DII FSx data collector generates excessive audit log entries in FSx audit logs
Applies to
Data Infrastructure Insights (DII)FSx data collectors
Issue
After installing the Data Infrastructure Insights (DII) FSx data collector the audit log generates a high volume of entries attributed to the DII collector user account.
Symptoms include:
- Tens of thousands of audit log entries per day (e.g., ~65,000/day) from the DII collector user
- Audit log entries showing "
Insufficient privileges: user '<username>' does not have write access to this resource" foraggr-check-spare-lowZAPI - Audit log entries showing "
authentication failed" from "unknown:unknown" for ZAPI calls, even when the DII collector login succeeds(HTTP 200) - Data collection in DII completes successfully with no errors reported in the DII console
- Audit log signal-to-noise ratio is degraded, making it difficult to identify legitimate security events
Example audit log entries:
aggr-check-spare-low :: Error: Insufficient privileges:user '<username>' does not have write access to thisresourceauthentication failed from unknown:unknown(ONTAPI/ZAPI call)