<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic netapp increase security log in General Discussion</title>
    <link>https://community.netapp.com/t5/General-Discussion/netapp-increase-security-log/m-p/149073#M499</link>
    <description>&lt;P&gt;Hello team!&lt;/P&gt;
&lt;P&gt;I turned on the cifs.audit.liveview.enable feature so that NetApp logs were written to security log so that later my SIEM could take them. But NetApp creates a large number of adtlog.YEAR_MONTH_DAY_NUMBER.evt files with a volume not exceeding 1000kb. This is very bad for handling such logs. Is it possible for NetApp to insist on log files exceeding 1000 kb with the cifs.audit.liveview.enable feature enabled?&lt;/P&gt;
&lt;P&gt;Here are my settings:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; options cifs.audit&lt;/P&gt;
&lt;P&gt;cifs.audit.account_mgmt_events.enable on&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.file.extension timestamp&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.file.extension.nanosecond_precision off&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.file.limit 999&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.onsize.enable on&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.onsize.threshold 99%&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.ontime.enable on&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.ontime.interval 5h&lt;/P&gt;
&lt;P&gt;cifs.audit.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;/P&gt;
&lt;P&gt;cifs.audit.file_access_events.enable on&lt;/P&gt;
&lt;P&gt;cifs.audit.liveview.allowed_users&lt;/P&gt;
&lt;P&gt;cifs.audit.liveview.enable&amp;nbsp;&amp;nbsp; on&lt;/P&gt;
&lt;P&gt;cifs.audit.logon_events.enable on&lt;/P&gt;
&lt;P&gt;cifs.audit.logsize&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 104857600&lt;/P&gt;
&lt;P&gt;cifs.audit.nfs.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;/P&gt;
&lt;P&gt;cifs.audit.nfs.filter.filename&lt;/P&gt;
&lt;P&gt;cifs.audit.saveas&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /etc/log/audit/adtlog.evt&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 12:27:13 GMT</pubDate>
    <dc:creator>ANANEVVYAC</dc:creator>
    <dc:date>2025-06-04T12:27:13Z</dc:date>
    <item>
      <title>netapp increase security log</title>
      <link>https://community.netapp.com/t5/General-Discussion/netapp-increase-security-log/m-p/149073#M499</link>
      <description>&lt;P&gt;Hello team!&lt;/P&gt;
&lt;P&gt;I turned on the cifs.audit.liveview.enable feature so that NetApp logs were written to security log so that later my SIEM could take them. But NetApp creates a large number of adtlog.YEAR_MONTH_DAY_NUMBER.evt files with a volume not exceeding 1000kb. This is very bad for handling such logs. Is it possible for NetApp to insist on log files exceeding 1000 kb with the cifs.audit.liveview.enable feature enabled?&lt;/P&gt;
&lt;P&gt;Here are my settings:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; options cifs.audit&lt;/P&gt;
&lt;P&gt;cifs.audit.account_mgmt_events.enable on&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.file.extension timestamp&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.file.extension.nanosecond_precision off&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.file.limit 999&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.onsize.enable on&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.onsize.threshold 99%&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.ontime.enable on&lt;/P&gt;
&lt;P&gt;cifs.audit.autosave.ontime.interval 5h&lt;/P&gt;
&lt;P&gt;cifs.audit.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;/P&gt;
&lt;P&gt;cifs.audit.file_access_events.enable on&lt;/P&gt;
&lt;P&gt;cifs.audit.liveview.allowed_users&lt;/P&gt;
&lt;P&gt;cifs.audit.liveview.enable&amp;nbsp;&amp;nbsp; on&lt;/P&gt;
&lt;P&gt;cifs.audit.logon_events.enable on&lt;/P&gt;
&lt;P&gt;cifs.audit.logsize&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 104857600&lt;/P&gt;
&lt;P&gt;cifs.audit.nfs.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;/P&gt;
&lt;P&gt;cifs.audit.nfs.filter.filename&lt;/P&gt;
&lt;P&gt;cifs.audit.saveas&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /etc/log/audit/adtlog.evt&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 12:27:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/General-Discussion/netapp-increase-security-log/m-p/149073#M499</guid>
      <dc:creator>ANANEVVYAC</dc:creator>
      <dc:date>2025-06-04T12:27:13Z</dc:date>
    </item>
  </channel>
</rss>

