ONTAP alerts reference in NetApp Console local deployment
This reference lists the ONTAP alerts that NetApp Console local deployment can monitor, organized by impact category.
Severity mapping
The same EMS alert can appear as Critical, Warning, or Info, depending on the ONTAP event that caused it:
-
Critical: Maps from ONTAP severities
alert,emergency -
Warning: Maps from ONTAP severity
error -
Info: Maps from ONTAP severities
notice,informational -
Other: Passed through as-is
Dynamic mapping lets a single alert rule emit different severities depending on the runtime context of the EMS event.
The sections below group alerts by impact category and sort each table alphabetically by alert name.
Availability alerts
These alerts can affect system, service, or data availability.
| Alert name | Severity | Type | Description |
|---|---|---|---|
Active Directory Server Connection Down |
Critical |
EMS |
All configured AD/LDAP servers for this SVM are unreachable. |
Aggregate isn't online |
Critical |
Metric |
Some aggregates are offline. Volume creation could cause duplicate FSIDs. |
Antivirus server busy |
Critical, Warning, Info |
EMS |
The antivirus server is overloaded and can't accept additional scan requests. |
AWS credentials not initialized |
Critical, Warning, Info |
EMS |
A module attempted to access AWS IAM role-based credentials before they were initialized. |
Cloud tier unreachable |
Critical, Warning, Info |
EMS |
A storage node cannot connect to Cloud Tier object store API. Some data will be inaccessible. |
Disk failure |
Critical |
Metric |
A disk has failed, is being sanitized, or is in Maintenance mode. |
Disk out of service |
Critical, Warning, Info |
EMS |
A disk was taken out of service due to failure, sanitization, or maintenance. |
Disk shelves power supply removed |
Critical, Warning, Info |
EMS |
A power supply unit was removed from the disk shelf. |
FC target port commands exceeded |
Critical, Warning, Info |
EMS |
The number of outstanding commands on the physical FC target port exceeds the supported limit. |
Giveback of storage pool failed |
Critical, Warning, Info |
EMS |
This event occurs during the relocation of a storage pool (aggregate) as part of a storage failover (SFO) giveback, when the destination node cannot reach the object stores. |
HA interconnect down |
Critical, Warning, Info |
EMS |
The high-availability (HA) interconnect is down. Risk of service outage when failover is not available. |
InstanceDown |
Critical |
Metric |
The monitored instance is unreachable and may be down or experiencing network issues. |
LUN destroyed |
Critical, Warning, Info |
EMS |
A LUN was destroyed and is no longer accessible. |
LUN offline |
Critical, Warning, Info |
EMS |
A LUN was taken offline manually. |
Main unit fan failed |
Critical, Warning, Info |
EMS |
One or more main unit fans have failed. The system remains operational. |
Main unit fan in warning state |
Critical, Warning, Info |
EMS |
One or more main unit cooling fans are in a warning state. |
Max sessions per user exceeded |
Critical, Warning, Info |
EMS |
You have exceeded the maximum number of sessions allowed per user over a TCP connection. |
Max times open per file exceeded |
Critical, Warning, Info |
EMS |
You have exceeded the maximum number of times that you can open the file over a TCP connection. |
MetroCluster automatic unplanned switchover disabled |
Critical, Warning, Info |
EMS |
Automatic unplanned switchover capability has been disabled on this cluster. |
MetroCluster monitoring |
Critical, Warning, Info |
EMS |
The system health monitor alert is detected. |
NFSv4 store pool exhausted |
Critical, Warning, Info |
EMS |
A NFSv4 store pool has been exhausted. |
NetBIOS name conflict |
Critical, Warning, Info |
EMS |
The NetBIOS Name Service has received a negative response to a name registration request, from a remote machine. |
No registered scan engine |
Critical, Warning, Info |
EMS |
The antivirus connector notified ONTAP that it does not have a registered scan engine. |
No Vscan connection |
Critical, Warning, Info |
EMS |
ONTAP has no Vscan connection to service virus scan requests. This might cause data unavailability if the scan-mandatory option is enabled. |
Non-responsive antivirus server |
Critical, Warning, Info |
EMS |
ONTAP detected a non-responsive antivirus server and forcibly closed its Vscan connection. |
Nonexistent admin share |
Critical, Warning, Info |
EMS |
Vscan issue: a client has attempted to connect to a nonexistent ONTAP_ADMIN$ share. |
NVRAM battery low |
Critical, Warning, Info |
EMS |
The NVRAM battery capacity is critically low. There might be a potential data loss if the battery runs out of power. |
NVMe namespace destroyed |
Critical, Warning, Info |
EMS |
An NVMe namespace was destroyed and is no longer accessible. |
NVMe namespace offline |
Critical, Warning, Info |
EMS |
An NVMe namespace was taken offline manually. |
NVMe namespace online |
Critical, Warning, Info |
EMS |
An NVMe namespace was brought back online. |
NVMe-oF license grace period active |
Critical, Warning, Info |
EMS |
This event occurs on a daily basis when the NVMe over Fabrics (NVMe-oF) protocol is in use and the grace period of the license is active. |
NVMe-oF license grace period expired |
Critical, Warning, Info |
EMS |
The NVMe over Fabrics (NVMe-oF) license grace period is over and the NVMe-oF functionality is disabled. |
NVMe-oF license grace period start |
Critical, Warning, Info |
EMS |
The NVMe over Fabrics (NVMe-oF) configuration was detected during the upgrade to ONTAP 9.5 software. |
Object store host unresolvable |
Critical, Warning, Info |
EMS |
The object store server host name cannot be resolved to an IP address. |
Object store intercluster LIF down |
Critical, Warning, Info |
EMS |
The object-store client cannot find an operational LIF to communicate with the object store server. |
Object store signature mismatch |
Critical, Warning, Info |
EMS |
The request signature sent to the object store server does not match the signature calculated by the client. |
Port Status Down |
Critical |
EMS |
This Ethernet port is down. Traffic on that link may be affected. |
READDIR timeout |
Critical, Warning, Info |
EMS |
A READDIR file operation has exceeded the timeout that it is allowed to run in WAFL. |
Relocation of storage pool failed |
Critical, Warning, Info |
EMS |
This event occurs during the relocation of an storage pool (aggregate), when the destination node cannot reach the object stores. |
SAN "active-active" state changed |
Critical, Warning, Info |
EMS |
The SAN pathing is no longer symmetric. |
Service Processor heartbeat missed |
Critical, Warning, Info |
EMS |
ONTAP is not receiving an expected heartbeat signal from the Service Processor (SP). |
Service Processor heartbeat stopped |
Critical, Warning, Info |
EMS |
ONTAP is no longer receiving heartbeats from the Service Processor (SP). |
Service Processor not configured |
Critical, Warning, Info |
EMS |
This event occurs on a weekly basis, to remind you to configure the Service Processor (SP). |
Service Processor offline |
Critical, Warning, Info |
EMS |
The Service Processor (SP) is offline. |
SFP in FC target adapter receiving low power |
Critical, Warning, Info |
EMS |
This alert occurs when the power received (RX) by a small form-factor pluggable transceiver (SFP in FC target) is at a level below the defined threshold. |
SFP in FC target adapter transmitting low power |
Critical, Warning, Info |
EMS |
This alert occurs when the power transmitted (TX) by a small form-factor pluggable transceiver (SFP in FC target) is at a level below the defined threshold. |
Shadow copy failed |
Critical, Warning, Info |
EMS |
A Volume Shadow Copy Service (VSS), a Microsoft Server backup and restore service operation, has failed. |
Shelf fan failed |
Critical, Warning, Info |
EMS |
The indicated cooling fan or fan module of the shelf has failed. |
SnapMirror lag time is high |
Critical |
Metric |
The SnapMirror relationship is more than one hour behind its expected update schedule. |
Storage Failover Interconnect One Or More Links Down |
Warning |
EMS |
One or more HA interconnect links to the partner node are down. Failover redundancy is reduced. |
Storage switch power supplies failed |
Critical, Warning, Info |
EMS |
There is a missing power supply in the cluster switch. Redundancy is reduced. |
Storage VM stop succeeded |
Critical, Warning, Info |
EMS |
The storage VM was stopped successfully. |
SVM Configuration Replication License Invalid |
Warning |
EMS |
The SVM-DR configuration replication license is missing, expired, or not applied |
System cannot operate due to main unit fan failure |
Critical, Warning, Info |
EMS |
One or more main unit fans have failed, disrupting system operation. This might lead to a potential data loss. |
Too many CIFS authentication |
Critical, Warning, Info |
EMS |
Many authentication negotiations have occurred simultaneously. There are 256 incomplete new session requests from this client. |
Unassigned disks |
Critical, Warning, Info |
EMS |
System has unassigned disks - capacity is being wasted. |
Volume state offline |
Informational |
Metric |
The volume has been taken offline. |
Volume restricted |
Critical, Warning, Info |
EMS |
This event indicates that a flexible volume is made restricted. |
Virus detected |
Critical, Warning, Info |
EMS |
A Vscan server reported that a file might be infected with a virus. |
Capacity alerts
These alerts indicate storage consumption or capacity pressure.
| Alert name | Severity | Type | Description |
|---|---|---|---|
FabricPool mirror replication resync completed |
Critical, Warning, Info |
EMS |
The FabricPool mirror resync process completed successfully from the primary object store to the mirror object store. |
FabricPool space usage limit nearly reached |
Critical, Warning, Info |
EMS |
The total cluster-wide FabricPool space usage of object stores from capacity-licensed providers has nearly reached the licensed limit. |
FabricPool space usage limit reached |
Critical, Warning, Info |
EMS |
The total cluster-wide FabricPool space usage of object stores from capacity-licensed providers has reached the license limit. |
Node root volume space low |
Critical, Warning, Info |
EMS |
The system has detected that the root volume is dangerously low on space. |
QoS monitor memory maxed out |
Critical, Warning, Info |
EMS |
A QoS subsystem's dynamic memory has reached its limit for the current platform hardware. |
Volume automatic resizing succeeded |
Critical, Warning, Info |
EMS |
The volume was automatically resized because automatic volume growth is enabled. |
Volume full |
Critical |
Metric |
The volume is over 90% full. Free up space or add capacity to prevent write failures. |
Configuration alerts
These alerts point to configuration changes or inventory updates.
| Alert name | Severity | Type | Description |
|---|---|---|---|
Disk shelf power supply discovered |
Critical, Warning, Info |
EMS |
A power supply unit was added to the disk shelf. |
Volume created |
Info |
Metric |
A volume was created. |
Volume deleted |
Warning |
Metric |
A volume was deleted. |
Volume modified |
Info |
Metric |
A volume was modified. |
WAFL Consistency Check Overdue |
Warning |
EMS |
WAFL consistency checks on this aggregate exceeded the hourly limit. |
Performance alerts
These alerts point to latency or node performance issues.
| Alert name | Severity | Type | Description |
|---|---|---|---|
Node NFS latency is high |
Critical |
Metric |
NFS operations on this node are experiencing high latency (>5000 us). |
Node panic |
Critical, Warning, Info |
EMS |
The node panicked and was restarted. |
Protection alerts
These alerts affect replication, failover, or recovery.
| Alert name | Severity | Type | Description |
|---|---|---|---|
Fanout SnapMirror relationship common snapshot deleted |
Critical, Warning, Info |
EMS |
An older Snapshot copy is deleted as part of a SnapMirror Synchronous resynchronize or update operation. |
ONTAP Mediator added |
Critical, Warning, Info |
EMS |
The ONTAP Mediator was successfully added to this cluster. |
ONTAP Mediator CA certificate expired |
Critical, Warning, Info |
EMS |
The ONTAP Mediator certificate authority (CA) certificate has expired. |
ONTAP Mediator CA certificate expiring |
Critical, Warning, Info |
EMS |
The ONTAP Mediator certificate authority (CA) certificate is due to expire within the next 30 days. |
ONTAP Mediator client certificate expired |
Critical, Warning, Info |
EMS |
The ONTAP Mediator client certificate has expired. |
ONTAP Mediator client certificate expiring |
Critical, Warning, Info |
EMS |
The ONTAP Mediator client certificate is due to expire within the next 30 days. |
ONTAP Mediator not accessible |
Critical, Warning, Info |
EMS |
The ONTAP Mediator is not accessible, either because it has been repurposed or the Mediator package is no longer installed. |
ONTAP Mediator removed |
Critical, Warning, Info |
EMS |
The ONTAP Mediator was successfully removed from this cluster. |
ONTAP Mediator unreachable |
Critical, Warning, Info |
EMS |
The ONTAP Mediator is unreachable, which means SnapMirror failover is not possible until connectivity is restored. |
ONTAP Mediator server certificate expired |
Critical, Warning, Info |
EMS |
The ONTAP Mediator server certificate has expired. |
ONTAP Mediator server certificate expiring |
Critical, Warning, Info |
EMS |
The ONTAP Mediator server certificate is due to expire within the next 30 days. |
SnapMirror active sync relationship out of sync |
Critical, Warning, Info |
EMS |
The SnapMirror synchronous relationship moved from in-sync to out-of-sync. Data protection is affected. |
SnapMirror active sync automatic unplanned failover completed |
Critical, Warning, Info |
EMS |
The SnapMirror Business Continuity (SMBC) automatic unplanned failover operation completed. |
SnapMirror active sync automatic unplanned failover failed |
Critical, Warning, Info |
EMS |
The SnapMirror Business Continuity (SMBC) automatic unplanned failover operation failed. |
SnapMirror active sync planned failover completed |
Critical, Warning, Info |
EMS |
The SnapMirror Business Continuity (SMBC) planned failover operation completed. |
SnapMirror active sync planned failover failed |
Critical, Warning, Info |
EMS |
The SnapMirror Business Continuity (SMBC) planned failover operation failed. |
SnapMirror relationship common snapshot failed |
Critical, Warning, Info |
EMS |
There is a failure in creating a common Snapshot copy. |
SnapMirror relationship initialization failed |
Critical, Warning, Info |
EMS |
The SnapMirror initialize command fails and no more retries will be attempted. |
SnapMirror relationship out of sync |
Critical, Warning, Info |
EMS |
The SnapMirror synchronous relationship moved from in-sync to out-of-sync. Data protection is affected. |
SnapMirror relationship resync attempt failed |
Critical, Warning, Info |
EMS |
A SnapMirror synchronization attempt between the source and destination volumes failed. |
SnapMirror relationship snapshot is not replicated |
Critical, Warning, Info |
EMS |
The Snapshot copy for SnapMirror Synchronous relationship is not successfully replicated. |
Security alerts
These alerts point to threats or unauthorized access.
| Alert name | Severity | Type | Description |
|---|---|---|---|
Ransomware activity detected |
Critical, Warning, Info |
EMS |
To protect the data from the detected ransomware, a Snapshot copy has been taken that can be used to restore original data. |
Storage VM anti-ransomware monitoring |
Critical, Warning, Info |
EMS |
The anti-ransomware state of the Storage VM has changed. |
Unauthorized user access to admin share |
Critical, Warning, Info |
EMS |
A client tried to connect to the privileged ONTAP_ADMIN$ share, but the logged-in user isn't part of any active Vscan scanner pool on this SVM. |
Volume anti-ransomware monitoring |
Critical, Warning, Info |
EMS |
The anti-ransomware state of a volume is changed. |