Does Fpolicy or Native auditing capture copy offload reads or writes
Applies to
ONTAP 9+
Answer
No, neither Fpolicy or Native auditing captures copy-offloads reads or writes. This is due to the use of the SMB operation IOCTL to facilitates the read/write process when leveraging copy offload rather than read or write operations. There is no option within the Fpolicy configuration for the file operation of IOCTL, so Fpolicy does not have a way to capture events related to IOCTL requests. Similarly, for native auditing SACLs are used to determine what access is audited. There is a portion of the ACE, within the SACL on the file/folder, the access mask that represents the auditing access, to which there is nothing to include copy offload.
Additional Information
- Microsoft on ODX
- Allocated Altitudes Microsoft Allocated Altitudes (list of filter drivers and companies that are associated with each one):
- DeployODX_Gather storage array information
- CDOT 8.2 File Access Management Guide for CIFS (ODX staring on page 325)
- CDOT 8.2 SAN Administration Guide (ODX staring on page 173)
