<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Events sent to Splunk only from one node in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Events-sent-to-Splunk-only-from-one-node/m-p/437941#M41142</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/111036"&gt;@nfantinato&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry i missed read your original post. You referring to audit logging which you would use cluster log-forwarding as the event notification if for ems logs that was generated by the system.&lt;/P&gt;&lt;P&gt;So regarding the issue receiving logs only from one node, is most likely since the cluster-mgmt lif live on the working node. Try moving the cluster-mgmt lif to node 2 and see if you are getting logs forwarded to the syslog server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Sep 2022 04:14:49 GMT</pubDate>
    <dc:creator>hmoubara</dc:creator>
    <dc:date>2022-09-02T04:14:49Z</dc:date>
    <item>
      <title>Events sent to Splunk only from one node</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Events-sent-to-Splunk-only-from-one-node/m-p/437870#M41133</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have configured audit logs to be sent via syslog to a Splunk server using command:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;cluster log-forwarding create -destination xx.xx.xx.xx -port 514 -protocol tcp-unencrypted -verify-server false -facility user&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;but it seems that logs are sent only from node 1 of the Netapp storage array. So node 2 always results as it is not sending anything to Splunk.&lt;/P&gt;&lt;P&gt;It is normal? I mean, are all logs normally sent only from node 1?&lt;/P&gt;&lt;P&gt;The storage is a FAS8200, Ontap version is&amp;nbsp;&lt;SPAN class=""&gt;9.7P17&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thanks in advance for any information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:57:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Events-sent-to-Splunk-only-from-one-node/m-p/437870#M41133</guid>
      <dc:creator>nfantinato</dc:creator>
      <dc:date>2025-06-04T09:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Events sent to Splunk only from one node</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Events-sent-to-Splunk-only-from-one-node/m-p/437906#M41137</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/111036"&gt;@nfantinato&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you run the below command and check if there is connection between the node the syslog server and also review history of events that were set to be forwarded to the server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cluster::&amp;gt; event notification destination check -node &amp;lt;node-name&amp;gt; -destination-name &amp;lt;&amp;gt;&lt;/P&gt;&lt;P&gt;cluster::&amp;gt; event notification history show -node&amp;nbsp; &amp;lt;node-name&amp;gt; -destination-name &amp;lt;&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Event_forwarding_to_a_Syslog_server" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Event_forwarding_to_a_Syslog_server&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 03:43:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Events-sent-to-Splunk-only-from-one-node/m-p/437906#M41137</guid>
      <dc:creator>hmoubara</dc:creator>
      <dc:date>2022-09-01T03:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Events sent to Splunk only from one node</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Events-sent-to-Splunk-only-from-one-node/m-p/437913#M41138</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/14855"&gt;@hmoubara&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your reply. Because we found a bit complex to set correct filters in event notification, instead of those commands you indicated we've run the following one for both nodes:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cluster log-forwarding statistics show -node &amp;lt;node_name&amp;gt; -destination 161.27.170.14 -port 514&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;and those statistics show no errors and all messages correctly sent. So everything on Netapp side seems to work well, but on Spunk side no logs arrive from node 2. And this beahaviour happens only for some storages, not all.&lt;/P&gt;&lt;P&gt;Is it better to use &lt;FONT face="courier new,courier"&gt;event notification&lt;/FONT&gt; command instead of &lt;FONT face="courier new,courier"&gt;cluster log-forwarding&lt;/FONT&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 09:55:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Events-sent-to-Splunk-only-from-one-node/m-p/437913#M41138</guid>
      <dc:creator>nfantinato</dc:creator>
      <dc:date>2022-09-01T09:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: Events sent to Splunk only from one node</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Events-sent-to-Splunk-only-from-one-node/m-p/437941#M41142</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/111036"&gt;@nfantinato&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry i missed read your original post. You referring to audit logging which you would use cluster log-forwarding as the event notification if for ems logs that was generated by the system.&lt;/P&gt;&lt;P&gt;So regarding the issue receiving logs only from one node, is most likely since the cluster-mgmt lif live on the working node. Try moving the cluster-mgmt lif to node 2 and see if you are getting logs forwarded to the syslog server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 04:14:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Events-sent-to-Splunk-only-from-one-node/m-p/437941#M41142</guid>
      <dc:creator>hmoubara</dc:creator>
      <dc:date>2022-09-02T04:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Events sent to Splunk only from one node</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Events-sent-to-Splunk-only-from-one-node/m-p/437962#M41146</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/14855"&gt;@hmoubara&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your reply.&lt;/P&gt;&lt;P&gt;Unfortunately we are can't move LIFs or our monitoring tools get crazy. We tried to compare settings of two different storages, one sending logs from both nodes and the other sending logs only from node 1 and they seem the same.&lt;BR /&gt;&lt;BR /&gt;Maybe with &lt;FONT face="courier new,courier"&gt;event notification&lt;/FONT&gt; commands, as you suggested initially, we can reach a deeper level of customization.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 15:19:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Events-sent-to-Splunk-only-from-one-node/m-p/437962#M41146</guid>
      <dc:creator>nfantinato</dc:creator>
      <dc:date>2022-09-02T15:19:57Z</dc:date>
    </item>
  </channel>
</rss>

