Hello,
I have a  FAS2040 with cifs share.
On this share I have a virus that hide folder and replace them by .exe. I suspect one of my user who is infecting file. I need to find at least his IP address.
First I have enabled audit but it was not enough detailled.
Then to correct this issue, I have installed Symantec Protection Engine 7 and configured with my NetApp
Symantec is working well, I can see in NetApp with vscan command that Symantec is doing the job. But I have no entry at all for my hidding virus.
Do you know if there is an option in NetAPP to monitor folder attribute with vscan ? I have make a lot of search but I'm unlucky.
Thank you.