Americas

  • United States

Getting baseline records established with Tripwire 7

Opinion
Apr 29, 20082 mins
Data CenterSecurityServers

We installed Tripwire 7 and have deployed the software agents to the systems we want to monitor, but are having trouble getting our baseline records established. We created nodes for each of our Windows servers and set up the Active Directory monitoring rules we want the system to use for monitoring directory service operations. For some reason the baseline operation runs very briefly and does not create a baseline record or provide any error messages to guide our troubleshooting. Any ideas?

It sounds like you are trying to apply Active Directory Rules to Windows Server Nodes.

There are multiple types of Node definitions in Tripwire and each Node type can be the target for matching types of monitoring rules. In short, Active Directory Rules can only be applied to Active Directory Nodes. Take a look at the Nodes view in the Tripwire console and determine whether the Node Type is listed as Windows Server or Directory Server. You may need to create another set of entries for the systems as Active Directory server nodes in addition to an existing set of Windows Server nodes. When you select a Node in the Nodes view and activate the Baseline action you should be presented with a dialog from which to select the Rules that will be applied to the Node for creating the Baseline. To monitor server operating system elements and Active Directory elements on the same physical system you will need Node definitions of type Windows Server for monitoring the operating system and associated Windows File System and/or Windows Registry Rules along with Active Directory Node definitions and Active Directory Rules.