Unable to access cifs share due to audit failures caused by MDV audit volume status
Applies to
- ONTAP 9
- CIFS
- Auditing
Issue
MDV_aud have been in marked failed state eventually being offline. After online, auditing logons\logoffs not possible, and caused cifs op timeouts.
[Node2: statd: wafl.vol.nvfail.recovery.needed:notice]: Volume MDV_aud_XX@vserver:X-X-X-X-X is marked as in-nvfailed-state. The recovery process needs to be initiated on the volume to recover from the NVFAIL event.[Node2: vv_config_worker07: wafl.vvol.offline:info]: Volume 'MDV_aud_XX@vserver:X-X-X-X-X' has been set temporarily offline[Node2: vv_config_worker10: wafl.config.req.error:debug]: Config request 'VV_CONFIG_REQ_OFFLINE' by WAFL for volume MDV_aud_XX-X-X-X-X is not being processed because of the error: '8 - CR_ALREADY_OFFLINE'.[Node2: vv_config_worker15: wafl.vvol.destroyed:notice]: Volume MDV_aud_XX@vserver:X-X-X-X-X destroyed.[Node2: mgwd: mgmtgwd.jobmgr.jobcomplete.failure:info]: Job "Vol Delete" [id 20956] (Delete MDV_aud_XX) completed unsuccessfully: Failed to delete volume "MDV_aud_XX" on Vserver "SVM1". Reason: Containing aggregate is not online (1).[Node2: wafl_spcd_main: monitor.volumes.one.ok:debug]: Volume MDV_aud_XX@vserver:X-X-X-X-X is OK.[Node2: kernel: Nblade_CifsOperationTimedOut_1:error]: params: {'commandName': 'SMB2_COM_LOGOFF', 'suspensionCnt': '7932', 'cmdRestartCnt': '0', 'lastCsmError': 'CSM_OK', 'remoteBladeID': 'b03303bf-65bd-11ed-9a5f-d039ea37f717 (Node2)', 'isQosEnabled': 'QoS_disabled', 'lastSpinNpError': 'SPINNP_ERR_RETRY', 'clientIpAddress': '10.X.X.X', 'localIpAddress': '10.X.X.X', 'vserverId': '4', 'dsId': '1038', 'vserverName': 'SVM1'}