Centrify DirectAudit

Why Centrify

High Fidelity, Efficient Session Capture and Replay

Most logging tools are system and application centric, simply rolling up higher-level events and notifications; they do not show you what users actually did or attempted to do. Or they may indicate they edited a file, but not show what changes they made. DirectAudit lets you visually replay any user session on any audited system to see exactly what the user did: the commands executed, the changes made to key files and data, and the results.

In addition, other auditing products can only support a historical view of system activity. DirectAudit gives you a real-time, at-a-glance view of activity across Windows, UNIX and Linux. For each session you can see who is logged on, and you can immediately drill down to see what they are currently doing.

Highly Scalable and Reliable, with Minimal Administrative Resources

  • Scalability. Multiple, load-balanced DirectAudit Collectors and Audit Stores can gather data from a large number of audited systems. A central SQL Audit Server acts as a large-scale data repository.
  • Reliability. DirectAudit continues to collect all audit data on a remote system if the network goes down and subsequently forwards it to the DirectAudit Collector when the network is back up.
  • Security. Audit data traffic is is communicated in an authenticated and encrypted format.
  • Cross-Platform. Centrify DirectAudit is the only solution on the market for monitoring privileged user activity on Window, Linux and UNIX.

Non-intrusive, Granular Role-based Access to Sensitive Session Data

  • Granular Audit Roles. DirectAudit's flexible, role-based access controls allow you to define the types of sessions that different IT auditor roles can search and replay.
  • Policy-Based Auditing. You can configure DirectAudit to trigger auditing sessions for specific users, computers or DirectAuthorize roles. DirectAudit policies be set within a Global Zone or Child Zone, enabling secure delegation of audit policy settings.

  • Non-intrusive. DirectAudit requires low local system overhead and is non-intrusive for end-users.
  • Agent-based. DirectAudit is not a proxy or gateway solution, but audits activity locally on each system and securely rolls auditing data into a central repository. This further ensures that users are not able to circumvent user session auditing.
  • Non-Proprietary Data Storage. DirectAudit uses a modern SQL Server database. This means you can easily report and search on all session data using the DirectAudit Console or third-party reporting tools. Archiving and purging session data is also easy as well.
  • Ad Hoc Querying and Reporting. DirectAudit not only provides out-of-the-box views of user sessions, but also lets you perform a full-text search for specific keywords. Mining key audit and system availability data is as easy as searching the Internet.

Part of an Integrated Solution for Unified Identity Services

The Centrify Suite provides Unified Identity Services for workstations, on-premise and cloud-based servers across UNIX, Linux, Windows and Mac OS by leveraging your existing identity infrastructure investment — Microsoft Active Directory. With Centrify Suite organizations gain control and establish visibility across heterogeneous systems through integrated authentication and single sign-on, policy management and authorization, auditing and analytics and server isolation and encryption. Built as a single architecture, Centrify Suite — consisting of DirectControl, DirectAuthorize, DirectAudit, DirectSecure and DirectManage — allows organizations to improve operational efficiency and strengthen security and compliance by consolidating islands of identity and centrally managing privilege and policy.