Syslog server filled with SNMP GET messages from ONTAP
Applies to
- ONTAP 9
- Syslog
Issue
- Audit logs forwarding has been configured on ONTAP
- Syslog server is filled with SNMP GET message, such as:
Sun Jul 09 2023 23:02:20 +00:00 [kern_audit:info:2305] 8203e8000186cbda :: cluster1:snmp :: 10.11.12.13:54957 :: cluster1:mplus :: e58ec5 : 1 : get : .1.3.6.1.4.1.789.1.5.4.1.2.1034 : /vol/svm0_root :: Success:
security audit show
shows the GET commands are discarding from being audited:
::> security audit show
Auditing State for
Operation Get Requests
--------- ------------------
CLI off
HTTP off
ONTAPI off