- Connector Migration Overview
- Cloud Collectors Overview
- Navigate the Cloud Collectors UI
- Which Collector to Use?
- Hybrid Deployment Experience
- Supported Regions for Cloud Collectors
- Access the Cloud Collectors Service
- Set up a New Cloud Connectors Instance
- New Cloud Collectors
- Armis Cloud Collector
- Armis Context Collector
- AWS Eventbridge Cloud Collector
- AWS Inspector Cloud Collector
- AWS Redshift Cloud Collector
- AWS Shield Cloud Collector
- Claude Enterprise Cloud Collector
- Egnyte Cloud Collector
- Cybereason Cloud Collector
- Google Workspace Context Cloud Collector
- OneLogin Cloud Collector
- Palo Alto Networks SaaS Security Cloud Collector
- Rest API Context Cloud Collector
- Symantec CloudSOC Cloud Collector
- Symantec Cloud Secure Web Gateway Cloud Collector
- Symantec Email Security Cloud Collector
- Troubleshooting Cloud Collectors
Configure the Egnyte Cloud Collector
Set up the Egnyte Cloud Collector to continuously ingest Egnyte audit logs that track data activity, user behavior, and system administration.
The following table displays audit source API and security events supported by the cloud collector.
Audit Source: API | Service or Module Covered | Event Types | Event Included |
|---|---|---|---|
Access | Login success Login failed Account locked-out | ||
Password management | Password reset Password changed | ||
Files | File copied, file created, file deleted, file moved, file renamed, file downloaded, file downloaded via anonymous link, file downloaded via authenticated link, file locked, file previewed, file previewed via anonymous link, file previewed via authenticated link, file unlocked, file uploaded | ||
Notes | Note created, note deleted, note added to file, note deleted from file, unsupported action | ||
Folders | Folder copied, folder created, folder deleted, folder renamed, folder moved | ||
Folder ACL | Add permission to group, add permission to user, remove permission from user, replace permission to user, add permission to role | ||
User Management | User created, user deleted, user email changed | Represents events related to user management | |
Settings | User first name changed, user last name changed, user disabled on expiration setting changed, user deleted on expiration setting changed, user disabled, user enabled, user second factor enabled, user second factor disabled, user verify email | ||
Roles Management | User downgraded from admin to power user, user downgraded from power user to standard user, user upgraded from standard to power user, user upgraded from power user to admin | ||
Password | User password changed, user password reset | ||
Group Management | Group created, group deleted, group renamed, user added to group, user removed from group | Represents events related to group management | |
Track activity in your Egnyte domain |
Use the following steps to set up the Egnyte Cloud Collector.
Before you configure the Egnyte Cloud Collector, ensure that you complete the prerequisites.
Log in to the New-Scale Security Operations Platform with your registered credentials as an administrator.
Navigate to Collectors > Cloud Collectors.
Click New Collector.
Click Egnyte.
Enter the following information for the cloud collector.
NAME – Specify a name for the Cloud Collector instance.
HOSTNAME – Enter your organization’s Egnyte domain. For example, myorg.egnyte.com.
CLIENT ID – Enter the application key that you obtained while completing the prerequisites.
CLIENT SECRET – Enter the OAuth 2 client secret that you obtained while completing the prerequisites from Engyte developer portal.
USERNAME – Enter the user name of Egnyte administrator.
PASSWORD – Enter the password for the Egnyte account.
DATA SOURCES – Select the data sources to retrieve Egnyte audit logs from: Audit Events, Files Audit Report, Groups Audit Report, Login Audit Report, Permissions Audit Report, and Users Audit Report.
INGEST FROM – Select the time and date from which the collector must start ingesting events.
(Optional) SITE – Select an existing site or to create a new site with a unique ID, click manage your sites. Adding a site name helps you to ensure efficient management of environments with overlapping IP addresses.
By entering a site name, you associate the logs with a specific independent site. A sitename metadata field is automatically added to all the events that are going to be ingested via this collector. For more information about Site Management, see Define a Unique Site Name.
(Optional) TIMEZONE – Select a time zone applicable to you for accurate detections and event monitoring.
By entering a time zone, you override the default log time zone. A timezone metadata field is automatically added to all events ingested through this collector.
A cloud collector determines whether Daylight Saving Time (DST) is active based on the current date and automatically adjusts the time by adding or subtracting one hour, ensuring more accurate time reporting.
To confirm that the New-Scale Security Operations Platform communicates with the service, click Test Connection.
Click Install.
A confirmation message informs you that the new Cloud Collector is created.