Go Up
You are here: DeploymentPrerequisites and System RequirementsSupported Data Sources

Supported Data Sources

The table below lists systems that can be monitored with Netwrix Auditor:

Data source Supported Versions

Active Directory

(including Group Policy and Logon Activity; stand-alone Inactive User Tracker, Password Expiration Notifier, and Netwrix Auditor Object Restore for Active Directory)

Domain Controller OS versions:

  • Windows Server 2019
  • Windows Server 2016
  • Windows Server 2012/2012 R2
  • Windows Server 2008/2008 R2

Active Directory Federation Services

  • AD FS 5.0 - Windows Server 2019
  • AD FS 4.0 - Windows Server 2016
  • AD FS 3.0 - Windows Server 2012 R2

Azure AD

Azure Active Directory version provided within Microsoft Office 365

NOTE: Netwrix Auditor collects data through Office 365 APIs. In order to access these APIs, you should have an Office 365 business account with global administrator privileges associated with one of suitable Office 365 plans (e.g., Office 365 Enterprise E1). See Assigning a Privileged Role for Azure AD and Office 365 for more information.

Exchange

  • Microsoft Exchange Server 2019
  • Microsoft Exchange Server 2016
  • Microsoft Exchange Server 2013
  • Microsoft Exchange Server 2010 SP1 and above

Exchange Online

Exchange Online version provided within Microsoft Office 365

Windows File Servers

  • Windows Server OS:
    • Windows Server 2019
    • Windows Server 2016
    • Windows Server 2012/2012 R2
    • Windows Server 2008/2008 R2
  • Windows Desktop OS (32 and 64-bit):
    • Windows 10
    • Windows 8.1
    • Windows 7

NOTE: To collect data from 32-bit operating systems, network traffic compression must be disabled.

To collect data from Windows Failover Cluster, network traffic compression must be enabled.

Scale-Out File Server (SOFS) cluster is not supported.

See File Servers for more information.

Dell EMC

  • Dell EMC Unity (Unity XT, UnityVSA) running any of the following operating environment (OE) versions:

    • 5.0.x
    • 4.5.x
    • 4.4.x
  • Dell EMC VNX/VNXe/Celerra families
  • Dell EMC Isilon:
    • 9.0.0.0
    • 8.2.x
    • 8.1.0.0
    • 8.0.0.0
    • 7.2.1.0 – 7.2.1.2
    • 7.2.0.0 – 7.2.0.4

NOTE: Only CIFS configuration is supported.

For Dell EMC Isilon, auditing of System zone is not supported. As stated by Dell, this zone should be reserved for configuration access only. Current data should be stored in other access zones. See this guide for more information.

NetApp

  • NetApp ONTAP 9.0 – 9.7
  • NetApp Clustered Data ONTAP 8.2.1 – 8.2.3, 8.3, 8.3.1, 8.3.2

NOTE: For NetApp storage systems, only CIFS configuration is supported.

Nutanix Files

  • Nutanix Files 3.6

Network Devices

Cisco devices

  • Cisco ASA (Adaptive Security Appliance) 8 and above
  • Cisco IOS (Internetwork Operating System) 12 and 15
  • Cisco Meraki: Netwrix recommends using the latest version of the Meraki Dashboard

Fortinet Fortigate

  • FortiOS 5.6 and above

SonicWall

  • SonicWall WAF 2.0.0.x / SMA v9.x & v10.x
  • SonicWall NS 6.5.х.х with SonicOS 6.5.х
  • SonicWall SMA 12.2

Juniper Networks

  • vSRX with Junos OS 12.1, Junos OS 18.1
  • vMX with Junos OS 17.1

Palo Alto

  • Palo Alto with PAN-OS 7.0, 8.0, 9.0

Pulse Secure

  • Pulse Connect Secure 9.1R3 and above

Aruba

  • Aruba OS 6.46.4.x – 8.6.0.x (Mobility Master, Mobility Controller)

Oracle Database

  • Oracle Database 19c On-Premise
  • Oracle Database 18c On-Premise
  • Oracle Database 12c On-Premise (12.1, 12.2)
  • Oracle Database 11g

    NOTE: Starting with version 9.96, Netwrix Auditor provides limited support of Oracle Database 11g. See Considerations for Oracle Database Auditing for more information.

  • Oracle Database Cloud Service (Enterprise Edition)

SharePoint

  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server 2016
  • Microsoft SharePoint Foundation 2013 and SharePoint Server 2013
  • Microsoft SharePoint Foundation 2010 and SharePoint Server 2010

SharePoint Online

SharePoint Online version provided within Microsoft Office 365

NOTE: Netwrix Auditor collects data through Office 365 APIs. In order to access these APIs, you should have an Office 365 business account with global administrator privileges associated with one of suitable Office 365 plans (e.g., Office 365 Enterprise E1). See Assigning a Privileged Role for Azure AD and Office 365 for more information.

SQL Server

  • Microsoft SQL Server 2019
  • Microsoft SQL Server 2017
  • Microsoft SQL Server 2016
  • Microsoft SQL Server 2014
  • Microsoft SQL Server 2012
  • Microsoft SQL Server 2008 R2
  • Microsoft SQL Server 2008

NOTE: Only stand-alone SQL Servers can be audited. Auditing of Always-On Availability groups is not supported.

Linux-based versions are not supported.

VMware

  • VMware ESX/ESXi: 6.0 – 6.7, 7.0
  • VMware vCenter Server: 6.0 – 6.7, 7.0

Event Log

  • Windows Server OS:
    • Windows Server 2019
    • Windows Server 2016
    • Windows Server 2012/2012 R2
    • Windows Server 2008/2008 R2
  • Windows Desktop OS (32 and 64-bit):
    • Windows 10
    • Windows 8.1
    • Windows 7

Windows Server

  • Windows Server OS:
    • Windows Server 2019
    • Windows Server 2016
    • Windows Server 2012/2012 R2
    • Windows Server 2008/2008 R2
  • Windows Desktop OS (32 and 64-bit):
    • Windows 10
    • Windows 8.1
    • Windows 7

DNS

Windows Server OS:

  • Windows Server 2019
  • Windows Server 2016
  • Windows Server 2012 R2
  • Windows Server 2012
  • Windows Server 2008 R2
  • Windows Server 2008 SP2 (32 and 64-bit)
DHCP

Windows Server OS:

  • Windows Server 2019
  • Windows Server 2016
  • Windows Server 2012 R2
  • Windows Server 2012
  • Windows Server 2008 R2

IIS

IIS 7.0 and above

User Activity

  • Windows Server OS:
    • Windows Server 2019
    • Windows Server 2016
    • Windows Server 2012/2012 R2
    • Windows Server 2008/2008 R2
  • Windows Desktop OS (32 and 64-bit):
    • Windows 10
    • Windows 8.1
    • Windows 7

Considerations for Oracle Database Auditing

Starting with version 9.95, Netwrix Auditor for Oracle Database is focused on versions 12c and above. It means that Oracle Database 11g users will not be able to benefit from latest features and improvements of the product. Oracle Database 11g users should also consider its support expiration dates set by the vendor. So, when planning your Netwrix Auditor deployment, consider the following:

  • Several limitations apply to Oracle 11g support in Netwrix Auditor 9.96:

    • Oracle wallets are not supported
    • Lightweight drivers for Oracle Instant Client are not supported
    • Netwrix Auditor client UI does not display any warnings and / or errors regarding to trail audit mode operation

  • If you are using Oracle Database 11g and Netwrix Auditor 9.9 (or earlier) and do not plan to upgrade your deployment, you will have all 9.9 capabilities unchanged.
  • If you are using Oracle Database 11g and have performed seamless upgrade to Newrix Auditor 9.96, the audit data collection will operate properly. However, consider General Considerations and Known Issues and keep in mind Oracle Database 11g support expiration dates.

If you are using Oracle Database 12c or later, make sure you have Unified auditing mode enabled. Otherwise, Netwrix Auditor may not operate properly. Refer to Migrate to Unified Audit

Check out the following documentation sections:

Technology Integrations

In addition to data sources monitored within product, Netwrix Auditor supports technology integrations leveraging Integration API. Download free add-ons from Netwrix Auditor Add-on Store to enrich your Netwrix Auditor audit trails with activity from the following systems and applications:

Integration Supported Versions

RADIUS server

  • Windows Server 2008/2008 R2
  • Windows Server 2012/2012 R2
  • Windows Server 2016

Amazon Web Services

Version currently provided by Amazon

Generic Linux Syslog

  • Red Hat Enterprise Linux 7 and 6
  • SUSE Linux Enterprise Server 12
  • openSUSE 42
  • Ubuntu 16
  • and others devices that support rsyslog messages
CyberArk Privileged Access Security Version 10.10.
Microsoft Hyper-V SCVMM Microsoft System Center Virtual Machine Manager 2019, 2016
Nutanix AHV Nutanix AOS 5.11

For more information about add-ons, refer to Add-Ons. Also, there are even more add-ons that can export data collected by Netwrix Auditor to other systems (e.g., ArcSight and ServiceNow).

Go Up