CLI change events that can be audited overview
ONTAP can audit certain CLI change events, including certain SMB-share events, certain audit policy events, certain local security group events, local user group events, and authorization policy events. Understanding which change events can be audited is helpful when interpreting results from the event logs.
You can manage storage virtual machine (SVM) auditing CLI change events by manually rotating the audit logs, enabling or disabling auditing, displaying information about auditing change events, modifying auditing change events, and deleting auditing change events.
As an administrator, if you execute any command to change configuration related to the SMB-share, local user-group, local security-group, authorization-policy, and audit-policy events, a record generates and the corresponding event gets audited:
Auditing Category |
Events |
Event IDs |
Run this command… |
---|---|---|---|
Mhost Auditing |
policy-change |
[4719] Audit configuration changed |
|
file-share |
[5142] Network share was added |
|
|
[5143] Network share was modified |
|
||
[5144] Network share deleted |
|
||
Auditing |
user-account |
[4720] Local user created |
|
[4722] Local user enabled |
|
||
[4724] Local user password reset |
|
||
[4725] Local user disabled |
|
||
[4726] Local user deleted |
|
||
[4738] Local user Change |
|
||
[4781] Local user Rename |
|
||
security-group |
[4731] Local Security Group created |
|
|
[4734] Local Security Group deleted |
|
||
[4735] Local Security Group Modified |
|
||
[4732] User added to Local Group |
|
||
[4733] User Removed from Local Group |
|
||
authorization-policy-change |
[4704] User Rights Assigned |
|
|
[4705] User Rights Removed |
|