Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

To change these using the GUI in OpenAudIT navigate to menu -> Admin -> Community -> All Configuration

 

Code Block
+------------------------------------+-------------------------------------------+--------+-----------------------------------------------------------------------------------------------------------------------------------------------+
| name                               | value                                     | descriptiontype          | description                                                                                                                                 |
+------------------------------------+-------------------------------------------+--------+-----------------------------------------------------------------------------------------------------------------------------------------------+
| blessedaccess_subnetstoken_usecount                 | 10 y                                       | number | ShouldAllow this wemany onlyaccess accepttokens datato frombe thestored blessedin subnetsthe listcookie.                                                                                  |
| access_token_enable         | | default_network_address     | y      |                                   | bool   | Should we enable |access Thetokens ipfor addressCSRF ormitigation. resolvable hostname used by external devices to talk to Open-AudIT.                                                                 | | delete_noncurrent           |
      | nblessed_subnets_use                | y                        | Should we delete any attributes that are not present when we audit a device.   | bool   | Should we only accept data from the blessed subnets list.                                                         | | discovery_create_alerts            | y          |
| collector_check_minutes            | 15                | Should Open-AudIT create an entry in the alert table if a change is detected.          | number | The default check interval for collectors.                                                       | | discovery_ip_exclude               |                         |
| database_show_row_limit            | 1000                                      | Populatenumber this| listThe withlimit ipof addressesrows to be excluded from discovery. IPs should be separated by a space. show, rather than download when exporting a database table.                                                           |
| default_network_address            |                                           | text   | The ip address or resolvable hostname used by external devices to talk to Open-AudIT.                                                      |
| delete_noncurrent                  | n                                         | bool   | Should we delete any attributes that are not present when we audit a device.                                                               |
| delete_noncurrent_netstat          | y                                         | bool   | Should we store non-current netstat data and generate change logs.                                                                         |
| delete_noncurrent_variable         | y                                         | bool   | Should we store non-current environment variable data and generate change logs.                                                            |
| discovery_create_alerts            | y                                         | bool   | Should Open-AudIT create an entry in the alert table if a change is detected.                                                              |
| discovery_ip_exclude               |                                           | text   | Populate this list with ip addresses to be excluded from discovery. IPs should be separated by a space.                                    |
| discovery_linux_script_directory   | /tmp/                                     | text   | The directory the script is copied into on the target device.                                                                              |
| discovery_linux_script_permissions | 700                                       | text   | The permissions set on the audit_linux.sh script when it is copied to the target device.                                                   |
| discovery_linux_use_sudo           | y                                         | bool   | When running discovery commands on a Linux target, should we use sudo.                                                                     |
| discovery_use_dns                  | y                                         | bool   | Should we use DNS for looking up |the | discovery_linux_script_directory hostname and domain.  | /tmp/                                     | The directory the script is copied into on the target device.                               |
| discovery_use_ipmi                 | y                                      | | discovery_linux_script_permissions | 700bool   | Should we use ipmitool for discovering management ports if ipmitool is installed.                         | The permissions set on the audit_linux.sh script when it is copied to the target device.                  |
| display_version                    | 2.2.2                     | | discovery_nmap_os              | text   | nThe version shown on the web pages.                                   | When discovery runs Nmap, should we use the -O flag to capture OS information (will slow down scan and requires SUID on the Nmap binary under Linux). | | discovery_use_dns                  | y                    |
| download_reports                   | Shoulddownload we use DNS for looking up the hostname and domain.                          | text   | Tells Open-AudIT to advise the browser to download as a file or display the csv, xml, json reports. Valid values are download and display. |
| graph_days                         | 30          | | discovery_use_ipmi                 | y          | number | The number of days to report on for the Enterprise graphs.                  | Should we use ipmitool for discovering management ports if ipmitool is installed.                                                   |
| gui_trim_characters                | 25 | display_version                    | 2.0.1                 | number | When showing a table of information in the web GUI, replace characters greater than this with "...". | The version shown on the web pages.                               |
| homepage                           | groups                                    | text   | Any links to the default page should be directed to this endpoint.  | | download_reports                   | download                                  | Tells Open-AudIT to advise the browser to download as a file or display the csv,|
xml, json reports. Valid values are download and display.| internal_version                   | |20180620 graph_days                         | 30       | number | The internal numerical version.                           | The number of days to report on for the Enterprise graphs.                                                                      |
| log_level                    | | homepage    | 5                      | groups                  | number | Tells Open-AudIT which severity of event (at least) should be logged.     | Any links to the default page should be directed to this endpoint.                                                     |
| log_retain_level_0                 | 180           | | internal_version                   | 20170620      | number | Tells Open-AudIT how many days to keep logs with severity 0.               | The internal numerical version.                                                            |
| log_retain_level_1                 | 180                                       | number | logoTells Open-AudIT how many days to keep logs with severity 1.                     | logo-banner-oac-oae                       | The logo to be used in Open-AudIT. Should be a 475x60 .png. Name should not include the file extension. logo-banner-oac-oae is the default.           |
| log_retain_level    _2                      | 5180                                       | number | Tells Open-AudIT whichhow severitymany ofdays eventto (atkeep least)logs shouldwith beseverity logged2.                                                                                 |
| log_retain_level_03                 | 180                                       | number | Tells Open-AudIT how many days to keep logs with severity 0.           3.                                                                               |
| log_retain_level_14                 | 180                                       | number | Tells Open-AudIT how many days to keep logs with severity 1.       4.                                                                                   |
| log_retain_level_25                 | 90   180                                     | number | Tells Open-AudIT how many days to keep logs with severity 2.           5.                                                                               |
| log_retain_level_36                 | 18030                                        | number | Tells Open-AudIT how many days to keep logs with severity 36.                                                                                          |
| log_retain_level_47                 | 7 180                                        | number | Tells Open-AudIT how many days to keep logs with severity 47.                                                                               |
| maps_api_key                      | | log_retain_level_5AIzaSyAhAUqssRASeC0Pfyx1TW1DXRmboG5bdG0   | text   | The API key for Google Maps.    | 90                                        | Tells Open-AudIT how many days to keep logs with severity 5.                                                       |
| maps_url                           | /omk/open-audit/map     | | log_retain_level_6                 | 30text   | The web server address of  opMaps.                              | Tells Open-AudIT how many days to keep logs with severity 6.                                                                 |
| match_dbus                       | | log_retain_level_7  | n                | 7                        | bool   | Should we match a device based on its dbus id.   | Tells Open-AudIT how many days to keep logs with severity 7.                                                                               |
| match_fqdn         | | maps_api_key              | y        | AIzaSyAhAUqssRASeC0Pfyx1TW1DXRmboG5bdG0   | The API key for Google Maps.                       | bool   | Should we match a device based on its fqdn.                                                                                      | | maps_url        |
| match_hostname                 | /omk/open-audit/map   | y                   | The web server address of opMaps.                | bool   | Should we match a device based only on its hostname.                                                                                       |
| match_hostname_dbus                | y        | n                                | bool        | Should we match a device based on its hostname and dbus id.                                                                                                        |
| match_hostname_fqdnserial              | y          | y                                      | bool   | Should we match a device based on its fqdn.hostname                      and serial.                                                                                     |
| match_hostname_uuid                | y    | y                                     | bool   | Should we match a device based only on its hostname and UUID.                                                                                   |
| match_ip             | | match_hostname_dbus            | n   | y                                     | bool   | Should we match a device based on its hostname and dbus id.    ip.                                                                                       | | match_hostname_serial            |
 | ymatch_mac                          | n              | Should we match a device based on its hostname and serial.                | bool   | Should we match a device based on its mac address.                                                              | | match_hostname_uuid                | y              |
| match_mac_vmware                   | n     | Should we match a device based on its hostname and UUID.                         | bool   | Should we match a device based mac address even if it's a known likely duplicate from   VMware.                                              |
| match_ipserial                       | y   | n                                     | bool   | Should we match a device based on its serial ip.              number.                                                                                               |
| match_serial_mactype                  | y       | n                                 |    bool    | Should we match a device based on its serial macand addresstype.                                                                                     |
     | match_uuid         | | match_mac_vmware              | y    | n                                    |  bool   | Should we match a device based macon address even if it's a known likely duplicate from VMware. its UUID.                                                              | | match_serial                       | y        |
| modules                            |   | Should we match a device based on its serial number.                              | text   | The list of installed Opmantek modules.                                                          | | match_serial_type                  | y                     |
| nmis                  | Should we match a device based on its serial and type.  | n                                         | bool   | Enable import / export to NMIS functions.                                         | | match_uuid                         | y                             |
| nmis_url          | Should we match a device based on its UUID.        |                                           | text   | The web server address of NMIS.                                              | | modules                            |                                |
| oae_license         | The list of installed Opmantek modules.         |                                           | text   | License status of Open-AudIT Enterprise.                                                  | | nmis                               | n               |
| oae_product                        | EnableOpen-AudIT importCommunity / export to NMIS functions.                 | text   | The name of the installed commercial    application.                                                                              | | nmis_url          |
| oae_prompt               |          | 2015-06-01                                | Thedate web server address| ofPrompt NMIS.to activate a license for Open-AudIT Enterprise.                                                                                    |
| oae_url                           | | oae_license/omk/open-audit                        | none  | text   | The web server address of Open-AudIT Enterprise.                         | License status of Open-AudIT Enterprise.                                                             |
| output_escape_csv                  | y                            | | oae_product           | bool   | Escape CSV output so Excel will not attempt |to Open-AudIT Communityrun contents.                      | The name of the installed commercial application.                                                  |
| page_size                          | 1000                      | | oae_prompt              | number | The default limit of rows to retrieve.  | 2017-06-28                                | Prompt to activate a license for Open-AudIT Enterprise.                                                          |
| process_netstat_windows_dns        | n                          | | oae_url             | bool   | Should we keep track of Windows netstat ports used by | /omk/open-audit  DNS above port 1000.                         | The web server address of Open-AudIT Enterprise.                                 |
| rss_enable                         | y                                         | bool   | page_refreshEnable the RSS feed.                    | 300                                       | Interval in seconds between auto-refreshing the page. Set to 0 to cancel auto-refresh.                                              |
| rss_url                | | process_netstat_windows_dns        |  | https://community.opmantek.com/rss/OA.xml | text   | The RSS feed URL.                               | Should we keep track of Windows netsta ports used by DNS above port 1000.                                                                             |
| rss_enableservers                            |  y                                         | Enabletext  the RSS| feed.The servers to report to when using Agent / Collector / Server.                                                                            |
| server_ip                          |               | | rss_url                          | text | https://community.opmantek.com/rss/OA.xml | The locally RSSdetected feedIP URL.Addresses of this server.                                                                                          |
| uuid                               |       | | uuid                               | 980906d2-5994-11e7-a4a3-1c1b0d60813b  | text   | The unique identfier of this Open-AudIT server.                                                                                                       |
+------------------------------------+-------------------------------------------+--------+-----------------------------------------------------------------------------------------------------------------------------------------------+