The Logon Collector and Logon Monitor run as Microsoft Windows services on a Windows Server, and require a system that meets these minimum requirements:
Component | Minimum requirement |
|---|---|
Operating System | Any one of the following Microsoft operating systems:
NoteWindows Server 2008 and 2008 R2 are not supported. |
Operating System — Domain controllers | Any one of the following Microsoft servers:
|
RAM (memory) | 4 GB or higher |
Disk space | 20 GB free space |
Processor | Pentium IV 2 GHz or faster |
Software framework | Microsoft .NET framework 3.5 NoteTrellix highly recommends to enable the .NET framework 3.5 to successfully install Logon Collector3.0. |
Browser |
NoteTrellix recommends to use the latest browser versions. |
Network connectivity | From Logon Collector servers to the domain controllers of the Microsoft Active Directory domain that the Logon Collector or Logon Monitor is monitoring |
Resolution | Display set to a resolution of 1024x768 or greater |
Monitored Domains | The domain user (entered while adding domain in Logon Collector) must have access rights to the security events logs on each domain controller |
Domain controllers | Domain controller's functional level should not be higher than Logon Collector's Windows Server version. Domain controllers must have port 389 enabled for LDAP and Secure LDAP queries. |
JRE | Version 8u331 or later |
Microsoft SQL Server | Versions later than Microsoft SQL server 2008, or SQL Server 2008 Express edition |
Tip
Consider installing the Logon Monitor on a virtual machine as the Logon Monitor is a less demanding application, and does not transmit as much information as the Logon Collector.
Note
The Logon Monitor memory usage depends on the number of users and groups in its database.
For more information, refer to Trellix Logon Collector 3.0 Administration Guide.