Product

Data Guard File Integrity Monitoring

Know when a file, directory or permission changes against a baseline you set — including the bulk change that matters more as one event than as thousands of lines.

Overview

Not Every Risk Is Data Leaving

Some risks are data changing while it stays exactly where it is. A configuration file overwritten outside a change window. A contract altered after it was approved. A directory of records modified at three in the morning when nobody was working. A permission quietly widened so a folder became readable across the organisation.

File integrity monitoring watches the locations you nominate and reports change against a baseline you set. The point is not to log everything — logs nobody reads are not evidence. The point is that an expected change stays quiet and an unexpected one does not, and that when you look at a change later you can see what the file was before as well as after.

Why It Matters

Integrity Is the Check on Everything Else

Four gaps that only change monitoring closes.

Prevention is never complete

Controls stop what they are configured to stop. Change monitoring is how you find out about the thing that got through.

Legitimate access, illegitimate use

Someone with valid permissions altering a record does not trigger an access alert, because nothing about the access was wrong.

Bulk change looks like noise

Thousands of files modified in minutes is one significant event, but most tooling reports it as thousands of separate lines nobody reads.

Nobody kept the before

Knowing a file changed is far less useful than being able to see what it said before somebody changed it.

Capabilities

Change You Can See, Explain and Prove

Six capability areas built around keeping the signal usable.

Baselines you define

You nominate which files and directories matter. Everything is measured against that known-good state rather than against a general assumption.

  • Baseline any file or directory you choose
  • Re-baseline after an approved change
  • Group locations so they are managed together

What counts as a change

Content is the obvious one, but a permission change or a quiet move is often the more meaningful signal.

  • Additions, modifications and deletions
  • Permission and ownership changes
  • Renames and moves within a watched location

Expected change stays quiet

A deployment window or a scheduled job should not produce alerts. Declaring what is routine is what keeps the unexpected visible.

  • Declare change windows per location
  • Expected processes recorded but not raised
  • Anything outside the window is raised

Bulk change as one event

When many files change together, that pattern is the finding. It is raised as a single event describing the shape of what happened.

  • Mass modification grouped into one finding
  • Scope, timing and rate described together
  • Individual files still available underneath

Before and after

The state of a monitored file is retained on both sides of a change, so an investigation reads the difference rather than inferring it.

  • Prior state retained for a monitored change
  • Attribution: who made the change, and when
  • Retention period set by you

Runs where the servers are

Monitoring continues on a host with no outbound connection, and records reconcile centrally once the link is available again.

  • Continues with no connection present
  • Resource ceilings you configure per host
  • Central view across all monitored locations
Open by Design

Change Events Belong in Your Existing Pipeline

Integrity findings are written as structured events in the same record as policy decisions, so an investigation does not have to join two systems by hand.

  • Structured event output for every change raised
  • Outbound notification on a change outside its window
  • Authenticated API for baselines, events and state
  • Scheduled export for reporting and archive systems
  • Shares one event record with the rest of the platform
Where Teams Use It

Four Situations Integrity Monitoring Is Built For

Configuration drift

A setting changed outside a change window is often the first visible sign of either a mistake or an intrusion.

Mass encryption events

A large number of files rewritten in a short period has a distinctive shape, and raising it as one event is what makes it noticeable.

Documents altered after approval

A signed agreement or an approved record that changes afterwards, with the previous state kept so the difference is provable.

Access that widened quietly

A permission change on a sensitive directory is reported as a change in its own right, not only as a difference at the next scan.

What Sets It Apart

Why This Integrity Monitoring

01

It protects the signal

Declared change windows and grouped bulk events exist so the alerts that do arrive are worth reading. An unread log is not evidence.

02

The before state is kept

An investigation can read what changed rather than reconstructing it from a timestamp and a hash.

03

One record with the rest

Change events sit beside policy decisions in the same searchable record, so an incident reads as one sequence.

04

Keeps working in isolation

A monitored host with no outbound connection keeps recording, and reconciles centrally when the link returns.

Questions

Frequently Asked

Will this flood us with alerts?

That is the main design problem, and it is addressed two ways: you declare the change windows and processes that are routine, and bulk change is raised as one event rather than thousands.

Does it keep a copy of our files?

It retains the prior state of a file you have explicitly put under monitoring, for the retention period you set, so a change can be examined. Nothing outside your nominated locations is retained.

What if the server has no internet connection?

Monitoring continues locally and the records reconcile with the central view once a connection is available again.

Does it detect permission changes, or only content?

Both. Permission and ownership changes are reported as changes in their own right, which is often the more meaningful signal.

How does this relate to the other three products?

The other three deal with data moving. This one deals with data changing where it sits. All four write to the same event record, so an investigation covers both without joining systems by hand.

The Rest of the Platform

Works With

The four products are designed to hand work to each other. Each one is stronger for what the others produce.

Name the Directory That Worries You

Integrity monitoring is easiest to judge against a location you already consider sensitive. Tell us which one and we will baseline it in the session.

EN عربي
Request a Demo ›