- ONTAP 9 and later
- CIFS auditing enabled
- MDV volume size increasing more than 2GB and consolidation job is not running on the node where MDV volume is located.
- Due to this, CIFS auditing is not working and no further log destination file is being generating.
- MDV volume full or nearly full alerts seen in ems logs:
[?] Tue Dec 14 06:06:43 +07 [Node1: wafl_exempt05: monitor.volume.nearlyFull:alert]: Volume MDV_aud_d0d5f94fae4b439e9d610f5b3e1882f9@vserver:b66e55a1-903b-11e8-a111-00a098db3479 is nearly full (using or reserving 95%% of space and 0%% of inodes).
[?] Tue Dec 14 08:16:45 +07 [Node1: wafl_exempt05: wafl.vol.full:notice]: Insufficient space on volume MDV_aud_d0d5f94fae4b439e9d610f5b3e1882f9@vserver:b66e55a1-903b-11e8-a111-00a098db3479 to perform operation. 4.00KB was requested but only 1.00KB was available.
[?] Tue Dec 14 08:16:45 +07 [Node1: AuditWorkerThread02: adt.stgvol.nospace:EMERGENCY]: Audit subsystem internal error: Staging volume MDV_aud_d0d5f94fae4b439e9d610f5b3e1882f9 is full.
[?] Tue Dec 14 08:19:07 +07 [Node1: AuditWorkerThread03: ems.engine.suppressed:debug]: Event 'adt.stgvol.nospace' suppressed 1607 times in last 142 seconds.
One or more MDV volume size is more than 2GB:
Filesystem kbytes used avail capacity Mounted on
/vol/MDV_aud_d0d5f94fae4b439e9d610f5b3e1882f9/ 4980736 4244800 735936 85% /vol/MDV_aud_d0d5f94fae4b439e9d610f5b3e1882f9
Consolidation job is not running on the node where MDV volume size is increasing:
cluster1::> job show -name *Consol*
There are no entries matching your query.