Dell Unity: How To Change the location of the Unity NAS Server Security Log file [c:security.evt] and increase the log size (User Correctable)

Summary: Change the location of the Unity NAS Server Security Log file [c:security.evt] and increase the log size.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

If you do not allow any missing logs during these steps, stop access from users by means such as stopping associated shares, etc.

If you must backup the security.evt already in use, disable auditing and save the file in prior to the steps below.
For details, refer to 


https://dl.dell.com/content/manual69194096-dell-emc-unity-family-configuring-hosts-to-access-smb-file-systems.pdf?language=en-us

Change the location of security.evt file from default ( \\SMB_server_netbios_name\C$\.etc\audit\security.evt ) to custom location on a NAS filesystem

As Domain Admin, open the Windows Registry Editor:  Start>Run>regedit and select "File -> "Connect Network Registry" and enter SMB server hostname/IPaddress/FQDN to connect: 

kA5f10000004KBKCA2_1_0

Once connected you see the local and remote registry, expand the following tree and highlight "Security":  

HKEY_LOCAL_MACHINE/System/CurrentControlSet/Services/Eventlog/Security

kA5f10000004KBKCA2_1_1

When the "File" entry is changed to a new location, the security file is created:

Path used is C:\UnityNASFS\1\security.evt.

kA5f10000004KBKCA2_1_2

kA5f10000004KBKCA2_1_3

Connect to the target CIFS server referring to https://support.emc.com/kb/501783.
Then navigate to Security, right-click it and Clear all Events in order for the change to take effect.

kA5f10000004KBKCA2_1_4

Change the size of the security.evt file from default size of 512 KB to a custom size: 

The size can be changed in registry, a few lines under the "File" location, "MaxSize" can be specified.

kA5f10000004KBKCA2_1_5

The size of security.evt file can as well be specified by using "Event Viewer" on Windows.

Connect to remote computer and choose SMB server using hostname/IPaddress/FQDN:
 
kA5f10000004KBKCA2_1_6

Right-click Security and select properties:

kA5f10000004KBKCA2_1_7

If you have stopped associated shares or disabled auditing, enable auditing and start the associated shares again.
 

Additional Information

NAS Server/SMB server and Filesystem used for this example are:

NAS Server = UnityNAS

kA5f10000004KBKCA2_3_0

SMB Server = \\unitynas.supportw2k8.muc.de

kA5f10000004KBKCA2_3_1

Filesystem = UnityNASFS

kA5f10000004KBKCA2_3_2

Affected Products

Dell EMC Unity Family

Products

Dell EMC Unity Family |Dell EMC Unity All Flash, Dell EMC Unity Family, Dell EMC Unity Hybrid, Dell EMC UnityVSA Professional Edition/Unity Cloud Edition
Article Properties
Article Number: 000010690
Article Type: How To
Last Modified: 23 May 2023
Version:  5
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.