Jump to Main Content

AuditLogin 3.2 monitors and logs licensed login/logout activity on one or more file servers on your network. It was written to address deficiencies in Netware 4/5 auditing, which is somewhat cumbersome and aggravating, especially when it comes time to retrieve and manipulate the data. Also, many find Novell's auditing to be too difficult just to setup and maintain. So, AuditLogin writes simple text-based log files that may be searched and manipulated using standard utilities and database analysis programs.

Key Benefits

  • Audits all objects in tree in a single operation - no configuring multiple containers.
  • Logs are automatically cleaned up based on user parameters. Logs never "fill up".
  • Logs from all servers are consolidated into a single set of comprehensive files.
  • Log files are simple text files that can be easily searched or imported into other programs for trends analysis.
  • 5 minute installation.
  • Self-Maintaining based on user options.
  • Multiple log formats supported.
  • Remote server configuration from Windows workstation.

Components

AuditLogin consists of 3 main components:

AuditLogin Consolidator

AuditLogin Administrator

The consolidator (CONSLDAT.NLM) provides 2 main functions:

1. Receives auditing records via secured NCP transactions from systems running the System Monitoring NLM. These records are written to a file of the form YYYYMMDD.001 where YYYYMMDD is the year, month, and day that the transaction actually occurred. A single file is used for store data for an entire day. The NLM will periodically sort the data in these files based on a schedule set by the administrator. When the log file is sorted, it is renamed so that the extension is "000". Old logs are automatically purged based on criteria set by the administrator.

2. Services parameter read requests via secured NCP transactions to the Administrator and the System Monitoring NLMs. The consolidator performs several other housekeeping functions as well as keeping a running total of logging information for all servers.

AuditLogin System Monitoring

AuditLogin System Monitoring

The system monitoring component (AUDITLGN.NLM) is the heart and soul of the system. It hooks login and logout system events and constantly monitors the connection table of the server it is running on. It maintains an unlicensed connection to the server running the consolidation server. When an event occurs on the server, the transaction is immediately sent to the consolidator via a secured NCP transaction. If for some reason the consolidator server is unreachable, the data will be stored locally until the consolidator is functioning again. At that time all locally stored data will be sent to the consolidator.

AuditLogin Administrator

AuditLogin Consolidator

The administrator is used to configure all AuditLogin parameters and install and maintain the System Monitoring NLM on remote servers. For more information, see the Configuration topic. 

Platforms

NetWare Versions

AuditLogin Version 3 is supported on the following Novell NetWare platforms:

• NetWare 4.10 with the latest patches will probably work but has not been tested.

• NetWare 4.11 support pack 6A and later

• NetWare 4.2  support pack 6A and later

• NetWare 5.0 support pack 4A and later

• NetWare 5.1 base and later

• NetWare 6.0 base and later

• NetWare 6.5 support pack 2 and later

NDS eDirectory Versions

AuditLogin Version 3.2 is supported with any version of NDS that is currently supported by Novell and shipped with the above NetWare service packs. AuditLogin has been tested with versions 4, 5, 6, 7, 8, 8.5, 8.6 and 8.7 of NDS/eDirectory.

NetWare Protocols

AuditLogin Version 3 is supported in the following NetWare communication environments:

• IPX only

• IP only

• Mixed IP and IPX 

Windows Versions

The Administrator Win32 application is supported on the following versions of Microsoft Windows:

• Windows 2000 service pack 4 or later.

• Windows 2003 service pack 1 or later.

• Windows XP service pack 1 or later.