Help Menu

File Sight Endpoint

By itself, the File Sight monitor sees activity on a file server, which includes which users are accessing files, what actions (reading, writing, deleting, etc) they are doing, their IP address, etc. However, once a file arrives on the client's computer, the server-based File Sight monitor can't see what is happening. Is the file being copied to a thumb drive? Opened in Word? Sent via Email? The File Sight Endpoint helps answer those questions.

The File Sight Endpoint is a small agent that gets installed on end-user Windows computers. It uses very little resources and shouldn't be noticed. It has no user interface.

By detecting a file being read from the server by Explorer.exe and then that same filename being written to the local computer, you can be fairly certain that a file copy is taking place. On the other hand, if you find the file was read into a process named Word.exe, and no local saves took place, this would appear to be a user just editing a document.

The File Sight Endpoint will add additional information to file I/O records that are saved by the File Sight Monitor. These extra fields will be in alerts and available in reports.

The client and server both need to be Windows 7 / Windows 2008 R2 or newer for the server to know which Endpoint to communicate with. If either is older, an older version of the SMB protocol is used which did not provide the client IP address.

Normal ClientClient with the File Sight Endpoint*
  • File Name
  • Time
  • File Operation
  • User Account
  • User IP Address*
  • User Computer*
  • Server Process
  • File Name
  • Time
  • File Operation
  • User Account
  • User IP Address*
  • User Computer*
  • Server Process
  • Client Process (Explorer.exe, Word.exe, etc)
  • Logged In User (usually same as User Account above)
  • List of files written by the Client Process
  • Probable Copy (meaning the file is probably being copied)
* Requires that the server and client are both Windows 7 / 2008 R2 or newer

The File Sight Endpoint performs the following functions:

We use the term "probable copy" because the actual file contents are not compared between all files read and all files written. This would have a large performance impact on the client computer. Instead, the File Sight Endpoint notes that a file (Finance.xls for example) is read from the network, and then a file also named Finance.xml is saved to disk by the same process (Explorer.exe for example). This looks very much like a copy.

Configuration

No changes to the File Sight monitor are required. If files are accessed from a computer running the File Sight Endpoint, the extra data will automatically be recorded and added to any alerts that are sent.

The only configuration needed for the File Sight Endpoint is to give a host name/IP address and port for the central service/Satellite that will be used for communication. This is done via the command line.

Only one connection to a central service/Satellite is needed. If the client computer will use files from multiple files servers that are all being watched by PA File Sight, and they are all part of the same Ultra installation, they will communicate amongst themselves to find the File Sight Endpoint if needed.

Installing the File Sight Endpoint

The actual File Sight Endpoint is found at:

C:\Program Files (x86)\PA File Sight\Install\pafsendp.exe

It does not require any additional files.

The File Sight Endpoint executable program (pafsendp.exe) just needs to be copied to a client computer and run with some command line options to direct it to the server it should connect to. The copy and execution steps can be done using any techniques or infrastructure that you already use. So the steps are simply:

  1. Copy pafsendp.exe to the client computer
  2. Run pafsendp.exe with configuration command-line options given below
  3. Start the pafsendp service on the client computer

The endpoint supports a few command line options. The command line options are not case sensitive.

-SDon't show a pop-up when installing or uninstalling the service
-IInstall the endpoint as a service named pafsendp
-UUninstall the endpoint as a service
-HOST={host:port}
-HOST2={host:port}
-HOST3={host:port}
-HOST4={host:port}
Give the hostname or IP address, and port, of the PA File Sight Central Service, or a Satellite that should be connected to. Because Satellites might be unavailable at times, or just for added robustness, additional hostnames can be given which the Endpoint will connect to if the current target host is not available.
-LOCKSet the endpoint service so it cannot be stopped. Unlocking happens via the Console in the Endpoint Operations view.

A few notes:

IMPORTANT

If you are monitoring servers at multiple sites (separate local networks), be sure the Endpoint is connected to and communicating with a Satellite or the Central Service that is on the same local network as the Endpoint.

Example Install Script

An example installation script is given below to show how to get the File Sight Endpoint installed on an end-user's computer. This example uses Microsoft's PsExec program. It also uses Sleep.exe which is in the same folder as pafsendp.exe.

REM Install the File Sight Endpoint service. PsExec will copy
REM pafsendp.exe to the client computer's Windows folder.
REM Run this from the C:\Program Files (x86)\PA File Sight\Install folder
REM so pafsendp.exe can be found by PsExec

psexec \\{target server} -u {username} -p {password} -c -d -h -v
    pafsendp.exe "-s -i
    -host={central service/Satellite IP address:port} -host2={failover service/second Satellite IP address:port} -lock"

REM wait just a bit for installation to finish

Sleep.exe 15000

REM start the remote service

psexec \\{target server} -u {username} -p {password} -s net start pafsendp

In the example below, our target client computer is 192.168.7.6. We'll be using an administrator account, with password s3cr3t. The central service is at 192.168.7.22, running on port 8000, with a Satellite at 192.168.10.4 that we'll use as a secondary connection.

CD "C:\Program Files (x86)\PA File Sight\Install"

c:\tools\psexec \\192.168.7.6 -u administrator -p s3cr3t -c -d -h -v pafsendp.exe "-s -i -host=192.168.7.22:8000 -host2=192.168.10.4:8000 -lock"

sleep.exe 15000

c:\tools\psexec \\192.168.7.6 -u administrator -p s3cr3t -s net start pafsendp

File Sight Endpoint Status

You can check to see which computers have the File Sight Endpoint installed and running by looking in the Console at Advanced Services > File Sight Endpoints.

If you have some File Sight Endpoints that are not up to the latest version, you can right click the File Sight Endpoint node and choose to have an update command sent to them.


PA File Sight

Help Map