<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIFS Audit log forwarding to Splunk Server in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Audit-log-forwarding-to-Splunk-Server/m-p/433259#M40306</link>
    <description>&lt;P&gt;Thanks. Yes for the normal "audit" log its clear. it will use the syslog framework.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Question was regarding "cifs audit" logs and forward directly into Splunk for parsing.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Mar 2022 09:01:39 GMT</pubDate>
    <dc:creator>STORAGE_CIT</dc:creator>
    <dc:date>2022-03-22T09:01:39Z</dc:date>
    <item>
      <title>CIFS Audit log forwarding to Splunk Server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Audit-log-forwarding-to-Splunk-Server/m-p/433210#M40279</link>
      <description>Hello Community We want to check which client IPs access a Cifs share and map/check the whole stuff in Splunk. Is a CIFS audit log forward to a Splunk server possible? If yes how? Any Documentation available how to configure? I find in the NetApp documentation only general information about the "audit" log forwarding but not explicitly about the CIFS audit. If it is not possible via Splunk, what solution does NetApp offer here? Many Thanks in advance. Juergen</description>
      <pubDate>Wed, 04 Jun 2025 10:03:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Audit-log-forwarding-to-Splunk-Server/m-p/433210#M40279</guid>
      <dc:creator>StorageIT</dc:creator>
      <dc:date>2025-06-04T10:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS Audit log forwarding to Splunk Server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Audit-log-forwarding-to-Splunk-Server/m-p/433231#M40290</link>
      <description>&lt;P&gt;You can forward CIFS audit logs to a syslog server. The following may be helpful in the needed configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_manage_administrative_Vserver_audit_logs_in_ONTAP_9" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_manage_administrative_Vserver_audit_logs_in_ONTAP_9&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_set_up_CIFS_auditing_with_clustered_Data_ONTAP" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_set_up_CIFS_auditing_with_clustered_Data_ONTAP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/system-admin/changes-audit-logging-ontap-9-concept.html" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/system-admin/changes-audit-logging-ontap-9-concept.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/system-admin/forward-command-history-log-file-destination-task.html" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/system-admin/forward-command-history-log-file-destination-task.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 01:55:43 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Audit-log-forwarding-to-Splunk-Server/m-p/433231#M40290</guid>
      <dc:creator>aladd</dc:creator>
      <dc:date>2022-03-22T01:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS Audit log forwarding to Splunk Server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Audit-log-forwarding-to-Splunk-Server/m-p/433259#M40306</link>
      <description>&lt;P&gt;Thanks. Yes for the normal "audit" log its clear. it will use the syslog framework.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Question was regarding "cifs audit" logs and forward directly into Splunk for parsing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 09:01:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Audit-log-forwarding-to-Splunk-Server/m-p/433259#M40306</guid>
      <dc:creator>STORAGE_CIT</dc:creator>
      <dc:date>2022-03-22T09:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS Audit log forwarding to Splunk Server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Audit-log-forwarding-to-Splunk-Server/m-p/433261#M40307</link>
      <description>&lt;P&gt;Correct. CIFS audit logs cannot be pushed to another server, only accessed through a CIFS share.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aladd_0-1647941601707.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/23111iD39277A911D244FA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aladd_0-1647941601707.png" alt="aladd_0-1647941601707.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Reference from documentation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.netapp.com/pdf.html?item=/media/16330-tr-4189pdf.pdf" target="_blank"&gt;https://www.netapp.com/pdf.html?item=/media/16330-tr-4189pdf.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Pg. 12&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 09:33:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CIFS-Audit-log-forwarding-to-Splunk-Server/m-p/433261#M40307</guid>
      <dc:creator>aladd</dc:creator>
      <dc:date>2022-03-22T09:33:54Z</dc:date>
    </item>
  </channel>
</rss>

