Storage Workload Security collector stops collecting CIFS user activity after brief FPolicy disconnection event
Applies to
Storage Workload Security (SWS)
Issue
The SWS data collector stops collecting CIFS/SMB user activity for a specific SVM after a brief network disruption between the SWS agent
and the SVM. The collector does not automatically recover and resume collecting audit events.
Symptoms:
- Gap in CIFS user activity on the SWS Forensics Activity page
- Data Collector may show
"Error"with message:Connector is in error state. Service name: audit. Reason for failure: External fpolicy server terminated. - Collector may appear "Running" despite not collecting events
- ONTAP EMS:
fpolicy.srv.disconnect for the affected SVM - Agent dsc.log:
[ERROR] - Service audit failed with reason: External fpolicy server terminated.
Activity that occurs during the outage window is permanently lost from the SWS forensic record.
