EMS 日志报告锁定的 vsadmin 的事件 security.invalid.login
适用于
- ONTAP 9
- ONTAPI
- SnapDrive
问题描述
- 获取有关外部系统登录尝试的通知警报中
EMS.LOG.GZ:security.invalid.login: Failed to authenticate login attempt to Vserver: svm_data, username: vsadmin, application: ontapi在 CLI 中:Cluster-01::> event log show -message-name security.invalid.login Time Node Severity Event ------------------- ---------------- ------------- --------------------------- 3/22/2021 08:00:07 Cluster-01 ALERT security.invalid.login: Failed to authenticate login attempt to Vserver: svm_data, username: vsadmin, application: ontapi.
- 识别登录尝试失败的 IP 地址和用户
security audit log showCluter-01::> security audit log show -timestamp "3/22/2021 08:00:07" Time Node Audit Message ------------------------ ----------- ----------------------- Mon Mar 22 08:00:07 2021 Cluster-01 [kern_audit:info:2345] 8503e800002b7bbe :: Cluster-01:ontapi :: 10.10.10.1:10101 :: svm_data:vsadmin :: Login Attempt :: Error: Error: Account currently locked. Contact the storage administrator to unlock it. Mon Mar 22 08:00:07 2021 Cluster-01 [kern_audit:info:2345] 8503e800002b7bbe :: Cluster-01:ontapi :: 10.10.10.1:10101 :: svm_data:vsadmin :: Login Attempt :: Error: Authentication failed. Mon Mar 22 08:00:07 2021 Cluster-01 [kern_audit:info:8617] 8503e800002b7bbe :: Cluster-01:ontapi :: 10.10.10.1:10101 :: svm_data:vsadmin :: POST /servlets/netapp.servlets.admin.XMLrequest_filer HTTP/1.1 :: Error: 401 Unauthorized 3 entries were displayed.
- 使用 vsadmin 用户标识为 Snapdrive 的 IP