Repeated false positive ransomware alerts on NAS volumes
Applies to
- ONTAP 9
- Anti-Ransomware Protection (ARP)
- NAS environment
Issue
- ActiveIQ Unified Manager repeatedly generates 'Ransomware activities detected' alerts for volumes after marking them as false positives.
- Anti-ransomware (ARW) alerts triggered by high encryption percentage on NFS datastore volumes (VMDK).
[node1:svc_queue_thread:callhome.arw.activity.seen:alert]: Callhome message for "POSSIBLE RANSOMWARE ACTIVITY DETECTED", Volume: "vol1" in Vserver: "vs1"