Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
One of my customers has multiple shares and needs SMB file share logs to get forwarded to the Syslog server. They need this to identify unauthorized access as well as if someone changes permission to everyone for the shares.
Is it possible in ONTAP? What I understand is ONTAP holds failure authentication logs with server name and not with share information.
Is it possible to match the ask?
1 REPLY 1
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unfortunately, not. Yes, ems events can be pushed to syslog such as authentication failure etc, but not share/file access audit information.
NAS audit logs are not integrated with the syslog framework and must be saved to a local path to the system. A pull mechanism can be used to retrieved them using CIFS or NFS.
ONTAP only supports remote logging of EMS messages:
https://kb.netapp.com/onprem/ontap/hardware/What_ONTAP_logs_can_be_exported_to_syslog
Related:
https://docs.netapp.com/us-en/ontap/nas-audit/auditing-events-concept.html#smb-events
https://www.netapp.com/pdf.html?item=/media/16330-tr-4189pdf.pdf
