Skip to content

Update EPP 2608 export logs, retention, and Audit Log Backup deprecation - #1509

Open
MRoscaNetwrix wants to merge 3 commits into
devfrom
epp-2608-export-logs-and-retention
Open

Update EPP 2608 export logs, retention, and Audit Log Backup deprecation#1509
MRoscaNetwrix wants to merge 3 commits into
devfrom
epp-2608-export-logs-and-retention

Conversation

@MRoscaNetwrix

Copy link
Copy Markdown
Collaborator

Reports and Analysis > Export list:

  • Correct the Export List description, which implied the list only shows exports created by an administrator.
  • Document the daily scheduled exports generated automatically for Device Control, Content Aware Protection, and eDiscovery, including the Scheduled_Export_ and Generated_Export file name prefixes and the absence of an associated user.
  • Fix the export retention period, which stated seven days. The default is 29 days and is configurable.
  • Clarify that export retention governs export files, not log data.

System Settings > Log Settings:

  • Document Enable Log Rotate After, the log data retention setting. The edscanning page already referred readers here for it.
  • Document Show old logs structure.

System Maintenance:

  • Mark Audit Log Backup as a legacy feature that applies only to pre-migration logs and receives no new data from 2608 onward.
  • Note that the Audit Log Backup externalization target is legacy-only.

Reports and Analysis > Export list:
- Correct the Export List description, which implied the list only shows
  exports created by an administrator.
- Document the daily scheduled exports generated automatically for Device
  Control, Content Aware Protection, and eDiscovery, including the
  Scheduled_Export_ and Generated_Export file name prefixes and the absence
  of an associated user.
- Fix the export retention period, which stated seven days. The default is
  29 days and is configurable.
- Clarify that export retention governs export files, not log data.

System Settings > Log Settings:
- Document Enable Log Rotate After, the log data retention setting. The
  edscanning page already referred readers here for it.
- Document Show old logs structure.

System Maintenance:
- Mark Audit Log Backup as a legacy feature that applies only to
  pre-migration logs and receives no new data from 2608 onward.
- Note that the Audit Log Backup externalization target is legacy-only.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Documentation PR Review

Editorial Review

docs/endpointprotector/admin/reports.md

  • Completeness — Line 209: "Completed exports are deleted automatically after a configurable retention period. The default is 29 days." The reader is told the period is configurable but never where to configure it. This is the first question anyone reading this sentence will have. Suggested fix: name the location, for example "Completed exports are deleted automatically after a configurable retention period. The default is 29 days, set under System Configuration > System Settings." — and link to the setting the same way the note below it does.
  • Completeness — Line 174: The scheduled-exports description says one export is generated per day per module, but not what each export contains — the full log table, or only the previous day's logs? A reader deciding whether to keep using manual exports can't tell. Suggested fix: add a sentence stating the scope, for example "Each scheduled export contains the logs for that module collected in the previous 24 hours."
  • Clarity — Line 174: "These scheduled exports are created during the upgrade to 2608" — "2608" appears here without context. Every other version reference in this file is fully qualified ("clients from the 5.9.0.0 release", "Endpoint Protector Server versions older than 5.7.0.0"). Suggested fix: "These scheduled exports are created during the upgrade to Endpoint Protector 2608 and require no configuration."
  • Structure — Line 170: The ### Scheduled exports heading is placed before ### Background processing, but Background processing describes the manual Create Export flow that the surrounding sections (and the "Export Content Aware reports" section above) lead the reader into. Placing the automatic-export digression first interrupts that path. Suggested fix: move ### Scheduled exports to after ### Background processing, so the order is manual flow → automatic exports → retention.
  • Structure — Line 170: The heading is narrower than the content. The section defines both export types and how to tell them apart, not just the scheduled ones. Suggested fix: retitle to "Export types" or "Scheduled and manual exports".
  • Clarity — Line 181: "no user name appears against them in the Export List" — "appears against" is an unusual construction and doesn't tell the reader what they'll actually see on screen. Suggested fix: "Scheduled exports belong to the system rather than to an administrator, so the user column is empty for these entries. This is expected and doesn't indicate a configuration problem."
  • Clarity — Line 214: The note links to the whole System Settings page, which is long — the reader lands at the top and has to hunt for Enable Log Rotate After. Suggested fix: link to the section anchor: [Log Settings](/docs/endpointprotector/admin/systemconfiguration/systemsettings.md#log-settings).
  • Clarity — Line 209: This page now states export retention defaults to 29 days, while System Maintenance > Exported Entities states scheduled exports are deleted after 14 days. Those are different features, but the reader has no way to know that from either page. Suggested fix: scope the sentence explicitly — "Completed log exports..." — so it doesn't read as a contradiction of the entity-export retention figure.
  • Clarity — Line 178: The two prefixes are formatted inconsistently (Scheduled_Export_... with a trailing underscore, Generated_Export ... with a space) and both trail into an ellipsis that the following examples already cover. Suggested fix: drop the ellipses and let the examples carry the format — "Scheduled_Export — generated automatically by Endpoint Protector. For example, Scheduled_Export_Device_Control_Logs_2026-09-09 06:00:00."
  • Clarity — Line 179: Line 172 introduces the two types in second person ("exports you create manually"), then the bullet switches to third person ("created manually by an administrator"). Suggested fix: keep second person in the bullet — "created manually by you or another administrator" — or make line 172 third person throughout.

docs/endpointprotector/admin/systemconfiguration/systemsettings.md

  • Completeness — Line 149: Every other numeric setting in this file gives its accepted range ("between 5 and 60 minutes", "between 100 and 1000", "between 15 min up to 1440 minutes"). Enable Log Rotate After gives the default and the disable value but no upper bound. Suggested fix: state the range, for example "sets how long logs are kept on the server, in months, between 1 and 24. The default is three months."
  • Clarity — Line 161: "the migration to the 2608 database structure" — this is the first mention of both "2608" and the migration on this page, and neither is explained. A reader who doesn't know whether their server has migrated can't decide whether to enable the setting. Suggested fix: "displays logs collected before Endpoint Protector 2608 migrated the server to a new log database structure."
  • Completeness — Line 162: "Enabling this option adds an Export Audit Logs tab and makes the legacy Audit Log Backup sections visible" — the reader isn't told where either of these appears, so they can't act on the setting. Suggested fix: name and link the destinations, for example "...and makes the Audit Log Backup sections under System Maintenance visible."
  • Completeness — Line 149: The Reports and Analysis page now points readers here to distinguish log retention from export retention, but this bullet doesn't make the reciprocal distinction. A reader setting log rotation could reasonably think it also governs how long export files are kept. Suggested fix: add a short note — "Log rotation controls how long log data is kept. It doesn't affect how long generated export files are kept; see Export retention."
  • Clarity — Line 152: "setting this option to 6 keeps six months of logs" mixes a numeral and a spelled-out number for the same value in one sentence. Suggested fix: "For example, set this option to 6 to keep six months of logs and remove anything older."

docs/endpointprotector/admin/systemmaintenance/overview.md

  • Completeness — Line 81: The warning sends the reader to "Reports and Analysis > Export Logs", but there's no section by that name on the Reports and Analysis page — the equivalent content is under "Export list". A reader following this pointer won't find it. Suggested fix: match the destination and link it: "Logs collected from 2608 onward are exported through the Export list in Reports and Analysis."
  • Clarity — Line 86: "Servers that hold no pre-migration logs don't need it." — "it" could refer to the setting, the section, or the feature, and the sentence doesn't tell the reader what to do. Suggested fix: "If your server holds no logs collected before the migration, leave the setting disabled."
  • Clarity — Line 79: "before the migration to the new database structure" assumes the reader knows a migration happened and what it changed. This is the only mention on this page. Suggested fix: "it applies only to logs collected before Endpoint Protector 2608 migrated the server to a new log database structure," and link to the Show old logs structure setting so the reader can see the two halves of the feature together.
  • Clarity — Line 81: "Base any new log export process on Export Logs rather than Audit Log Backup" is indirect for what is a simple instruction. Suggested fix: "Use Export Logs for any new log export process."
  • Completeness — Line 124: The note explains that the Audit Log Backup externalization option covers legacy logs only, but doesn't tell the reader how to externalize the new log exports instead — which is the action they'll want next. Suggested fix: add one sentence stating whether export files can be externalized and, if not, how to retrieve them (download from the Export list).

Summary

20 editorial suggestions across 3 files. Vale and Dale issues are auto-fixed separately.


What to do next:

Comment @claude on this PR followed by your instructions to get help:

  • @claude fix all issues — fix all editorial issues
  • @claude help improve the flow of this document — get writing assistance
  • @claude explain the voice issues — understand why something was flagged

You can ask Claude anything about the review or about Netwrix writing standards.

Automated fixes are only available for branches in this repository, not forks.

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Auto-Fix Summary

61 issues fixed, 26 skipped across 3 files

Category Fixes
OxfordComma (rewrite) 2
Dale: misplaced-modifiers 2
Dale: passive-voice 39
Dale: positional-references 1
Dale: undefined-acronyms 3
Dale: wordiness 14
Skipped (needs manual review) Reason
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:171 — Netwrix.FirstPersonPlural False positive — 'US' here is the country abbreviation in 'US SSN' (a Content Aware Protection threat identifier), not the pronoun 'us'. Rewording would break the product identifier name.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:241 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:249 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:259 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:268 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:269 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:303 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:313 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:322 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:323 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:324 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:351 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:361 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:370 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:391 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:401 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:411 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:412 — Netwrix.FirstPersonPlural False positive — 'US' is the country abbreviation in the 'SSN US' content detection identifier, not the pronoun 'us'.
docs/endpointprotector/admin/systemmaintenance/overview.md:9 — Dale: wordiness 'is crucial for ensuring the optimal performance and reliability' is inflated, but a concise rewrite would change the author's framing of why maintenance matters
docs/endpointprotector/admin/systemmaintenance/overview.md:102 — Dale: misplaced-modifiers 'For Endpoint Protector 5.7.0.0, reports, only one file containing all threats discovered' is garbled in the source; multiple valid readings of what reports what, so a fix could change the technical meaning
docs/endpointprotector/admin/reports.md:138 — Dale: positional-references 'located above the Content Aware Reports list' and 'located below' (line 143) describe physical placement of controls in the product UI, not a reference to other documentation content
docs/endpointprotector/admin/reports.md:181 — Dale: xy-slop 'This is expected and doesn't indicate a configuration problem' is deliberate reassurance about a surprising behavior; removing the negative clause would drop the reassurance the author intended
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:29 — Dale: wordiness 'set the amount of time the user is inactive until the session expires between 5 and 60 minutes' is wordy, but it's ambiguous whether the 5-60 minute range binds to the inactivity period or the expiry, so a rewrite risks changing the stated limits
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:122 — Dale: wordiness 'as one row corresponds with one log' explains the ratio behind the example; condensing it risks losing the explanation of why 1.0 equals 1 million logs
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:225 — Dale: passive-voice 'If enabled' has no stated subject in the source and could refer to either the Limit Reporting setting or the policy; naming an actor would be a guess
docs/endpointprotector/admin/systemconfiguration/systemsettings.md:263 — Dale: passive-voice 'the policy is satisfied' / 'the Threat Threshold is met' repeats verbatim across the four scenario examples (lines 263, 317, 365, 405); the acting component (client vs. scan engine vs. server) isn't stated, so supplying a subject could misstate which component evaluates the policy

Ask @claude on this PR if you'd like an explanation of any fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants