Topics Topics


How to configure the Intrusion Detection Monitor

You can detect a possible intrusion / malicious event on your Domino server by using Intrusion Detection Monitor feature in SecurTracTM. The Intrusion Detection monitor scans the Domino Server console looking to match a certain string of keywords. To configure the Intrusion Detection Monitor, you need to open the SecurTrac Configuration Database (SCTCFG.NSF)

To create an Intrusion Detection Monitor:
  1. Open the SecurTrac Configuration Database (SCTCFG.NSF).
  2. In the left pane, select .
  3. Click the button on the action bar.
  4. Specify the preferred configuration settings and click the button.
  5. Below is a table describing each of the available configurations within the Intrusion Detection Monitor.


Basics Tab:

SectionFieldDescription
Server To MonitorServer(s)Either select "All in the Domain" or "Only the following" servers.

If you select "All in the Domain", intrusion detection events on all servers in the current domain will be monitored by SecurTracTM.

If you select "Only the following", a list box will be shown for you to select the specific server(s) in the current domain to be monitored. Click on the button to choose the server(s) you want to monitor.

Log DatabaseFile nameSelect

Log to the default databaseThe corresponding log will be stored in a Central Log Database (SctLog.nsf).
Log to the specified databaseThe corresponding log will be stored in the database you specified.
Server nameSelect

Log to the server where the event occurredThe corresponding log will be created on the same server where the event occurred.
Log to the specified serverThe corresponding log will be created on the server you specified. If you select this option, please make sure the originating server has sufficient access to the remote log database on this specified server.
Multiple Monitors Matched HandlingSingle log entryThis is the default option. Select this option if you want SecurTracTM to generate one log entry only for all monitor(s) matched.
Multiple log entries Select this option if you want SecurTracTM to generate a new log entry for each monitor matched.
EnablementDisable this Intrusion Detection MonitorIf this field was checked, SecurTracTM will temporarily disable the monitoring of any intrusion detection events.


Monitor Tab:

SectionFieldDescription
Event to matchPre-defined EventClick on the button next to 'Pre-defined Event' and a list of pre-defined events will be shown. Select the specific event that you want to monitor.
Event DescriptionWhen a pre-defined event is selected, the event description will be automatically populated. If you decide to specify a custom event to monitor(wording(s) to be matched), you can manually specify the related event description.
Wording(s) to be matchedWhen a pre-defined event is selected, this field will automatically be populated. If the event that you want to monitor is not listed in the pre-defined event list, SecurTracTM will allow you to type a keyword string in the "Wording(s) to be matched" field in order to log a specific event that appears on the Domino Server console. For example, you can add * WAS GRANTED FULL ADMINISTRATOR ACCESS to detect every time someone invokes the "Full Access Administration" privilege.
Notification ListMailing AddressSelect the person who will receive an e-mail notification immediately when the configured Intrusion Detection event occurs.
ImportanceYou can set the importance of the e-mail notification.
Delivery Priority You can set the delivery priority of the e-mail notification.
Customize E-Mail Notification MessageSelect this option if you want to customize the subject and content of the e-mail notification message.
Add fieldAllows you to select predefined reserved fields.
Bulk Action DetectionEnable Bulk Action DetectionSelect this option to generate a Bulk Action Log if the defined events occurred a defined no. of times within a defined period.
Send e-mail notification toSelect the person(s) who will receive an e-mail notification immediately when there are events that match the defined bulk action criteria.
ImportanceYou can set the importance of the e-mail notification.
Delivery Priority You can set the delivery priority of the e-mail notification.
Customize E-Mail Notification MessageSelect this option if you want to customize the subject and content of the e-mail notification message.
Add fieldAllows you to select predefined reserved fields.


Report Tab:

SectionFieldDescription
ScheduleRun FrequencySelect the frequency of which the report is run. Daily, Weekly, Monthly.
Run at timeSpecify the time that the report should be run at.
Days of weekSpecify the days of the week that the report should run on.
Notification ListMailing AddressSpecify the mailing addresses of the people who should be notified of the reports.
ImportanceSpecify the importance of the message.
Delivery PrioritySpecify the delivery priority of the message.
Customize E-mail Notification MessageOption to customize the E-mail notification.
EnablementDisable sending reportIf this field is checked, SecurTracTM will temporarily disable the sending of any reports.


Administration Tab:

SectionFieldDescription
AdministrationOwnerSpecify the owner of the monitor document.
AdministratorsSpecify person(s) who can modify the current monitor document.
Settings Modification HistoryDateShows the date of modification for the current monitor document.
Updated byShows the persons who have modified the current monitor document.



-------------------------------------------------------------------------------------------------------------------------------------------