Active Directory
S. No. | Folder Path | Notes |
1 | C:\lepidedebugdeep | For AD Logs |
2 | C:\lepidedebugdeepdeep | For AD Logs |
3 | C:\lepidedebugdeepgp | For GPO Logs |
4 | C:\lplogondbg | On the end computer for Logon Logoff debug |
5 | C:\LPEnumADUser and collect the file InitDlg.txt | Web Console |
6 | C:\dumpqry_one\log.txt (create this file log.txt in this folder to generate logs) and C:\LepideScanLog | Permission Scans |
7 | C:\Program Files (x86)\Lepide Data Security Platform\FSA\MBExchLogFile.txt | Exchange Permission Scan |
8 | C:\LepperQuerylog (create this folder and run the PBO report) | Permission by Object report not generating |
9 | Search-mailboxauditlog -Showdetails | out-file c:\logs.txt | Command to check the last date of access performed in Exchange Server for Non-Owner Mailbox issue |
10 | Customer not receiving Threat Model Alerts emails. |
|
11 | Customer having issue with Agent installation on Server core OS. | From the Server OS GUI machine, check the file OLEDLG.dll from the path C:\Windows\system32 and C:\Windows\Syswow64. Copy the file from each location and paste it in Server Core OS in the same locations (C:\Windows\system32 and C:\Windows\Syswow64). Then Reinstall the Agent. |
12 | Receiving Critical Notification for LASALERT. | Delete these three keys from registry LASAlertsDetails, LASALerts_err, LASAlerts_stat Registry path: HKEY_Local_Machine --- Software ---- Wow6432node----LepideAuditor Suite-----LepideAuditorSuite----LCILPEL |
13 | C:\PDAlertAD | For debug log on threat model for AD |
14 | C:\Lp_ndbg | For Debug log in Non Owner mailbox |
15 | lepidedebugdeep | For AD back up issues. |
File Server
S. No. | Folder Path | Notes |
1 | C:\Windows\LFSAgent\DeepLog | Stop the auditing from the File Server Settings Console. |
2 | C:\Windows\LFSAgent\FSAAgentLog.txt | Collect this file for any agent related issue in case of indirect insertion. |
3 | FSAAlertLog in the installation diretory | For File Server alert issue with change alert |
4 | FSAAlertLog_ALLCOMP in the installation direcotry | for other components alert issue except file server |
5 | PDAlertFSA in the installation directory | For File Server Threat Model |
SIEM
C:\lepthadbg_M | SIEM alert debug log |
C:\lepthadbg_SIEM |
Archive
Archiving | |
Normal Debug Logs for Archiving | Lepide Data Security Platform\ArchiveModules\Logs |
enable deep log for Archiving, create a file under this location | Lepide Data Security Platform\ArchiveModules\SQLArchiver_LogTrigger |
SharePoint on Premise
S. No. | Folder Path | Notes |
1 |
|
|
2 |
|
|
3 |
|
|
4 |
|
|
5 |
|
|
6 |
|
|
7 |
|
|
8 |
|
|
9 |
|
|
10 |
|
|
Exchange Online
S. No. | Folder Path | Notes |
1 | ExchangeOnlineErrorLogs > DebugLog |
|
2 |
|
|
3 |
|
|
4 |
|
|
5 |
|
|
Scheduler
S. No. | Folder Path | Notes |
1 | C:\sch_elmp | To get debug logs of scheduler |
2 |
|
|
3 |
|
|
4 |
|
|
5 |
|
|
6 |
|
|
7 |
|
|
8 |
|
|
9 |
|
|
10 |
|
|
Current Permissions Analysis
S. No. | Folder Path | Symptoms |
1 | C:\dumpqry_one\log.txt |
|
2 | C:\LepideScanLog |
|
3 | <installation directory>\FSA\CPALog |
|
4 | <installation directory>FSA\MBExchLogFile.txt | This is for Exchange |
5 |
|
|
6 |
|
|
7 |
|
|
8 |
|
|
9 |
|
|
10 |
|
|
LUPER
S. No. | Folder Path | Notes |
1 | <installation directory>\LUPER\ShowLog | This writes the logs for LUPER issues, like, email notification failed to send.,etc. |
2 |
|
|
3 |
|
|
4 |
|
|
5 |
|
|
6 |
|
|
7 |
|
|
8 |
|
|
9 |
|
|
10 |
|
|
Web Console
S. No. | Folder Path | Notes |
1 | C:\LPEnumADUser |
|
2 |
|
|
3 |
|
|
4 |
|
|
5 |
|
|
6 |
|
|
7 |
|
|
8 |
|
|
9 |
|
|
10 |
|
|
SQL Server
S. No. | Folder Path | Notes |
1 | Se |
|
2 |
|
|
3 |
|
|
4 |
|
|
5 |
|
|
6 |
|
|
7 |
|
|
8 |
|
|
9 |
|
|
10 |
|
|
Session Recording
S. No. | Folder Path | Notes |
1 | C:\Windows\M_ourfol3, | On the Agent Machine to check Session rec agent is installed |
2 |
|
|
3 |
|
|
4 |
|
|
5 |
|
|
6 |
|
|
7 |
|
|
8 |
|
|
9 |
|
|
10 |
|
|