Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Community We want to check which client IPs access a Cifs share and map/check the whole stuff in Splunk. Is a CIFS audit log forward to a Splunk server possible? If yes how? Any Documentation available how to configure? I find in the NetApp documentation only general information about the "audit" log forwarding but not explicitly about the CIFS audit. If it is not possible via Splunk, what solution does NetApp offer here? Many Thanks in advance. Juergen
Solved! See The Solution
1 ACCEPTED SOLUTION
hmoubara has accepted the solution
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Correct. CIFS audit logs cannot be pushed to another server, only accessed through a CIFS share.
Reference from documentation:
https://www.netapp.com/pdf.html?item=/media/16330-tr-4189pdf.pdf
Pg. 12
3 REPLIES 3
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can forward CIFS audit logs to a syslog server. The following may be helpful in the needed configuration:
https://docs.netapp.com/us-en/ontap/system-admin/changes-audit-logging-ontap-9-concept.html
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks. Yes for the normal "audit" log its clear. it will use the syslog framework.
My Question was regarding "cifs audit" logs and forward directly into Splunk for parsing.
hmoubara has accepted the solution
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Correct. CIFS audit logs cannot be pushed to another server, only accessed through a CIFS share.
Reference from documentation:
https://www.netapp.com/pdf.html?item=/media/16330-tr-4189pdf.pdf
Pg. 12
