ONTAP Discussions
ONTAP Discussions
Solved! See The Solution
Correct. CIFS audit logs cannot be pushed to another server, only accessed through a CIFS share.
Reference from documentation:
https://www.netapp.com/pdf.html?item=/media/16330-tr-4189pdf.pdf
Pg. 12
You can forward CIFS audit logs to a syslog server. The following may be helpful in the needed configuration:
https://docs.netapp.com/us-en/ontap/system-admin/changes-audit-logging-ontap-9-concept.html
Thanks. Yes for the normal "audit" log its clear. it will use the syslog framework.
My Question was regarding "cifs audit" logs and forward directly into Splunk for parsing.
Correct. CIFS audit logs cannot be pushed to another server, only accessed through a CIFS share.
Reference from documentation:
https://www.netapp.com/pdf.html?item=/media/16330-tr-4189pdf.pdf
Pg. 12