Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products

PowerScale OneFS 9.6.x.x CLI Administration Guide

PDF

Enable protocol access auditing

Audit SMB, NFS, and S3 protocol access to generate events on a per-access zone basis and forward the events to the Common Event Enabler (CEE) for export to third-party products.

About this task

NOTE: Because each audited event consumes system resources, it is recommended that you only configure zones for events that are required by your auditing application. In addition, it is recommended that you install and configure third-party auditing applications before you enable the OneFS auditing feature. Otherwise, the large backlog that is performed by this feature may cause results to not be up to date for a considerable amount of time. Also, you can manually configure the time that you want audit events to be forwarded by running the isi audit settings global modify --cee-log-time command.

Steps

Run the isi audit settings global modify command.
The following command enables auditing of protocol access events in the zone3 and zone5 access zones, and forwards logged events to a CEE server:
isi audit settings global modify --protocol-auditing-enabled=yes \
 --cee-server-uris=http://sample.com:12228/cee \
 --hostname=cluster.domain.com --audited-zones=zone3,zone5
OneFS logs audited protocol events to a binary file within /ifs/.ifsvar/audit/logs. The CEE service forwards the logged events through an HTTP PUT operation to a defined endpoint.

Next steps

You can modify the types of protocol access events to be audited by running the isi audit settings modify command. You can also enable forwarding of protocol access events to the remote syslog server by running the isi audit settings modify command with the --syslog-forwarding-enabled option.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\