Is it possible to trace user access history only when detected as an attack?
Applies to
Answer
No, there has no dedicated history log to trace user access when it detected as an attack.
Additional Information
- ARP alert and report can be used to track the attack details on a volume include attack time schedule, file name, file extension, directory, etc.
- CIFS Auditing log can be used to trace SMB/NFS access history of all users on a volume.
