CIFS File Auditing

Added by Frater Greg about 1 year ago

Greetings,

We are in the evaluation phase of NexentaStor as a replacment for our current storage system. One of our requirements for CIFS storage is the abilty to audit file activity, things like read access or file deletions. It's not something that we do very often but when we need it, it is a must. I have been unable to find any mention of auditing in Nexenta documenation or through google searches. Can anyone tell me what if any auditing/logging abilities Nexenta has for files accessed on NexentaStor via CIFS?

Thanks,

-greg


Replies

RE: CIFS File Auditing - Added by Linda Kateley about 1 year ago

Nexentastor is built on top of illumos. Illumos has a very robust auditing system, but i am checking on whether we provide support for this feature.

I will let you know asap

RE: CIFS File Auditing - Added by Frater Greg about 1 year ago

Thank you Linda. We'd prefer something that would work natively within a Windows environment but understand that is difficult/unlikely with a Unix based product. The primary requirement is the ability to track who deleted, read, moved, etc. a file or folder through a CIFS connection. We would be using this in a Active Directory environment. Thanks again.

RE: CIFS File Auditing - Added by Linda Kateley about 1 year ago

We can log those things, but because it is not something we do in nmc, we can't support it at this time. There are a number of add-on products on the market that can do this kind of auditing..

RE: CIFS File Auditing - Added by Frater Greg about 1 year ago

Linda,

Thanks for gettting back to me. When you say you can log these things but it's not currently supported does that mean the OS or ZFS can do it but the commands to enable and control it have not been built into nmc? If I wanted to take a look at a 3rd party product that does this can you give me the name of one or two (not asking for a recommnedation just someplace to start looking)?

Thanks again,

-greg

RE: CIFS File Auditing - Added by Linda Kateley about 1 year ago

Yes it is baked into the os but not accessable by nmc.

If you want to have a look at it, start with auditd. It has a config file that you can tailor to fit what you want logged and where. If you goggle solaris auditd you should probably have a good start.

RE: CIFS File Auditing - Added by Frater Greg about 1 year ago

Great will do. Appreciate the help.

-greg