View audit reports
Export configuration audit reports
-
In NetScaler Console, navigate to Infrastructure > Configuration > Configuration Audit.
-
On the Configuration Audit page, click inside the NetScaler Config Drift chart.
-
The Audit Reports page lists instances that have a difference. The page also displays a list of instances that does not have any difference in their running configurations.
In the image you can see that for some instances a diff is present only in Saved Vs Running Diff and for some instances, a diff is present only in Template vs Running Diff. For some instances, differences exist in both Saved Vs Running Diff and Template vs Running Diff.
-
Compares the audit template configuration with the running configuration on the instance.
-
Compares the running configuration on the instance with the audit template.
View the file status audit reports
nsconfig folder. For example: if the license file is updated on a NetScaler instance, you can check when this file was last updated and take actions appropriately.
-
In NetScaler Console, navigate to Infrastructure > Configuration > Configuration Audit.
-
On the Configuration Audit page, click inside the NetScaler File Status chart.The Audit Reports page lists instances with the Diff status.
The Diff Status is calculated for the interval between the Previous Polled Time to the Latest Polled Time. The Diff Status can be one of the following:-
Diff exists - This status indicates the files have changed in the
nsconfigfolder of an instance since the Previous Polled Time. To view what has changed on the file, click Diff Exists.
-
No Diff - This status indicates the files in the
nsconfigfolder hasn't changed since the previous polled time. -
NA - This status indicates monitoring the file status is not applicable. This status appears when the NetScaler Console doesn't poll the instance. For example, when an instance is added newly or instance state is inactive the polling of the instance doesn't occur.
-
Export the report of this dashboard
-
Select Export Now tab. To view and save the report in PDF, JPEG, PNG, or CSV format.
-
Select Schedule Export tab. To schedule the report daily, weekly, or monthly and send the report over email or slack message.
-
If you select Weekly recurrence, ensure that you select the weekdays on which you want the report to be scheduled.
-
If you select Monthly recurrence, ensure that you enter all the days that you want the report to be scheduled separated by commas.
Exclude files from Config Audit
-
Valid file name (or relative path)
-
ns.conf,ssl/ns.cert
-
-
Invalid file name (or relative path)
-
/ns.txt,\nsconfig\ns.conf(Excluded file name must be a relative path) -
ñs.conf(Excluded file name must contain only ASCII characters) -
C:/nsconfig/ns.conf(Excluded file name must not use drive-letter paths) -
ssl/../../ns.conf(Excluded file name must not contain parent-directory traversal..)
-
-
All files under
/nsconfig/license/are excluded from Config Audit by default. NetScaler Console writes LAS files to this directory every 8 hours during token refresh cycles. Since these files are entirely NetScaler Console-managed and not part of the customer's NetScaler configuration, they trigger false-positive Diff Exists alerts. Thelicense/directory is now seeded as a default exclusion to prevent this false-positive. You can remove this exclusion if needed. -
File diff comparison is applicable only to files under the
/nsconfigdirectory. -
When excluding files from Config Audit, users must specify relative paths under
/nsconfig. For example, if there is ansslfolder under/nsconfig, exclusions can be provided as:ssl/abc.pem -
File differences outside
/nsconfigare not considered as part of the Config Audit diff.
-
Navigate to Infrastructure > Configuration > Configuration Audit.
-
Select Settings.
-
Under NetScaler Config File Settings, add the file paths you want to exclude from auditing.
-
Click Save.