<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access type missing in CIFS audit logs ? in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-type-missing-in-CIFS-audit-logs/m-p/69035#M6287</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I anwer to myself because nobody seems to know ....&lt;SPAN __jive_emoticon_name="plain" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon jive_emote" src="https://community.netapp.com/5.0.1/images/emoticons/plain.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The too I was using&amp;nbsp; (psloglist) wasn't able to extract cifs access type from evt but logparser tool from Microsoft can extract this type of information (evt have to be converted in evtx format otherwise it will not work)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nevertheless, cifs and nfs format logs are really different and we have to do a huge work to be able to parse them. If you have a feedback on how to parse cifs and nfs audit logs ... &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon jive_emote" height="1" src="https://community.netapp.com/5.0.1/images/emoticons/happy.gif" width="1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Mar 2014 08:23:26 GMT</pubDate>
    <dc:creator>XFRSQUAD42</dc:creator>
    <dc:date>2014-03-05T08:23:26Z</dc:date>
    <item>
      <title>Access type missing in CIFS audit logs ?</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-type-missing-in-CIFS-audit-logs/m-p/69029#M6285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to monitor file access events for CIFS and NFS like read, write, delete ....We want to know who did what for each file access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we call "access type" is the action operated by the user like READ, WRITE, DELETE etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use Data ONTAP 7.3.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I activated audit function, and it works well, but I see a difference between NFS and CIFS audit&amp;nbsp; logs. One important informations which is present in NFS audit logs&amp;nbsp; is not present in CIFS audit logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An example is better to understand :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;NFS audit log&amp;nbsp; : &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 448px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="xl65" height="19" width="88"&gt;Security&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" height="19"&gt;File&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" colspan="2"&gt;NFS access = &lt;STRONG&gt;READ&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" colspan="2"&gt;Vol ID = 0x2300fd0b&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" colspan="2"&gt;Snap ID = 0x0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" colspan="2"&gt;Inode = 0x975e05&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" colspan="2"&gt;IP = 1.2.3.4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65"&gt;UID = 0x3da&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" colspan="3"&gt;Full Path = /vol/vol3/home/share/script.ksh&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" colspan="2" height="19"&gt;NetApp Data ONTAP&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" height="19"&gt;(0x0, 0x3e7)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" height="19"&gt;%%4416&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" height="19"&gt;0x1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All informations needed are present : Access type (read in this example) - IP Address - UID - Path&amp;nbsp; and some others informations like inode etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Now take a CIFS audit log : &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 446px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="xl65" height="19" width="94"&gt;Security&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 446px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="xl66" height="19"&gt;File&lt;/TD&gt;&lt;TD class="xl66"&gt;&lt;/TD&gt;&lt;TD class="xl66"&gt;&lt;/TD&gt;&lt;TD class="xl66"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl66" colspan="4" height="19"&gt;\vol\vol0\data\procedure_SLAG&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="right" class="xl65" height="19"&gt;3011&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="right" class="xl65" height="19"&gt;2048&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" colspan="2" height="19"&gt;NetApp Data ONTAP&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" height="19"&gt;toto&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" height="19"&gt;NetApp Data ONTAP&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" height="19"&gt;(0x0, 0x1006)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" colspan="2" height="19"&gt;1.2.3.4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65" height="19"&gt;%%4416&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65"&gt;%%4423&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="xl65"&gt;%%1538&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 446px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="xl65" height="19"&gt;0x20081&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP Address - UID - Path are well present&amp;nbsp; &lt;SPAN style="color: #575757; text-decoration: underline;"&gt;&lt;STRONG&gt;but access type is missing &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #575757;"&gt;. So with this audit log, we can' t know what the user did : read ? write ? delete ? We just know that he accessed a certain file but that's all...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #575757;"&gt;Do you know if it comes from a misconfiguation ? &lt;/SPAN&gt;&lt;SPAN style="color: #575757;"&gt;Or does CIFS audit logs can't provide the access type ? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #575757;"&gt;Thx for your feedback &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 05:42:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-type-missing-in-CIFS-audit-logs/m-p/69029#M6285</guid>
      <dc:creator>XFRSQUAD42</dc:creator>
      <dc:date>2025-06-05T05:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Access type missing in CIFS audit logs ?</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-type-missing-in-CIFS-audit-logs/m-p/69035#M6287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I anwer to myself because nobody seems to know ....&lt;SPAN __jive_emoticon_name="plain" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon jive_emote" src="https://community.netapp.com/5.0.1/images/emoticons/plain.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The too I was using&amp;nbsp; (psloglist) wasn't able to extract cifs access type from evt but logparser tool from Microsoft can extract this type of information (evt have to be converted in evtx format otherwise it will not work)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nevertheless, cifs and nfs format logs are really different and we have to do a huge work to be able to parse them. If you have a feedback on how to parse cifs and nfs audit logs ... &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon jive_emote" height="1" src="https://community.netapp.com/5.0.1/images/emoticons/happy.gif" width="1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 08:23:26 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-type-missing-in-CIFS-audit-logs/m-p/69035#M6287</guid>
      <dc:creator>XFRSQUAD42</dc:creator>
      <dc:date>2014-03-05T08:23:26Z</dc:date>
    </item>
  </channel>
</rss>

