Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleWhat is the format for classification log
Info

The result format is selected from the GEODI classification policy manager. DB, syslog, CEF pr CSV options are available.

Ypu You may use a SIEM or Log Analysis Dashboard to monitor and analyse the logs.

GEODI Classifier Log Analysis Panel and Classifier Project

Expand
titleHow will the agents deploy?
Info
  • You can use ManageEngine, PDQ, SCCM or a similar tool. GEODI Classification solution automatically generates the MSI and parameters required for agent deployment. Updating of agents is automatic, checked every 2 days.

  • If a there is few machine you can manually run the MSI.

  • Agents are monitored from a panel. GEODI Agent Management Panel

GEODI Classifier Windows Client Installation

...

Expand
titleCan Classification Add-ons work offline
Info

Yes, offline is possible for add-ons

  • The add-ons must at least once access to GEODI server to get the policies

  • Only Manual classification is possible. The automatic classification is not available.

  • Rules from the last connection are used.

  • Logs are accumulated and transferred when a connection to the server is established.

Expand
titleHow are files without label support classified?
Info
  • Files without label support are classified using the ADS (Alternate Data Stream) method for file types other than PDF and Office documents.

Expand
titleHow can see ADS labels?

ADS(Alternate Data Stream) is an NTFS feature. You may use “dir /r" command to list them.

ADS labels are a feature of the NTFS filesystem and may not be preserved in some cases.

  1. Labels are preserved

    1. Rename the file

    2. Change file extension txt → log - mp4 → avi

    3. Copy the file to another NTFS filesystem with or w/o the GEODI classifier installed.

  2. Labels are not preserved

    1. The file is copied through RDP, Wetransfer, or similar ways.

    2. The file is copied to non-NTFS filesystem

    3. The file is carried in a compressed file (Rar/zip=

    4. The file is attached to an e-mail

...