Possible Ransomware Activity Detected” Alerts After ONTAP 9_17_1 Upgrade
Applies to
- NetApp ONTAP 9.17.1and later
- Anti-Ransomware Protection (ARP/AI) for SAN volumes.
Issue
- After upgrading a cluster 9.17.1 started receiving daily “Possible Ransomware Activity Detected” alerts for SAN volumes. The alerts appear in EMS logs as:
[node-01:svc_queue_thread:callhome.arw.activity.seen:alert]: Callhome message for "POSSIBLE RANSOMWARE ACTIVITY DETECTED", Volume: "vol1" in Vserver: "svm1"Similar alerts are seen for other volumes in the cluster.