Skip to main content

Responses are generated using AI and may contain mistakes.

CollectorsGet Started with Collector Onboarding

Configure the Egnyte Cloud Collector

Set up the Egnyte Cloud Collector to continuously ingest Egnyte audit logs that track data activity, user behavior, and system administration.

The following table displays audit source API and security events supported by the cloud collector.

Audit Source: API

Service or Module Covered

Event Types

Event Included

Login audit report

Access

Login success Login failed Account locked-out

Password management

Password reset Password changed

Files audit report

Files

File copied, file created, file deleted, file moved, file renamed, file downloaded, file downloaded via anonymous link, file downloaded via authenticated link, file locked, file previewed, file previewed via anonymous link, file previewed via authenticated link, file unlocked, file uploaded

Notes

Note created, note deleted, note added to file, note deleted from file, unsupported action

Folders

Folder copied, folder created, folder deleted, folder renamed, folder moved

Permissions audit report

Folder ACL

Add permission to group, add permission to user, remove permission from user, replace permission to user, add permission to role

Users audit report

User Management

User created, user deleted, user email changed

Represents events related to user management

Settings

User first name changed, user last name changed, user disabled on expiration setting changed, user deleted on expiration setting changed, user disabled, user enabled, user second factor enabled, user second factor disabled, user verify email

Roles Management

User downgraded from admin to power user, user downgraded from power user to standard user, user upgraded from standard to power user, user upgraded from power user to admin

Password

User password changed, user password reset

Groups audit report

Group Management

Group created, group deleted, group renamed, user added to group, user removed from group

Represents events related to group management

Audit Events

Track activity in your Egnyte domain

Use the following steps to set up the Egnyte Cloud Collector.

  1. Before you configure the Egnyte Cloud Collector, ensure that you complete the prerequisites.

  2. Log in to the New-Scale Security Operations Platform with your registered credentials as an administrator.

  3. Navigate to Collectors > Cloud Collectors.

  4. Click New Collector.

  5. Click Egnyte.

  6. Enter the following information for the cloud collector.

    • NAME – Specify a name for the Cloud Collector instance.

    • HOSTNAME – Enter your organization’s Egnyte domain. For example, myorg.egnyte.com.

    • CLIENT ID – Enter the application key that you obtained while completing the prerequisites.

    • CLIENT SECRET – Enter the OAuth 2 client secret that you obtained while completing the prerequisites from Engyte developer portal.

    • USERNAME – Enter the user name of Egnyte administrator.

    • PASSWORD – Enter the password for the Egnyte account.

    • DATA SOURCES – Select the data sources to retrieve Egnyte audit logs from: Audit Events, Files Audit Report, Groups Audit Report, Login Audit Report, Permissions Audit Report, and Users Audit Report.

    • INGEST FROM – Select the time and date from which the collector must start ingesting events.

  7. (Optional) SITE – Select an existing site or to create a new site with a unique ID, click manage your sites. Adding a site name helps you to ensure efficient management of environments with overlapping IP addresses.

    By entering a site name, you associate the logs with a specific independent site. A sitename metadata field is automatically added to all the events that are going to be ingested via this collector. For more information about Site Management, see Define a Unique Site Name.

  8. (Optional) TIMEZONE – Select a time zone applicable to you for accurate detections and event monitoring.

    By entering a time zone, you override the default log time zone. A timezone metadata field is automatically added to all events ingested through this collector.

    A cloud collector determines whether Daylight Saving Time (DST) is active based on the current date and automatically adjusts the time by adding or subtracting one hour, ensuring more accurate time reporting.

  9. To confirm that the New-Scale Security Operations Platform communicates with the service, click Test Connection

  10. Click Install.

    A confirmation message informs you that the new Cloud Collector is created.