由于缺少SACL、CIFS审核无法按预期工作
适用场景
- ONTAP 9
- CIFS审核
问题描述
- 不会生成文件访问审核事件
- 可能会出现登录和注销事件
- 文件名未显示在审核事件中
vserver security file-directory在卷或CIFS共享上不显示SACL
::> vserver security file-directory show -vserver svm_netapp -path /vol_netapp -instanceVserver: svm_netappFile Path: /vol_netappFile Inode Number: 64Security Style: ntfsEffective Style: ntfsDOS Attributes: 10DOS Attributes in Text: ----D---Expanded Dos Attributes: -UNIX User Id: 0UNIX Group Id: 0UNIX Mode Bits: 777UNIX Mode Bits in Text: rwxrwxrwxACLs: NTFS Security DescriptorControl:0x9504Owner:BUILTIN\AdministratorsGroup:BUILTIN\AdministratorsDACL - ACEsALLOW-NT AUTHORITY\SYSTEM-0x1f01ff-OI|CIALLOW-BUILTIN\Administrators-0x1f01ff-OI|CIALLOW-Everyone-0x1f01ff-OI|CI- 审核设置正确:
::*> vserver audit show -vserver svm1 -fields events
vserver events
---------- --------------------------------------------------------------------------
svm1 file-ops,cifs-logon-logoff,user-account,security-group,audit-policy-change