FAQ: Storage Workload Security Forensics Activity
Applies to
Cloud Insight (CI)
Storage Workload Security (SWS)
Answer
| Question | Answer | 
| Do we have SWS Forensics activity (user activity / audit trail) available if Fpolicy agent server is down/disconnect/disable? | No | 
| Do we have SWS Forensics activity (user activity / audit trail) available in Fpolicy agent server logs? | No, Forensics acitivity will only be pulled from Tenant Forensics acitivity page and it is fetching the information directly from backend database. | 
| Can SWS Forensics activity (user activity / audit trail) be filtered and pulled into CSV file? | Yes, you can filter for "31 days" of actitivity at a time using "custom" filter. | 
| What information SWS Forensics activity will audit? | Only CIFS(SMB) / NFS operations if they are both enable on SWS data collector. | 
| Define CIFS operation? | Customer working of a CIFS share and read/write/delete the file or folder. | 
| If the file and folder get deleted using system manager > volume > file system > explorer page > API, can SWS Forensics activity will show the "delete" operation? | No, SWS will not audit API operations, You will how ever find the "delete" operation in ONTAP cluster logs | 
| If the file and folder get deleted using PowerShell CLI on CIFS/SMB share, can SWS Forensics activity will show the "delete" operation? | Yes, SWS will show the "delete" operation | 
| If the file and folder get deleted using PowerShell API on CIFS/SMB share, can SWS Forensics activity will show the "delete" operation? | No, SWS will not audit API operations, You will how ever find the "delete" operation in ONTAP cluster logs | 
| If the file and folder get deleted using cluster CLI [system shell], can SWS Forensics activity will show the "delete" operation? | No | 
| If the file and folder get deleted using cluster CLI [Node shell], can SWS Forensics activity will show the "delete" operation? | No | 
| How to prevent users from deleting file and directories in ONTAP System Manager? | How to prevent users from deleting file and directories in ONTAP System Manager using RBAC for FSA | 
| Do we need Cifs Auditing, How to enable it? | Cifs auditing can be enabled in parallel to SWS | 
| SWS Forensic User Overview | Forensic User Overview | 
| SWS Forensics - All Activity | Forensics - All Activity | 
| SWS Forensic User Activity Data | Forensic User Activity Data | 
| SWS Forensic Entities Page | Forensic Entities Page | 
| Collect packet traces from Fpolicy Agent and ONTAP Simultaneously NOTE: If you see the issue is occurring, especially at that time collect the packet traces from both ends. It will help troubleshoot the issue tremendously. | ONTAP: How to use debug network tcpdump in ONTAP 9.10+ FPolicy Agent: How to capture client side packet trace from Red Hat Linux | 
Additional Information
additionalInformation_text
