ActiveIQ Unified Manager会为ONTAP 9.10及更高版本的集群触发过时的安全事件
适用场景
- ActiveIQ Unified Manager (AIQUM) 9.6及更高版本
- ONTAP 9.10.1及更高版本
- CVE-安全漏洞
- AIQ规则
问题描述
- ActiveIQ Unified Manager正在检测ONTAP 9.10及更高版本集群上的旧事件
- 此版本不受生成的任何升级事件的影响
- 即使手动标记为已解决、警报也会在每个每周AutoSupport (ASUP)之后返回
- 对于先前ONTAP版本中已解决的漏洞、将触发影响区域为"升级"的安全事件
- 使用较旧ONTAP版本的集群不受影响
- AIQCASecure日志中充满了
404
在触发这些事件当日搜索旧ASUP的错误消息:
AIQCASecure - 2022-03-28 00:16:17,160 - [INFO] > Collection of ASUPs '202202231317.0.files/, 202202231317.1.files/, 202202231317.2.files/, 202202231318.0.files/, 202202231318.1.files/, 202202231319.0.files/, 202202231339.0.files/, 202202231339.1.files/, 202202231340.0.files/, 202202231340.1.files/, 202202231340.2.files/, 202202231341.0.files/, 202203071310.0.files/, 202203071311.0.files/, 202203071311.1.files/, 202203071311.2.files/, 202203071312.0.files/, 202203071312.1.files/, 202203071332.1.files/, 202203071333.0.files/, 202203071333.1.files/, 202203071333.2.files/, 202203071334.0.files/, 202203071334.1.files/' were not completed in earlier runs. Retrying them.
AIQCASecure - 2022-03-28 00:16:17,386 - [INFO] > ASUP_Download_Begin from x.x.x.x/node-01, ASUP ID - 202202231317.0.files/
AIQCASecure - 2022-03-28 00:16:25,589 - [ERROR] > ASUP_Download_Fail Could not fetch asup 202202231317.0.files/ from /etc/log/autosupport/. Reason - 404 - Not Found
AIQCASecure - 2022-03-28 00:16:25,589 - [INFO] > ASUP_Download_Begin from x.x.x.x/node-01, ASUP ID - 202202231317.1.files/
AIQCASecure - 2022-03-28 00:16:33,795 - [ERROR] > ASUP_Download_Fail Could not fetch asup 202202231317.1.files/ from /etc/log/autosupport/. Reason - 404 - Not Found
AIQCASecure - 2022-03-28 00:16:33,795 - [INFO] > ASUP_Download_Begin from x.x.x.x/node-01, ASUP ID - 202202231317.2.files/
AIQCASecure - 2022-03-28 00:16:42,026 - [ERROR] > ASUP_Download_Fail Could not fetch asup 202202231317.2.files/ from /etc/log/autosupport/. Reason - 404 - Not Found
……Truncated