CIFS auditing does not work as expected due to missing SACLs
Applies to
- ONTAP 9
- CIFS auditing
Issue
- No file access auditing events are generated
- logon and logoff events may be seen
- Filename is not shown in audit events
vserver security file-directoryshows no SACL on the volume or CIFS shares
::> vserver security file-directory show -vserver svm_netapp -path /vol_netapp -instanceVserver: svm_netappFile Path: /vol_netappFile Inode Number: 64Security Style: ntfsEffective Style: ntfsDOS Attributes: 10DOS Attributes in Text: ----D---Expanded Dos Attributes: -UNIX User Id: 0UNIX Group Id: 0UNIX Mode Bits: 777UNIX Mode Bits in Text: rwxrwxrwxACLs: NTFS Security DescriptorControl:0x9504Owner:BUILTIN\AdministratorsGroup:BUILTIN\AdministratorsDACL - ACEsALLOW-NT AUTHORITY\SYSTEM-0x1f01ff-OI|CIALLOW-BUILTIN\Administrators-0x1f01ff-OI|CIALLOW-Everyone-0x1f01ff-OI|CI- Auditing is correctly setup:
::*> vserver audit show -vserver svm1 -fields events
vserver events
---------- --------------------------------------------------------------------------
svm1 file-ops,cifs-logon-logoff,user-account,security-group,audit-policy-change
