<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Audit logs in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Audit-logs/m-p/27210#M6340</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt; &lt;BR /&gt;I am an Security Analyst and i was assigned to a Storage Project[Netapp] for which i need some information in regard with the logging..,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;One more query is the log format same as filer O/P in data ontap.&lt;/P&gt;&lt;P&gt; &lt;BR /&gt; &lt;BR /&gt;Log Format for Messages &lt;BR /&gt;log format:&lt;BR /&gt;&amp;lt;PRI&amp;gt; &amp;lt;TIME&amp;gt; ' ' &amp;lt;MESG&amp;gt; '[' &amp;lt;MDATA&amp;gt; ' ' &amp;lt;SIG&amp;gt; ' '] &lt;BR /&gt;&amp;lt;DAY&amp;gt; Event Day &lt;BR /&gt;&amp;lt;DATE&amp;gt; Event Date &lt;BR /&gt;&amp;lt;TIME&amp;gt;&amp;nbsp; Event Time &lt;BR /&gt;&amp;lt;[EVENT:&amp;gt; Event Name which is Event ID &lt;BR /&gt;&amp;lt;:Severity]&amp;gt; Severity is categories like emerg, alert, crit, err, warning, notice, info, debug &lt;BR /&gt;&amp;lt;MSG&amp;gt; Details About Message &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;Log Format of adtlog.evt &lt;BR /&gt;log format: &lt;BR /&gt;DATE | TIME | Event ID | Operation Outcome | Number of seconds of duplicated events | Filer Name | Number of duplicate events detected | Protocol used | User | Object | Access Code&amp;nbsp; &lt;BR /&gt; &lt;BR /&gt;Sample Log: &lt;BR /&gt;&amp;nbsp; 20060801|104748|560|Success|0|DATA|0|CIFS|petemo|DATA|-|\vol\vol0\etc|Read Attributes| &lt;BR /&gt; &lt;BR /&gt;&amp;lt;Date&amp;gt;&amp;nbsp; Date (20060801) &lt;BR /&gt;&amp;lt;Time&amp;gt;&amp;nbsp; Time (104742) &lt;BR /&gt;&amp;lt;Event ID&amp;gt; Event ID (540,538,560) Support Windows Event ID’s &lt;BR /&gt;&amp;lt;Operation Outcome&amp;gt;&amp;nbsp; Operation Details (Success or Failure) &lt;BR /&gt;&amp;lt;Number of seconds of duplicated events&amp;gt; Number &lt;BR /&gt;&amp;lt;Filer Name&amp;gt; Filer Name (Data) &lt;BR /&gt;&amp;lt;Number of duplicate events detected&amp;gt; Number &lt;BR /&gt;&amp;lt;Protocol used&amp;gt;&amp;nbsp; Protocol Used (Unknown, CIFS, NFS,HTTP) &lt;BR /&gt;&amp;lt;User&amp;gt;&amp;nbsp; User Name (administrator, petemo) &lt;BR /&gt;&amp;lt;Object&amp;gt;&amp;nbsp; Object Details e.g.(\vol\vol0\etc\lclgroups.cfg) &lt;BR /&gt;&amp;lt;Access Code&amp;gt;&amp;nbsp; (Read:Read Attributes)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Iyyappan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jun 2025 06:59:18 GMT</pubDate>
    <dc:creator>vairavaniyyappan</dc:creator>
    <dc:date>2025-06-05T06:59:18Z</dc:date>
    <item>
      <title>Audit logs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Audit-logs/m-p/27210#M6340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt; &lt;BR /&gt;I am an Security Analyst and i was assigned to a Storage Project[Netapp] for which i need some information in regard with the logging..,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;One more query is the log format same as filer O/P in data ontap.&lt;/P&gt;&lt;P&gt; &lt;BR /&gt; &lt;BR /&gt;Log Format for Messages &lt;BR /&gt;log format:&lt;BR /&gt;&amp;lt;PRI&amp;gt; &amp;lt;TIME&amp;gt; ' ' &amp;lt;MESG&amp;gt; '[' &amp;lt;MDATA&amp;gt; ' ' &amp;lt;SIG&amp;gt; ' '] &lt;BR /&gt;&amp;lt;DAY&amp;gt; Event Day &lt;BR /&gt;&amp;lt;DATE&amp;gt; Event Date &lt;BR /&gt;&amp;lt;TIME&amp;gt;&amp;nbsp; Event Time &lt;BR /&gt;&amp;lt;[EVENT:&amp;gt; Event Name which is Event ID &lt;BR /&gt;&amp;lt;:Severity]&amp;gt; Severity is categories like emerg, alert, crit, err, warning, notice, info, debug &lt;BR /&gt;&amp;lt;MSG&amp;gt; Details About Message &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;Log Format of adtlog.evt &lt;BR /&gt;log format: &lt;BR /&gt;DATE | TIME | Event ID | Operation Outcome | Number of seconds of duplicated events | Filer Name | Number of duplicate events detected | Protocol used | User | Object | Access Code&amp;nbsp; &lt;BR /&gt; &lt;BR /&gt;Sample Log: &lt;BR /&gt;&amp;nbsp; 20060801|104748|560|Success|0|DATA|0|CIFS|petemo|DATA|-|\vol\vol0\etc|Read Attributes| &lt;BR /&gt; &lt;BR /&gt;&amp;lt;Date&amp;gt;&amp;nbsp; Date (20060801) &lt;BR /&gt;&amp;lt;Time&amp;gt;&amp;nbsp; Time (104742) &lt;BR /&gt;&amp;lt;Event ID&amp;gt; Event ID (540,538,560) Support Windows Event ID’s &lt;BR /&gt;&amp;lt;Operation Outcome&amp;gt;&amp;nbsp; Operation Details (Success or Failure) &lt;BR /&gt;&amp;lt;Number of seconds of duplicated events&amp;gt; Number &lt;BR /&gt;&amp;lt;Filer Name&amp;gt; Filer Name (Data) &lt;BR /&gt;&amp;lt;Number of duplicate events detected&amp;gt; Number &lt;BR /&gt;&amp;lt;Protocol used&amp;gt;&amp;nbsp; Protocol Used (Unknown, CIFS, NFS,HTTP) &lt;BR /&gt;&amp;lt;User&amp;gt;&amp;nbsp; User Name (administrator, petemo) &lt;BR /&gt;&amp;lt;Object&amp;gt;&amp;nbsp; Object Details e.g.(\vol\vol0\etc\lclgroups.cfg) &lt;BR /&gt;&amp;lt;Access Code&amp;gt;&amp;nbsp; (Read:Read Attributes)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Iyyappan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:59:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Audit-logs/m-p/27210#M6340</guid>
      <dc:creator>vairavaniyyappan</dc:creator>
      <dc:date>2025-06-05T06:59:18Z</dc:date>
    </item>
    <item>
      <title>Audit logs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Audit-logs/m-p/27214#M6343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; &lt;SPAN style="font-family: 'Verdana','sans-serif'; color: #3333ff; font-size: 10pt;"&gt;&lt;A href="https://kb.netapp.com/support/index?page=content&amp;amp;id=1011243" target="_blank"&gt;https://kb.netapp.com/support/index?page=content&amp;amp;id=1011243&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Verdana','sans-serif'; color: #3333ff; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 12pt;"&gt;&lt;SPAN style="font-family: 'Verdana','sans-serif'; color: #3333ff; font-size: 10pt;"&gt;Please make sure that the auditing is enabled in the windows. I have copy pasted the section below for your convenience.&lt;BR /&gt;&lt;BR /&gt;===========================================================&lt;BR /&gt;To setup additional items that will be audited, you will need to configure specific audit rules for each share or qtree:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL start="1"&gt;&lt;LI&gt;&lt;SPAN style="font-family: 'Verdana','sans-serif'; color: #3333ff; font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; In Computer Manager, go to the qtree or folder that you wish to audit.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: 'Verdana','sans-serif'; color: #3333ff; font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select the Security tab , then the Advanced tab, and select Auditing.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: 'Verdana','sans-serif'; color: #3333ff; font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Specify the groups and events to be audited.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Verdana','sans-serif'; color: #3333ff; font-size: 10pt;"&gt;============================================================&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Aug 2011 03:24:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Audit-logs/m-p/27214#M6343</guid>
      <dc:creator>TNQNETAPPADMIN</dc:creator>
      <dc:date>2011-08-07T03:24:11Z</dc:date>
    </item>
  </channel>
</rss>

