Supported file operation and filter combinations that FPolicy can monitor for NFSv4
When you configure your FPolicy event, you need to be aware that only certain combinations of file operations and filters are supported for monitoring NFSv4 file access operations.
Beginning with ONTAP 9.15.1, FPolicy supports the NFSv4.1 protocol.
The list of supported file operation and filter combinations for FPolicy monitoring of NFSv4 or NFSv4.1 file access events is provided in the following table:
Supported file operations |
Supported filters |
---|---|
close |
offline-bit, exclude-directory |
create |
offline-bit |
create_dir |
Currently no filter is supported for this file operation. |
delete |
offline-bit |
delete_dir |
Currently no filter is supported for this file operation. |
getattr |
offline-bit, exclude-directory |
link |
offline-bit |
lookup |
offline-bit, exclude-directory |
open |
offline-bit, exclude-directory |
read |
offline-bit, first-read |
write |
offline-bit, first-write, write-with-size-change |
rename |
offline-bit |
rename_dir |
Currently no filter is supported for this file operation. |
setattr |
offline-bit, setattr_with_owner_change, setattr_with_group_change, setattr_with_mode_change, setattr_with_sacl_change, setattr_with_dacl_change, setattr_with_modify_time_change, setattr_with_access_time_change, setattr_with_size_change, exclude_directory |
symlink |
offline-bit |
Beginning with ONTAP 9.13.1, users can receive notifications for failed file operations due to lack of permissions. The list of supported access denied file operation and filter combinations for FPolicy monitoring of NFSv4 or NFSv4.1 file access events is provided in the following table:
Supported access denied file operation |
Supported filters |
---|---|
access |
NA |
create |
NA |
create_dir |
NA |
delete |
NA |
delete_dir |
NA |
link |
NA |
open |
NA |
read |
NA |
rename |
NA |
rename_dir |
NA |
setattr |
NA |
write |
NA |