<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About vserver audit function in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159733#M36487</link>
    <description>&lt;P&gt;HI Thanks ALL&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Base on scottgelb's weblink....I find a step that I need to do ..&lt;/P&gt;
&lt;P&gt;after xml been generated...I "must be set" SACLs to folder's security .&lt;/P&gt;
&lt;P&gt;so now my auditing xml has capture these file operation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wencheng&lt;/P&gt;</description>
    <pubDate>Fri, 25 Sep 2020 09:30:08 GMT</pubDate>
    <dc:creator>Wencheng</dc:creator>
    <dc:date>2020-09-25T09:30:08Z</dc:date>
    <item>
      <title>About vserver audit function</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159574#M36432</link>
      <description>&lt;P&gt;HI All&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; I build a OnTAP simulator lab server and want to collect audit log...&lt;/P&gt;
&lt;P&gt;so I create a CIFS volume to let user place their data (eningeering), the root mount&amp;nbsp; (/) I name is nsroot&lt;/P&gt;
&lt;P&gt;I also&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;create a volume which name is audit...&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="002.png" style="width: 999px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/10096i62266BEB242B0A5B/image-size/large?v=v2&amp;amp;px=999" role="button" title="002.png" alt="002.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I create audit role and enable it&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(1).vserver audit create -vserver netapp-svm1 -destination "/nsroot/audit" -events file-ops -format xml -rotate-size 10MB -rotate-limit 10&lt;/P&gt;
&lt;P&gt;(2).vserver audit enable -vserver netapp-svm1&lt;/P&gt;
&lt;P&gt;I try to create a testing on engineer volume and audit volume , and add some content to these files...but the audit xml file seem no detect any change event....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could I ask when I create such audit role....for my SVM...what scope that audit log could monitor ?? ( root mount / engineering &amp;amp; audit) or only audit volume ??&lt;/P&gt;
&lt;P&gt;about file-ops parameter....does it could monitor any file action (create/modity/rename/delete&amp;amp;permission change )??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wencheng&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:52:48 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159574#M36432</guid>
      <dc:creator>Wencheng</dc:creator>
      <dc:date>2025-06-04T10:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: About vserver audit function</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159576#M36433</link>
      <description>&lt;P&gt;For more information about auditing, please refer to the below document:&lt;/P&gt;
&lt;P&gt;&lt;A title="How auditing works" href="https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cifs-nfs-audit%2FGUID-A3E3170A-6ACB-4655-A37A-3395A099602E.html" target="_blank" rel="noopener"&gt;How auditing works&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 04:30:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159576#M36433</guid>
      <dc:creator>tahmad</dc:creator>
      <dc:date>2020-09-22T04:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: About vserver audit function</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159577#M36434</link>
      <description>&lt;P&gt;Hi Wencheng,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAS auditing is first stored in a staging volume and then moved to the actual audit log. The log location directory (&lt;SPAN&gt;/nsroot/audit)&lt;/SPAN&gt;&amp;nbsp;specified in the configuration command must be created prior to running the command or the operation will fail. In addition, you must configure an auditing policy for files and folders on the Windows side for NTFS volumes&amp;nbsp;&lt;SPAN&gt;by using the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Windows Security&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;tab in the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword wintitle"&gt;Windows Properties&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;window.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After enabling auditing you will see a staging volume created with the prefix "MDV"; did you see one get created?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also check the auditing configuration status via the following command:&lt;/P&gt;
&lt;P&gt;::&amp;gt; vserver audit show -instance -vserver netapp-svm1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below are several documentation that explains auditing in more detail:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.netapp.com/ontap-9/topic/com.netapp.doc.dot-cifs-nfs-audit/home.html?cp=13_4" target="_self"&gt;SMB/CIFS and NFS Auditing and Security Tracing Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.netapp.com/us/media/tr-4189.pdf" target="_self"&gt;Clustered Data ONTAP CIFS Auditing Quick Start Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Team NetApp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 05:20:40 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159577#M36434</guid>
      <dc:creator>ttran</dc:creator>
      <dc:date>2020-09-22T05:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: About vserver audit function</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159609#M36444</link>
      <description>&lt;P&gt;For the scope of what is audited, that is set by the host SACL or file-directory command...I prefer setting from the host side especially windows where the multiple select saves time. &amp;nbsp;Here is an end-to-end NAS audit setup in a blog I posted on this that should answer your question.. &amp;nbsp;The goal was to show all steps for both CIFS and NFS auditing. &amp;nbsp;The NetApp docs are great but I wanted to demo every step in one guide. &amp;nbsp;&lt;A href="https://storageexorcist.wordpress.com/2020/06/03/ontap-native-nas-auditing-smb-and-nfs/" target="_blank"&gt;https://storageexorcist.wordpress.com/2020/06/03/ontap-native-nas-auditing-smb-and-nfs/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 22:39:43 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159609#M36444</guid>
      <dc:creator>scottgelb</dc:creator>
      <dc:date>2020-09-22T22:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: About vserver audit function</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159668#M36464</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Thanks your reply&lt;/P&gt;
&lt;P&gt;I run the show command...my setting indeed set well and generate a xml file on destination location.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AuditPolicyShow.png" style="width: 749px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/10113iCE527B2F12A3AE9F/image-size/large?v=v2&amp;amp;px=999" role="button" title="AuditPolicyShow.png" alt="AuditPolicyShow.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;as this screenshot ....I add cifs-logon-logoff and file-share &amp;amp; audit-policy-change....but now the audit file seem only been trigger by logon-logoff event ...no matter of folder/file action...the audit file still no event been generated to audit xml file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wencheng&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 05:11:48 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159668#M36464</guid>
      <dc:creator>Wencheng</dc:creator>
      <dc:date>2020-09-24T05:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: About vserver audit function</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159733#M36487</link>
      <description>&lt;P&gt;HI Thanks ALL&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Base on scottgelb's weblink....I find a step that I need to do ..&lt;/P&gt;
&lt;P&gt;after xml been generated...I "must be set" SACLs to folder's security .&lt;/P&gt;
&lt;P&gt;so now my auditing xml has capture these file operation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wencheng&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 09:30:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-vserver-audit-function/m-p/159733#M36487</guid>
      <dc:creator>Wencheng</dc:creator>
      <dc:date>2020-09-25T09:30:08Z</dc:date>
    </item>
  </channel>
</rss>

