callhome.arw.activity.seen alerts received after ONTAP upgrade
Applies to
- ONTAP 9.11.1P14 or later
- ONTAP 9.12.1P11 or later
- ONTAP 9.13.1P7 or later
- ONTAP 9.14.1 or later
- Anti-ransomware or Autonomous Ransomware Protection (ARP)
- ONTAP has been upgraded from the previous version which does not contain the fix of CONTAP-105971( Bug 1585064)
Issue
- Following ONTAP upgrade, several ARP alerts are triggered:
Sat Feb 17 15:36:42 +0100 [Cluster_01: svc_queue_thread: callhome.arw.activity.seen:alert]: Call-home message for vol1 (UUID: 44152c45-519f-4ef8-ad05-xxxxxxxxxxxx) svm1 (UUID: 3bbbba15-36eb-11e6-xxxxxx)
- AutoSupport-triggered alert is sent:
HA Group Notification (POSSIBLE RANSOMWARE ACTIVITY DETECTED) ALERT
- Unknown extensions that existed before the upgrade are newly detected