Isilon OneFS:Isilon 稽核裝載值清單
Summary: 可在isi_audit結果的原始輸出中看到的可能 Isilon 值清單。
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Instructions
以下列出可能的 Isilon 值,可在以下資料的原始輸出中看到: isi_audit 結果。
此清單不是特定於版本的。其中一些代碼僅存在於特定版本的 OneFS 上。OneFS 的更高版本具有擴展選項;本文列出了所有版本的所有審核有效負載。此清單旨在作為審查一般單個審計事件的參考。
稽核可以監控和追蹤在 SMB 和 NFS 等通訊協定上連接至 OneFS 檔案系統的帳戶動作。
以原始形式記錄的動作如下所示 (OneFS 的版本和時代有所不同):
{"id":"8f0ae523-1741-12ea-8d1f-010e1ea7b298","timestamp":1575538065995502,"payloadType":"c411a642-c139-4c7a-be58-93680bc20b41","payload":{"protocol":"NFS","zoneID":5,"zoneName":"AuditedZone","eventType":"delete","isDirectory":false,"clientIPAddr":"10.51.221.92","fileName":"\\ifs\\home\\user00001\\staging\\datareview\\infa\\client\\Temp\\datapoint_file.txt","userSID":"S-1-22-2000","userID":2000,"ntStatus":0,"fsId":1,"partialPath":"datapoint_file.txt","rootInode":4512436961,"inode":5128815920}}
{"id":"87b8bbh5-181c-71ea-8d1f-000g1ia7j295","timestamp":1575522001272734,"payloadType":"c411a642-c139-4c7a-be58-93680bc20b41","payload ":"protocol":"NFS","zoneID":5,"zoneName":"AuditedZone","eventType":"create","createResult":"OPENED","isDirectory":true,"desiredAccess":0,"clientIPAddr":"10.14.73.184","createDispo":1,"userSID":"S-1-22-1-2000","userID":2000,"fileName":"\\ifs\\data\\project00004\\dev\\logs\\ABC\\that-one-project-data","ntStatus":0,"fsId":1,"inode":4725492968}}
其中,術語被定義為:
clientIPAddr: String of the IP of the user performing the actionclientIp: The IP address of the client which initiated the request (causing the event)createDispo: Creation disposition specified by user at create/open timedesiredAccess: Desired access specified by user at create/open timeencodedNewName: The encoded new name, if there is a renameencodedPath: The encoded UNC Path of the fileencodedRelativePath: The encoded relative pathencodingType: The encoding used for values, if the value contains characters that cannot be included with XMLevent: The event that caused the checkfileName: String of the absolute path of the file or "UNKNOWN" if audit cannot get the path. The path uses UNC style of path separators ("\\")fileSize: Size of the file at the time of manipulationflag: One of the CEPP_FLAG_XXX defined abovefsId: File system Id of parent directory. This integer is the ID value of the file system in question (default value of 1)id: A value based on the cluster GUID and the audited Zone ID, and is unique for the audited event; this is a UUID for that eventinode: Integer of the inode of the file or directoryisDirectory: Boolean for whether the event is for a file or a directorynewFSId: new file system id (if different from fsId) of target parent directory (rename)newName: The new name (on a rename operation)newParentInode: The inode of the target parent directory (rename)ntStatus: The NTSTATUS code of the action. (0 is STATUS_SUCCESS)ownerId: The id of the owner of the fileownerSid: Sid of the file ownerparentInode: The inode of the containing directorypartialPath: String of the relative path of the file or directory. The path uses UNC style of path separators ("\\")partialPathParentInode: parent inode of the partial path abovepath: UNC name of the file (or dir) - absolute pathpayload: The complete delivered audit event, encapsulating most of these valuespayloadType: String of "4b66b1eb-6e1a-416d-b80c-5a642a603a0b: For Protocol Activity EventspayloadType: String of "7afb8d54-0aa7-4ed4-9691-341313ee37e3: For Audit Driver Loaded Audit EventspayloadType: String of "bbce6a72-a92d-4330-a1f3-e9fd5aed8152: For Audit Driver Unload Audit EventspayloadType: String of "c411a642-c139-4c7a-be58-93680bc20b41: For Protocol Data Eventsprotocol: String of the protocol the action occurred under. Usually one of the following in OneFS 7.2 and later: "CIFS" (for SMB1); "SMB2"; "NFS" (for NFSv3); "NFS4"; "HDFS"relativePath: UNC name of the file (or dir) as accessed by the clientrootInode: Integer of the inode of the directory where the partialPath isserverIp: The IP address of the server at which the event was recordedserver: The Server name where the event occurred. Server IP for NFSshare: The Share on the server; the Export name for NFStimeStamp: The time at which the file operation occurred (cluster local time). It is a 64-bit value, where the high 32 bits represent the time and the lower 32 bits represent the microseconds (Format: 0x1234abcd1234abcd)type: File, Directory, etc.userID: Integer of the UID of the user performing the action (OneFS 7.2 and later)userSID: String of the SID of the user performing the action ("userSID" is not available in "logon" failure events.)zoneID: Integer of the OneFS access zone ID the action is being performed on/throughzoneName: String of the OneFS access zone name at the time of the event that the action is being performed on/through
還有一些其他值和欄位可能有幾個可能的變數。
對於”eventType」物件,某些事件類型在以下類型下列出了額外的有效負載欄位:
eventType = create: For creating or opening a file or directoryeventType = close: For closing a file or directory
額外裝載欄位:(僅在以下情況下有意義”
isDirectory“ 為檔案的 false。)
-
bytesRead: Integer of the total number of bytes read since the open or createbytesWritten: Integer of the total number of bytes written since the openingnumberOfReads: Integer of the total number of reads made to the file since openingnumberOfWrites: Integer of the total number of writes made to the file
eventType = read: The first read to a file since opening it
額外裝載欄位:
-
bytesRead: Integer of the number of bytes read in the first read.
eventType = write: The first write to a file since opening it
額外裝載欄位:
-
bytesWritten: Integer of the number of bytes written in the first write
eventType = rename: Rename of a file or directory.
額外裝載欄位:
-
newFileName: String of the absolute path of the new file name or "UNKNOWN"; the path uses UNC style of path separators ("\\").newPartialPath: String of the relative path of the new file name. The path uses UNC style of path separators ("\\").newRootInode: Integer of the new parent directory's inode that contains "newPartialPath"
eventType = get-security: Get security information or permissions from the file or directory.
-
- (沒有額外的欄位)
eventType = set-security: Set security information or permissions on the file or directory.
-
- (沒有額外的欄位)
eventType = delete: Delete a file or directory.
-
- (沒有額外的欄位)
eventType = logon: Logging on.
-
- (沒有額外的欄位)
eventType = logoff: Logging off.
-
- (沒有額外的欄位)
eventType = tree-connect: Performing an SMB tree connect.-
- (沒有額外的欄位)
對於審計事件 payloadType = "7afb8d54-0aa7-4ed4-9691-341313ee37e3" (審核驅動程式載入的審核事件)。
- 這些是載入審核篩選器驅動程式時發出的審核事件信號。
- 這些審核事件包含一個「有效負載」,其中包含指定載入的審核驅動程式的 JSON 字串。
-
Audit Driver: flt_audit Loaded: SMB audit driver loaded.Audit Driver: flt_audit_nfs Loaded: NFS audit driver loaded.Audit Driver: flt_audit_hdfs Loaded: HDFS audit driver loaded.
對於審計事件 payloadType = "bbce6a72-a92d-4330-a1f3-e9fd5aed8152" (審核驅動程式卸載審核事件)。
- 這些是卸載審核篩選器驅動程式時的審核事件信號。
- 這些稽核事件包含一個「payload」,其中包含指定哪個稽核驅動程式停止的 JSON 字串。
-
Shutting down audit driver: flt_audit: SMB audit driver stopped.Shutting down audit driver: flt_audit_nfs: NFS audit driver loaded.Shutting down audit driver: flt_audit_hdfs: HDFS audit driver loaded.
eventType:String of the audit event type of action. One of:create: Create or open a file or directory.close: Close a file or directory.read: First read on a file since opening it.write: First write on a file since opening it.rename: Rename a file or directory.delete: Delete a file or directory.set-security: Set security information or permissions on a file or directory.get-security: Get security information or permissions on a file or directory.
createDispo: Integer of the create/open disposition; this is the request of how the file or directory should be opened or created:0 - FILE_SUPERSEDE - Replace an existing file or create it.1 - FILE_OPEN - Open an existing file or fail.2 - FILE_CREATE - Create a nonexisting file or fail.3 - FILE_OPEN_IF - Open an existing file or create it.4 - FILE_OVERWRITE - Open and overwrite an existing file or fail.5 - FILE_OVERWRITE_IF - Open and overwrite an existing file or create it.
createResult: String of the create/open result. One of:SUPERSEDED: The file existed and was replaced.OPENED: The file existed and was opened.CREATED: The file did not exist and was created.EXISTS: The file exists and was not created.DOES_NOT_EXIST: The file did not exist and was not opened.UNKNOWN: Unknown
desiredAccess: Integer of the bitwise combined wanted access of the following:
Affected Products
IsilonProducts
IsilonArticle Properties
Article Number: 000019850
Article Type: How To
Last Modified: 25 Mar 2026
Version: 5
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.