By default all that is enabled is LOGON and LOGOFF events, which does not track the share name or anything like that... You have a whole slew of options, but (and I can't stress this enough) USE CAUTION. Excess logging can and will cause performance issues with the entire cluster. That being said, here are some examples:
To log share a which share a user accesses: isi smb config global modify --audit-fileshare=success
To log file deleted: isi smb config global modify --audit-global-sacl-success=std_delete
To log file opens: isi smb config global modify --audit-global-sacl-success=generic_exec
To log creation, edits, and renames: isi smb config global modify --audit-global-sacl-success=generic_write
To log opens, deleted, creates, edits, renames: isi smb config global modify --audit-global-sacl-success=generic_all
Also the logs will fill up very, very, very quickly if you have a lot of activity...
There are a bunch more, but that is the basic idea... again BE CAREFUL.... don't kill your cluster... when in doubt, engage support.
You should see a file smb.log, which has the info you want. It has a log rotate setup to move them at 50gb (I think) and compress them inside that same path.
i seen all logon & logoff events at this point. just now i deleted one folder which is not logged a msg here also is there any additional setting for this audit to change to view the share name like /ifs/serverfolder/file1 is access by user1 / deleted by user1 like that.. all your help is really appreciated
You may also want to look at audit logs on all the nodes that are accessible over the network. Audit logs are individual for each nodes. So you may not find all the activity in one node audit logs as there may be a Round-Robin policy enabled for cifs connection.
cincystorage
2 Intern
•
467 Posts
4356
1
Posted May 14th, 2013 11:00
By default all that is enabled is LOGON and LOGOFF events, which does not track the share name or anything like that... You have a whole slew of options, but (and I can't stress this enough) USE CAUTION. Excess logging can and will cause performance issues with the entire cluster. That being said, here are some examples:
To log share a which share a user accesses: isi smb config global modify --audit-fileshare=success
To log file deleted: isi smb config global modify --audit-global-sacl-success=std_delete
To log file opens: isi smb config global modify --audit-global-sacl-success=generic_exec
To log creation, edits, and renames: isi smb config global modify --audit-global-sacl-success=generic_write
To log opens, deleted, creates, edits, renames: isi smb config global modify --audit-global-sacl-success=generic_all
Also the logs will fill up very, very, very quickly if you have a lot of activity...
There are a bunch more, but that is the basic idea... again BE CAREFUL.... don't kill your cluster... when in doubt, engage support.