diff --git a/docs/endpointprotector/admin/reports.md b/docs/endpointprotector/admin/reports.md index ba48310db8..4263e49083 100644 --- a/docs/endpointprotector/admin/reports.md +++ b/docs/endpointprotector/admin/reports.md @@ -11,15 +11,15 @@ This section provides an overview of the system logs, Device Control logs and sh logs and shadows, eDiscovery logs, admin actions, statistics, and other helpful information. eDiscovery scan results are accessible both from this section and from the dedicated -**eDiscovery** > **Scan Results and Actions** section. Enforced Encryption details can be viewed in +**eDiscovery** > **Scan Results and Actions** section. You can view Enforced Encryption details in the Enforced Encryption section. -As an additional security measure, this section can be protected by an additional password set by -the Super Administrator from **System Configuration** > **System Security**. +As an additional security measure, the Super Administrator can protect this section with an +additional password from **System Configuration** > **System Security**. ## Device Control logs -Device Control logs display events related to device connections, file transfers, and policy enforcement. When the scalability architecture is active, Device Control logs are stored in CrateDB and displayed in an updated log view with improved filtering and sorting. +Device Control logs display events related to device connections, file transfers, and policy enforcement. When the scalability architecture is active, Endpoint Protector stores Device Control logs in CrateDB and displays them in an updated log view with improved filtering and sorting. The log view supports: @@ -30,9 +30,9 @@ The log view supports: ## Logs report -From this section, you can view, sort, and export the main logs in the system. There are several -event types such as User Login, User Logout, AD Import, AD Synchronization, Uninstall Attempt, and others -included in this section. Additionally, the main Device Control logs can be viewed in this section. +From this section, you can view, sort, and export the main logs in the system. This section includes +several event types, such as User Login, User Logout, AD Import, AD Synchronization, Uninstall +Attempt, and others. You can also view the main Device Control logs in this section. ![Logs Report Settings](logsreport.webp) @@ -44,7 +44,7 @@ list. ## File tracing -This section provides an overview of trace files that have been transferred from a protected computer +This section provides an overview of trace files transferred from a protected computer to a portable device or another computer on the network, and vice versa. Endpoint Protector computes an MD5 hash for most files to which the File Tracing feature applies. This approach helps mitigate threats from changing file content. @@ -115,19 +115,19 @@ Expand each entry to view detailed log information: Use the **Show/Hide Columns** dropdown to customize which columns are visible in the report. The **Date/Time(Client UTC)** column is available in this dropdown but is hidden by default. -From the Filters section, select the **Include old logs before 5.7** upgrade option from the filter -section to include all logs in your searches. If the option isn't selected, the filters apply +From the Filters section, select the **Include old logs before 5.7** upgrade option to include all +logs in your searches. If you don't select the option, the filters apply only to the new structure of logs. The **Date/Time(Client UTC)** field is also available as a filter option. ![Content Aware Protection Filters](capfilters.webp) For macOS users, when the Deep Packet Inspection feature is enabled on the Endpoint Protector agent -for macOS, certain scenarios might occur where the agent doesn't provide full destination details -for files being transferred from a network share through monitored applications, such as browsers. In -such cases, the destination information might not be fully captured. +for macOS, the agent might not provide full destination details for files transferred from a network +share through monitored applications, such as browsers. In such cases, the destination information +might not be complete. -For Linux users, the Endpoint Protector agent doesn't support network share visibility, except when -files are transferred from a network share through Deep Packet Inspection monitored applications, +For Linux users, the Endpoint Protector agent doesn't support network share visibility, except for +files transferred from a network share through Deep Packet Inspection monitored applications, such as browsers. ### Export Content Aware reports @@ -146,7 +146,7 @@ type, Matched type, Matched items, and Count. ![Creating Export](createexport.webp) -After the message displays that a new export has been made and is available on the Export List, +After the message displays that a new export is available on the Export List, click **View Export List** to open the list of Reports, where you can download or delete a report. ![Viewing Export List](viewexportlist.webp) @@ -157,15 +157,32 @@ click **View Export List** to open the list of Reports, where you can download o eDiscovery scan results are accessible from the Reports and Analysis section. The eDiscovery log view displays discovered files with their detection details, remediation status, and associated policies. -eDiscovery logs are stored in CrateDB and support the same filtering, sorting, and export capabilities as Device Control and Content Aware logs. +Endpoint Protector stores eDiscovery logs in CrateDB, and they support the same filtering, sorting, and export capabilities as Device Control and Content Aware logs. For detailed information on viewing and managing eDiscovery scan results, see [Scan results and actions](/docs/endpointprotector/admin/ed_module/edscanresults.md). ## Export list -The Export List shows all exports you've created, regardless of log type. Access it at any time by clicking **View Export List** in any log report section. The Export List includes exports for Device Control, Content Aware Protection, and eDiscovery logs. +The Export List shows all exports held on the server, regardless of log type. Access it at any time by clicking **View Export List** in any log report section. The Export List includes exports for Device Control, Content Aware Protection, and eDiscovery logs. -From the Export List you can download completed exports or delete entries you no longer need. +From the Export List you can download completed exports or delete entries you no longer need. Deleting an entry removes both the record and the archive file from the server. + +### Scheduled exports + +The Export List contains two types of export: exports you create manually, and exports Endpoint Protector generates automatically. + +Endpoint Protector generates a scheduled export once per day for each module: Device Control, Content Aware Protection, and eDiscovery. Endpoint Protector creates these scheduled exports during the upgrade to 2608, and they run without any configuration. + +Identify the two types by the file name prefix: + +- `Scheduled_Export_...` — Endpoint Protector generates these automatically. For example, `Scheduled_Export_Device_Control_Logs_2026-09-09 06:00:00`. +- `Generated_Export ...` — an administrator creates these manually. For example, `Generated_Export 2026-09-09_14-22-05`. + +Scheduled exports belong to the system rather than to an administrator, so no user name appears against them in the Export List. This is expected and doesn't indicate a configuration problem. + +:::note +You can't view, change, or disable the daily schedule for automatic exports from the interface. +::: ### Background processing @@ -184,12 +201,18 @@ When an export is in progress, a banner appears at the top of the page: Wait for the current export to finish before starting a new one. The banner disappears when processing is complete. Large exports might take several minutes depending on the number of records and the load on the server. :::note -If a system backup is running at the same time as an export, queued exports are cancelled automatically. Create the export again after the backup completes. +If a system backup is running at the same time as an export, Endpoint Protector cancels queued exports automatically. Create the export again after the backup completes. ::: ### Export retention -Completed exports are automatically deleted after seven days. +Endpoint Protector deletes completed exports automatically after a configurable retention period. The default is 29 days. It removes both the entry in the Export List and the archive file on disk. + +This cleanup applies to manual and scheduled exports alike, so exports don't accumulate on the server over time. + +:::note +Export retention controls how long Endpoint Protector keeps the generated export files. It doesn't affect how long Endpoint Protector stores the log data itself. To control log data retention, use the **Enable Log Rotate After** setting described in [Log Settings](/docs/endpointprotector/admin/systemconfiguration/systemsettings.md). +::: ## Admin actions @@ -200,7 +223,8 @@ Action column, you can view additional information. ## SCIM provisioning logs -The logs display detailed information for each SCIM request, including: +The logs display detailed information for each System for Cross-domain Identity Management (SCIM) +request, including: - Request ID - Timestamp @@ -291,8 +315,8 @@ for the active view. The page updates to reflect the saved filter settings and column visibility. :::note -When you return to a page where you previously used a saved filter, the last used filter and column -view are loaded automatically. +When you return to a page where you previously used a saved filter, Endpoint Protector loads the +last used filter and column view automatically. ::: ### Reset filters @@ -308,6 +332,6 @@ its default (unfiltered) state. ### Column visibility -Column visibility preferences are saved automatically per view. When you show or hide columns using -the **Show/Hide Columns** control, the change is retained for your administrator account on that -specific page. +Endpoint Protector saves column visibility preferences automatically per view. When you show or hide +columns using the **Show/Hide Columns** control, the change persists for your administrator account +on that specific page. diff --git a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md index 0c08efd391..e2498f0054 100644 --- a/docs/endpointprotector/admin/systemconfiguration/systemsettings.md +++ b/docs/endpointprotector/admin/systemconfiguration/systemsettings.md @@ -31,7 +31,7 @@ You can modify the following session timeout settings: - Timeout counter – set the amount of time for the session timeout countdown between 5 seconds and Session Timeout minus one minute -Example: If you set the Session Timeout to 5 minutes and the Timeout counter to 60 seconds, a pop-up window will notify you after 4 minutes of inactivity that you will be logged out in 60 seconds. +Example: If you set the Session Timeout to 5 minutes and the Timeout counter to 60 seconds, a pop-up window will notify you after 4 minutes of inactivity that Endpoint Protector will log you out in 60 seconds. ![Session Settings](sessionsettings.webp) @@ -54,14 +54,14 @@ or computer rights. Manage settings related to Smart Groups, Default Groups for Computers or Users. :::note -Smart Groups are dynamic groups for which membership can be defined based on element name +Smart Groups are dynamic groups whose membership you can define based on an element name pattern. ::: -- Enable Smart Groups – when this setting is disabled, it will convert Smart Groups to regular - groups with no entities assigned and will remove the Default Group for Computers and the Default - Group for Users. +- Enable Smart Groups – when you disable this setting, Endpoint Protector converts Smart Groups to + regular groups with no entities assigned and removes the Default Group for Computers and the + Default Group for Users. - Enable Default Group for Computers – this will create a default group for computers containing all computers that aren't part of a Smart Group. @@ -78,7 +78,7 @@ By disabling this setting, you will delete the Default Group for Users. ::: :::note -Smart Group sync job interval: the default configured time is 60 min. There is a possible configuration time between that goes from 15 min up to 1440 minutes. +Smart Group sync job interval: the default configured time is 60 min. You can configure an interval between 15 and 1440 minutes. ::: ![Smart Groups](SmartGroupSettings.png) @@ -93,7 +93,7 @@ and port. using the default port 443. :::note -Note: Ensure that your specified hostname and port settings comply with your network +Ensure that your specified hostname and port settings comply with your network policies and any security requirements. ::: @@ -124,7 +124,7 @@ Report .csv export as one row corresponds with one log. ::: -When having partitions for logs on the server, ensure the dates are also selected when making the +If the server has partitions for logs, also select the dates when making the export. - Reporting V2 – enabled by default, use this setting to modify the Content Aware Report log @@ -136,7 +136,7 @@ enabled by default. ::: -The structure enabled by this setting will also be reflected in SIEM. +SIEM also reflects the structure that this setting enables. - Set the Maximum number of reported threats per event to display in the Content Aware Report log structure, expanded Log Details section, in the Count column. @@ -146,6 +146,22 @@ You can set a number of reported threats between 100 and 1000. ::: +- Enable Log Rotate After – sets how long Endpoint Protector keeps logs on the server, in months. + The default is three months. Log rotation runs every five minutes and deletes Device Control, Content Aware + Protection, and eDiscovery logs older than the retention period, together with their associated + file shadows. For example, setting this option to 6 keeps six months of logs and removes anything + older. Set the value to 0 to disable log rotation. + +:::warning +Disabling log rotation means Endpoint Protector never removes logs automatically, and the server +continues to consume storage until you intervene. +::: + + +- Show old logs structure – displays logs collected before the migration to the 2608 database + structure. Enabling this option adds an **Export Audit Logs** tab and makes the legacy Audit Log + Backup sections visible. Leave it disabled if the server holds no pre-migration logs. + ![Log Settings](logsettings.png) ### Log Settings Use Case and Terminology @@ -189,12 +205,12 @@ performance. :::warning The Limit Reporting Content Aware Protection setting has priority over Ignore -Thresholds setting. If Limit Reporting Content Aware Protection is enabled, the reporting will stop -when the threshold is reached. +Thresholds setting. If you enable Limit Reporting Content Aware Protection, reporting stops +when the threat count reaches the threshold. ::: -The maximum number of reported threats will be automatically modified as follows: +Endpoint Protector automatically modifies the maximum number of reported threats as follows: | User Input | Input Updated | | ---------- | ------------- | @@ -211,16 +227,16 @@ Limit Reporting Content Aware Protection refers to Report Only policies. The "Content Aware Protection - Ignore Thresholds" toggle refers to Block & Report policies. -- When this toggle is On, scanning will not stop when a block verdict is determined, but will - continue to report further threats found in a transfer. -- To limit the number of reported threats in this case, the value of the "Maximum number of reported - threats" setting can be set to a value greater than zero. The set value is only indicative for the - number of reported threats, the actual number reported can be slightly larger. +- When this toggle is On, scanning doesn't stop at a block verdict, but continues to report further + threats found in a transfer. +- To limit the number of reported threats in this case, set the "Maximum number of reported threats" + setting to a value greater than zero. The value you set is only indicative for the number of + reported threats, the actual number reported can be slightly larger. -The ‘Global/Threat Threshold’ values in Content Aware Protection policies will be ignored/overridden -by the setting ‘Ignore Thresholds’ when the Boolean logic of the Content Aware Protection policy -contains at least one “AND” operator. A policy will be satisfied when the Boolean logic (example: see -below) is met with one or more matches per identifier. +The ‘Ignore Thresholds’ setting ignores and overrides the ‘Global/Threat Threshold’ values in +Content Aware Protection policies when the Boolean logic of the Content Aware Protection policy +contains at least one “AND” operator. A policy will be satisfied when the Boolean logic (see the +following example) is met with one or more matches per identifier. Eg. ( E-mail AND SSN US) OR CC Visa @@ -254,16 +270,16 @@ Protector Server - Etc. :::note -Identifiers that aren't part of the Boolean logic in a Content Aware Protection policy -will not be reported. +Endpoint Protector doesn't report identifiers that aren't part of the Boolean logic in a Content +Aware Protection policy. ::: Generally, a Content Aware Protection policy (Block & Report) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in the policy, the scan engine will ignore the ‘Threat Threshold’ setting and continue the scan until -the total threat of 10 is reached, no matter if “Limit Reporting” (under DEVICE CONTROL - Global -Settings) is being enabled or disabled. +the total threat of 10 is reached, regardless of whether “Limit Reporting” (under DEVICE CONTROL - +Global Settings) is enabled. Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in @@ -310,8 +326,8 @@ Protector Server Generally, a Content Aware Protection policy (Block & Report) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in the policy, the scan engine will ignore the ‘Threat Threshold’ setting and continue the scan until -the total threat of 4 from setting ‘Maximum number of reported threats’ is reached, no matter if -“Limit Reporting” (under DEVICE CONTROL - Global Settings) is being enabled or disabled. +the total threat of 4 from setting ‘Maximum number of reported threats’ is reached, regardless of +whether “Limit Reporting” (under DEVICE CONTROL - Global Settings) is enabled. Generally, a Content Aware Protection policy (Report only) will trigger when the Boolean logic of the policy is satisfied. However, with ‘Ignore Thresholds’ enabled and with 1+ ‘AND’ operators in @@ -430,17 +446,17 @@ After you’ve set all the mandatory information, scroll to the bottom of the se **Save** and then return to the Server Certificate Stack section and click **Regenerate Server Certificate Stack**. -The Server certificate will be regenerated in a couple of minutes, and the user will be logged out. +Endpoint Protector regenerates the server certificate in a couple of minutes and logs the user out. :::note -download the Deep Packet Inspection certificate again on both macOS and Linux, and -ensure that it is trusted in the respective keychain on each system. +Download the Deep Packet Inspection certificate again on both macOS and Linux, and +ensure that each system's keychain trusts it. ::: :::note -Regenerating the CA certificate requires manually adding it to the macOS keychain, as well -as to Linux systems. +Regenerating the CA certificate requires manually adding it to the macOS keychain and to Linux +systems. ::: @@ -480,11 +496,11 @@ To import an Active Directory group of administrators, follow these steps: **Step 1 –** Fill in the fields with the required information, considering: 1. In some cases, you need to add the domain in front of the username (domain\username) -2. Active Directory Administrators Group can be synchronized with any other groups of users except - for "primary groups" which is limited from this action by Microsoft +2. You can synchronize the Active Directory Administrators Group with any other groups of users + except for "primary groups", which Microsoft limits from this action -**Step 2 –** Scroll to the bottom of the page and save the changes. You will view a successful -message at the top of the page. +**Step 2 –** Scroll to the bottom of the page and save the changes. A success message appears at the +top of the page. **Step 3 –** Return to the Active Directory Authentication section and click **Test Connection** to confirm the process was successful. @@ -492,10 +508,10 @@ confirm the process was successful. **Step 4 –** Click **Sync AD Administrators**. :::warning -After the Active Directory Administrators Group has been defined, only users that are -part of this AD group will be synced and imported as Super Administrators for Endpoint Protector. -Any additional administrators (with different access control levels) can be created manually from -the System Administrators section. +After you define the Active Directory Administrators Group, Endpoint Protector syncs and imports +only users that are part of this AD group as Super Administrators. You can create any additional +administrators (with different access control levels) manually from the System Administrators +section. ::: @@ -504,7 +520,7 @@ the System Administrators section. ## E-mail Server Settings :::warning -The E-mail Server Settings have been moved to a new section. Go to **System Configuration** > **[Mail Settings](/docs/endpointprotector/admin/systemconfiguration/mailsettings.md)** to configure email server settings and authentication. +The E-mail Server Settings moved to a new section. Go to **System Configuration** > **[Mail Settings](/docs/endpointprotector/admin/systemconfiguration/mailsettings.md)** to configure email server settings and authentication. ::: ## Proxy Server Settings @@ -516,10 +532,10 @@ Configure Proxy server settings by managing the following: - IP and Port - Proxy access credentials (username/password) -After you provide all the information, click **Test** to confirm the settings are working successfully. +After you provide all the information, click **Test** to confirm the settings work. :::note -If a Proxy Server isn't configured, Endpoint Protector will connect directly to +If you don't configure a Proxy Server, Endpoint Protector will connect directly to liveupdate.endpointprotector.com. ::: @@ -534,13 +550,13 @@ Edit contact details for the main administrator and then click Save to keep all ### Server Display Name -Endpoint Protector users can visually differentiate environments within the Endpoint Protector console, ensuring precise identification and preventing unintended actions in the wrong environment. This customization feature lets users add custom text at the Endpoint Protector logo on the login page and alongside the logo in the console header. Users can also upload a custom logo for further personalization. +Endpoint Protector users can visually differentiate environments within the Endpoint Protector console, ensuring precise identification and preventing unintended actions in the wrong environment. This customization feature lets users add custom text at the Endpoint Protector logo on the login page and alongside the logo in the console header. Users can also upload a custom logo. -Organizations managing multiple EPP Server consoles (such as production and testing environments) can use distinct visual cues—custom text, icon markings, and extended legal banners—to differentiate between them. These elements help administrators identify the environment they are working in and ensure appropriate console usage. +Organizations managing multiple Endpoint Protector Server consoles (such as production and testing environments) can use distinct visual cues—custom text, icon markings, and extended legal banners—to differentiate between them. These elements help administrators identify the environment they are working in and ensure appropriate console usage. To customize these elements, refer to the image in the Server Display Name section. You can enable custom login and header displays, enter your desired text, and choose colors to highlight your environment’s uniqueness. You can also upload a custom logo and configure legal banners for clarity and compliance. Using these visual indicators helps administrators distinguish between different operational contexts and enhance both security and workflow efficiency. -![EPP Server Display Name](serverdisplayname.webp) +![Endpoint Protector Server Display Name](serverdisplayname.webp) :::note The legal banner placeholder can accommodate up to 5,000 characters. diff --git a/docs/endpointprotector/admin/systemmaintenance/overview.md b/docs/endpointprotector/admin/systemmaintenance/overview.md index b8e763def1..eae294e1b9 100644 --- a/docs/endpointprotector/admin/systemmaintenance/overview.md +++ b/docs/endpointprotector/admin/systemmaintenance/overview.md @@ -27,10 +27,10 @@ of files from the Endpoint Protector Server, click **Delete**. ## Exported Entities -From this section, you can view the list of exported entities, download or delete them, and view the -scheduled export in the system and reschedule them accordingly. +From this section, you can view the list of exported entities. You can also download or delete them, +view the scheduled export in the system, and reschedule them accordingly. -![View the list of exported entities, download or delete them, and view the scheduled export in the system and reschedule them accordingly](listofentities.webp) +![List of exported entities with options to download or delete them and to view or reschedule the scheduled export](listofentities.webp) You can initiate the manual generation of the scheduled export from the Device Control, List of Devices / List of Computers / List of Users / List of Groups sections. @@ -39,15 +39,15 @@ Devices / List of Computers / List of Users / List of Groups sections. ![Manual generation of the scheduled export from the Device Control](dcscheduleexport.webp) -The scheduled exports can be sent automatically via e-mail to all the Administrators that have the -**Scheduled Export Alert** setting enabled. +Endpoint Protector can send the scheduled exports automatically by e-mail to all the Administrators +that have the **Scheduled Export Alert** setting enabled. -The Scheduled Exports are reoccurring (Daily / Weekly or Monthly), and, as such, will continuously -take up more and more storage on the Endpoint Protector Server. +The Scheduled Exports are reoccurring (Daily / Weekly or Monthly), and so they take up progressively +more storage on the Endpoint Protector Server. -To maintain performance—and since scheduled exports can also be sent automatically via email to -specific administrators—scheduled exports already generated are automatically deleted from the -server after 14 days. +To maintain performance—and because Endpoint Protector can also email scheduled exports to specific +administrators—the server automatically deletes scheduled exports it has already generated after 14 +days. The Disable Logging option lets you keep logs on the Endpoint Protector Server or only in the SIEM Server. @@ -56,7 +56,7 @@ The Disable Logging option lets you keep logs on the Endpoint Protector Server o The System Snapshots module lets you save all device control rights and settings and restore them later if needed. :::info -After installing the Endpoint Protector Server, create a System Snapshot before modifying anything. This way, you can revert back to the original settings if you configure the server incorrectly. +After installing the Endpoint Protector Server, create a System Snapshot before modifying anything. This way, you can revert to the original settings if you configure the server incorrectly. ::: **Step 1 –** Go to **System Configuration** and click **Make Snapshot**. @@ -75,14 +75,24 @@ then confirm your action. ## Audit Log Backup +:::warning +Audit Log Backup is a legacy feature. From Endpoint Protector 2608, it applies only to logs collected +before the migration to the new database structure, and it receives no new log data. Endpoint Protector +exports logs collected from 2608 onward through **Reports and Analysis** > **Export Logs** instead. Base any new +log export process on Export Logs rather than Audit Log Backup. +::: + +To display this section, enable **Show old logs structure** under **System Configuration** > +**System Settings** > **Log Settings**. Servers that hold no pre-migration logs don't need it. + Like the Log Backup and Content Aware Log Backup sections, this area lets you save and export old logs. You can select the number of logs to export, specify the period, and set the file size. -Additionally, options are available to view a Backup List or set a Backup Scheduler. +You can also view a Backup List or set a Backup Scheduler. -Both the Audit Log Backup and Audit Backup Scheduler offer several options like what type of logs to -backup, how old should the included logs be, to keep or delete them from the server, to include file -shadows or not, etc. +Both the Audit Log Backup and Audit Backup Scheduler offer several options, such as which types of +logs to back up, how old the included logs must be, whether to keep or delete them from the server, +and whether to include file shadows. -![Allows old logs to be saved and exported](auditlogbackup.webp) +![Audit Log Backup section for saving and exporting old logs](auditlogbackup.webp) However, exported logs use an improved visual format that makes auditing simpler and report generation easier for executives. @@ -92,7 +102,7 @@ The Backup export CSV file will differ based on the Endpoint Protector Server v - For Endpoint Protector 5.7.0.0, reports, only one file containing all threats discovered, separated by an underscore -When backing up Content Aware logs, the export includes the **Date/Time(Client UTC)** field. +When you back up Content Aware logs, the export includes the **Date/Time(Client UTC)** field. :::warning The audit log backups feature lets you create copies and/or exports of logs and file shadows, either manually or on a scheduled basis. The initial storage location for export files isn't suitable for long-term storage. Download and store these files in secure locations. In SaaS environments, upgrades may delete export files, so download them regularly and store them securely. @@ -110,6 +120,12 @@ the time and frequency (daily, weekly, monthly, yearly, etc.). From this section, you can externalize files generated by Endpoint Protector to network storage. You can save Shadows, Audit Log Backups, and System Backups to FTP, SFTP, Samba, or Network Share servers. +:::note +The **Audit Log Backup** externalization option covers legacy pre-migration logs only, because Audit +Log Backup itself receives no new log data from Endpoint Protector 2608 onward. Shadows and System +Backups are unaffected. +::: + You can enable the option to keep a copy of the files on the Endpoint Protector Server for all External Storage Types.