Registry Management Test

Typically, changes to the Windows Registry have to be carried out carefully, and on a need-only basis. If such changes are wrongly done, particularly on a mission-critical server such as the Active Directory server, they can adversely impact the availability, operations, and performance of the server. AD administrators therefore need to have their eyes open for registry changes, capture such changes as and when they occur, and find out what changed and who did it. To achieve this, administrators can use the Registry Management test.

This test tracks registry changes on the AD server and notifies administrators when such changes are made. The detailed diagnostics of the test additionally describes the registry entry that was changed and the user who made the change. With the help of this information, administrators can figure out whether/not the change was valid and was done by an authorized person.

Target of the test : An Active Directory

Agent deploying the test : An internal agent

Outputs of the test : One set of results for every Active Directory site that is being monitored

Configurable parameters for the test
Parameters Description

Test period

This indicates how often should the test be executed.

Host

The IP address of the machine where the Active Directory is installed.

Port

The port number through which the Active Directory communicates. The default port number is 389.

DD Frequency

Refers to the frequency with which detailed diagnosis measures are to be generated for this test. The default is 1:1. This indicates that, by default, detailed measures will be generated every time this test runs, and also every time the test detects a problem. You can modify this frequency, if you so desire. Also, if you intend to disable the detailed diagnosis capability for this test, you can do so by specifying none against DD Frequency.

Detailed Diagnosis

To make diagnosis more efficient and accurate, the eG Enterprise embeds an optional detailed diagnostic capability. With this capability, the eG agents can be configured to run detailed, more elaborate tests as and when specific problems are detected. To enable the detailed diagnosis capability of this test for a particular server, choose the On option. To disable the capability, click on the Off option.

The option to selectively enable/disable the detailed diagnosis capability will be available only if the following conditions are fulfilled:

  • The eG manager license should allow the detailed diagnosis capability
  • Both the normal and abnormal frequencies configured for the detailed diagnosis measures should not be 0.
Measurements made by the test
Measurement Description Measurement Unit Interpretation

Registry value changed

Indicates the number of times during the last measurement period registry values were changed.

Number

The detailed diagnosis of this measure describes the change and points administrator to the user who made the change.