I'm looking for a way to see when users access CIFS on specific SVM from specific IP what files they are accessing.
Have a network segment will be isolating and want to verify if clients in this range are accessing CIF shares.
See The Solution
Basic CIFS Audit will have what you need. You can collect the load (use the XLM collect) and grab the file and search via IP.
View solution in original post
Looks like security trace filters will do what I need. Thanks for pointing me in right direction.
Keep in mind you don't want to keep security trace filters enabled indefinitely (if you're referring to vserver security trace).
Instead, use native SMB audit or a 3rd party fpolicy server.
No problem Eric, and keep in mind what @parisi said.