Skip to main content
NetApp Knowledge Base

Search

  • Filter results by:
    • View attachments
    Searching in
    About 16 results
    • https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/How_to_allow_users_to_manage_Microsoft_CIFS_auditing
      Applies to ONTAP 9 CIFS Description As per internal company policy, every user should be allowed to manage auditing on CIFS files and directories.
    • https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/Unable_to_create_audit_configuration_in_On_board_key-manager_system
      Unable to create auditing in encrypted volumes, getting the below errors: ClusterA::> vserver audit create -vserver clusterA-cifs -destination /storage_audits_ims_image_share -events file-ops,file-sha...Unable to create auditing in encrypted volumes, getting the below errors: ClusterA::> vserver audit create -vserver clusterA-cifs -destination /storage_audits_ims_image_share -events file-ops,file-share -format xml -rotate-schedule-dayofweek Sunday-Saturday -rotate-schedule-hour 0 -rotate-schedule-minute 0 -rotate-limit 3 Error: command failed: Failed to create audit configuration for Vserver "clusterA-cifs -destination". Reason: [Job 11276] Job failed: Metadata verification failed.
    • https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/How_to_review_native_audit_logs_in_EVTX_format
      Applies to ONTAP 9+ Description How to review EVTX formatted logs generated by native file auditing
    • https://kb.netapp.com/Cloud/BlueXP/Cloud_Manager/Cloud_Manager__How_can_I_delete_an_aggregate_without_deleting_the_auditing_configuration
      Applies to Cloud Manager Cloud Volumes ONTAP (CVO) Issue Deletion of Aggregate in Cloud Manager fails due to auditing configuration present.
    • https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/Native_NAS_Auditing_ONTAP_vs_7Mode
      Can we configure Auditing in ONTAP to capture CIFS events with path in “\” backslash format like 7Mode? There is a field in the Audit event named "Source" which differentiates the protocol of access l...Can we configure Auditing in ONTAP to capture CIFS events with path in “\” backslash format like 7Mode? There is a field in the Audit event named "Source" which differentiates the protocol of access like CIFS, NFSV3 etc. Can we capture audit logs in .evt format like in 7Mode ? No, ONTAP can only capture Audit logs in XML or EVTX format The output format can be either Data ONTAP-specific XML or Microsoft Windows EVTX log format.
    • https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/What_is_a_staging_volume_and_how_to_use_it_to_troubleshoot_issues
      While creating the Audit config for a SVM, the SVM administrator specifies a valid destination path in the SVM’s namespace, where the final consolidated audit logs in the specified format will be stor...While creating the Audit config for a SVM, the SVM administrator specifies a valid destination path in the SVM’s namespace, where the final consolidated audit logs in the specified format will be stored. If the path configured to store final consolidated logs runs out of space, the consolidation service cannot continue; and hence, it will not be able to consume and delete the staging files on the staging volume.
    • https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/Administrators_are_unable_to_configure_CIFS_auditing_in_Windows
      Applies to ONTAP 9 CIFS / SMB auditing in Microsoft Windows Issue Error received when configuring auditing in Microsoft Windows: You do not have permission to view or edit this object's audit settings
    • https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/How_to_delete_the_leftover_AUDIT_MDV_staging_volume_when_CIFS_auditing_is_already_disabled
      Applies to ONTAP 9 Issue CIFS auditing is disabled on all SVMs. There is still one MDV volume which is present in the system. Cluster01::*> vol show *MDV* Vserver Volume Aggregate State Type ---------...Applies to ONTAP 9 Issue CIFS auditing is disabled on all SVMs. There is still one MDV volume which is present in the system. Cluster01::*> vol show *MDV* Vserver Volume Aggregate State Type --------- ------------ ------------ ---------- ---- Cluster01 MDV_aud_3a65277539ad4ed89d46ab1c86c32d45 aggr1_n1 - RW
    • https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/Can_NAS_audit_logs_be_forwarded_to_a_syslog_server_or_an_external_path
      NAS audit logs cannot be integrated with the syslog framework, they must be stored in a local path on the system. NAS audit events cannot generate email alerts. A pull mechanism can be utilized to ret...NAS audit logs cannot be integrated with the syslog framework, they must be stored in a local path on the system. NAS audit events cannot generate email alerts. A pull mechanism can be utilized to retrieve them using CIFS or NFS. NetApp does not provide a push option to transfer NAS audit logs directly to a destination syslog server. Auditing NAS events on SVMs ONTAP audit logs can be sent to external syslog server - Manage audit log destinations.
    • https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/Cannot_enable_auditing_for_Vserver_Final_consolidation_is_in_progress
      Auditing cannot be enabled for an SVM due to the following error: Error: command failed: Cannot enable auditing for Vserver "svm1". Reason: Final consolidation is in progress. With this final consolid...Auditing cannot be enabled for an SVM due to the following error: Error: command failed: Cannot enable auditing for Vserver "svm1". Reason: Final consolidation is in progress. With this final consolidation stuck in progress, the staging volume may fill up. Tue Mar 23 07:22:26 [clus01: wafl_spcd_main: monitor.volume.nearlyFull:error]: Volume MDV_aud_97dd@vserver is nearly full Tue Mar 23 07:32:48 [clus01: wafl_spcd_main: monitor.volume.full:debug]: Volume MDV_aud_97dd@vserver is full
    • https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/How_to_ingest_native_auditing_logs_into_Splunk
      Applies to ONTAP 9+ Splunk Enterprise Description The following process explains how to ingest SMB/NFS auditing logs into Splunk.