<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Audit log in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Audit-log/m-p/455858#M10088</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you have already done the storage side configuration for this CIFS audit.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/How_to_set_up_NAS_auditing_in_ONTAP_9" target="_blank"&gt;https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/How_to_set_up_NAS_auditing_in_ONTAP_9&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can run a “vserver audit show” to check where the logs are getting stored.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;cluster1::&amp;gt; vserver audit show&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Vserver&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; State&amp;nbsp; Event Types Log Format &lt;STRONG&gt;Target Directory&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;----------- ------ ----------- ---------- --------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;vs1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;false&amp;nbsp; file-ops&amp;nbsp;&amp;nbsp;&amp;nbsp; evtx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;/audit_log&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;You can map the same Target Directory path on to one of your windows clients to access the audit logs.&lt;/P&gt;&lt;P&gt;The audit file gets created automatically within the same vserver while configuraing the audits.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this information helps.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 02:02:21 GMT</pubDate>
    <dc:creator>ChLokesh</dc:creator>
    <dc:date>2024-10-17T02:02:21Z</dc:date>
    <item>
      <title>Audit log</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Audit-log/m-p/455607#M10085</link>
      <description>&lt;P&gt;A customer asked about Audit log.&lt;BR /&gt;If I set Auditing in the Security Advanced tab of the window properties, where do the logs go?&lt;BR /&gt;Do I create a shared volume so that the logs for each SVM or Share item are recorded?&lt;BR /&gt;I would appreciate it if you could tell me about this issue.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 05:14:27 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Audit-log/m-p/455607#M10085</guid>
      <dc:creator>SMH</dc:creator>
      <dc:date>2024-10-04T05:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Audit log</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Audit-log/m-p/455858#M10088</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you have already done the storage side configuration for this CIFS audit.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/How_to_set_up_NAS_auditing_in_ONTAP_9" target="_blank"&gt;https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/How_to_set_up_NAS_auditing_in_ONTAP_9&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can run a “vserver audit show” to check where the logs are getting stored.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;cluster1::&amp;gt; vserver audit show&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Vserver&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; State&amp;nbsp; Event Types Log Format &lt;STRONG&gt;Target Directory&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;----------- ------ ----------- ---------- --------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;vs1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;false&amp;nbsp; file-ops&amp;nbsp;&amp;nbsp;&amp;nbsp; evtx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;/audit_log&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;You can map the same Target Directory path on to one of your windows clients to access the audit logs.&lt;/P&gt;&lt;P&gt;The audit file gets created automatically within the same vserver while configuraing the audits.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this information helps.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 02:02:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Audit-log/m-p/455858#M10088</guid>
      <dc:creator>ChLokesh</dc:creator>
      <dc:date>2024-10-17T02:02:21Z</dc:date>
    </item>
  </channel>
</rss>

