<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Auditing netapps in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65341#M19381</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm new to auditing netapps, does anyone have a doc I read on the basics? I've gotten as far as the&lt;/P&gt;&lt;P&gt;adtlog.evt file being created but I can't read the contents of the logs themselves using the windows event log viewer. I receive the error:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The description for Event ID ( 538 ) in Source ( Security ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: rlee, UNITED, (0x0, 0x3b1e5), 3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Jan 2010 01:38:54 GMT</pubDate>
    <dc:creator>dwutke</dc:creator>
    <dc:date>2010-01-14T01:38:54Z</dc:date>
    <item>
      <title>Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65314#M19375</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I configured my netapps to be able to audit access of files with the following commands&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;options cifs.audit.enable on&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;options cifs.audit.autosave.ontime.enable on&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;options cifs.audit.autosave.onsize.enable on&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;options cifs.audit.liveview.enable on&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;options cifs.audit.logsize 52428800&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;options cifs.audit.autosave.onsize.threshold 50m&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;options cifs.audit.autosave.ontime.interval 20m&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my aim was to have external log files (.evt) with size of 50 MB or each 20 minuts. i tried many times but always the result is files with size almost 500 KB and it is generated each 11 to 20 seconds.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as you know if i want to manage number of these log files i have the ability to 999 files only which is not available with this small size of the file becuase in one day i got more than 2000 log files.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so is there a mistake or missing commands?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2025 07:34:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65314#M19375</guid>
      <dc:creator>CCIC4EPSO</dc:creator>
      <dc:date>2025-06-05T07:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65318#M19376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried out your commands, I found the same behavior - an evt file was getting created every minute.  Then I found below piece of info in "Data ONTAP® 7.2&lt;/P&gt;&lt;P&gt;File Access and Protocols Management Guide" : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __default_attr="#0000ff" __jive_macro_name="color"&gt;When Live View is enabled, an Access Logging Facility (ALF) daemon runs
once a minute, flushing audit events from memory to the internal log file
/etc/log/cifsaudit.alf on disk. The ALF daemon also attempts to save and convert
ALF records to EVT records that can be viewed by Event Viewer. It does so
either once every minute, or when the .alf file becomes 75 percent full.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used " options cifs.audit.liveview.enable off" to disable live view and the file creation (every minute) stopped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2008 11:56:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65318#M19376</guid>
      <dc:creator>nagendrk</dc:creator>
      <dc:date>2008-05-08T11:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65321#M19377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried out your commands on my system, the behavior was the same - an evt file was being created every minute.   I found this piece of info in "Data ONTAP® 7.2&lt;/P&gt;&lt;P&gt;File Access and Protocols Management Guide" :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When Live View is enabled, an Access Logging Facility (ALF) daemon runs&lt;/P&gt;&lt;P&gt;once a minute, flushing audit events from memory to the internal log file&lt;/P&gt;&lt;P&gt;/etc/log/cifsaudit.alf on disk. The ALF daemon also attempts to save and convert&lt;/P&gt;&lt;P&gt;ALF records to EVT records that can be viewed by Event Viewer. It does so&lt;/P&gt;&lt;P&gt;either once every minute, or when the .alf file becomes 75 percent full. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On disabling live view using "options cifs.audit.liveview.enable off" the evt file creation stopped.   Try this out !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 May 2008 16:51:37 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65321#M19377</guid>
      <dc:creator>nagendrk</dc:creator>
      <dc:date>2008-05-08T16:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65327#M19378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried this and it seems OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2008 06:21:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65327#M19378</guid>
      <dc:creator>CCIC4EPSO</dc:creator>
      <dc:date>2008-05-19T06:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65331#M19379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm attempting to set up something similar, and was wondering if there is any overhead associated with turning audting on other than tthe space the log files take up on the disk.&amp;nbsp; Also, I only want to keep a few hours worth in order to respond to events that just occured.&amp;nbsp; What command would I use to have audit logs older than a specific age automatically deleted/overwritten?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 16:08:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65331#M19379</guid>
      <dc:creator>philmcneill</dc:creator>
      <dc:date>2009-04-17T16:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65336#M19380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are also working to enable auditing on our CIFS volumes, and then retrieving the audit log from a log management system.&lt;/P&gt;&lt;P&gt;After disabling LiveView, did you correctly see the audit log rotation at the intervals you wanted? (50MB/20 Mins), or did you need to use a different method to 'keep up' with the audit log creation?&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jan 2010 14:27:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65336#M19380</guid>
      <dc:creator>jmcreynolds</dc:creator>
      <dc:date>2010-01-07T14:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65341#M19381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm new to auditing netapps, does anyone have a doc I read on the basics? I've gotten as far as the&lt;/P&gt;&lt;P&gt;adtlog.evt file being created but I can't read the contents of the logs themselves using the windows event log viewer. I receive the error:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The description for Event ID ( 538 ) in Source ( Security ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: rlee, UNITED, (0x0, 0x3b1e5), 3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jan 2010 01:38:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65341#M19381</guid>
      <dc:creator>dwutke</dc:creator>
      <dc:date>2010-01-14T01:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65345#M19382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same here,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a pair of filers, and want to know the best way of saving the CIFS audit logs. You would think it has neverbeen done before, as my NetApp supplier has never had the issue before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there has got to be an accepted souloution by NetApp of how to manage the audit logs for CIFS shares on a Filer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Feb 2010 13:59:40 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65345#M19382</guid>
      <dc:creator>miststech</dc:creator>
      <dc:date>2010-02-22T13:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65351#M19383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see this KB entry for the basic setup of CIFS auditing and the various options that can be set: &lt;A href="https://now.netapp.com/Knowledgebase/solutionarea.asp?id=kb44724" target="_blank"&gt;https://now.netapp.com/Knowledgebase/solutionarea.asp?id=kb44724&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A more detailed explanation is availabe in the docs: &lt;A href="http://now.netapp.com/NOW/knowledge/docs/ontap/rel732/html/ontap/filesag/GUID-90C286C7-95ED-48A5-ADF9-0DA7C85CF2B8.html" target="_blank"&gt;http://now.netapp.com/NOW/knowledge/docs/ontap/rel732/html/ontap/filesag/GUID-90C286C7-95ED-48A5-ADF9-0DA7C85CF2B8.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any specific questions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hendrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Feb 2010 22:10:45 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65351#M19383</guid>
      <dc:creator>hland</dc:creator>
      <dc:date>2010-02-23T22:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65355#M19384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the event details differ a lot between different Windows versions. Ontap can't support all these different versions simultanously. When copying the .evt file to your local Windows machine and viewing it in event viewer, Windows will attempt to use the local event description of that Windows version. Depending on the Windows version it will not recognize some events, which leads to the error message you've posted. IIRC Vista should work pretty well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also use the /auxsource parameter when starting the management console to tell Windows to look at the source machine for event descriptions. Basically you would start it like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;mmc /a /AUXSOURCE=&amp;lt;Filer-IP&amp;gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="http://support.microsoft.com/kb/312216/en-us" target="_blank"&gt;http://support.microsoft.com/kb/312216/en-us&lt;/A&gt; for more details on that parameter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..- Hendrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Feb 2010 22:33:00 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65355#M19384</guid>
      <dc:creator>hland</dc:creator>
      <dc:date>2010-02-23T22:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65360#M19385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the auditing configured, Want i want to know, is as the evt files are not "REAL" evt file,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best was of getting them off a NetApp filer, and archiving them to allow compliance with SOX (Specifically J-SOX). The actual audit configuration is complete, I just need to be able to search the logs and use some tool to collect and aggregate the files.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Feb 2010 08:15:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65360#M19385</guid>
      <dc:creator>miststech</dc:creator>
      <dc:date>2010-02-24T08:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing netapps</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65364#M19386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They are "real"evt files. However, you can't query them via RPC as you can with a Windows server. Therefore you need to work with the actual files. Any tool that can read .evt files should work fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess the easiest way to get the event files off the filer is via CIFS or NFS. Either copy them to whatever location you like via a script or use a backup application if you just want to archive them on tape or something.Then process them with your preferred event log tool (as long as it can open .evt files) or convert them to text and go from there (&lt;A href="http://now.netapp.com/NOW/download/tools/evt2text/" target="_blank"&gt;http://now.netapp.com/NOW/download/tools/evt2text/&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hendrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Feb 2010 14:08:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Auditing-netapps/m-p/65364#M19386</guid>
      <dc:creator>hland</dc:creator>
      <dc:date>2010-02-24T14:08:59Z</dc:date>
    </item>
  </channel>
</rss>

