Users, Advanced Configuration screen


The Advanced option on the Messages > Catalogs > Users screen provides access to various more advanced settings of the system related to User Name Auto-discovery, and the ability to add and delete users by list. The Users Advanced Configuration screen is depicted as follows:

image2019-3-22_13-34-27.png

The preceding screen contains advanced settings and controls, available only to administrators, that affect the processing and monitoring of the system user list. The various fields and controls are as follows:

  • Enable User Name Auto-Discovery—This select menu controls whether new user names are automatically added to the list of users based upon the User Name Discovery Match Specifications as follows. To stop the discovery of user names, set the value of this field to False.
  • Edit User Name Discovery Match Specifications—This option accesses the match specifications that specify the user name portion of received messages. When any message is received, these patterns check to see if a user name exists in the message. When a user name is detected, it is added to the system.
  • Exclude User Names Containing '$' Chars—This select menu allows the operator to exclude user names containing a '$' character. These user names are common on Windows systems, and indicate machine-to-machine logons, that are ignored by default.)
  • Exclude Windows DWM Names—This select menu allows the operator to exclude certain system user names, in particular, the DWM-N users associated with Windows 8 and later operating systems.
  • Require User Names to Be Three Or More Characters—This special select menu should usually be set to False, but can be set to True to permit organizations to support user names of two characters. (By default, the minimum number of characters in a user name is three characters, to support good site security.)
  • Drop Inactive Users—This setting indicates when a user name is automatically dropped from the list after a period of inactivity. This setting is useful for keeping the list of users current. (The operator might also delete user names manually, or using the Delete Users By List option, described as follows.)
  • Execution Debug Trace—This setting enables extra debug information to be logged to the system\CO-muslog-trace.log file, useful for debug and performance tuning. The default value is False.
  • Edit User Name Exclusion List—This option accesses the special User Name Exclusion List, that is a list of names that are never monitored. This setting can be used to eliminate those users or keywords from the list that are not interesting or are not actual user names. The system comes pre-configured with a list of keywords, and the operator adds to this list (as needed) using this option.
  • Edit Message Keyword Auto-Discovery Exclude List—This option allows the system to ignore certain types of messages, where a user name is never added. For instance, messages associated with a failed logon attempt are excluded to prevent the list from being filled with mistyped user names. The system comes pre-configured with a list of exclusions, and the operator will add to this list (as needed) using this option.
  • Import New Users By List—This option accesses a special screen that allows the operator to add user names using a list. The Import New User Name screen allows the operator to cut and paste a list of user name keywords into the system, where the list of keywords is automatically added to the system. This usually is not necessary, since user names are automatically added to the system (if the Enable Auto-Discovery setting on this screen is set to the default True value. 
  • Delete Users By List—This option accesses a special screen that allows the operator to delete user names using a list. The Delete User Name screen allows the operator to cut and paste a list of user name keywords into the system that is subsequently deleted. This is one of several ways to delete managed user names (another way to delete the user names manually is by deleting the associated catalog). Once a user name is deleted, it might be automatically added back to the system if it begins sending messages again, and if the user name is not excluded. 
  • Edit User Classes—This option accesses a special screen that permits the operator to classify user names. The values on the User Classes can be assigned to users using the User Information screen (accessed by clicking a user name hyperlink anywhere within the system). The user classes types are used in Audit reports and other locations and are useful in identifying and organizing managed users. The system comes with a limited number of generic user classes, that can be further refined using this screen.


 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

BMC Defender SIEM Correlation Server 6.2