Enabling or disabling file integrity validation

Last Updated : Sep 26, 2022 |

About this task

You can enable file integrity validation on Avaya Common Services servers if you require Advanced Intrusion Detection Environment (AIDE) logs. By default, file integrity validation is disabled.

When file integrity validation is enabled, the server contains additional log files that consume up to 400 MB of additional disk space. This feature also consumes additional CPU while initializing the integrity database and executing the validation. By default, the file integrity validation software runs at 3:00 a.m. every day, but this can be delayed depending on when the validation is enabled.

  • If the validation is enabled before 3:00 p.m., the first report is ready by 3:00 a.m. the following day.

  • If the validation is enabled after 3:00 p.m., the first report might be ready by 3:00 a.m. the following day or it might be delayed until 3:00 a.m. on the day after.

AIDE logs are only generated if the system detects a problem.

Before you begin

Perform a full backup of Common Services and application data.

Procedure

  1. Log in to Cluster Control Manager.
  2. To see whether file integrity validation is enabled or disabled, run the clusterFileIntegrity command.
  3. To enable file integrity validation, run the clusterFileIntegrity enable command.

    When file integrity validation is enabled, the system generates AIDE logs when problems are detected.

  4. Optional To disable file integrity validation, run the clusterFileIntegrity disable command.