
NexLog Recorder User Manual v2.2.0
109
4.9.2. System Security
NexLog Recorder provides options to allow recorder administrators to fine tune
the recorder's security policies which are configured from the Security: System
Security NexLog page.
General
Audit Changes
: If this option is enabled, then any configuration changes made
via NexLog Configuration Manager, Front Panel, or the SOAP Service will result
in Audit event entries being placed in the audit history table. The audit history
can be viewed by visiting the Alerts and Logs: Audit History Setup page.
Audit Verbose
: To have an effect, this option requires "Audit Changes" to also
be enabled. If enabled, then the full SOAP/XML Configuration Change request
message will be stored along with the audit entries in the audit history table.
This information can be viewed by clicking on the audit event on the audit
history page.
Audit non-destructive events
: To have an effect, this option requires "Audit
Changes" to also be enabled. This causes audit history entries to be generated
not only for commands which alter the configuration state of the recorder, but
also those which simply view the state. With this option enabled you will be able
to audit any time a configuration entity such as a user record is viewed via
NexLog Configuration Manager or the SOAP Server (Access directly to the
onboard database via ODBC or MediaWorks/MediaAgent are exempt from
auditing). Normally this should be disabled unless for troubleshooting purposes
as a large amount of audit history will be generated; a simple "login and view a
few pages in NexLog Configuration Manager" session could generate dozens or
even hundreds of audit events.
Disable encrypted terminal
(ssh)
: The ssh terminal is only used by Eventide
support personnel to assist with diagnostics. Normally enabled, only disable this
if your organization’s security rules require it.
Authenticate users via SMB service
: Can connect to a CIF service that checks
authentication with Active Directory.
Front Panel
Front Panel Login Required
: If disabled, the Recorder's Front Panel will be
usable without first logging in. If enabled, users will need to supply login
credentials in order to view or use the Front Panel. Normally this would only be
disabled if the recorder is physically secured, for example by being in a locked
rack or in a locked room. The Front Panel auto-login user determines which
user account is automatically logged in if "Front Panel login required" is
disabled. When Front Panel Login requires is disabled, there is no way to log in
to the front panel as any user other than the auto-login user other than first
enabling Front Panel Login Required in setup.