<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB logs forwarding to syslog server in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/SMB-logs-forwarding-to-syslog-server/m-p/445204#M42426</link>
    <description>&lt;P&gt;Unfortunately, not. Yes, ems events can be pushed to syslog such as authentication failure etc, but not share/file access audit information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAS audit logs are &lt;STRONG&gt;not integrated&lt;/STRONG&gt; with the syslog framework and must be saved to a local path to the system. A &lt;STRONG&gt;pull&lt;/STRONG&gt; mechanism can be used to retrieved them using CIFS or NFS.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/da/NAS/Can_NAS_audit_logs_be_forwarded_to_a_syslog_server_or_an_external_path" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/da/NAS/Can_NAS_audit_logs_be_forwarded_to_a_syslog_server_or_an_external_path&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ONTAP only supports remote logging of &lt;STRONG&gt;EMS&lt;/STRONG&gt; messages:&lt;BR /&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/hardware/What_ONTAP_logs_can_be_exported_to_syslog" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/hardware/What_ONTAP_logs_can_be_exported_to_syslog&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Related:&lt;BR /&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/nas-audit/auditing-events-concept.html#smb-events" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/nas-audit/auditing-events-concept.html#smb-events&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.netapp.com/pdf.html?item=/media/16330-tr-4189pdf.pdf" target="_blank"&gt;https://www.netapp.com/pdf.html?item=/media/16330-tr-4189pdf.pdf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jun 2023 10:33:30 GMT</pubDate>
    <dc:creator>Ontapforrum</dc:creator>
    <dc:date>2023-06-13T10:33:30Z</dc:date>
    <item>
      <title>SMB logs forwarding to syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SMB-logs-forwarding-to-syslog-server/m-p/445202#M42424</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of my customers has multiple shares and needs SMB file share logs to get forwarded to the Syslog server. They need this to identify unauthorized access as well as if someone changes permission to everyone for the shares.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible in ONTAP? What I understand is ONTAP holds failure authentication logs with server name and not with share information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to match the ask?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:48:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SMB-logs-forwarding-to-syslog-server/m-p/445202#M42424</guid>
      <dc:creator>Ankit15</dc:creator>
      <dc:date>2025-06-04T09:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: SMB logs forwarding to syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SMB-logs-forwarding-to-syslog-server/m-p/445204#M42426</link>
      <description>&lt;P&gt;Unfortunately, not. Yes, ems events can be pushed to syslog such as authentication failure etc, but not share/file access audit information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAS audit logs are &lt;STRONG&gt;not integrated&lt;/STRONG&gt; with the syslog framework and must be saved to a local path to the system. A &lt;STRONG&gt;pull&lt;/STRONG&gt; mechanism can be used to retrieved them using CIFS or NFS.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/da/NAS/Can_NAS_audit_logs_be_forwarded_to_a_syslog_server_or_an_external_path" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/da/NAS/Can_NAS_audit_logs_be_forwarded_to_a_syslog_server_or_an_external_path&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ONTAP only supports remote logging of &lt;STRONG&gt;EMS&lt;/STRONG&gt; messages:&lt;BR /&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/hardware/What_ONTAP_logs_can_be_exported_to_syslog" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/hardware/What_ONTAP_logs_can_be_exported_to_syslog&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Related:&lt;BR /&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/nas-audit/auditing-events-concept.html#smb-events" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/nas-audit/auditing-events-concept.html#smb-events&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.netapp.com/pdf.html?item=/media/16330-tr-4189pdf.pdf" target="_blank"&gt;https://www.netapp.com/pdf.html?item=/media/16330-tr-4189pdf.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 10:33:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SMB-logs-forwarding-to-syslog-server/m-p/445204#M42426</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-06-13T10:33:30Z</dc:date>
    </item>
  </channel>
</rss>

