Data Vault
The Data Vault is a software component that installs as a Windows service on a network server. The purpose of the Data Vault is to provide a central repository for all recorded events from every Spector Client (Client) computer.
As an alternative, Spector CNE can be configured so that each Client computer stores the recorded events locally on its hard drive and retains them on that computer only to be deleted according to the Client configuration. In this scenario, the data files would be accessed remotely over the network using a file share.
Note: This configuration does not provide for security,
backup, or off-line access to the recorded events of the individual Client
computers. It is not recommended unless you are working in a small network
or you only have need to review the most recent activity of the computers
and you are not interested in archiving or off-line access.
The Data Vault service runs continually, receiving
recorded events from each Client computer and storing those events in
a Windows folder.
The Data Vault storage folder contains a subfolder for each computer from which it received recorded events
The subfolder has the same computer name of the computer
The recorded events for
each Client are stored as files within the subfolder, corresponding to
the computer name
of the computer on which the events were recorded
The data files are in a proprietary format that includes compression and encryption. They cannot be read without the Spector Viewer
There will be a single data file for each Client that contains all of the Keystroke, Web site, Program, Email, P2P, and Chat/IM events for a specific day
There may be multiple data files for each Client containing the Snapshot events for a given day
The date and timestamp on the files can be used to facilitate the archiving of the data files from the Data Vault folders
The Data Vault can
be configured to automatically delete data files that have aged or it
can be configured to keep the data files indefinitely, which allows the
backup and archive procedure to control the deletion of data files. This
process increases the storage room on the Data Vault server
Security to the Data Vault
is controlled through the file permissions of the Data Vault folders.
By default, the Spector CNE administrator has full access to the Data
Vault folders in order to store the recorded events being received from
the Client computers. Additional permissions to the Data Vault folders
would need to be added for non-Spector CNE administrators to view the
recorded events
Additional security can
be enabled by configuring the Data Vault to have a Data File Password.
If a Data File Password is configured, this password is used by the Data
Vault to encrypt the recorded events and the password will be requested
and its entry required each time the recorded events for a Client is accessed.
The Data File Password is stored as part of each data file
|
|
Multiple Data Vaults
In larger Spector CNE installations, it may be necessary to scale the Spector CNE installation to use multiple instances of the Data Vault on additional servers. This will only be necessary if the Data Vault service receiving the recorded events from the installed Clients is unable to handle the volume of traffic being archived. This should only become an issue when you start configuring hundreds of Client computers. If the server hosting the Data Vault is unable to support the volume of recorded events received from the computers, an additional Data Vault server can be configured to receive the recorded events.
|
|
Verify Service is Running
To verify that the Data Vault service is running,
you should see the red lock icon in the System Tray of
the server on which the Data Vault is installed. Selecting this icon will
verify the configuration settings and provide access to the log file for
this service. Use the Control Center to modify the Data Vault configuration
by selecting Properties and then
the Data Vault tab.