Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 6 additions & 2 deletions docs/kb/threatmanager/_category_.json
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,10 @@
{
"label": "Troubleshooting Articles",
"label": "Knowledge Base",
"position": 999,
"collapsed": true,
"collapsible": true
"collapsible": true,
"link": {
"type": "doc",
"id": "index"
}
}
Original file line numberDiff line numberDiff line change
Expand Up@@ -27,4 +27,4 @@ It can be annoying for users when their Netwrix Threat Manager console times out
4. Click into **User Access** then select the **Token Expiration** tab
5. Adjust timer from the drop down

![Graphical user interface, text, application Description automatically generated](./images/ka0Qk000000DmBh_0EM4u000004d64Y.png)
![Graphical user interface, text, application Description automatically generated](../0-images/ka0Qk000000DmBh_0EM4u000004d64Y.png)
Original file line numberDiff line numberDiff line change
Expand Up@@ -38,7 +38,7 @@ Alter the default Netwrix Threat Prevention Event Service listening port(s) via
```

For example, change the FS port to `514` and click **OK**:
![port512.png](./images/ka0Qk000000DkZh_0EM4u000008LC2a.png)
![port512.png](../0-images/ka0Qk000000DkZh_0EM4u000008LC2a.png)

6. In the window below click the **Save Data Changes** icon.
7. Restart the Netwrix Threat Prevention Event Service.
13 changes: 10 additions & 3 deletions docs/kb/threatmanager/index.md
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,21 @@
---
title: "Threat Manager Knowledge Base"
description: "Threat Manager knowledge base articles and troubleshooting guides"
description: "Knowledge base articles for Netwrix Threat Manager"
slug: threatmanager
---

# Threat Manager Knowledge Base

Welcome to the Threat Manager knowledge base. Browse our collection of troubleshooting guides, configuration instructions, and best practices.
Welcome to the Netwrix Threat Manager knowledge base. This section contains troubleshooting guides, configuration instructions, best practices, and reference materials for Threat Manager.

Use the search function above to find specific articles or browse through all Threat Manager KB articles in this section.
## Browse by Category

- **Configuration and Administration** - System configuration, permissions, logging, playbooks, and administrative tasks
- **Installation and Upgrade** - Installation troubleshooting, upgrade procedures, and deployment issues
- **Integration and Event Collection** - External system integrations, event collection, syslog configuration, and Active Directory sync
- **Troubleshooting and Diagnostics** - Agent diagnostics, threat detection troubleshooting, and log file analysis
- **Licensing and System Issues** - License activation, console crashes, and system-level problems
- **Threat Management and Operations** - Ransomware protection, quarantine management, and operational procedures

## Need Help?

Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -22,9 +22,9 @@ knowledge_article_id: kA0Qk0000001xvhKAA
- The Netwrix Threat Manager Dashboard in Microsoft Edge stalls at the loading screen and does not proceed to the login screen.
- The following error is present in the Developer Tools **Console** panel. To access the panel, navigate to **Settings (...) > More tools > Developer tools** (or press `CTRL + SHIFT + I`) > **Console** tab:

![Screenshot 1](./images/ka0Qk000000E7Cv_0EMQk00000C80X1.png)
![Screenshot 1](../0-images/ka0Qk000000E7Cv_0EMQk00000C80X1.png)

![Screenshot 2](./images/ka0Qk000000E7Cv_0EMQk00000AzSUg.png)
![Screenshot 2](../0-images/ka0Qk000000E7Cv_0EMQk00000AzSUg.png)

## Cause

Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,24 +26,24 @@ You may see that Netwrix Threat Manager (NTM) is not receiving events from Netwr

The incorrect **Syslog** message template of **LEEF** was selected.

![](./images/ka0Qk000000CpYD_0EMQk00000BJq9S.png)
![](../0-images/ka0Qk000000CpYD_0EMQk00000BJq9S.png)

## Resolution

To resolve this issue, change the Syslog message template from **LEEF** to **Netwrix Threat Prevention** as per the steps below:

1. Within the NAM console, click **Monitored Hosts** to select the needed host output for the **Syslog** item and Select **Edit**.
![](./images/ka0Qk000000CpYD_0EMQk00000BJoNm.png)
![](../0-images/ka0Qk000000CpYD_0EMQk00000BJoNm.png)

2. Confirm the server and port needed for NTM.

3. Click the ellipsis to open the Message Template window, select the **Netwrix Threat Manager (Netwrix Threat Prevention)** Template, and click **OK**.
![](./images/ka0Qk000000CpYD_0EMQk00000BJssn.png)
![](../0-images/ka0Qk000000CpYD_0EMQk00000BJssn.png)

4. Click **Test** to verify the template setting and click **OK**.

> **NOTE:** This is UDP, so there is no true confirmation that a connection is/was made.
> ![](./images/ka0Qk000000CpYD_0EMQk00000BJrGo.png)
> ![](../0-images/ka0Qk000000CpYD_0EMQk00000BJrGo.png)

5. Return to the NTM Web console and check for new events once posted.

Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -64,4 +64,4 @@ Edit the Active Directory Service configuration to implement the HTTPS protocol.

Refer to the following example of the `appsettings.json` file:

![appsettings.json example](./images/ka0Qk0000005sxR_0EMQk000007sh3x.png)
![appsettings.json example](../0-images/ka0Qk0000005sxR_0EMQk000007sh3x.png)
Original file line numberDiff line numberDiff line change
Expand Up@@ -17,7 +17,7 @@ After navigating to the **Licensing** page when attempting to update the license
License activation error 2.
```

![Licensing error screenshot](./images/ka0Qk000000CDMT_0EMQk00000Asaf3.png)
![Licensing error screenshot](../0-images/ka0Qk000000CDMT_0EMQk00000Asaf3.png)

## Cause

Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -45,4 +45,4 @@ knowledge_article_id: kA04u0000000Hw5CAE
## Related articles

- Reporting Module ⸱ v7.3
- [Threat Manager Reporting Console Crashes](/docs/kb/threatmanager/threat-manager-reporting-console-crashes.md)
- [Threat Manager Reporting Console Crashes](/docs/kb/threatmanager/licensing-and-system-issues/threat-manager-reporting-console-crashes.md)
Original file line numberDiff line numberDiff line change
Expand Up@@ -45,7 +45,7 @@ To resolve this issue, follow the steps provided in the first resolution. If the

1. To verify this setting, review the **AD Agent** column in the interface:

![AD](./images/servlet_image_6a2f3ac990a0.png)<br /><br />
![AD](../0-images/servlet_image_6a2f3ac990a0.png)<br /><br />

2. Enable or disable this setting using the **Agent Update Settings** option. Navigate to: https://docs.netwrix.com/docs/threatprevention/7_5 (Set Options Window).
3. Access the settings via the following path: **Netwrix Threat Manager v7.3 > Administration > Policy Center > Agents Interface > Agents Interface Right-Click Menu > Update Agent Settings**. For details, see: https://docs.netwrix.com/docs/threatprevention/7_5 (Update Agent Settings).
Expand Down
Original file line numberDiff line numberDiff line change
Expand Up@@ -30,4 +30,4 @@ To resolve the issue, add all domains and systems to be tracked:
1. Navigate to the policy settings in **Threat Prevention**.
2. Select **Event Type** > **Additional Agents** > **Add All Agents and Domains**.

![Screenshot showing the policy settings in Netwrix Threat Prevention with the Add All Agents and Domains option highlighted](./images/servlet_image_6a2f3ac990a0.png)
![Screenshot showing the policy settings in Netwrix Threat Prevention with the Add All Agents and Domains option highlighted](../0-images/servlet_image_6a2f3ac990a0.png)
15 changes: 7 additions & 8 deletions sidebars/threatmanager/3.0.js
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,16 @@
// DIAGNOSTIC TEST: const generateKBSidebar = require('../../src/utils/generateKBSidebar');
const generateKBSidebar = require('../../src/utils/generateKBSidebar');

module.exports = {
sidebar: [
{
type: 'autogenerated',
dirName: '.',
},
// DIAGNOSTIC TEST: Comment out entire KB section
// {
// type: 'category',
// label: 'Knowledge Base',
// collapsed: true,
// items: generateKBSidebar('threatmanager')
// },
{
type: 'category',
label: 'Knowledge Base',
collapsed: true,
items: generateKBSidebar('threatmanager')
},
],
};