Quest InTrust 9.5 - System Requirements

Last revised September 8, 2006

 

This document contains system requirements and minimal user rights necessary to install and run Quest InTrust 9.5 components.

Contents

Quest InTrust Manager
Quest InTrust Server
    Microsoft Windows Events
    Microsoft Exchange Server Events
    Microsoft IIS Events
    Microsoft ISA Server Events
    Microsoft Proxy Server Events
    Microsoft DHCP Server Events
    Sun Solaris Syslog and BSM Log
    Red Hat Enterprise Linux Syslog
    SUSE Linux Syslog
Quest InTrust Knowledge Portal
Quest InTrust Monitoring Console
Quest Repository Viewer

 

Reporting Web Portal
Reporting Web Part for Microsoft SharePoint Portal Server


Minimal Rights and Permissions Required for InTrust Operations

 

Quest InTrust Manager

PlatformIntel x86
Operating systemMicrosoft Windows 2000 Service Pack 3 or higher,
-OR-
Microsoft Windows XP Service Pack 1 or higher,
-OR-
Microsoft Windows Server 2003,
-OR-
Microsoft Windows Server 2003 R2
Additional Software Microsoft Internet Explorer 6.0 or higher

Windows Script Host 5.6 or higher
Microsoft Data Access Components 2.7 or higher

To create reports interactively using InTrust Knowledge Portal:

Note: For requirements on local or remote installation of Quest InTrust Knowledge Portal, refer to the Quest InTrust Knowledge Portal section below.

To work with OLAP cubes (legacy reporting):

 

Quest InTrust Server

PlatformIntel x86
Operating systemMicrosoft Windows 2000 Service Pack 4 with Update Rollup 1 or higher,
-OR-
Microsoft Windows XP Service Pack 1 or higher,
-OR-
Microsoft Windows Server 2003,
-OR-
Microsoft Windows Server 2003 R2
MemoryMin. 512Mbytes
Hard Disk SpaceMin. 4 Gbytes when installing all components
Additional Software Windows Script Host 5.6 or higher,
Microsoft Data Access Components 2.7 or higher

For the configuration, alert and audit databases:

For reporting jobs:

Notes:

* - a local or remote installation can be used. If you plan to use Microsoft IIS 6.0, make sure ASP extensions are allowed.

** - report creation capabilities are not supported in this version of Reporting Services, so it is recommended to use Microsoft SQL Server 2005 Reporting Services.

*** - a local or remote installation of Reporting Services can be used.

For requirements on local or remote installation of Quest InTrust Knowledge Portal, refer to the Quest InTrust Knowledge Portal section below.

For legacy reporting jobs:

To save reports in VSD format:

To publish reports:

To process OLAP cubes:

Notes:

 

Microsoft Windows Events

InTrust provides auditing and real-time monitoring facilities for the following logs in Windows event log format:

Server side:

Processed computer:

ArchitectureIntel x86; other architectures supported for certain operating systems are listed below
Operating systemMicrosoft Windows NT 4.0 Service Pack 6 or higher,
-OR-
Microsoft Windows 2000,
-OR-
Microsoft Windows XP Professional (32-bit, EMT64, and AMD-64 architectures)
-OR-
Microsoft Windows Server 2003 (32-bit, EMT64, AMD-64, and IA64 architectures),
-OR-
Microsoft Windows Server 2003 R2
Additional Software & Services
  • Remote Registry Service for data gathering without agents
  • Microsoft Windows Script Host 5.6 or higher for executing response action scripts,
  • ADSI 2.5 or higher for executing response action scripts

Rights and permissions for gathering without agents:

Rights and permissions for gathering with agents and real-time monitoring:

The following rights and permissions must be assigned to the InTrust agent account if the agent is not running under the LocalSystem account:

 

Note: For more information about job and task accounts, see the Creating Tasks and Jobs section in the InTrust 9.5 User Guide.

 

Microsoft Exchange Server Events

Server side:

Processed computer:

PlatformIntel x86
Operating systemMicrosoft Windows NT 4.0 Service Pack 6 or higher,
-OR-
Microsoft Windows 2000,
-OR-
Microsoft Windows Server 2003
Microsoft Exchange Server5.5 or higher
Additional Software & Services Remote Registry Service for data gathering without agents

Rights and permissions for gathering without agents:

Rights and permissions for gathering with agents:

The following rights and permissions must be assigned to the InTrust agent account if the agent is not running under the LocalSystem account:

 

Note: For more information about job and task accounts, see the Creating Tasks and Jobs section in the InTrust 9.5 User Guide.

 

Microsoft IIS events

Server side:

Processed computer:

PlatformIntel x86; EMT64, AMD-64, and IA-64 architectures
Operating systemMicrosoft Windows NT 4.0 Service Pack 6 or higher,
-OR-
Microsoft Windows 2000,
-OR-
Microsoft Windows XP Professional,
-OR-
Microsoft Windows Server 2003,
-OR-
Microsoft Windows Server 2003 R2
Microsoft Internet Information Services4.0 or higher
Additional Software & Services
  • Remote Registry Service for data gathering without agents,
    -OR-
    Microsoft IIS Administrative Components for data gathering with agents
  • Microsoft Windows Script Host 5.6 or higher for executing response action scripts

Notes:

Rights and permissions for data gathering without agents:

Rights and permissions for data gathering with agents:

The following rights and permissions must be assigned to the InTrust agent account if the agent is not running under the LocalSystem account:

Rights and permissions for real-time monitoring:

The InTrust agent account must have the following privilege if the agent is not running under the LocalSystem account:

 

Note: For more information about job and task accounts, see the Creating Tasks and Jobs section in the InTrust 9.5 User Guide.

 

Microsoft ISA Server Events

Server side:

Processed computer:

PlatformIntel x86
Operating systemMicrosoft Windows 2000,
-OR-
Microsoft Windows Server 2003,
-OR-
Microsoft Windows Server 2003 R2
Microsoft ISA Server2000, 2004
Additional Software & Services Remote Registry Service for data gathering without agents,
-OR-
Microsoft ISA Administrative Components for data gathering with agents

Rights and permissions for data gathering without agents:

Rights and permissions for data gathering with agents:

The following rights and permissions must be assigned to the InTrust agent account if the agent is not running under the LocalSystem account:

 

Note: For more information about job and task accounts, see the Creating Tasks and Jobs section in the InTrust 9.5 User Guide.

 

Microsoft Proxy Server Events

Server side:

Processed computer:

PlatformIntel x86
Operating systemMicrosoft Windows NT 4.0 Service Pack 6 or higher
Microsoft Proxy Server2.0
Additional Software & Services Remote Registry Service for data gathering without agents

Rights and permissions for data gathering without agents:

Rights and permissions for data gathering with agents:

The following rights and permissions must be assigned to the InTrust agent account if the agent is not running under the LocalSystem account:

 

Note: For more information about job and task accounts, see the Creating Tasks and Jobs section in the InTrust 9.5 User Guide.

 

Microsoft DHCP Server Events

Server side:

Processed computer:

PlatformIntel x86
Operating systemMicrosoft Windows NT 4.0 Service Pack 6 or higher,
-OR-
Microsoft Windows 2000,
-OR-
Microsoft Windows Server 2003,
-OR-
Microsoft Windows Server 2003 R2
Microsoft DHCP ServerN/A
Additional Software & Services Remote Registry Service for data gathering without agents

Rights and permissions for data gathering without agents:

Rights and permissions for data gathering with agents:

 

Note: For more information about job and task accounts, see the Creating Tasks and Jobs section in the InTrust 9.5 User Guide.

 

Sun Solaris Syslog and BSM Log

Server side:

Processed computer:

Architecture Intel x86,
-OR-
Sun SPARC

(supported architectures for certain operating systems are listed below)

Operating system Sun Solaris 8 with patch 112439-01: 32-bit and 64-bit (on SPARC v9 architecture)

-OR-

Sun Solaris 9 standard installation: 32-bit and 64-bit (on SPARC v9 architecture)

-OR-

or Sun Solaris 10 standard installation: 32-bit and 64-bit (on SPARC v9 and AMD-64 architecture)

 

Red Hat Enterprise Linux Syslog

Server side:

Processed computer:

PlatformIntel x86
Operating systemRed Hat Enterprise Linux AS 3.x or 4.x
-OR-
Red Hat Enterprise Linux ES 3.x or 4.x

 

SUSE Linux Syslog

Server side:

Processed computer:

ArchitectureIntel x86, AMD-64
Operating systemSUSE Linux Enterprise Server 9.0: 32-bit and 64-bit (on AMD-64)

Quest InTrust Knowledge Portal

Server side:

PlatformIntel x86
Operating systemMicrosoft Windows 2000 Server SP4,
-OR-
Microsoft Windows Server 2003 (with or without SP1),
-OR-
Microsoft Windows Server 2003 R2
Additional Software & Services Microsoft IIS 5.0 or higher; if you plan to use Microsoft IIS 6.0, make sure ASP extensions are allowed
 

Microsoft SQL Server 2000 SP2 Reporting Services*

-OR-

(recommended) Microsoft SQL Server 2005 Reporting Services** and Microsoft .NET Framework 1.1

* - report creation capabilities are not supported in this version of Reporting Services, so it is recommended to use Microsoft SQL Server 2005 Reporting Services

** - Quest InTrust Knowledge Portal can use a local or remote installation of Reporting Services.

Client side:

PlatformIntel x86
Operating systemMicrosoft Windows 2000 Server SP4
-OR-

Microsoft Windows XP SP1, SP2

-OR-
Microsoft Windows Server 2003 with or without SP1

-OR-

Microsoft Windows Server 2003 R2

Additional Software & Services Microsoft Internet Explorer 6.0 or later

Microsoft .NET Framework 2.0 (required for report creation)

If you install InTrust Knowledge Portal on a computer running any of the following platforms:

and Internet Explorer 6.0 is installed on this computer, then check Internet Explorer's security settings as follows:

  1. In the Control Panel, open Internet Options.
  2. On the Security tab, click the Trusted Sites icon and make sure the web site where InTrust Knowledge Portal runs is included in the list of trusted sites.
  3. Click Custom Level and make sure Misc | Use Pop-Up Blocker is set to Disabled, and Misc | Allow script-initiated windows without size or positioning constraints is set to Enabled.

Quest InTrust Monitoring Console

Server side:

PlatformIntel x86
Operating systemMicrosoft Windows 2000,
-OR-
Microsoft Windows XP Professional,
-OR-
Microsoft Windows Server 2003,
-OR-
Microsoft Windows Server 2003 R2
Additional Software & Services Microsoft IIS 5.0 or higher; if you plan to install Monitoring Console on Microsoft IIS 6.0, make sure ASP extensions are allowed
Microsoft Data Access Components 2.7 or higher

Client side:

PlatformIntel x86
Operating systemMicrosoft Windows 98,
-OR-
Microsoft Windows ME,
-OR-
Microsoft Windows NT 4.0 Service Pack 6 or higher,
-OR-
Microsoft Windows 2000,
-OR-
Microsoft Windows XP Professional,
-OR-
Microsoft Windows Server 2003
Additional Software & Services Microsoft Internet Explorer 5.5 or higher

If you install InTrust Monitoring Console on a computer running any of the following platforms:

and Internet Explorer 6.0 is installed on this computer, then check Internet Explorer's security settings as follows:

  1. In the Control Panel, open Internet Options.
  2. On the Security tab, click the Trusted Sites icon and make sure the web site where Monitoring Console runs is included in the list of trusted sites.
  3. Click Custom Level and make sure Misc | Use Pop-Up Blocker is set to Disabled, and Misc | Allow script-initiated windows without size or positioning constraints is set to Enabled.

 

Quest InTrust Repository Viewer

PlatformIntel x86
Operating systemMicrosoft Windows 2000,
-OR-
Microsoft Windows XP Professional,
-OR-
Microsoft Windows Server 2003,
-OR-
Microsoft Windows Server 2003 R2
Additional Software & Services Microsoft Internet Explorer 5.5 or higher,
Microsoft Management Console 1.2 or higher,
Microsoft Data Access Components 2.7 or higher

 

Reporting Web Portal

Server side:

Microsoft Internet Information Services5.0 or later with VBScript and JScript support
Microsoft Data Access Components2.6 or later

Client side:

Microsoft Internet Explorer5.0 or later with JScript support

To view reports in certain formats, you must have the corresponding software installed (for example, Adobe Acrobat Reader for PDF files.)

To enable searching in reports saved in PDF and RTF formats, the following Indexing Service plug-ins should be installed:

 

Reporting Web Part for Microsoft SharePoint Portal Server

Server side:

Microsoft SharePoint Portal Server2001 only

Client side:

Microsoft Internet Explorer5.0 or later with VBScript and JScript support

 

 

Minimal Rights and Permissions Required for InTrust Operations

OPERATION OR ACCOUNT PERMISSIONS OR DATABASE ROLES NOTES
Run InTrust suite setup Setup must be launched under the account having a dbo role for all InTrust databases, or under the account having access rights for these databases at least as prescribed by this table.

 

To install the reports from the Knowledge Packs you select, the following is required:

  1. Membership in the local Administrators group on the target computer
  2. Content Manager role for the Home folder in SQL Reporting Services.
 

 

Use the Reporting Services Report Manager to assign the required roles with Security settings for each item you need.

InTrust Server account
  1. Membership in the local Administrators group on the computer where InTrust Server runs
  2. The following security settings must be turned on:
    • Act as part of the operating system
    • Log on as a service
    • Increase quotas (only on Windows 2000)
    • Replace a process level token
 
Install agent Membership in the local Administrators group on the agent computer The Admin$ share must exist on the target computer if you are installing the agent using InTrust.
Agent account Membership in the local Administrators group,
-OR-
LocalSystem account
 
Access the configuration database ADCCfgUser role for the Configuration Database This role is created by setup or by the configdb.sql script and is granted the following permissions:
  • Create Table (on the database level)
  • INSERT,SELECT,DELETE,UPDATE to all user tables in the database
  • EXECUTE to all user stored procedures in the database
Task/Job execution Membership in the local Administrators group on the computer where InTrust Server runs
Gather events from site computers without agents
  1. Full control permission to the InTrust Server installation folder.
  2. Access this computer from the network
  3. Manage auditing and security log (required to gather the Security log only)
To gather events from an event log on a Windows Server 2003 or Windows XP computer with event log security through a GPO  or registry settings, Read access permission must be given in the ACE of appropriate log(s) to the account used to run a job. For details refer to Microsoft KB article 323076.
Gather events from site computers with agents Full control permission to the InTrust Server installation folder. To gather events from an event log on a Windows Server 2003 or Windows XP computer with event log security through a GPO  or registry settings, Read access permission must be given in the ACE of appropriate log(s) to the account of the agent. For details refer to Microsoft KB article 323076.
Store events in a repository Modify permission to the repository In case a job that uses this repository is run by a Windows 2000-based InTrust server, make sure the account of that job has the Act as part of the operating system and Log on as a batch job user rights on the InTrust Server computer. For InTrust Server computers running Windows Server 2003, only the Log on as a batch job right is required.
Consolidate repositories
  1. Full control permission to the InTrust Server installation folder.
  2. Read permission to the source repository
  3. Modify permission to the target repository
Import data from a Repository
  1. Full control permission to the InTrust Server installation folder.
  2. Read permission to the repository
Clean up a Repository Modify permission to the repository
Store events in an audit database (gathering or import) InTrust Gathering role for the Audit Database This role is created by setup or by the auditdb.sql script.
Clean up an Audit Database To clean up all events
db_owner role for the Audit Database
 
To clean up part of the events (for specific time periods)
InTrust AuditDB Cleanup role for the Audit Database
This role is created by setup or by the auditdb.sql script.
Run reporting job or work with reports in InTrust Knowledge Portal (without using Report Builder)
  1. Content Manager role for the InTrust 9.5\SharedDatasources folder and for the folder where the report is located (under \InTrust 9.5 folder) in SQL Reporting Services.
  2. Browser role for the Home folder in SQL Reporting Services.
  3. Reporting Console User role for the account that will be used to connect to the database.
  4. Read permission for the %WinDir%.
 
  • For a reporting job, this account is specified when setting the Credentials in the job properties.
  • For account that will be used to work with InTrust Knowledge Portal, use Data Source properties to assign the required credentials.

Note that this account must belong to the same domain where SRS (hosting InTrust Knowledge Portal) is installed, otherwise membership in the Authenticated Users group (for SRS' domain) is required.

Create reports interactively using Report Builder System User or System Administrator role for the web site where InTrust Knowledge Portal application runs. This role can be assigned using SQL Reporting Services Report Manager (site-level security settings).
Run reporting job (legacy)
  1. Reporting Console User role for the Configuration, Audit, or Alert database selected as a data source for reporting
  2. Full control permission on Report Library
  3. Modify permission on the Report Storage
This role is created by the InTrust9_0_configuration_schema.sql, ITFE80_EventsData.sql, and InTrust9_0_alerts_schema.sql scripts (corresponding to the database type) and is granted the following permissions:
  • Create Table
  • Create View
  • Create SP
  • Create Function
Publish reports to a SharePoint Portal server (legacy reporting job)

The legacy reporting job must use an account for which the following has been configured on the InTrust Server computer:

  1. In the Control Panel, open Internet Options.
  2. On the Security tab, click the Trusted sites icon.
  3. Make sure that the relevant SharePoint site is a trusted site.
  4. Click Custom Level and select the User Authentication | Logon | Automatic Logon with current username and password option.
This account is often inherited by the job from the task or the InTrust server. However, you can set an explicit account for a job.
Store alerts in an Alert Database InTrust Real-Time Monitoring role for the Alert Database This role is created by setup or by the alertdb.sql script.
Clean up an Alert Database InTrust AlertDB Cleanup role for the Alert Database This role is created by setup or by the alertdb.sql script.
Manage Alerts from InTrust Monitoring Console InTrust Monitoring Console role for the Alert Database This role is created by setup or by the alertdb.sql script.

For information on specifying the accounts, permissions and database roles, see the InTrust 9.5 Installation and Configuration Guide and InTrust 9.5 User Guide. For details about configuration scripts, see the InTrust 9.5 Upgrade Path document.

 

 

 


Disclaimer

The information in this publication is furnished for information use only, does not constitute a commitment from Quest Software Inc. of any features or functions discussed and is subject to change without notice. Quest Software, Inc. assumes no responsibility or liability for any errors or inaccuracies that may appear in this publication.

 

Copyright © 2006 Quest Software, Inc.