Arctera Enterprise Vault™ Insight Surveillance Installation Guide
- Introducing Insight Surveillance
- Preparing to install Insight Surveillance
- Configuration options for Insight Surveillance
- Supported versions of Enterprise Vault in Insight Surveillance environments
- Prerequisites for Arctera Insight Surveillance
- Configuring Outlook to enable the processing of items with many attachments or many recipients
- Setting the Windows and ASP.NET Temp folder permissions
- Security requirements for temporary folders
- Disabling networking facilities that can disrupt a Insight Surveillance environment
- Disabling the Windows Search Service on the Insight Surveillance server
- Ensuring that the Windows Server service is running on the Insight Surveillance server
- Configuring the SQL Server Agent service
- Assigning SQL Server roles to the Vault Service account
- Installing and configuring the SQL full-text search indexing service
- Verifying that Enterprise Vault expands distribution lists
- Configuring Intelligent Review API Authentication and Authorization
- Installing Insight Surveillance
- Installing the Insight Surveillance server software
- Allowing Enterprise Vault to communicate with Insight Surveillance through the Windows firewall
- Creating the configuration database and customer databases
- Configuring a dedicated server for Intelligent Review processing (optional deployment configuration)
- Configuring Insight Surveillance for use in a SQL Server Always On environment
- Installing Insight Surveillance in a clustered environment
- Maximizing security in your Insight Surveillance databases
- Uninstalling Insight Surveillance
- Installing the Insight Surveillance server software
- Appendix A. Ports that Insight Surveillance uses
- Appendix B. Troubleshooting
- Error messages appear in the event log when upgrading to Insight Surveillance 15.2
- Enterprise Vault eDiscovery Manager service not created
- Enterprise Vault eDiscovery Manager service does not start
- "Access is denied" message is displayed when you try to create a customer database on a UAC-enabled computer
- Cannot create or upgrade Insight Surveillance customer databases when Symantec Endpoint Protection is running
- Error messages when the Intelligent Review (IR) API authentication and authorization fails
- Appendix C. Installing and configuring the Enhanced Auditing feature
- Overview
- Prerequisites for the Enhanced Auditing feature
- Installing the Enhanced Auditing feature
- Post installation steps
- Upgrading the Enhanced Auditing setup
- Modifying the Enhanced Auditing setup
- Repairing the Enhanced Auditing setup
- Uninstalling the Enhanced Auditing setup
- Managing access from Arctera Insight Surveillance
Assigning SQL Server roles to the Vault Service account
The Vault Service account is the account that Enterprise Vault services and tasks use when accessing Enterprise Vault databases. You must assign a number of SQL Server roles to this account to perform various activities with Insight Surveillance. The two required roles are as follows:
dbcreator (database creator). The facility to create configuration and customer databases with Insight Surveillance is dependent on the Vault Service account having this role.
sysadmin (system administrator). Insight Surveillance provides the facility to create schedules with which you can conduct searches repeatedly or at some future time. These schedules are SQL Server Agent jobs and, by default, Insight Surveillance assumes that you want to make a user with the sysadmin role the creator and owner of them.
Note:
The dbcreator and sysadmin roles are server-wide roles that may grant more security privileges to the Vault Service account than you are comfortable with. If this is the case, you can give the Vault Service account the minimum required permissions by following the instructions in this article on the Arctera Support website:
https://www.veritas.com/docs/100038151
After the Insight Surveillance is installed, you must change the value of the security configuration option "Use SQL Server SysAdmin Server Role for Schedules". For instructions on how to do this, see the Administrator's Guide.
To assign SQL Server roles to the Vault Service account
- On the SQL Server computer, start SQL Server Management Studio.
- In the left pane of the SQL Server Management Studio window, expand the tree to display first the required SQL Server and then the Security folder.
- Under the Security folder, double-click Logins to display the users in the right pane.
- In the Logins list, right-click the Vault Service account, and then click Properties.
- In the Login Properties dialog box, select the Server Roles page.
- In the Server roles box, make sure that dbcreator and sysadmin are selected.
- Click OK.