How to get CIFS audit log path on storage to implement in a syslog server
Applies to
- ONTAP 9
- Syslog
- IBM WinCollect Qradar
Answer
To know the path used for the audit logs in your NetApp storage system run the command below:
cluster1::> vserver audit show -instance
Vserver: EmployeeData
Auditing State: true
Log Destination Path: /auditlog
Categories of Events to Audit: file-ops, cifs-logon-logoff,
audit-policy-change
Log Format: evtx
Log File Size Limit: -
Log Rotation Schedule: Month: January-December
Log Rotation Schedule: Day of Week: Sunday-Saturday
Log Rotation Schedule: Day: -
Log Rotation Schedule: Hour: 12
Log Rotation Schedule: Minute: 30
Rotation Schedules: @12:30
Log Files Rotation Limit: 0
Log Retention Duration: 0s
Strict Guarantee of Auditing: true
Then update the path in IBM WinCollect Qradar or other syslog server to integrate and obtain the cifs audit logs.