What is a one sentence summary of your feature request?
endpoint agent initiated events acquisition (push from client instead of pulling from server)
Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.
In large, distributed, or highly segmented environments, the Netwrix Auditor Server may not be able to establish direct connectivity to every endpoint or monitored system due to firewall rules, network segmentation, or isolated security zones.
It would be useful to have a lightweight agent that could be deployed within these isolated network segments and act as a policy retriever and data forwarder.
The agent could periodically retrieve its configuration and auditing policies from the central Netwrix Auditor Server, apply or manage the required auditing configuration on local endpoints, collect the relevant audit data, and then securely forward the collected information back to the central Auditor Server.
This architecture would allow organizations to maintain a centralized Netwrix Auditor deployment while supporting environments where direct server-to-endpoint connectivity is not feasible.
Ideally, the agent should support:
Outbound-only communication from the isolated network to the central Auditor Server.
Centralized policy retrieval and configuration management.
Local collection and buffering of audit data when connectivity to the central server is temporarily unavailable.
Secure, authenticated and encrypted communication.
Deployment across multiple endpoints within the same network segment.
Centralized monitoring of agent health, connectivity and last successful synchronization.
This would be particularly valuable in large enterprises with multiple sites, DMZs, security zones, restricted VLANs, overlapping networks or networks where firewall policies prevent the Netwrix Auditor Server from directly accessing all monitored endpoints.
How do you currently solve the challenges you have by not having this feature?
Cannot be solved with a secure configuration. without this feature, it is possibile we’ll have to evaluate a different auditing solution.