-shortly-after-it-was-started-you-will-see-an-application-error-event-log-entry-in-the-application-event-log-indicating-that-the-eventsentry_hb_svc-exe-faulted): This problem appears when you have one or more duplicate computers in your configuration.Check your entire configuration and make sure that there is no compute - [How do I exclude a folder / directory size monitoring alert? | EventSentry](https://www.eventsentry.com/kb/358-how-do-i-exclude-a-folder-directory-size-monitoring-alert): Open the management console Navigate to Packages -) System Health In the ribbon, click on the arrow below "Filter" and select "Disk Sp - [I am trying to install the web reports on a machine that has Windows | EventSentry](https://www.eventsentry.com/kb/88-i-am-trying-to-install-the-web-reports-on-a-machine-that-has-windows-sharepoint-services-installed-every-time-i-try-to-access-the-web-reports-i-get-the-error-http-error-404-file-or-directory-not-found): You will need to exclude the EventSentry ASP pages from SharePoint Services, which is intercepting requests to the EventSentry web reports.Follow the first - [Why do I get access denied when trying to install an agent to a non | EventSentry](https://www.eventsentry.com/kb/253-why-do-i-get-access-denied-when-trying-to-install-an-agent-to-a-non-domain-machine): If you are trying to monitor a non-domain machine on a workstation, you may run into an issue where you get access is denied, even if you are using the credentia - [The heartbeat monitor is reporting an "Unknown Agent Status (-1)". What](https://www.eventsentry.com/kb/23-the-heartbeat-monitor-is-reporting-an-unknown-agent-status-1-what-do-unknown-and-1-mean): An unknown status means that the service control manager on the remote host did not return any valid service status.This usually happens under the following ci - [Does EventSentry support to the x64 editions of Windows (e.g. Windows | EventSentry](https://www.eventsentry.com/kb/92-does-eventsentry-support-to-the-x64-editions-of-windows-e-g-windows-2003-2008-x64-is-there-a-native-64-bit-version-of-the-eventsentry-agent): EventSentry supports all x64 editions of Windows, including Windows Server 2003/2008, Windows XP, Windows Vista and Windows 7. Support for these versions is acco - [How do I monitor a different subnet with the ARP Daemon? | EventSentry](https://www.eventsentry.com/kb/265-how-do-i-monitor-a-different-subnet-with-the-arp-daemon): In order to monitor a different subnet with the ARP component of the network services, first install the network services on a host in the subnet which needs to - [When trying to connect to an OpenFire XMPP (Jabber) server, I get the | EventSentry](https://www.eventsentry.com/kb/182-when-trying-to-connect-to-an-openfire-xmpp-jabber-server-i-get-the-error-sasl-authentication-failed): When connecting to an OpenFire server, the value in the "Server" field in the EventSentry action dialog needs to match the xmpp.domain field in the OpenFire conf - [When installing EventSentry and selecting the "Setup MS SQL Server" | EventSentry](https://www.eventsentry.com/kb/36-when-installing-eventsentry-and-selecting-the-setup-ms-sql-server-option-during-installation-we-repeatedly-get-a-microsoft-odbc-driver-manager-data-source-name-not-found-and-no-default-driver-specified-error): This error appears when you specify a invalid username and/or password or a username with insufficient rights to be used for the database setup.The installatio - [After running/installing the IIS Lockdown or URLScan tool, we are | EventSentry](https://www.eventsentry.com/kb/129-after-running-installing-the-iis-lockdown-or-urlscan-tool-we-are-unable-to-view-the-web-reports-and-get-errors-that-indicate-that-the-file-cannot-be-found): The above tools may restrict you from viewing .asp pages which are required for the web reports to run correctly. Follow the steps below to allow .asp pages from - [I get "Error 1610: The configuration data for this product is corrupt](https://www.eventsentry.com/kb/278-i-get-error-1610-the-configuration-data-for-this-product-is-corrupt-when-starting-the-heartbeat-service): The EventSentry Heartbeat Monitor service requires administrator rights on the EventSentry server. If the account being used to run this service does not have a - [Can I install the v3.x beta release over an existing non-beta | EventSentry](https://www.eventsentry.com/kb/221-can-i-install-the-v3-x-beta-release-over-an-existing-non-beta-installation): Yes, the installer of the beta release can be run over an existing 2.93 (or earlier) EventSentry installation. The installer will then upgrade the existing 2.x i - [Can I collect NetFlow or sFlow data from Cisco network devices? | EventSentry](https://www.eventsentry.com/kb/334-can-i-collect-netflow-or-sflow-data-from-cisco-network-devices): Not all Cisco network devices are capable of producing NetFlow or sFlow data. Please refer to your particular device's product documentation to see if your devi - [Is it possible to send only one issue (event) per email instead of | EventSentry](https://www.eventsentry.com/kb/322-is-it-possible-to-send-only-one-issue-event-per-email-instead-of-combining-multiple-issues-per-email): Yes, it is possible to only send one event per email. In the EventSentry console, scroll down the left side to the Actions section, and then select one of your - [Can EventSentry assist with CJIS Security Policy compliance? | EventSentry](https://www.eventsentry.com/kb/277-can-eventsentry-assist-with-cjis-security-policy-compliance): Yes, you can download a customized version of the built-in "Compliance" event log package which is geared towards CJIS compliance from the "Links" section below. - [Can I use a license key that was generated for a current version of | EventSentry](https://www.eventsentry.com/kb/145-can-i-use-a-license-key-that-was-generated-for-a-current-version-of-eventsentry-e-g-v2-80-with-an-older-version-of-eventsentry-e-g-v2-43): License keys that were generated for EventSentry prior to v2.50 will work with all versions of EventSentry, including version 2.80.License keys for EventSentry - [Can I install the heartbeat monitoring service on more than one | EventSentry](https://www.eventsentry.com/kb/38-can-i-install-the-heartbeat-monitoring-service-on-more-than-one-computer-and-still-write-to-the-same-database): Yes, you can install the heartbeat service on multiple computers and configure all of them to write their heartbeat information to the same database.Please not - [Can I perform remote update actions using different credentials (a | EventSentry](https://www.eventsentry.com/kb/34-can-i-perform-remote-update-actions-using-different-credentials-a-different-username): Added with version 2.21 was the ability to specify different credentials when using Remote Update. Please see the additional links for more information on this f - [I just upgraded to EventSentry v2.9x, and when I try to view the web | EventSentry](https://www.eventsentry.com/kb/210-i-just-upgraded-to-eventsentry-v2-9x-and-when-i-try-to-view-the-web-reports-i-receive-the-following-error-invalid-object-name-tablename): You are receiving this error message because the EventSentry database was not updated to 2.9x and is missing some of the required tables and/or additional column - [I am a Microsoft Certified Trainer (MCT), how do I request a NFR | EventSentry](https://www.eventsentry.com/kb/318-i-am-a-microsoft-certified-trainer-mct-how-do-i-request-a-nfr-license): NETIKUS.NET provides 5 free licenses for EventSentry to individuals who possess an active MCT certification in a relevant field (e.g. Windows Server, SQL Server, - [I am using the $FILTER variable but an email from EventSentry shows | EventSentry](https://www.eventsentry.com/kb/32-i-am-using-the-filter-variable-but-an-email-from-eventsentry-shows-unknown-filter-instead-of-the-actual-filter-name): EventSentry Version 2.60 and earlier:This occurs only if you are using the summary notification feature and restarted the EventSentry service (or the ent - [I am trying to track file access for files that are located in a SAN, | EventSentry](https://www.eventsentry.com/kb/194-i-am-trying-to-track-file-access-for-files-that-are-located-in-a-san-and-events-logged-by-windows-do-not-show-a-drive-letter-is-this-supported): Under some circumstances, Windows will log file names with a path to the device object (e.g. \Device\Harddiskvolume3\file.txt) instead of the path to a logical d - [We are receiving ASP 0177 : 800700c1 on Windows 2000? | EventSentry](https://www.eventsentry.com/kb/56-we-are-receiving-asp-0177-800700c1-on-windows-2000): After installing the latest patches on our Windows 2000 Server, we get the following error when trying to use the EventSentry web reports: Server object error 'A - [The "EventSentry Network Services" service will not start | EventSentry](https://www.eventsentry.com/kb/190-the-eventsentry-network-services-service-will-not-start): The "EventSentry Network Services" service has the following prerequisites:LicensingWhile the Syslog and SNMP daemon functionality is included with Eve - [A database action using Microsoft Access has been found, but multiple | EventSentry](https://www.eventsentry.com/kb/139-a-database-action-using-microsoft-access-has-been-found-but-multiple-computers-were-also-found): It is not recommended that you use the supplied Access database in an EventSentry installation that includes more than one computer.Microsoft Access does not h - [How do I customize disk space monitoring to prevent alerts? | EventSentry](https://www.eventsentry.com/kb/357-how-do-i-customize-disk-space-monitoring-to-prevent-alerts): Open the management console Navigate to Packages -) System Health In the ribbon, click on the arrow below "Filter" and select "Disk Sp - [When trying to install EventSentry I get the following error: "Internal](https://www.eventsentry.com/kb/28-when-trying-to-install-eventsentry-i-get-the-following-error-internal-error-2755-3): This error can appear when running the setup either from the network or from a nested directory, that is a subdirectory beneath many other subdirectories. This i - [When trying to view a remote event log, I get the error message "A | EventSentry](https://www.eventsentry.com/kb/246-when-trying-to-view-a-remote-event-log-i-get-the-error-message-a-security-package-specific-error-occurred): This error can usually be resolved in one of two ways:1. If you are selecting the host name from an existing EventSentry group, and the host has an IP address - [When installing EventSentry with the heartbeat agent and supplying | EventSentry](https://www.eventsentry.com/kb/43-when-installing-eventsentry-with-the-heartbeat-agent-and-supplying-credentials-i-get-the-following-error-message-no-mapping-between-account-names-and-security-ids-was-done-the-installation-then-terminates): This error occurs when the user account specified for the heartbeat agent during the installation does not exist or was not specified in the form DOMAIN\us - [How do I remove the legacy ASP web reports? | EventSentry](https://www.eventsentry.com/kb/248-how-do-i-remove-the-legacy-asp-web-reports): As of EventSentry v3.0, the web reports no longer use IIS. By default they are left behind on upgrade for customers who still need access to them. To remove them - [Can I reduce the size of the EventSentry service logs? | EventSentry](https://www.eventsentry.com/kb/7-can-i-reduce-the-size-of-the-eventsentry-service-logs): The EVENTSENTRY_SVC.LOG file, located in the %SYSTEMROOT% directory (usually c:\winnt or c:\windows) is the debug log file of the EventSentry agent.To reduce t - [What do I need to do so that the agent rescans an event log? | EventSentry](https://www.eventsentry.com/kb/44-what-do-i-need-to-do-so-that-the-agent-rescans-an-event-log): EventSentry is an event log monitoring application, and does, by design, not rescan the event logs. It monitors the event logs and processes current and new even - [I just purchased 5 EventSentry licenses, but I am not able to add the | EventSentry](https://www.eventsentry.com/kb/124-i-just-purchased-5-eventsentry-licenses-but-i-am-not-able-to-add-the-5th-computer-to-a-group-i-can-add-4-computers-just-fine-but-i-cannot-add-the-5th-one-why-not): The default installation of EventSentry includes a "Heartbeat" group that includes the host www.myeventlog.com for illustration purposes. This host does u - [Will the environment sensor (temperature, humidity, smoke, water, | EventSentry](https://www.eventsentry.com/kb/125-will-the-environment-sensor-temperature-humidity-smoke-water-motion-still-work-even-if-the-usb-ports-are-disabled-in-the-bios): The enviroment sensors used and supported by EventSentry require the USB port only to draw power, no communication is sent via USB.It depends on the mainboard - [Every time I expand a particular container (e.g. computer group, filter](https://www.eventsentry.com/kb/108-every-time-i-expand-a-particular-container-e-g-computer-group-filter-package-all-the-other-containers-that-were-expanded-before-are-automatically-collapsed-why-is-that-and-can-i-disable-that): You can configure this behaviour in Tools -) Options by setting or clearing the Automatically collapse unselected groups check box.By default, only one - [Logon Tracking is not enabled in the active security policy. The | EventSentry](https://www.eventsentry.com/kb/142-logon-tracking-is-not-enabled-in-the-active-security-policy-the-eventsentry-logon-tracking-feature-will-not-work): The "Logon Tracking" feature of EventSentry relies on the Operating System logging security events to the security event log, indicating when users log on and l - [Are Windows 8 and Windows Server 2012 supported? | EventSentry](https://www.eventsentry.com/kb/239-are-windows-8-and-windows-server-2012-supported): Yes. Starting with version 2.93.1 of EventSentry, the following components of EventSentry are supported on Windows Server 2012 and Windows 8: EventSentry Agen - [How do I open the files (.evt) saved by the "Backup Event Logs" | EventSentry](https://www.eventsentry.com/kb/12-how-do-i-open-the-files-evt-saved-by-the-backup-event-logs-feature): Starting with EventSentry version 2.70 you can view the native event log files (usually with a .evt extension) with the built-in event log viewer of EventSentry. - [We have more than one license key, can we combine/consolidate our | EventSentry](https://www.eventsentry.com/kb/127-we-have-more-than-one-license-key-can-we-combine-consolidate-our-license-keys-into-one-single-license-key): If you have more than one license key, then you can enter multiple licenses keys into EventSentry using the license management feature (Tools -) License Manageme - [Does EventSentry work with Windows Event Forwarding (WEF)? | EventSentry](https://www.eventsentry.com/kb/355-does-eventsentry-work-with-windows-event-forwarding-wef): Using EventSentry in conjunction with WEF has not been tested and is not a supported setup.Instead, EventSentry agents should be deployed and used to transfer - [Process Tracking is not enabled in the active audit policy. The | EventSentry](https://www.eventsentry.com/kb/141-process-tracking-is-not-enabled-in-the-active-audit-policy-the-eventsentry-process-tracking-feature-will-not-work): The "Process Tracking" feature of EventSentry relies on the Operating System logging security events to the security event log, indicating when processes are sta - [No database actions are configured, you will not be able to consolidate](https://www.eventsentry.com/kb/144-no-database-actions-are-configured-you-will-not-be-able-to-consolidate-events-system-health-and-other-information-in-a-central-database): Since no database action was found in the EventSentry configuration, you will not be able to consolidate any information (e.g. events, performance information, i - [How do I update from a beta version to the official release? | EventSentry](https://www.eventsentry.com/kb/77-how-do-i-update-from-a-beta-version-to-the-official-release): To update from the beta version, perform the following steps:1. Export your configuration with the EventSentry management application (File -) Export).2. Unin - [I installed the patch (or latest setup), but the build number of my | EventSentry](https://www.eventsentry.com/kb/104-i-installed-the-patch-or-latest-setup-but-the-build-number-of-my-management-console-and-or-agent-do-not-match-the-build-number-shown-on-the-web-site-instead-they-are-higher): Your installation is up to date as long as the build number on your system is equal to or higher than the build number listed on our web site.NETIKUS.NE - [Every time I try to add, view or edit an email action, I get the | EventSentry](https://www.eventsentry.com/kb/167-every-time-i-try-to-add-view-or-edit-an-email-action-i-get-the-following-error-message-unable-to-enumerate-dial-up-networking-entries-due-to-error-711-i-am-not-interested-in-the-remote-access-connections): This error is being displayed because remote access connections, which are available for selection on the SMTP action dialog, cannot be enumerated.You should b - [I am using the odbc target to write events to an access database | EventSentry](https://www.eventsentry.com/kb/20-i-am-using-the-odbc-target-to-write-events-to-an-access-database-located-on-a-network-share-but-the-events-are-not-written-to-the-database-the-file-exists-and-i-can-access-it-but-nothing-is-being-written-to-the-file-by-the-agent): This is usually a permissions issue since the EventSentry agent is running under the LocalSystem account by default.Please click the help link below (DOC-ID 18 - [When installing the EventSentry agent(s) on remote computers, I get the](https://www.eventsentry.com/kb/8-when-installing-the-eventsentry-agent-s-on-remote-computers-i-get-the-error-no-network-provider-accepted-the-given-network-path-why-can-t-i-install-the-agent-s): This error, reported by Windows, usually appears when "Client for Microsoft Networks" and/or NetBIOS are not installed on the management workstation and target m - [EventSentry keeps going through all of the events of a particular log | EventSentry](https://www.eventsentry.com/kb/62-eventsentry-keeps-going-through-all-of-the-events-of-a-particular-log-e-g-security-and-emailing-them-over-and-over-how-can-i-resolve-this): This can happen when a monitored event log is corrupt. You can check whether a particular log is corrupt by opening up the Windows Event Viewer and trying to acc - [I connected the temperature sensor to the COM port of my server, | EventSentry](https://www.eventsentry.com/kb/101-i-connected-the-temperature-sensor-to-the-com-port-of-my-server-however-the-sensor-doesn-t-seem-to-be-working-do-i-need-to-connect-the-usb-cable-as-well): Yes, in order for the sensors to work you will have to connect the USB cable as well as the serial cable. The sensor draws power through the USB cable. - [Do I have to uninstall the light version of EventSentry before I | EventSentry](https://www.eventsentry.com/kb/5-do-i-have-to-uninstall-the-light-version-of-eventsentry-before-i-install-the-trial-version): Yes, it is recommended that you uninstall EventSentry Light with the setup application prior to installing the trial or full version of EventSentry.You will no - [What are the hardware requirements for EventSentry? | EventSentry](https://www.eventsentry.com/kb/102-what-are-the-hardware-requirements-for-eventsentry): Please see the following page in the EventSentry manual for a list of hardware requirements:(a alt="Hardware Requirements" href="https://www.eventsentry.com/do - [When using the test button in the ODBC target, the test entry shows the](https://www.eventsentry.com/kb/26-when-using-the-test-button-in-the-odbc-target-the-test-entry-shows-the-date-as-gmt-instead-of-our-local-time-zone): This inconsistency only applies to entries written to the database by the TEST button. Regular entries (written by the agent(s)) will show the time in your local - [When trying to install EventSentry on a Windows 2000 (Win2k) machine | EventSentry](https://www.eventsentry.com/kb/42-when-trying-to-install-eventsentry-on-a-windows-2000-win2k-machine-with-sp4-you-get-an-error-message-and-the-installation-will-not-proceed-the-event-log-shows-entries-from-the-msiinstaller-source-with-an-id-of-1015): This error usually appears when your MSI installation is corrupt. Reinstalling the Microsoft Installer, or upgrading to the latest version should resolve this pr - [How can I delete/remove old data (e.g. information from disks that are](https://www.eventsentry.com/kb/97-how-can-i-delete-remove-old-data-e-g-information-from-disks-that-are-no-longer-in-existance-or-retired-computers-from-the-eventsentry-database): You can remove information from the EventSentry database using the "Maintenance Wizard" from the web reports. The maintenance wizard can be found in the MAINTENA - [Can any user with local administrative privileges view and change the | EventSentry](https://www.eventsentry.com/kb/14-can-any-user-with-local-administrative-privileges-view-and-change-the-eventsentry-configuration): Yes, any user with administrative privileges can view and change the EventSentry configuration.The entire EventSentry configuration is stored on a per-machine - [Does EventSentry work with Windows FIPS 140-2 mode enabled? | EventSentry](https://www.eventsentry.com/kb/446-does-eventsentry-work-with-windows-fips-140-2-mode-enabled): The Federal Information Processing Standard (FIPS) Publication 140-2 is a U.S. government standard. - [Can EventSentry assist with the "Protecting Controlled Unclassified | EventSentry](https://www.eventsentry.com/kb/351-can-eventsentry-assist-with-the-protecting-controlled-unclassified-information-in-nonfederal-systems-and-organizations-requirement): Yes, EventSentry can help with the following provisions of the Controlled Unclassified Information (CUI) Compliance requirement:3.3.2 3.3.3(/ - [What is PingSentry? | EventSentry](https://www.eventsentry.com/kb/531-what-is-pingsentry): PingSentry is a free service that allows you to quickly monitor the availability of your external resources.• Check if an IP address is responding to ICMP ping - [Can EventSentry assist with PCI compliance? | EventSentry](https://www.eventsentry.com/kb/204-can-eventsentry-assist-with-pci-compliance): Yes, many of EventSentry's features can help organizations with the efforts to become and remain PCI compliant. The following features assist with (a href="https - [Why don't I receive an alert when testing the smoke sensor? | EventSentry](https://www.eventsentry.com/kb/233-why-don-t-i-receive-an-alert-when-testing-the-smoke-sensor): Each day the smoke sensor does an internal self test that lasts about 20 seconds. EventSentry therefore ignores readings that last less than this time period. If - [I'm trying to download an EventSentry update in the management console](https://www.eventsentry.com/kb/252-i-m-trying-to-download-an-eventsentry-update-in-the-management-console-that-is-located-behind-a-firewall-or-router-but-the-update-fails-what-ips-ports-do-i-need-to-open-on-the-firewall-for-these-updates-to-succeed): To download an update from the EventSentry management console, you need access to the following IPs & PORTS: 216.92.10.83:80 (EVENTSENTRY.COM) 216.92.16.192 - [Does restarting the EventSentry service on the management machine cause](https://www.eventsentry.com/kb/15-does-restarting-the-eventsentry-service-on-the-management-machine-cause-any-other-events-to-occur-rescanning-event-logs-on-remote-servers-etc): No, restarting the EventSentry service on any machine will have no effect on other machines since the agent only works with the local event logs.The EventSentr - [How do I filter an event with a severity of "Success"? | EventSentry](https://www.eventsentry.com/kb/170-how-do-i-filter-an-event-with-a-severity-of-success): Events logged with a severity of "Success", which is displayed like an informational event, are not very common but are nevertheless logged by some applications - [Are there any EventSentry issues with the new US Daylight Savings Time](https://www.eventsentry.com/kb/126-are-there-any-eventsentry-issues-with-the-new-us-daylight-savings-time-dst-changes-in-2007): No, EventSentry obtains all time and time zone information from the Operating System, and EventSentry will report the dates and times as they are logged/generate - [With which versions of MySQL does EventSentry work? | EventSentry](https://www.eventsentry.com/kb/70-with-which-versions-of-mysql-does-eventsentry-work): EventSentry was tested and works with the following versions of MySQL: MySQL Server 5.0.x and higherIt is HIGHLY recommended that you always install the lat - [Can EventSentry detect the ZeroLogon attack? | EventSentry](https://www.eventsentry.com/kb/440-can-eventsentry-detect-the-zerologon-attack): EventSentry can detect both successful and unsuccessful ZeroLogon attacks by examing various event patterns on domain computers. To use this package: Download - [I am using the file action to write events to a file located on a | EventSentry](https://www.eventsentry.com/kb/19-i-am-using-the-file-action-to-write-events-to-a-file-located-on-a-network-share-but-the-events-are-not-written-to-the-file): This is usually a permissions issue since the EventSentry agent is running under the LocalSystem account by default.Please click the help link below (KB-ID 18) - [Do I have to purchase the annual maintenance of EventSentry in order to](https://www.eventsentry.com/kb/174-do-i-have-to-purchase-the-annual-maintenance-of-eventsentry-in-order-to-keep-using-the-software): No. Purchasing maintenance is optional and EventSentry will continue to work after maintenance is expired, however you will not be eligible for customer support - [Our maintenance for EventSentry is currently expired, can we get it | EventSentry](https://www.eventsentry.com/kb/179-our-maintenance-for-eventsentry-is-currently-expired-can-we-get-it-re-instated): If maintenance for EventSentry expired less then 90 days ago then you can simply purchase maintenance in the sales area at https://store.netikus.net. If maintena - [What are the system requirements for EventSentry? | EventSentry](https://www.eventsentry.com/kb/299-what-are-the-system-requirements-for-eventsentry): Please review Requirements in the official EventSentry documentati - [Which Compliance Standards can EventSentry help fulfill? | EventSentry](https://www.eventsentry.com/kb/346-which-compliance-standards-can-eventsentry-help-fulfill): There are several compliance standards that EventSentry can help fulfill, such as: PCI-DSS 3.x FISMA HIPAA Sarbanes Oxley (SOX) GLBA ISO 27001:2013 - [How do I upgrade from the beta to the official release? | EventSentry](https://www.eventsentry.com/kb/222-how-do-i-upgrade-from-the-beta-to-the-official-release): To upgrade an existing beta installation of EventSentry to the official release, simply run the latest installer of the official release. It will automatically d - [I setup a summary notification filter, but I am not getting any emails](https://www.eventsentry.com/kb/9-i-setup-a-summary-notification-filter-but-i-am-not-getting-any-emails-at-the-configured-time-interval): It is important that filters using summary notifications are NOT configured to notify "All Targets".When using summary notifications, make sure that one (and o - [Can I use the file checksums provided by EventSentry's File Monitoring](https://www.eventsentry.com/kb/389-can-i-use-the-file-checksums-provided-by-eventsentry-s-file-monitoring-fim-or-process-tracking-reports-with-virustotal): Yes. EventSentry's File Monitoring and Process Tracking features can create SHA-256 checksums of monitor or executed files which can be submitted on (VirusTotal' - [Can multiple instances of the EventSentry agent write to the same file](https://www.eventsentry.com/kb/31-can-multiple-instances-of-the-eventsentry-agent-write-to-the-same-file-target): While it is possible for multiple EventSentry agents to write to the same file it is not recommended. A file is always locked during a write operation which will - [Which web browsers are supported by the EventSentry web interface? Will](https://www.eventsentry.com/kb/73-which-web-browsers-are-supported-by-the-eventsentry-web-interface-will-firefox-or-chrome-or-safari-work): The EventSentry web reports are compatible with:1. Mozilla Firefox2. Google Chrome3. Safari4. Internet Explorer 8 and higherMobile browsers on the iOS and - [How do I import custom dashboards? | EventSentry](https://www.eventsentry.com/kb/494-how-do-i-import-custom-dashboards): Copy the previously exported \template.xml file to following path on the server hosting the web reports:C:\Program Files\EventSentry\WebReports\web\weba - [To which (Microsoft SQL Server) compatability level can I set the | EventSentry](https://www.eventsentry.com/kb/187-to-which-microsoft-sql-server-compatability-level-can-i-set-the-eventsentry-database-to): When running Microsoft SQL Server, it is safe to set the database compatibility level to the highest setting available. For example, if you are running SQL Serve - [Is there a downloadable manual and quick start guide in pdf format? | EventSentry](https://www.eventsentry.com/kb/4-is-there-a-downloadable-manual-and-quick-start-guide-in-pdf-format): Yes, please navigate to https://www.eventsentry.com/support/documentation to download the help file and/or quickstart guide. Both documents are available in the - [Can I place an order with a corporate purchase order? | EventSentry](https://www.eventsentry.com/kb/176-can-i-place-an-order-with-a-corporate-purchase-order): If your company is located in the US then you can place an order with a corporate PO. Simply select "Purchase Order" as the payment method in our shopping system - [Can I add additional table fields to the tables used by the ODBC | EventSentry](https://www.eventsentry.com/kb/33-can-i-add-additional-table-fields-to-the-tables-used-by-the-odbc-targets): While it is possible to add additional fields to the tables used by EventSentry, we generally do not recommend modifying the existing table layout.Please conta - [Is there a way to import my configuration from the command prompt? | EventSentry](https://www.eventsentry.com/kb/344-is-there-a-way-to-import-my-configuration-from-the-command-prompt): There are no command line tools to import the EventSentry configuration. The recommended way to import your configuration is using the EventSentry management con - [How do I backup / export my dashboards? | EventSentry](https://www.eventsentry.com/kb/493-how-do-i-backup-export-my-dashboards): 1) Open the Dashboard Manager2) Navigate to the Export tab3) Select the Dashboard to export4) Click the Export button5) On the web reports server, locate the - [Do you have desktop backgrounds with the EventSentry logo? | EventSentry](https://www.eventsentry.com/kb/426-do-you-have-desktop-backgrounds-with-the-eventsentry-logo): Yes! We have three desktop backgrounds/wallpapers in blue, gray and orange, each with a 3840x2160 resolution, available for download. Each background also come - [What is the difference between file monitoring and file access | EventSentry](https://www.eventsentry.com/kb/168-what-is-the-difference-between-file-monitoring-and-file-access-tracking): Please see the link below for a detailed discussion on the differences between File Monitoring (System Health) and File Access Tracking (Compliance Tracking). - [Does EventSentry have an app for mobile devices (iPhone, Android, | EventSentry](https://www.eventsentry.com/kb/228-does-eventsentry-have-an-app-for-mobile-devices-iphone-android-etc): Yes, there is an EventSentry mobile application but it is published by a 3rd party.iPhone/IPad/Apple WatchEventMonitorAndroid-based devicesSo - [I downloaded the evaluation version of EventSentry, but my initial | EventSentry](https://www.eventsentry.com/kb/172-i-downloaded-the-evaluation-version-of-eventsentry-but-my-initial-evaluation-period-has-expired-can-you-download-another-evaluation): Yes, simply navigate to the evaluation download page and request another evaluation version. You may also contact our sales team. - [Do EventSentry licenses include maintenance and support? | EventSentry](https://www.eventsentry.com/kb/171-do-eventsentry-licenses-include-maintenance-and-support): Yes, every new EventSentry license includes one year of support and maintenance. Each additional year of maintenance cost 20% of the current price. - [Does the remote update facility of EventSentry require NetBIOS? | EventSentry](https://www.eventsentry.com/kb/100-does-the-remote-update-facility-of-eventsentry-require-netbios): No, EventSentry does not require NetBIOS to be enabled. Remote Update will still work correctly even after you disable NetBIOS on the hosts monitored by EventSen - [Can I allow other people from my team to have access to the EventSentry](https://www.eventsentry.com/kb/177-can-i-allow-other-people-from-my-team-to-have-access-to-the-eventsentry-download-area): Yes, the primary account holder can authorize additional email addresses in the customer area at https://store.netikus.net/customer/. - [Do I have to uninstall the evaluation version after I purchase | EventSentry](https://www.eventsentry.com/kb/173-do-i-have-to-uninstall-the-evaluation-version-after-i-purchase-eventsentry): No. The full license keys you receive after a purchase activate an evaluation version. - [Where can I see when our maintenance for EventSentry expires? | EventSentry](https://www.eventsentry.com/kb/178-where-can-i-see-when-our-maintenance-for-eventsentry-expires): The maintenance expiration date can be seen in the customer area, at https://store.netikus.net/customer/. - [What does the annual maintenance include? | EventSentry](https://www.eventsentry.com/kb/175-what-does-the-annual-maintenance-include): The annual maintenance includes all software updates as well as customer support (email & telephone). ## Pricing - [Partners | EventSentry](https://www.eventsentry.com/pricing/partners): EventSentry Partner Program helps organizations get the most out of their EventSentry installation. Please see our partners listed below. - [Partner Program | EventSentry](https://www.eventsentry.com/pricing/partner-program): EventSentry Partner Program helps organizations get the most out of their EventSentry installation. Please see our partners listed below. - [Microsoft Certificated Trainer | EventSentry](https://www.eventsentry.com/pricing/mct): EventSentry MCT Program: Please fill out the short form below to receive a free NFR license key of EventSentry. Please allow up to 48 hours for processing and make sure that your spam filter will al... - [Quote Request | EventSentry](https://www.eventsentry.com/pricing/quote): Complete the form below to receive a custom quote via email. Please note that we can only issue quotes in US Dollar, we cannot issue quotes in any foreign currency. ## Sales - [Request Demo | EventSentry](https://www.eventsentry.com/sales/request-demo): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Become a Partner | EventSentry](https://www.eventsentry.com/sales/become-a-partner): Become an EventSentry Partner. Start by filling out the form below. EventSentry Partner Program helps organizations get the most out of their EventSentry installation. Please see our partners listed... ## Solutions - [SIEM Monitoring Software for your network | EventSentry](https://www.eventsentry.com/solutions/siem): EventSentry offers full SIEM capabilities by monitoring and visualizing operating system, database and application logs in real time. Complex Windows events, including logon/logoff and Active Direct... - [DevOps Monitoring | EventSentry](https://www.eventsentry.com/solutions/devops-monitoring): Through its wide array of monitoring capabilities - which go beyond traditional system or log monitoring - EventSentry can support DevOps teams by providing insights and alerting capabilities for bo... - [Cloud & Virtual Monitoring | EventSentry](https://www.eventsentry.com/solutions/cloud-monitoring): Powerful virtualization monitoring made easy.To EventSentry, there is no difference as to whether you are monitoring a physical or a virtual machine. - [Hyper-V Monitoring | EventSentry](https://www.eventsentry.com/solutions/hyper-v-monitoring) - [Software Version Checker | EventSentry](https://www.eventsentry.com/solutions/software-version-check): Audit the software versions on your network and identify software that is out of date or end-of-life. - [NIST 800-171 with EventSentry | EventSentry](https://www.eventsentry.com/solutions/nist-800-171): NIST 800-171 is a set of controls that outline how your infrastructure and internal policies need to be setup in order to protect Controlled Unclassified Information (CUI). - [Custom Application Scheduler | EventSentry](https://www.eventsentry.com/solutions/application-scheduler): You can schedule to run any command-line application from within EventSentry for custom system monitoring. - [CJIS Security Policy Compliance with EventSentry | EventSentry](https://www.eventsentry.com/solutions/cjis-security-policy): EventSentry provides in-depth guidance and built-in reporting for CJIS Security Policy compliance. - [HIPAA compliance | EventSentry](https://www.eventsentry.com/solutions/hipaa): HIPAA is a set of controls that outline how your infrastructure and internal policies need to be setup in order to protect user's data. - [IIS Logs | EventSentry](https://www.eventsentry.com/solutions/iis-logs): EventSentry can monitor your IIS web access logs and help you identify any slow loading or missing resources. - [Windows Event Logs | EventSentry](https://www.eventsentry.com/solutions/windows-event-logs): EventSentry offers the ability to trigger automated actions when critical events occur on your network - [VPN Logs | EventSentry](https://www.eventsentry.com/solutions/vpn-logs): EventSentry can monitor you VPN to see who is currently active. - [DHCP Logs | EventSentry](https://www.eventsentry.com/solutions/dhcp-logs): EventSentry can monitor and alert any time a new lease is given. - [VMware ESXi Monitoring | EventSentry](https://www.eventsentry.com/solutions/vmware-monitoring): EventSentry monitors your physical VMware servers as well as any running virtual machine. Keep track of critical events or monitor the overall health of your virtualization environment. - [Windows Server 2022 Monitoring | EventSentry](https://www.eventsentry.com/solutions/windows-server-2022-monitoring): EventSentry provides robust Windows Server 2022 Monitoring - [Windows Server 2025 Monitoring | EventSentry](https://www.eventsentry.com/solutions/windows-server-2025-monitoring): EventSentry provides robust Windows Server 2025 Monitoring - [Windows Server 2019 Monitoring | EventSentry](https://www.eventsentry.com/solutions/windows-server-2019-monitoring): EventSentry provides robust Windows Server 2019 Monitoring - [Windows Server 2016 Monitoring | EventSentry](https://www.eventsentry.com/solutions/windows-server-2016-monitoring): EventSentry provides robust Windows Server 2016 Monitoring - [RAID Logs | EventSentry](https://www.eventsentry.com/solutions/raid-logs): EventSentry uniformly alerts you about software / hardware issues like failed drives or RAID issues - [Sysmon Integration | EventSentry](https://www.eventsentry.com/solutions/sysmon): System Monitor (Sysmon) is a Windows system service and device driver that, once installed on a system, remains resident across system reboots to monitor and log system activity to the Windows event... - [Windows 10 Monitoring | EventSentry](https://www.eventsentry.com/solutions/windows-10-monitoring): EventSentry provides robust Windows 10 monitoring - [Windows Server 2012 Monitoring | EventSentry](https://www.eventsentry.com/solutions/windows-server-2012-monitoring): EventSentry provides robust Windows Server 2012 Monitoring - [Windows Server 2003 Monitoring | EventSentry](https://www.eventsentry.com/solutions/windows-server-2003-monitoring): EventSentry provides robust Windows 2003 Monitoring - [Windows Server 2008 Monitoring | EventSentry](https://www.eventsentry.com/solutions/windows-server-2008-monitoring): EventSentry provides robust Windows Server 2008 monitoring - [Windows XP Monitoring | EventSentry](https://www.eventsentry.com/solutions/windows-xp-monitoring): EventSentry provides robust Windows XP monitoring - [Windows 7 Monitoring | EventSentry](https://www.eventsentry.com/solutions/windows-7-monitoring): EventSentry provides robust Windows 7 monitoring - [Windows 8.1 Monitoring | EventSentry](https://www.eventsentry.com/solutions/windows-8-monitoring): EventSentry provides robust Windows 8 monitoring - [Syslog Monitoring | EventSentry](https://www.eventsentry.com/solutions/syslog-server): EventSentry includes a Windows syslog server that ingests events and converts them to actionable events. - [Ping Monitor | EventSentry](https://www.eventsentry.com/solutions/ping-monitoring): Monitoring the heartbeat of your network with EventSentry's Network Services - [NetFlow Monitoring | EventSentry](https://www.eventsentry.com/solutions/netflow): Visualize network traffic on your network and alert based on suspicious hosts. - [Network Bandwidth Monitoring | EventSentry](https://www.eventsentry.com/solutions/network-bandwidth-monitoring): Measure the bandwidth utilization on your network. ## Support - [Tutorials | EventSentry](https://www.eventsentry.com/support/tutorials): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Screencasts | EventSentry](https://www.eventsentry.com/support/screencasts): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Support vs Training | EventSentry](https://www.eventsentry.com/support/support-vs-training): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Documentation | EventSentry](https://www.eventsentry.com/support/documentation): EventSentry v4.2.3 is now available with validation scripts, enhanced ransomware detection, software version checking, plus expanded Syslog formats - [Archived Tutorials | EventSentry](https://www.eventsentry.com/support/archived-tutorials): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Getting Started with CMMC and EventSentry | EventSentry](https://www.eventsentry.com/support/compliance-quickstart): EventSentry' SIEM functionality helps your organization track access to CUI data and track changes in Active Directory down to the attribute. - [EventSentry Email Alerts](https://www.eventsentry.com/support/email_alerts): Filters are an integral part of EventSentry and allow you create rules as to which event log record gets forwarded to which notification. - [Getting Started with CMMC and EventSentry](https://www.eventsentry.com/support/cmmc): EventSentry helps your organization track access to CUI data and track changes in Active Directory down to the attribute. - [EventSentry Training | EventSentry](https://www.eventsentry.com/support/training): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Knowledge Base | EventSentry](https://www.eventsentry.com/support/kb/category): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. ## Validationscripts - [Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [STIG Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/stig): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [NIST Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/nist): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Compliance Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/compliance): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [STIG Medium Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/stig-medium-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Compliance Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/compliance-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [NIST 800 53 Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/nist800-53-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [CMMC Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cmmc): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [NIST 800 53 Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/nist800-53-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Compliance Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/compliance-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [STIG Medium Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/stig-medium-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Security Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/security-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [NIST 800 171 Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/nist800-171-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [CMMC2 L2 Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cmmc2-l2-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Security Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/security-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [NIST 800 171 Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/nist800-171-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [CMMC2 L2 Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cmmc2-l2-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Pci Dss V4 Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/pci-dss-v4-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Pci Dss V4 Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/pci-dss-v4-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Cis Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cis): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Cis Csc Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cis-csc-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Hipaa Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/hipaa-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Mitre Att Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/mitre-att): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Mitre Att Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/mitre-att-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Cis Csc Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cis-csc-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Bestpractice Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/bestpractice-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Mitre Att Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/mitre-att-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Bestpractice Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/bestpractice-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Domaincontroller Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/domaincontroller): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Hipaa Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/hipaa-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Pci Dss V3.2 Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/pci-dss-v3.2-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Domainmember Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/domainmember): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [CMMC2 L1 Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cmmc2-l1-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [STIG High Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/stig-high-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [CMMC2 L1 Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cmmc2-l1-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [STIG High Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/stig-high-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Pci Dss V3.2 Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/pci-dss-v3.2-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [CMMC2 L3 Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cmmc2-l3-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Tisax Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/tisax): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Bestpractice Domaincontroller Validation Scripts by EventSentry](https://www.eventsentry.com/validationscripts/tag/bestpractice-domaincontroller): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Sig Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/sig-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [CMMC2 L3 Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cmmc2-l3-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Privacy Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/privacy-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Domain Member: must be configured to at least negotiate signing for](https://www.eventsentry.com/validationscripts/guid/5c9b1fb7-3d92-4d13-be5f-13d7894e50d0): Unsigned network traffic is susceptible to man-in-the-middle attacks. In such attacks, an intruder captures packets between the server and the client device, modifies them, and then forwards them to... - [Threat Intel Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/threat-intel-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Sec Hardening Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/sec-hardening-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Sec Hardening Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/sec-hardening-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Threat Intel Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/threat-intel-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Privacy Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/privacy-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Domain Member: Must be running Credential Guard on domain-joined](https://www.eventsentry.com/validationscripts/guid/52b8eaca-e97b-4b7b-bda8-2f67dd947dbc): Credential Guard uses virtualization-based security to protect information that could be used in credential theft attacks if compromised. This authentication information, which was stored in the Loc... - [Csa Cmm Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/csa-cmm-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Passwords: must, at a minimum, be 14 characters | EventSentry](https://www.eventsentry.com/validationscripts/guid/e352dda0-c735-4b4e-ba26-097f5dbab32c): Types of password attacks include dictionary attacks (which attempt to use common words and phrases) and brute force attacks (which try every possible combination of characters). Also, attackers som... - [STIG Low Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/stig-low-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Shutdown: Clear virtual memory pagefile | EventSentry](https://www.eventsentry.com/validationscripts/guid/bbf7d8e7-9ffe-4643-8910-55c5a6f9f824): Important information that is kept in real memory might be written periodically to the paging file. This helps devices handle multitasking functions. A malicious user who has physical access to a se... - [NIST Privacy Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/nist-privacy-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Remote Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/remote-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Domain Controller: The password for the krbtgt account on a domain](https://www.eventsentry.com/validationscripts/guid/18ef977d-1c89-4ea7-ac53-0438873cb1db): The krbtgt account acts as a service account for the Kerberos Key Distribution Center (KDC) service. The account and password are created when a domain is created and the password is typically not c... - [Accounts: Deny log on locally user right must be configured to](https://www.eventsentry.com/validationscripts/guid/fd44a45e-ef9e-4c54-bebf-22bba68a185c): Accounts: Deny log on locally user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems In... - [STIG Low Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/stig-low-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Accounts: Must have the built-in Windows password complexity policy](https://www.eventsentry.com/validationscripts/guid/be6a2756-21d7-452c-b0a1-e6032f14f422): Description The use of complex passwords increases their strength against attack. The built-in Windows password complexity policy requires passwords to contain at least three of the four types of ch... - [Owasptop Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/owasptop-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Domain Member: Maximum age for machine account passwords must be](https://www.eventsentry.com/validationscripts/guid/ad52728e-be9b-4ab7-b329-5b11001e42de): Computer account passwords are changed automatically on a regular basis. This setting controls the maximum password age that a machine account may have. This must be set to no more than 30 days, ens... - [Health Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/health): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Passwords: Windows must be configured to prevent the storage of the](https://www.eventsentry.com/validationscripts/guid/8fbc83d9-7409-41aa-bf3c-a2360a8d9749): The LAN Manager hash is relatively weak and prone to attacks compared to the cryptographically stronger NTLM hash. Because the LM hash is stored on the local device in the security database, the pas... - [NIST Privacy Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/nist-privacy-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Cce Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cce-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Cce Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cce-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Accounts: Users must be prompted to authenticate when the system](https://www.eventsentry.com/validationscripts/guid/ef3c9259-d0d3-434a-8e7c-ab945deaa3f0): A system that does not require authentication when resuming from sleep may provide access to unauthorized users. Authentication must always be required when accessing a system. This setting ensures ... - [Accounts: Users must be prompted to authenticate when the system](https://www.eventsentry.com/validationscripts/guid/bf4a43bc-9605-4596-a562-5e4073fe21d5): A system that does not require authentication when resuming from sleep may provide access to unauthorized users. Authentication must always be required when accessing a system. This setting ensures ... - [STIG Medium Ie Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/stig-medium-ie): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Network Access: LAN Manager authentication level must be configured](https://www.eventsentry.com/validationscripts/guid/2718ea3f-5f25-4e6d-a693-3c426f14357f): The Kerberos v5 authentication protocol is the default protocol for authentication of users who are logging on to a Windows domain with domain accounts. NTLM, which is less secure, is retained in la... - [Owasptop Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/owasptop-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Accounts: Must require passwords | EventSentry](https://www.eventsentry.com/validationscripts/guid/00279417-0255-4ff4-8b5c-dbb7866085e2): The lack of password protection enables anyone to gain access to the information system, which opens a backdoor opportunity for intruders to compromise the system as well as other resources. Account... - [Network Access: Must have the Server Message Block (SMB) v1 protocol](https://www.eventsentry.com/validationscripts/guid/9a3ba1fc-6a60-4752-9827-152b821e5c0a): SMBv1 is a legacy protocol that uses the MD5 algorithm as part of SMB. MD5 is known to be vulnerable to a number of attacks such as collision and preimage attacks as well as not being FIPS compliant. - [Network Access: Must Have the Server Message Block (SMB) v1 protocol](https://www.eventsentry.com/validationscripts/guid/78c4c60a-a039-4a47-b614-3138d7bcfe4f): SMBv1 is a legacy protocol that uses the MD5 algorithm as part of SMB. MD5 is known to be vulnerable to a number of attacks such as collision and preimage attacks as well as not being FIPS compliant. - [Security: Virtualization-based security must be enabled with platform](https://www.eventsentry.com/validationscripts/guid/b056102b-3477-4a44-bda9-536330033264): Windows OS: Virtualization-based security must be enabled with the platform security level configured to Secure Boot or Secure Boot with DMA Protection Virtualization Based Security (VBS) provides t... - [Sig Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/sig-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Domain Controller: SYSVOL directory must have proper access control](https://www.eventsentry.com/validationscripts/guid/15074903-9e8a-4d2f-b6d4-4e5ab30e64d7): Improper access permissions for directory data files could allow unauthorized users to read, modify, or delete directory data. The SYSVOL directory contains public files (to the domain) such as poli... - [Passwords: Minimum Password Age | EventSentry](https://www.eventsentry.com/validationscripts/guid/c3b194cc-701a-43f4-bd84-86caada64337): Permitting passwords to be changed in immediate succession within the same day allows users to cycle passwords through their history database. This enables users to effectively negate the purpose of... - [Network Access: Windows must not have the Server Message Block (SMB)](https://www.eventsentry.com/validationscripts/guid/934a1499-9d7e-407b-86ab-9a58e10f4ed1): SMBv1 is a legacy protocol that uses the MD5 algorithm as part of SMB. MD5 is known to be vulnerable to a number of attacks such as collision and preimage attacks and is not FIPS compliant. - [File System: Local volumes must be formatted with NTFS | EventSentry](https://www.eventsentry.com/validationscripts/guid/b6493fb9-ad83-494c-93e3-3dbfaeb9b303): The ability to set access permissions and auditing is critical to maintaining the security and proper access controls of a system, it's also best practice and required for several compliance require... - [Niap Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/niap-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Niap Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/niap-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [PowerShell: v2 should not be installed / enabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/f69ae077-386f-4543-9036-30e5b3377f62): PowerShell 2.0 is deprecated and should be uninstalled. https://devblogs.microsoft.com/powershell/windows-powershell-2-0-deprecation https://www.stigviewer.com/stig/windowsserver2016/2017-11-20/find... - [Auditing: System must be configured to audit Privilege Use -](https://www.eventsentry.com/validationscripts/guid/cc84129b-345b-4e6d-91d4-39bc1e8ee328): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Privilege Use -](https://www.eventsentry.com/validationscripts/guid/9345b515-8295-47a6-a353-fcdc72ff45ea): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit logon successes](https://www.eventsentry.com/validationscripts/guid/d46bf70a-28b8-489a-bb63-b549d576fc4f): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Object Access -](https://www.eventsentry.com/validationscripts/guid/af074caf-14a4-41f5-9ebd-e2214dc48240): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: Permissions for the Security event log must prevent access](https://www.eventsentry.com/validationscripts/guid/f67457c3-6d39-425d-9831-b5e44eaf7d6f): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit logon failures | EventSentry](https://www.eventsentry.com/validationscripts/guid/b052b9fc-5f3e-45e6-94f6-e0823790f14c): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Account Management -](https://www.eventsentry.com/validationscripts/guid/d3e3b256-80cd-4f3a-bd46-487cda3513f2): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Account Management -](https://www.eventsentry.com/validationscripts/guid/b7a6152d-607d-424f-a0d1-78000be3512a): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Policy Change -](https://www.eventsentry.com/validationscripts/guid/48e1aa69-0cc4-44e2-8f00-8db93be2cdc1): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Policy Change -](https://www.eventsentry.com/validationscripts/guid/7338cb96-3198-4665-8c6e-755e05005b58): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: Permissions for the System event log must prevent access by](https://www.eventsentry.com/validationscripts/guid/31096f12-75ea-425b-b416-f0c0b87dc6ff): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit System - Security State](https://www.eventsentry.com/validationscripts/guid/38e08d5e-0bc4-41e9-aec3-d30e8b243af6): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Account Management -](https://www.eventsentry.com/validationscripts/guid/43fd3c2b-daf3-4408-8a5b-d04a79bd3bd4): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit System - Security System](https://www.eventsentry.com/validationscripts/guid/cac02598-d29e-489c-afe0-8349bd676bf6): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Accounts: Administrator accounts must not be enumerated during](https://www.eventsentry.com/validationscripts/guid/f3afb7e7-d38a-42f2-8290-56da3b445913): Enumeration of administrator accounts when elevating can provide part of the logon information to an unauthorized user. This setting configures the system to always require users to type in a userna... - [Auditing: System must be configured to audit Logon/Logoff - Special](https://www.eventsentry.com/validationscripts/guid/0a6702c1-b417-4100-b6af-8ee48a5d2f23): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Compliance: BitLocker should be configured in FIPS mode | EventSentry](https://www.eventsentry.com/validationscripts/guid/330f6517-5c88-4086-b456-d3026307c001): The Federal Information Processing Standard (FIPS) Publication 140-2 is a U.S. government standard. FIPS is based on Section 5131 of the Information Technology Management Reform Act of 1996. It defi... - [Auditing: System must be configured to audit Policy Change - Audit](https://www.eventsentry.com/validationscripts/guid/23e1491c-ff4e-45b1-be08-fe8c2a6209da): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Fips140 2 Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/fips140-2): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Auditing: System must be configured to audit Object Access - Other](https://www.eventsentry.com/validationscripts/guid/81abf498-85f9-4536-a8c4-f6d26fe5f26f): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit logoff successes](https://www.eventsentry.com/validationscripts/guid/282bb2eb-115f-483f-85fb-637124552335): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Account Management -](https://www.eventsentry.com/validationscripts/guid/b0fb3bb1-4400-4a94-bea1-8d64d4b170b3): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Object Access - Other](https://www.eventsentry.com/validationscripts/guid/8110968d-1cd4-430b-909e-52a487b78106): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit System - Other System](https://www.eventsentry.com/validationscripts/guid/ffcd14a5-06ae-44e3-846b-c0661de732a6): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit System - Other System](https://www.eventsentry.com/validationscripts/guid/501bae98-8af9-4dd4-b71e-30fc202958d5): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Object Access -](https://www.eventsentry.com/validationscripts/guid/352b582c-c55c-4d71-9a19-4c9448d1c96d): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit System - System](https://www.eventsentry.com/validationscripts/guid/14903b11-6904-4913-a981-5f3422dafaa4): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Account Logon -](https://www.eventsentry.com/validationscripts/guid/82478e12-7206-4b9c-8a68-2ccb6e3fe144): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Windows OS: Data Execution Prevention (DEP) must be configured to at](https://www.eventsentry.com/validationscripts/guid/df8e6841-1dd4-42ce-b374-28f997e12b6d): Attackers are constantly looking for vulnerabilities in systems and applications. Data Execution Prevention (DEP) prevents harmful code from running in protected memory locations reserved for Window... - [Auditing: System must be configured to audit Account Management -](https://www.eventsentry.com/validationscripts/guid/980236d7-5ee7-436d-83ce-5504b366d913): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit Account Logon -](https://www.eventsentry.com/validationscripts/guid/20d10fd0-520a-4b7e-b915-5e2e6649cf99): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: System must be configured to audit System - System](https://www.eventsentry.com/validationscripts/guid/0634f6e9-e443-4576-b0a2-e7013116b350): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Accounts: Users must be required to enter a password to access](https://www.eventsentry.com/validationscripts/guid/c9946229-3c27-4eb5-ae8f-6f777a9ad637): If the private key is discovered, an attacker can use the key to authenticate as an authorized user and gain access to the network infrastructure. The cornerstone of the PKI is the private key used ... - [Security Hardening: Check if Sysmon is installed and running](https://www.eventsentry.com/validationscripts/guid/f50d3fee-c961-4fab-bc51-54a0fed6b59f): Installing the System Monitor service & driver (Sysmon for short) is a critical step in hardening an organization's security posture due to its advanced monitoring and logging capabilities extending... - [PowerShell: Script block logging must be enabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/ab3e18c8-5f9b-4a08-8474-ff10619965bd): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Msoffice Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/msoffice): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Auditing: System must be configured to audit Policy Change - Audit](https://www.eventsentry.com/validationscripts/guid/d7a89b74-da6a-4b5b-a3f7-1ead34cbc837): Vulnerability Discussion Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as w... - [Auditing: System must be configured to audit Logon/Logoff - Group](https://www.eventsentry.com/validationscripts/guid/52b16e39-5909-4145-a76d-8fa0fc554dab): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Remote Desktop Services: Must require secure Remote Procedure Call](https://www.eventsentry.com/validationscripts/guid/20a8c861-e142-4e51-bf82-b0ef8bd1343c): Allowing unsecure RPC communication exposes the system to man-in-the-middle attacks and data disclosure attacks. A man-in-the-middle attack occurs when an intruder captures packets between a client ... - [Accounts: Local Administrator account should be disabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/822e9bf2-405a-42cb-9566-8532df68939f): It is best practice that the local Administrator account is disabled due to several known vulnerabilities: 1. The built-in administrator account cannot be locked out no matter how many failed logons... - [Security Hardening: Check Required Event Logs are Enabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/6fe1d89b-8e3e-49c2-9cc8-76cd1beb63ef): This script verifies that key Windows operational event logs are enabled on the local system. These logs provide visibility into core system activities such as PowerShell execution, DNS resolution, ... - [Network: Internet Protocol version 6 (IPv6) source routing must use](https://www.eventsentry.com/validationscripts/guid/d5030382-fcd1-4d7c-88e3-f1defebc7cf0): Network: Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing. Configuring the system to disable IPv6 source routing prot... - [Ul2900 1 Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/ul2900-1-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Accounts: User Account Control (UAC) must be configured to detect](https://www.eventsentry.com/validationscripts/guid/ed5ca948-5cbf-431d-a5da-39d02bd64c48): User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting requires Windows to respond to applica... - [Privacy: Windows Telemetry must not be set to Full | EventSentry](https://www.eventsentry.com/validationscripts/guid/0001b667-c79a-4486-802c-32d860cae99e): Telemetry and Data collection was introduced in Windows 2016 Server, this check is for Windows 10, Server 2016, Server 2019. Some features may communicate with the vendor, sending system information... - [Csf Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/csf-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Threat Intel: Attack Vector: Credential dumping protections using LSA](https://www.eventsentry.com/validationscripts/guid/368b50e1-18bd-4cc8-a296-b42030468dbe): In a Windows setup, when users log onto their systems (be it directly or via remote access), they use their usernames and passwords. Behind the scenes, this authentication duty is managed by the Loc... - [Cjis Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cjis-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Ul2900 1 Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/ul2900-1-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Fedramp Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/fedramp-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Fedramp Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/fedramp-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Cjis Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cjis-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Csf Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/csf-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Bitlocker Security Desktop Validation Scripts by EventSentry](https://www.eventsentry.com/validationscripts/tag/bitlocker-security-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Cve Desktop High Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cve-desktop-high): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Cve Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cve-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Domaincontroller Health Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/domaincontroller-health): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Security: TLS/SSL Insecure Ciphers (SCHANNEL) | EventSentry](https://www.eventsentry.com/validationscripts/guid/78fcd8a8-18af-49f4-8a64-bccb901e5557): Security: must implement protection methods such as TLS, encrypted VPNs, or IPsec if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every st... - [Hyper V Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/hyper-v): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Vm Guest Host Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/vm-guest-host): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Cve Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cve-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Cve Server High Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/cve-server-high): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Sigma Server Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/sigma-server): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Auditing: Event Log / Viewer must be protected from unauthorized](https://www.eventsentry.com/validationscripts/guid/09651036-eca5-4f3a-83fb-0ff12719b201): Protecting audit information also includes identifying and protecting the tools used to view and manipulate log data. Therefore, protecting audit tools is necessary to prevent unauthorized operation... - [Domainmember Health Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/domainmember-health): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Sigma Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/sigma-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Network Access: Microsoft network Server: Digitally sign | EventSentry](https://www.eventsentry.com/validationscripts/guid/707d1ae2-c6f2-46af-966d-d3559db69094): The server message block (SMB) protocol provides the basis for many network operations. Digitally signed SMB packets aid in preventing man-in-the-middle attacks. If this policy is enabled, the SMB s... - [Exchange Security Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/exchange-security): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Info Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/info-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Auditing: Windows must be configured to audit System - IPsec Driver](https://www.eventsentry.com/validationscripts/guid/b67f6feb-ff6f-4e4c-a9d4-1d6cc8fd3fbd): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Auditing: Command line data must be included in process creation](https://www.eventsentry.com/validationscripts/guid/c787dcd2-355b-4ff5-8265-3eb860f11670): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Iis STIG High Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/iis-stig-high): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Auditing: Windows must be configured to audit System - IPsec Driver](https://www.eventsentry.com/validationscripts/guid/2189409b-e597-47c5-a781-728c637258ae): Vulnerability Discussion Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as w... - [Auditing: System must be configured to audit Detailed Tracking - Plug](https://www.eventsentry.com/validationscripts/guid/f5278646-f9f7-41df-b807-b1fd1c57cdfa): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Csa Cmm Desktop Validation Scripts by EventSentry | EventSentry](https://www.eventsentry.com/validationscripts/tag/csa-cmm-desktop): EventSentry provides exceptional real time server monitoring, including server health, log file and event log monitoring at an affordable price. - [Network Access: Microsoft network Client: Digitally sign | EventSentry](https://www.eventsentry.com/validationscripts/guid/af452788-473f-4255-bb87-72b7390e187f): The server message block (SMB) protocol provides the basis for many network operations. Digitally signed SMB packets aid in preventing man-in-the-middle attacks. If this policy is enabled, the SMB c... - [Threat Intel: Attack Vector: Utilizing Image File Execution Options](https://www.eventsentry.com/validationscripts/guid/bc1d2ae4-f7cc-4e71-83ed-a842c099897a): In today’s ever-evolving threat landscape, the most sophisticated attackers are able to hide their malware in places few would suspect. Take, for example, a legitimate Windows feature, Image File Ex... - [Domain Member: Caching of logon credentials must be limited - Desktop](https://www.eventsentry.com/validationscripts/guid/a256ebbf-e5b2-4b73-a375-6587c8d1b0ba): The default Windows configuration caches the last logon credentials for users who log on interactively to a system. This feature is provided for system availability reasons, such as the user's machi... - [Accounts: Enable computer and user accounts delegation user right not](https://www.eventsentry.com/validationscripts/guid/64f28abd-921c-4d04-b2c0-f047d20d673e): Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. The "Enable computer and user accounts to be trusted for delegation" user right allows th... - [Accounts: Enable computer and user accounts to be trusted user right](https://www.eventsentry.com/validationscripts/guid/42587e5b-a61b-49e2-b25b-5413d52ebd05): Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. The "Enable computer and user accounts to be trusted for delegation" user right allows th... - [Windows OS: Windows Update must not obtain updates from other PCs on](https://www.eventsentry.com/validationscripts/guid/133e9e0a-de38-477b-a29c-3451f6c505ec): Windows Update can obtain updates from additional sources instead of Microsoft. In addition to Microsoft, updates can be obtained from and sent to PCs on the local network as well as on the internet... - [Passwords: history must be configured to 24 passwords remembered](https://www.eventsentry.com/validationscripts/guid/d0163b5f-23ab-4377-bc49-709e891a6b2b): The longer a user uses the same password, the greater the chance that an attacker can determine the password through brute force attacks. In addition, any accounts that may have been compromised rem... - [Network Access: Restrict remote calls to the Security Account Manager](https://www.eventsentry.com/validationscripts/guid/6f17b478-ef66-4c12-8e61-0ffaae9cd6b4): Network Access: Must restrict remote calls to the Security Account Manager (SAM) to Administrators on domain-joined member servers and standalone systems. The Windows SAM stores users' passwords. Re... - [Domain Member: must limit the caching of logon credentials to four or](https://www.eventsentry.com/validationscripts/guid/95498795-fa0a-428a-8fd8-bbcc31cb79e8): The default Windows configuration caches the last logon credentials for users who log on interactively to a system. This feature is provided for system availability reasons, such as the user's machi... - [Accounts: Local Admin accounts must have their privileged token](https://www.eventsentry.com/validationscripts/guid/e4710a99-9bc1-4e34-80ad-5d2f84f57732): A compromised local administrator account can provide means for an attacker to move laterally between domain systems. With User Account Control enabled, filtering the privileged token for local admi... - [Passwords: Maximum Password Age | EventSentry](https://www.eventsentry.com/validationscripts/guid/794aed82-0f0a-46e0-8135-204c50b12462): The longer a password exists, the higher the likelihood that it will be compromised by a brute force attack, by an attacker gaining general knowledge about the user, or by the user sharing the passw... - [Threat Intel: Attack Vector: Preventing Unauthorized Application](https://www.eventsentry.com/validationscripts/guid/28c9bd0b-46c9-4740-aa57-88705ff28fb1): Certain applications that come bundled with Windows operating systems have become prime targets for exploitation by malicious actors. These seemingly innocuous tools, often overlooked in security pr... - [Accounts: The number of allowed bad logon attempts must be configured](https://www.eventsentry.com/validationscripts/guid/409871a1-6b58-45ab-9dfd-8b40e948ecd2): The account lockout feature, when enabled, prevents brute-force password attacks on the system. The higher this value is, the less effective the account lockout feature will be in protecting the loc... - [Network Access: Kerberos encryption types must be configured to](https://www.eventsentry.com/validationscripts/guid/582c56ca-6381-4b12-aca9-13cdfc465e73): Certain encryption types are no longer considered secure. The DES and RC4 encryption suites must not be used for Kerberos encryption. Note: Organizations with domain controllers running earlier vers... - [General: Machine inactivity limit must be set to 15 minutes or less,](https://www.eventsentry.com/validationscripts/guid/bf06c136-7223-41ac-8288-e0940126a884): Unattended systems are susceptible to unauthorized use and should be locked when unattended. The screen saver should be set at a maximum of 15 minutes and be password protected. This protects critic... - [Windows Update: Windows Recovery Partition Size | EventSentry](https://www.eventsentry.com/validationscripts/guid/d80aa4e9-fdce-477d-bd3a-ee056191d4ee): Microsoft has changed how it updates PCs that run the Windows Recovery Environment (WinRE). WinRE will be updated using the monthly cumulative update. This change only applies to PCs that get update... - [Domain Member: Group policy objects must be reprocessed even if they](https://www.eventsentry.com/validationscripts/guid/0652c1f1-ca23-46d0-a60f-7f62281b866e): Registry entries for group policy settings can potentially be changed from the required configuration. This could occur as part of troubleshooting or by a malicious process on a compromised system. ... - [Accounts: Local Guest account should be disabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/538d811a-0a0a-4336-8294-63bc2c092ebb): The default Guest account allows unauthenticated network users to log on as a Guest with no password. These unauthorized users could access any resources that are accessible to the Guest account ove... - [Accounts: Passwords for the built-in Administrator account must be](https://www.eventsentry.com/validationscripts/guid/e228712c-a432-4f66-898d-f0698df9e862): The longer a password is in use, the greater the opportunity for someone to gain unauthorized knowledge of the password. The built-in Administrator account is not generally used and its password may... - [Windows OS: Must not have the Telnet Client Installed | EventSentry](https://www.eventsentry.com/validationscripts/guid/8fbc28fc-2d54-4b3c-af3f-9ec8d62e959b): Unnecessary services increase the attack surface of a system. Some of these services may not support the required levels of authentication or encryption or may provide unauthorized access to the sys... - [Network Access: Microsoft network Server: Digitally sign | EventSentry](https://www.eventsentry.com/validationscripts/guid/189e99fb-1c5c-43ed-b044-4dcbccf3820f): The server message block (SMB) protocol provides the basis for many network operations. Digitally signed SMB packets aid in preventing man-in-the-middle attacks. If this policy is enabled, the SMB s... - [Accounts: Must have the period of time before the bad logon counter](https://www.eventsentry.com/validationscripts/guid/56655e04-3824-4810-9be4-aaa6e1c1c2ac): The account lockout feature, when enabled, prevents brute-force password attacks on the system. This parameter specifies the period of time that must pass after failed logon attempts before the coun... - [Domain Controller: Must require LDAP access signing | EventSentry](https://www.eventsentry.com/validationscripts/guid/9e1e28ee-d597-49db-b33d-cfee0ba15c69): Unsigned network traffic is susceptible to man-in-the-middle attacks, where an intruder captures packets between the server and the client and modifies them before forwarding them to the client. In ... - [General: Early Launch Antimalware, Boot-Start Driver Initialization](https://www.eventsentry.com/validationscripts/guid/a9b5b413-0fc5-49c2-ab77-6761b329950c): Compromised boot drivers can introduce malware prior to protection mechanisms that load after initialization. The Early Launch Antimalware driver can limit allowed drivers based on classifications d... - [Auditing: Must force audit policy subcategory settings to override](https://www.eventsentry.com/validationscripts/guid/9929dbd2-a4fb-40ea-9a2d-8a1db39a5729): Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Au... - [Network Access: Microsoft network Client: Digitally sign | EventSentry](https://www.eventsentry.com/validationscripts/guid/a35d34f6-b9b1-4c82-8cac-31a7c4fdbc14): The server message block (SMB) protocol provides the basis for many network operations. If this policy is enabled, the SMB client will request packet signing when communicating with an SMB server th... - [Network: Source routing must be configured to the highest protection](https://www.eventsentry.com/validationscripts/guid/655d213f-bed4-43aa-9bbf-f4bf77a2defd): Configuring the system to disable IP source routing protects against spoofing. - [FIPS 140: Security Requirements for Cryptographic Modules | EventSentry](https://www.eventsentry.com/validationscripts/guid/b6109218-a32b-479a-8465-055340a1759c): FIPS Mode must be enabled at Windows OS level to comply Fips140-2: This Federal Information Processing Standard (140-2) specifies the security requirements that will be satisfied by a cryptographic ... - [Windows OS: Build Version Check (End Of Life) | EventSentry](https://www.eventsentry.com/validationscripts/guid/07b6c273-cdb3-4a4d-889d-d1d54dc0eb5f): It is critical to install security updates and maintain the latest OS Build to protect your computer from malicious attacks. If your OS reached End Of Life, won't receive security updates and will b... - [Autoplay: Should be disabled for all drives | EventSentry](https://www.eventsentry.com/validationscripts/guid/2cb75d59-8ef3-4fa3-90e1-8bec9e51c703): Allowing autoplay to execute may introduce malicious code to a system. Autoplay begins reading from a drive as soon as you insert media in the drive. As a result, the setup file of programs or music... - [Windows OS: Must not have the Fax Server role installed | EventSentry](https://www.eventsentry.com/validationscripts/guid/f5e7d547-a431-4a6e-b4bd-b95e6e8cac99): Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption or may provide unauthorized access to the system. - [Accounts: User Account Control must only elevate UIAccess | EventSentry](https://www.eventsentry.com/validationscripts/guid/b6f678d0-7ffc-48e8-b89c-ca6d301de838): User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting configures Windows to only allow appli... - [Accounts: must disable automatically signing in the last interactive](https://www.eventsentry.com/validationscripts/guid/30d230a9-ff8e-44a2-ac87-f35b77bff14a): Description Windows can be configured to automatically sign the user back in after a Windows Update restart. Some protections are in place to help ensure this is done in a secure fashion; however, d... - [General: Solicited Remote Assistance must not be allowed | EventSentry](https://www.eventsentry.com/validationscripts/guid/ac242343-8a24-414b-8615-7de95dffd90d): Remote assistance allows another user to view or take control of the local session of a user. Solicited assistance is help that is specifically requested by the local user. This may allow unauthoriz... - [Network Access: Do not allow anonymous enumeration of Security](https://www.eventsentry.com/validationscripts/guid/752e0588-decf-451b-9fef-cc3235765d54): An unauthorized user could anonymously list account names and shared resources and use the information to attempt to guess passwords or perform social-engineering attacks. https://docs.microsoft.com... - [Threat Intel: PetitPotam NTLM Relay Attack: Disable NTLM Incoming](https://www.eventsentry.com/validationscripts/guid/744b05b3-e1aa-47d0-b4ca-0d327bd6ab3d): PetitPotam abuses the Encrypting File System (MS-EFSRPC) protocol, which is designed for performing maintenance and management operations on encrypted data that is stored remotely and accessed over ... - [Threat Intel: Attack Vector: Disable Windows Event Logging | EventSentry](https://www.eventsentry.com/validationscripts/guid/f1bc38dc-fbda-45cd-9ec9-7f69dfd7b00e): Adversaries may disable Windows event logging to limit the data available for detection and auditing purposes. Windows event logs capture user and system activities, including login attempts, proces... - [Accounts: Local accounts with blank passwords must be restricted to](https://www.eventsentry.com/validationscripts/guid/3ef29cdc-8018-48a9-b210-13e18cf14d07): An account without a password can allow unauthorized access to a system as only the username would be required. Password policies should prevent accounts with blank passwords from existing on a syst... - [Remote Desktop Services: Idle session time limit | EventSentry](https://www.eventsentry.com/validationscripts/guid/a06670b6-460f-45ae-93ef-02d41f52d45e): This setting controls how long a session may be idle before it is automatically disconnected from the server. Users should log off if they plan on being away from their terminals for extended period... - [Network Access: Do not allow anonymous enumeration of shares](https://www.eventsentry.com/validationscripts/guid/0d97c353-2198-4a09-a41b-9df3498067dc): Allowing anonymous logon users (null session connections) to list all account names and enumerate all shared resources can provide a map of potential points to attack the system. - [Windows OS: Must not have the Microsoft FTP service installed](https://www.eventsentry.com/validationscripts/guid/b9695d6b-88c2-41e6-9fd9-611790f33f59): Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption. - [Domain Controllers: Deny log on locally user right on domain](https://www.eventsentry.com/validationscripts/guid/8d9748ad-695f-489e-bf31-4d1e8e397a7b): Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. The "Deny log on locally" user right defines accounts that are prevented from logging on ... - [Microsoft Edge: Users must not be allowed to ignore Windows Defender](https://www.eventsentry.com/validationscripts/guid/857ef3ca-acd6-4d9e-900c-211b7ea5a04d): The Windows Defender SmartScreen filter in Microsoft Edge provides warning messages and blocks potentially malicious websites and file downloads. If users are allowed to ignore warnings from the Win... - [General: Printing over HTTP must be turned off | EventSentry](https://www.eventsentry.com/validationscripts/guid/21735bdc-fd91-44a8-beca-9a48b6c5e166): Some features may communicate with the vendor, sending system information or downloading data or components for the feature. Turning off this capability will prevent potentially sensitive informatio... - [Exploit Protection: system-level mitigation, Validate exception](https://www.eventsentry.com/validationscripts/guid/3f0d630e-d744-450e-8e8a-6478118649fb): Exploit protection enables mitigations against potential threats at the system and application level. Several mitigations, including "Validate exception chains (SEHOP)", are enabled by default at th... - [Privacy: Windows Telemetry Should Be disabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/7b982402-135c-44d3-a35d-3ab41833719f): Windows Telemetry Should Be Disabled Windows Telemetry and Data Collection was introduced in Windows 2016 Server. This script will work on Windows 2016 Server, Windows 2019 Server, and Windows 10. A... - [Accounts: User Account Control (UAC) must, at a minimum, prompt](https://www.eventsentry.com/validationscripts/guid/0b28a1d9-618b-45ce-8938-f73cc84fce81): UAC is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting configures the elevation requirements for logged-on administr... - [Accounts: Built-in Administrator account must be renamed | EventSentry](https://www.eventsentry.com/validationscripts/guid/b1981ae3-ba91-4758-a98c-a5937a0498f7): The built-in Guest and Administrator accounts are well-known user accounts on all Windows systems and, as initially installed, do not require a password. This can allow access to system resources by... - [Internet Browser: Basic authentication for RSS feeds over HTTP must](https://www.eventsentry.com/validationscripts/guid/a140d78e-249b-4c39-9d82-f54aeef02be0): Basic authentication uses plain-text passwords that could be used to compromise a system. Disabling Basic authentication will reduce this potential. - [Exploit Protection: Structured Exception Handling Overwrite | EventSentry](https://www.eventsentry.com/validationscripts/guid/d50f88d1-0103-4194-9add-21f3846dc0d2): Attackers are constantly looking for vulnerabilities in systems and applications. Structured Exception Handling Overwrite Protection (SEHOP) blocks exploits that use the Structured Exception Handlin... - [Accounts: User Account Control (UAC) approval mode for the built-in](https://www.eventsentry.com/validationscripts/guid/b505fc16-70d3-4275-bcc5-02fac2fdb3af): User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting configures the built-in Administrator ... - [Domain Member: Hardened UNC paths must require mutual authentication](https://www.eventsentry.com/validationscripts/guid/7b2d6eab-fc7f-4759-8ad5-ff7e774c5b97): Domain Member: Hardened UNC paths must be defined to require mutual authentication and integrity for at least the \\\SYSVOL and \\\NETLOGON shares. Additional security requirements are applied to UN... - [Logon: Require CTRL+ALT+DEL for interactive logons | EventSentry](https://www.eventsentry.com/validationscripts/guid/d2d523f6-4e7a-46e3-b553-ab395a7563e4): Disabling the Ctrl+Alt+Del security attention sequence can compromise system security. Because only Windows responds to the Ctrl+Alt+Del security sequence, you can be assured that any passwords you ... - [Domain Controller: Permissions on the Active Directory data files](https://www.eventsentry.com/validationscripts/guid/1bb127e7-c293-41f4-a937-c9c76d35cb8a): Improper access permissions for directory data-related files could allow unauthorized users to read, modify, or delete directory data or audit trails. Satisfies: SRG-OS-000324-GPOS-00125, SRG-OS-000... - [Accounts: User Account Control (UAC) must virtualize file and](https://www.eventsentry.com/validationscripts/guid/938c99da-1577-427d-908d-8c5e31bd9546): User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting configures non-UAC-compliant applicati... - [Domain Member: Domain-joined systems must have a Trusted Platform](https://www.eventsentry.com/validationscripts/guid/b7074672-cbee-4409-a64a-9b03894fcf2f): Credential Guard uses virtualization-based security to protect data that could be used in credential theft attacks if compromised. A number of system requirements must be met in order for Credential... - [Network Access: Unencrypted passwords must not be sent to third-party](https://www.eventsentry.com/validationscripts/guid/9cce3400-f772-4b0c-8f12-11157e102f87): Some non-Microsoft SMB servers only support unencrypted (plain-text) password authentication. Sending plain-text passwords across the network when authenticating to an SMB server reduces the overall... - [Windows OS: Explorer Data Execution Prevention must be enabled](https://www.eventsentry.com/validationscripts/guid/c4e3c7a1-5b63-407a-8eb9-c6a4b52b9f93): Data Execution Prevention provides additional protection by performing checks on memory to help prevent malicious code from running. This setting will prevent Data Execution Prevention from being tu... - [Threat Intel: Persistence - AppInit DLLs | EventSentry](https://www.eventsentry.com/validationscripts/guid/bf92b536-95cc-4060-bea3-a61ba1e4c9bb): Windows operating systems offer the capability for almost all application processes to load custom Dynamic Link Libraries (DLLs) into their memory space. This feature can be exploited for maintainin... - [Passwords: must be configured to expire | EventSentry](https://www.eventsentry.com/validationscripts/guid/89d6a5d0-bc9a-4c29-9a58-3764c36677ab): Passwords that do not expire or are reused increase the exposure of a password with greater probability of being discovered or cracked. This script does not relay on any GPO set, or Registry entry. ... - [Remote Management: Windows Remote Management (WinRM) client must not](https://www.eventsentry.com/validationscripts/guid/e4dd3ff4-f585-4e08-b91e-8bb3e02737c5): Basic authentication uses plain-text passwords that could be used to compromise a system. Disabling Basic authentication will reduce this potential. - [Debug Programs: User right must only be assigned to the | EventSentry](https://www.eventsentry.com/validationscripts/guid/76794e3a-d350-45a6-adf9-a4a9708271f9): Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. Accounts with the "Debug programs" user right can attach a debugger to any process or to ... - [General: Downloading print driver packages over HTTP must be turned](https://www.eventsentry.com/validationscripts/guid/925b056c-6bae-4e27-aa19-f8d383455774): Some features may communicate with the vendor, sending system information or downloading data or components for the feature. Turning off this capability will prevent potentially sensitive informatio... - [Network: Simple TCP/IP Services must not be installed on the system](https://www.eventsentry.com/validationscripts/guid/d0f0e951-4cca-4ca9-9b9e-e9e13e39ca99): Unnecessary services increase the attack surface of a system. Some of these services may not support the required levels of authentication or encryption or may provide unauthorized access to the sys... - [Privacy: Application Compatibility Program Inventory must not collect](https://www.eventsentry.com/validationscripts/guid/554ca683-aaaa-43da-9a97-e093af29457e): Privacy: The Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft Some features may communicate with the vendor, sending system... - [General: AntiVirus/Antimalware Status | EventSentry](https://www.eventsentry.com/validationscripts/guid/6d48a68a-3e44-4a00-8d42-670e41c9942c): It's best practice to run AntiVirus software in order to protect computers from malware, viruses and other threats. Note: This script only supports desktop editions of Windows. - [General: Windows Defender SmartScreen must be enabled (Server)](https://www.eventsentry.com/validationscripts/guid/4595ee72-d404-4b45-aae4-102fefd1a165): Windows Defender SmartScreen helps protect systems from programs downloaded from the internet that may be malicious. Enabling SmartScreen can block potentially malicious programs or warn users. - [Credentials: WDigest Authentication must be disabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/13cb0c87-4b9a-4923-9768-87bafab6ef87): When the WDigest Authentication protocol is enabled, plain-text passwords are stored in the Local Security Authority Subsystem Service (LSASS), exposing them to theft. WDigest is disabled by default... - [Accounts: Automatic logons must be disabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/5db60bfa-0318-430e-ab7e-c2ff3e749ae9): Allowing a system to automatically log on when the machine is booted could give access to any unauthorized individual who restarts the computer. Automatic logon with administrator privileges would g... - [Accounts: Built-in Guest account must be renamed | EventSentry](https://www.eventsentry.com/validationscripts/guid/20dbd0a4-0373-4913-9f75-4ab7f6fcbdb0): The built-in guest account is a well-known user account on all Windows systems and, as initially installed, does not require a password. This can allow access to system resources by unauthorized use... - [General: Windows must prevent the display of slide shows on the lock](https://www.eventsentry.com/validationscripts/guid/f63c8b4d-8b8d-4327-8c5a-5bc64bf7245c): Slide shows that are displayed on the lock screen could display sensitive information to unauthorized personnel. Turning off this feature will limit access to the information to a logged-on user. - [Remote Management: Windows Remote Management (WinRM) client must not](https://www.eventsentry.com/validationscripts/guid/1a0eb6a5-9009-4dc3-b12f-bed65052c49d): Digest authentication is not as strong as other options and may be subject to man-in-the-middle attacks. Disallowing Digest authentication will reduce this potential. - [Accounts: Lockout duration must be configured to 15 minutes or](https://www.eventsentry.com/validationscripts/guid/d9b675fb-1bb2-4ff3-88ea-0e74ab40e2a7): The account lockout feature, when enabled, prevents brute-force password attacks on the system. This parameter specifies the amount of time that an account will remain locked after the specified num... - [Accounts: User Account Control (UAC) must automatically deny standard](https://www.eventsentry.com/validationscripts/guid/2a28f305-e508-40e1-80e4-e7702143703b): User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting controls the behavior of elevation whe... - [Security: Kernel (Direct Memory Access) DMA Protection must be](https://www.eventsentry.com/validationscripts/guid/7464d97c-90d5-49f3-8f02-e3c5e854744d): Kernel DMA Protection to protect PCs against drive-by Direct Memory Access (DMA) attacks using PCI hot plug devices connected to Thunderbolt 3 ports. Drive-by DMA attacks can lead to disclosure of s... - [Accounts: UIAccess applications must not be allowed to prompt for](https://www.eventsentry.com/validationscripts/guid/80e6af5a-3633-408e-b890-8b7581adda66): User Account Control (UAC) is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting prevents User Interface Accessibility ... - [Remote Management: Windows Remote Management (WinRM) service must not](https://www.eventsentry.com/validationscripts/guid/4edbaac6-37f7-4a8f-a4d1-d5dd241d1c6d): Basic authentication uses plain-text passwords that could be used to compromise a system. Disabling Basic authentication will reduce this potential. - [Accounts: The computer account password must not be prevented from](https://www.eventsentry.com/validationscripts/guid/e0059e71-73e6-4c05-9f59-b224041025ea): Computer account passwords are changed automatically on a regular basis. Disabling automatic password changes can make the system more vulnerable to malicious access. Frequent password changes can b... - [Privacy: Windows location services should be disabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/902983b9-3aed-423a-971d-7c69668df490): The location service on systems may allow sensitive data to be used by applications on the system. This should be turned off unless explicitly allowed for approved systems/applications. Wherever you... - [Remote Desktop Services: Must be configured with the client | EventSentry](https://www.eventsentry.com/validationscripts/guid/0cf4a80a-705e-4831-9e1d-bc91c93e4625): Remote connections must be encrypted to prevent interception of data or sensitive information. Selecting "High Level" will ensure encryption of Remote Desktop Services sessions in both directions. - [Windows OS: Windows Activation Status | EventSentry](https://www.eventsentry.com/validationscripts/guid/de96957d-bcf1-4d41-be46-aa14b00135f3): Why Windows Activation Matters: Security Updates: Many compliance frameworks require systems to be patched and updated in a timely manner. If Windows is not activated, it may not receive security pa... - [Windows OS: Build Version Check (OS Updated) | EventSentry](https://www.eventsentry.com/validationscripts/guid/c7b058ab-6360-4b5d-9cd2-45eafef8c489): It is critical to install security updates and maintain the latest OS Build and Build Revision (Build SubVersion/Patch Level) to protect your computer from malicious attacks. - [Logon: Required legal notice must be configured to display before](https://www.eventsentry.com/validationscripts/guid/80422550-1cbd-4710-adcc-957dec2da87d): Failure to display the logon banner prior to a logon attempt will negate legal proceedings resulting from unauthorized access to system resources. - [General: The Microsoft Defender SmartScreen for Explorer must be](https://www.eventsentry.com/validationscripts/guid/4d189e65-af8b-463f-95d1-3880b7c459ec): Windows Defender SmartScreen helps protect systems from programs downloaded from the internet that may be malicious. Enabling SmartScreen can block potentially malicious programs or warn users. - [Windows Installer: Users must be notified if a web-based program](https://www.eventsentry.com/validationscripts/guid/1a13721a-4304-4286-a89d-243a4f41f192): Web-based programs may attempt to install malicious software on a system. Ensuring users are notified if a web-based program attempts to install software allows them to refuse the installation. - [Remote Desktop Services: Must be configured to set a time limit for](https://www.eventsentry.com/validationscripts/guid/d47a831c-3a18-43bd-996d-12c3002cd98e): This setting controls how long a session will remain connected if it is unexpectedly terminated. Such sessions use system resources and pose a security risk. Disconnected sessions should be terminat... - [Autoplay: Must be turned off for non-volume devices | EventSentry](https://www.eventsentry.com/validationscripts/guid/d2ac90ea-b1de-49bb-aa59-fe8b271c7c2b): Allowing autoplay to execute may introduce malicious code to a system. Autoplay begins reading from a drive as soon as you insert media in the drive. As a result, the setup file of programs or music... - [Network Access: Session security for NTLM SSP-based CLIENTS must](https://www.eventsentry.com/validationscripts/guid/0316290c-8617-4662-b2a6-637e043717a8): Network Access: session security for NTLM SSP-based clients must be configured to require NTLMv2 session security and 128-bit encryption Microsoft has implemented a variety of security support provi... - [Threat Intel: Attack Vector: Vulnerable Fan Driver (WinRing0x64 sys)](https://www.eventsentry.com/validationscripts/guid/8d1e0d7a-165c-4ba4-bc06-59a8fc8ea705): A vulnerability, which was classified as critical, has been found in TechPowerUp Ryzen DRAM Calculator 1.2.0.5. This issue affects some unknown processing in the library WinRing0x64.sys. The manipul... - [Remote Management: Unauthenticated RPC clients must be restricted](https://www.eventsentry.com/validationscripts/guid/56db7e62-0a85-4531-9e71-97528bd04e43): Unauthenticated RPC clients may allow anonymous access to sensitive information. Configuring RPC to restrict unauthenticated RPC clients from connecting to the RPC server will prevent anonymous conn... - [Remote Management: Windows Remote Management (WinRM) service must not](https://www.eventsentry.com/validationscripts/guid/84308839-5335-424f-bd4b-79b1c463e4d6): Storage of administrative credentials could allow unauthorized access. Disallowing the storage of RunAs credentials for Windows Remote Management will prevent them from being used with plug-ins. Sat... - [Windows OS: Must not have the Peer Name Resolution Protocol installed](https://www.eventsentry.com/validationscripts/guid/58ca06da-2c01-47dc-8d37-ff0afe984eed): Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption or may provide unauthorized access to the system. - [Remote Desktop Services: Must always prompt a client for passwords](https://www.eventsentry.com/validationscripts/guid/8cbb9955-eb5c-4bcf-9352-3bbc31f7ed71): This setting controls the ability of users to supply passwords automatically as part of their remote desktop connection. Disabling this setting would allow anyone to use the stored credentials in a ... - [Accounts: must be configured to enable Remote host allows delegation](https://www.eventsentry.com/validationscripts/guid/64e32afe-9577-4372-8f00-81829fd38ebf): An exportable version of credentials is provided to remote hosts when using credential delegation which exposes them to theft on the remote host. Restricted Admin mode or Remote Credential Guard all... - [General: Windows firewall status | EventSentry](https://www.eventsentry.com/validationscripts/guid/1f229f09-4c15-4bfe-b9f7-ed63d03cd70e): This script will check if the firewall is on. It's a best practice to have the firewall ON and required for most compliance requirements including PCI-DSS, ISO 27001, NIST, SANS, NERC-CIP and others. - [Microsoft Office: Application Guard for Office should be enabled](https://www.eventsentry.com/validationscripts/guid/b4297f3f-27aa-48bb-ae0c-a996d8db5b70): It is best practice and highly recommended to enable Application Guard for Office. This feature is available on Windows 10 2004 (20H1) build 19041 or later. Microsoft Defender Application Guard for ... - [Accounts: Block Microsoft accounts | EventSentry](https://www.eventsentry.com/validationscripts/guid/6e815a39-7aa8-42e4-88d3-1778dfe85333): Although Microsoft accounts are password-protected, they also have the potential of greater exposure outside of the enterprise. Additionally, if the owner of a Microsoft account is not easily distin... - [Remote Desktop Services: Must not save passwords in the Remote](https://www.eventsentry.com/validationscripts/guid/bfb98113-cc94-400b-a385-af36657755f6): Saving passwords in the Remote Desktop Client could allow an unauthorized user to establish a remote desktop session to another system. The system must be configured to prevent users from saving pas... - [Windows Installer: Disable -Always install with elevated privileges-](https://www.eventsentry.com/validationscripts/guid/a6d113ff-fd83-4631-84b3-f58e266b4976): Standard user accounts must not be granted elevated privileges. Enabling Windows Installer to elevate privileges when installing applications can allow malicious persons and applications to gain ful... - [Windows OS: Must not have the TFTP Client Installed | EventSentry](https://www.eventsentry.com/validationscripts/guid/a5eca000-8a44-410e-ab8d-9f7eeae34216): Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption or may provide unauthorized access to the system. - [Accounts: User Account Control (UAC) must run all administrators in](https://www.eventsentry.com/validationscripts/guid/417239de-2859-45e4-9a8f-43c47f4daedb): UAC is a security mechanism for limiting the elevation of privileges, including administrative accounts, unless authorized. This setting enables UAC. Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-0003... - [Autorun: behavior must be configured to prevent Autorun commands](https://www.eventsentry.com/validationscripts/guid/746184bf-3f96-4365-8bb4-c7abf8a772ac): Allowing AutoRun commands to execute may introduce malicious code to a system. Configuring this setting prevents AutoRun commands from executing. - [Auditing: Event Log size for Application log must be at least 32768](https://www.eventsentry.com/validationscripts/guid/b38cea25-93f2-42d7-ac5f-f2c1e93f974a): Inadequate log size will cause the log to fill up quickly. This may prevent audit events from being recorded properly and require frequent attention by administrative personnel. - [File System: File Explorer shell protocol must run in protected mode](https://www.eventsentry.com/validationscripts/guid/d7438fe1-eecf-411c-b855-1a03847ac2d7): The shell protocol will limit the set of folders that applications can open when run in protected mode. Restricting files an application can open to a limited set of folders increases the security o... - [General: Internet Information System (IIS) or its subcomponents must](https://www.eventsentry.com/validationscripts/guid/06778df5-6411-408f-9ea9-6637a3f5aab2): Installation of Internet Information System (IIS) may allow unauthorized internet services to be hosted. Websites must only be hosted on servers that have been designed for that purpose and can be a... - [Network Access: Services using Local System when reverting to NTLM](https://www.eventsentry.com/validationscripts/guid/0b49395c-beb5-480b-a1b8-1096622607a1): Network Access: Services using Local System that use Negotiate when reverting to NTLM authentication must use the computer identity instead of authenticating anonymously Services using Local System ... - [Security: Systems must have UEFI firmware and be configured to run in](https://www.eventsentry.com/validationscripts/guid/e0fcf99c-99e4-44e1-ba65-7799bb95df91): UEFI provides additional security features in comparison to legacy BIOS firmware, including Secure Boot. UEFI is required to support additional security features in Windows 11, including virtualizat... - [Network Access: Restrict anonymous access to Named Pipes and Shares](https://www.eventsentry.com/validationscripts/guid/e7aa340c-ec27-4603-b780-851d94a0ecbf): Allowing anonymous access to named pipes or shares provides the potential for unauthorized system access. This setting restricts access to those defined in "Network access: Named Pipes that can be a... - [Auditing: Event Log size for System log must be at least 32768 KB](https://www.eventsentry.com/validationscripts/guid/4decda12-e17d-45d8-bb5e-53f26706acbf): Inadequate log size will cause the log to fill up quickly. This may prevent audit events from being recorded properly and require frequent attention by administrative personnel. - [Network Access: Insecure logons to an SMB server must be disabled](https://www.eventsentry.com/validationscripts/guid/5b92eab1-8909-4598-8e4c-61eeb308c9f9): Insecure guest logons allow unauthenticated access to shared folders. Shared resources on a system must require authentication to establish proper access. - [Auditing: Event Log size for Security log must be at least 196608 KB](https://www.eventsentry.com/validationscripts/guid/f9befa07-2636-4c53-a43f-db2035b9cdff): Inadequate log size will cause the log to fill up quickly. This may prevent audit events from being recorded properly and require frequent attention by administrative personnel. - [Domain Member: Digitally encrypt or sign secure channel data (always)](https://www.eventsentry.com/validationscripts/guid/8d6589f4-20fe-4018-bc26-7891353eac40): Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted, but not all information is encrypted. If this policy is enabled, outgoing secure ch... - [Remote Management: Windows Remote Management (WinRM) service must not](https://www.eventsentry.com/validationscripts/guid/39413247-a65e-4c0f-ad88-481cc82b1610): Unencrypted remote access to a system can allow sensitive information to be compromised. Windows remote management connections must be encrypted to prevent this. Satisfies: SRG-OS-000393-GPOS-00173,... - [File System: Back up files and directories user right must only be](https://www.eventsentry.com/validationscripts/guid/abefa69d-079c-4110-bd76-c91be82174c7): Inappropriate granting of user rights can provide system, administrative, and other high level capabilities. Accounts with the "Back up files and directories" user right can circumvent file and dire... - [Threat Intel: Attack Vector: Windows downgrade attacks | EventSentry](https://www.eventsentry.com/validationscripts/guid/87e9a8db-ba56-4e89-829f-ecc5fc01f848): Attackers can downgrade Windows kernel components to bypass security features such as Driver Signature Enforcement and deploy rootkits on fully patched systems. This is possible by taking control of... - [Internet Browser: Attachments must be prevented from being downloaded](https://www.eventsentry.com/validationscripts/guid/5ba4fbad-193e-4b62-8326-4bd0705112bd): Attachments from RSS feeds may not be secure. This setting will prevent attachments from being downloaded from RSS feeds. - [Network Access: Must be configured to prevent anonymous users from](https://www.eventsentry.com/validationscripts/guid/35f2c214-8c49-47cf-b324-9f7620f8dd16): Access by anonymous users must be restricted. If this setting is enabled, anonymous users have the same rights and permissions as the built-in Everyone group. Anonymous users must not have these per... - [File System: Windows must prevent Indexing of encrypted files](https://www.eventsentry.com/validationscripts/guid/138956a4-8987-4f7f-b830-bf58e4ca7778): Indexing of encrypted files may expose sensitive data. This setting prevents encrypted files from being indexed. - [Remote Management: Windows Remote Management (WinRM) client must not](https://www.eventsentry.com/validationscripts/guid/0ccb829b-b4e0-45eb-9ba8-82a643949d74): Unencrypted remote access to a system can allow sensitive information to be compromised. Windows remote management connections must be encrypted to prevent this. - [Accounts: Reversible password encryption must be disabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/71ebd815-0ca9-44c9-b7b8-c96e155e7afb): Storing passwords using reversible encryption is essentially the same as storing clear-text versions of the passwords, which are easily compromised. For this reason, this policy must never be enabled. - [Security Hardening: Sound Recorder should be disabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/99f1c794-245e-4fc0-b878-6fe712bfc248): Sound Recorder is a feature of Microsoft Windows that allows audio from a device with a microphone to be recorded and saved as an audio file on the local hard drive. Malicious actors with remote acc... - [Logon: Network selection UI must not be displayed | EventSentry](https://www.eventsentry.com/validationscripts/guid/3476077b-5d03-4819-9ef0-213402f37eed): Enabling interaction with the network selection UI allows users to change connections to available networks without signing into Windows. There are several attacks based on this. - [Microsoft Edge: Windows 10 must be configured to prevent certificate](https://www.eventsentry.com/validationscripts/guid/0d7e861b-915f-42c7-ade4-1bef056aac90): Web security certificates provide an indication whether a site is legitimate. This policy setting prevents the user from ignoring Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate ... - [Domain Member: Digitally encrypt secure channel data (when possible)](https://www.eventsentry.com/validationscripts/guid/9a6ea78e-a170-4015-9193-666f003f74f4): Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted, but not all information is encrypted. If this policy is enabled, outgoing secure ch... - [Network Access: Session security for NTLM SSP-based SERVERS must](https://www.eventsentry.com/validationscripts/guid/53cdfc2e-4826-4d65-89d1-454fbdd6aa8c): Microsoft has implemented a variety of security support providers for use with Remote Procedure Call (RPC) sessions. All of the options must be enabled to ensure the maximum security level. - [Domain Member: Digitally sign secure channel data (when possible)](https://www.eventsentry.com/validationscripts/guid/5ef4fc08-d231-41c5-95c2-1bb8abc26209): Requests sent on the secure channel are authenticated, and sensitive information (such as passwords) is encrypted, but the channel is not integrity checked. If this policy is enabled, outgoing secur... - [Internet Browser: Software must be disallowed to run or install with](https://www.eventsentry.com/validationscripts/guid/7732d84e-90be-4734-bae5-e3c6d3be7568): It's best practice to configure Internet Explorer to enforce the verification of signatures for downloaded files, and to disallow running or installing files when an invalid signature is detected. T... - [Microsoft Edge: Users must not be allowed to ignore SmartScreen](https://www.eventsentry.com/validationscripts/guid/cc4e8e33-1af6-4c11-b010-2d102e48a767): The Windows Defender SmartScreen filter in Microsoft Edge provides warning messages and blocks potentially malicious websites. This only applies to Windows 10 OS, others OS versions will be marked a... - [Windows Installer: Must prevent users from changing installation](https://www.eventsentry.com/validationscripts/guid/938832a1-8ded-48d6-99b6-2b783cd2d3ae): Installation options for applications are typically controlled by administrators. This setting prevents users from changing installation options that may bypass security features. - [Threat Intel: PetitPotam Certificate Enrollment Web Service on Domain](https://www.eventsentry.com/validationscripts/guid/e1e6e9f0-1825-4f22-ab9a-f1a238843c01): PetitPotam abuses the Encrypting File System (MS-EFSRPC) protocol, which is designed for performing maintenance and management operations on encrypted data that is stored remotely and accessed over ... - [Windows OS: Must have the DoD Root Certificate Authority (CA)](https://www.eventsentry.com/validationscripts/guid/d070ac89-35b5-44c1-a417-154e3d8e35be): To ensure secure DoD websites and DoD-signed code are properly validated, the system must trust the DoD Root CAs. The DoD root certificates will ensure that the trust chain is established for server... - [Domain Member Health: Check the domain join health | EventSentry](https://www.eventsentry.com/validationscripts/guid/1dfd8950-7d31-4fd1-84ab-f3ecc3c95f00): This script checks the domain join health of the host. It will exit with an error if the machine's domain trust is not healthy. Note: The script will also fail if no domain controller is available a... - [Network Access: Must prevent NTLM from falling back to a Null session](https://www.eventsentry.com/validationscripts/guid/793452ad-d37f-461b-a270-cc4e0ea1c2a5): NTLM sessions that are allowed to fall back to Null (unauthenticated) sessions may gain unauthorized access. - [Compliance: BitLocker should use AES 256 encryption | EventSentry](https://www.eventsentry.com/validationscripts/guid/77de846e-473b-4c4d-8d70-85d27342fc45): Some compliance requirements may require that AES 256-bit encryption is used for BitLocker. - [Domain Member: Local users on domain-joined member servers must not](https://www.eventsentry.com/validationscripts/guid/a115da09-58b1-40dd-85ca-6f6e4cac977d): The username is one part of logon credentials that could be used to gain access to a system. Preventing the enumeration of users limits this information to authorized personnel. - [Printing: Prevent users from installing printer drivers | EventSentry](https://www.eventsentry.com/validationscripts/guid/889cec97-07a1-4c83-b5cb-c4d92203aa17): It may be appropriate in some organizations to allow users to install printer drivers on their own workstations. On servers however only administrators should be allowed install printer drivers as t... - [Domain Controller: Must be configured to allow reset of machine](https://www.eventsentry.com/validationscripts/guid/4d599278-5660-4513-abe4-715f546475bb): Enabling this setting on all domain controllers in a domain prevents domain members from changing their computer account passwords. If these passwords are weak or compromised, the inability to chang... - [Microsoft Edge: The Windows Defender SmartScreen filter for Microsoft](https://www.eventsentry.com/validationscripts/guid/7a337b09-3a6f-4270-8611-005b2a71cba4): The "Windows Defender SmartScreen Filter" in Microsoft Edge provides warning messages and blocks potentially malicious websites. This only applies to Windows 10 OS, others OS versions will be marked... - [Threat Intel: Log4j Remote Code Execution - | EventSentry](https://www.eventsentry.com/validationscripts/guid/a01ac7ca-b4f4-44e2-badd-dd7eb11e765d): In Apache Log4j2 versions up to and including 2.14.1 (excluding security release 2.12.2), the JNDI features used in configurations, log messages, and parameters do not protect against attacker-contr... - [Windows OS: Secure Boot must be enabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/e8bb4b60-e081-427e-924e-e99a1aacf387): Secure Boot is a standard that ensures systems boot only to a trusted operating system. Secure Boot is required to support additional security features in Windows, including Virtualization Based Sec... - [Internet Browser: Checking for signatures on downloaded programs must](https://www.eventsentry.com/validationscripts/guid/f09f451c-2ec0-4a03-b578-637db9c8ffbf): It's best practice that Internet Explorer is configured to verify the signature of downloaded executables. This identifies the publisher of signed software and verifies it hasn't been modified or ta... - [Remote Desktop Services: Must prevent drive redirection | EventSentry](https://www.eventsentry.com/validationscripts/guid/f412c653-14b4-4829-8fd8-0263d996cf04): Preventing users from sharing the local drives on their client computers with Remote Session Hosts that they access helps reduce possible exposure of sensitive data - [Logon: Enable Display Last Logon Info | EventSentry](https://www.eventsentry.com/validationscripts/guid/a108b75a-f851-4e02-b377-1bc6a2698949): Checks whether the "Display Last Logon" option, which shows a user the last time his/her account was used to log interactively, is enabled. It's best practive and recommend to enable this option on ... - [Privacy: The location feature must be turned off | EventSentry](https://www.eventsentry.com/validationscripts/guid/b5e9fae5-f161-4c39-a915-7282a3896dd9): The location service on systems may allow sensitive data to be used by applications on the system. This should be turned off unless explicitly allowed for approved systems/applications. - [Domain Controller: Health - DCDiag - Warnings and Errors | EventSentry](https://www.eventsentry.com/validationscripts/guid/076772fc-6412-430e-97ee-c4a7c0028bc1): This script will run and end in error if DCDiag reports warnings or errors. As an end-user reporting program, dcdiag is a command-line tool that encapsulates detailed knowledge of how to identify ab... - [Virtualization: Hyper-V: Virtual Disks Folder Free Space Under 2GB](https://www.eventsentry.com/validationscripts/guid/58be460d-237f-404f-a74c-14defec187f3): Free space less than 2GB on Virtual Disk Folder is considered a warning. To avoid data loss on Hyper-V Server, free disk space should be greater than 2GB. https://docs.microsoft.com/en-us/previous-v... - [Threat Intel: Attack Vector: Disable WinRM (Windows Remote | EventSentry](https://www.eventsentry.com/validationscripts/guid/1c1e3c39-98a3-41cb-8bf1-1a5f36a6c950): There are known vulnerabilities based on WinRM and it's best practice to disable WinRM. https://attack.mitre.org/techniques/T1028/ - [Virtualization: VirtualBox Tools Installed | EventSentry](https://www.eventsentry.com/validationscripts/guid/df6218d9-2dbe-46c6-afb7-406a7382abb3): Guest Additions are designed to be installed inside a virtual machine after the guest operating system has been installed. They consist of device drivers and system applications that optimize the gu... - [Services: List services containing a space in service path not](https://www.eventsentry.com/validationscripts/guid/ac341c51-3c29-4437-92a5-9b1e8506b2c8): In some scenarios spaces in services can allow a malicious person to execute programs under that service user level:. - [Virtualization: VMWare Tools Installed | EventSentry](https://www.eventsentry.com/validationscripts/guid/dfaf90e7-3d8b-4676-9473-4ed2bea0f5e5): VMware Tools is a set of services and modules that enable several features in VMware products for better management of, and seamless user interactions with, guest operating systems. This validation ... - [Threat Intel: Attack Vector: Disable LLMNR | EventSentry](https://www.eventsentry.com/validationscripts/guid/3724e477-bdea-4a74-96b7-7ac79e157087): There are known vulnerabilities based on LLMNR. https://attack.mitre.org/techniques/T1171/ https://nvd.nist.gov/vuln/detail/CVE-2011-0657 - [Exchange Server: Build Version Check (Exchange Updated) | EventSentry](https://www.eventsentry.com/validationscripts/guid/7772c56a-ec1f-43d5-b8ce-548359123060): It is critical to install security updates and maintain the latest Microsoft Exchange Server Build Version to protect your server from malicious attacks. - [Microsoft Office: Check Activation Status | EventSentry](https://www.eventsentry.com/validationscripts/guid/3fc47ab6-4ea2-43cb-9221-5e8c258dd59b): This script will search for office installation and will check their respective activation status. This check supports office versions: 2007, 2010, 2013, 2016, 2019, 2024 and Office 365. - [Info: Check Windows 11 Upgrade Readiness | EventSentry](https://www.eventsentry.com/validationscripts/guid/12613046-99bc-4bb7-acac-57456094bba1): Check if the computer is capable to run Windows 11 - [Health: Directory Size: WinSxs\Temp\PendingDeletes | EventSentry](https://www.eventsentry.com/validationscripts/guid/233b6308-be50-487f-ad61-dec44a3d4402): The PendingDeletes directory can occupy a significant amount of disk space which can easily be freed up. - [Domain Controller: IPv6 Should be enabled | EventSentry](https://www.eventsentry.com/validationscripts/guid/d07a9025-c87c-48ce-af0c-c3ced03c01e8): IPv6 should be enabled https://gallery.technet.microsoft.com/Disable-IPV6-Domain-69c4ef31