SlideShare a Scribd company logo
1 of 9
NetApp CIFS Audit
Recommendations:
Every aggregate should have minimum 2GB of space in order to enable the Audit including
aggr0.
NetApp recommends to use vserver security file-directory command to configure SACLS but
in our environment we cannot do it as it will replace existing permission. Need to follow
process for new volumes. (Required inputs from Harry/Karthik) .
NetApp recommends the following to configure a destination volume
The destination volume holds the consolidated audit log files. The destination volume must
be set while configuring the audit policy.
The destination volume should never be filled up to more than 90% at any point in time,
this rule should be followed in each SVM in the cluster. To prevent it we need hourly
monitoring for destination volume.
The optimal size of the destination volume depends on the generated log size, which in
turn depends on:
Destination volume size = generated log size x [rotate limit + 1].
In our case:
7-8GB (approx.) = 240MB x [30 + 1].
NetApp recommends keeping an additional buffer of 10% to 15% in the destination volume .
Currently we have 100GB volume.
NetApp recommends the following to configure guaranteed auditing:
Guaranteed auditing is a new feature enabled by default in clustered Data ONTAP , so
audit event recorded for each and every operation, thus provide highly reliable audit for
compliance.
When guaranteed audit is enabled and the destination and staging volume is full cifs
client operation are blocked.
NetApp recommends turning off this feature if regulatory requirements do not mandate
guaranteed auditing.
Testing:
Test Suite 1
Consider 1000 users are moving files at a given time(PDF File Only)
Current Size of
Evtx file
After Move
size of evtx
file size
Size of files
moved
Rotation Identifications Observation
4.94MB 6.94MB 1.39GB 1
evtx file size increased by 2MB
for moving 1.39GB files
Move will
generate
two events
one for
delete and
one for
move
Test Suite 2
Consider 1000 users are deleting files at a given time(PDF File Only)
Current Size of
Evtx file
After Move
size of evtx
file size
Size of files
moved
Rotation Identifications Observation
6.94MB 8MB 1.39GB 1
evtx file size increased by 1MB
for moving 1.39GB files
delete will
generate
one event
only
Test Suite 3
Consider 5000 users are moving files at a given time(PDF File Only)
Current Size of
Evtx file
After Move size
of evtx file size
Size of files
moved
Rotation Identifications Observation
11MB 21.6MB,32.3MB 6.98GB 2
evtx file size increasedby11MB
for moving 6.98GB files
Move will
generate
two events
one for
delete and
one for
move
Test Suite 4
Consider 5000 users are deleting files at a given time(PDF File Only)
Current Size of
Evtx file
After Move
size of evtx file
size
Size of files
moved
Rotation Identifications Observation
32.3MB 37.6MB 6.98GB 1
evtx file size increased by 5MB for
deleting 6.98GB files
delete will
generate
one event
only
Test Suite 6
Consider 5000 users are deleting files at a given time(Mix file types xls,doc,pdf)
Current Size of
Evtx file
After Move
size of evtx file
size
Size of files
moved
Rotation Identifications Observation
78.9MB 89.5MB 24.6GB 1
evtx file size increased by 10.6MB
for moving 24.6GB files
delete will
generate
one event
only
Considering 10,000 files being moved and deleted same time, it will generate 30MB of file
every hour, accounting that every 8 hour it will generate 240MB evtx file, currently we
have 200MB file setup with 30 files rotation which will cause approx. 6-7GB space on audit
log volumes, and we have 100GB total space on that volu me.
Test Suite 5
Consider 10,000 users are moving files at a given time(Mix file types xls,doc,pdf)
Current Size
of Evtx file
After Move size of
evtx file size
Size of files
moved
Rotation Identifications Observation
37.6MB 58.2MB,78.9MB 24.6GB 2
evtx file size increased by
20.6MB for moving 24.6GB
files
Move will
generate two
events one for
delete and one
for move
IOPs and CPU utilization report:
Vserver: IRV_CIFS01
We have enabled audit on 24/04/2018 and below is the screenshot of statistics for node7
and node8 before enabling audit.
Node8 Utilization before Audit enabling:
Node7 Utilization before Audit enabling:
After enabling the audit below are the observations.
Node8 Utilization After Audit enabled:
Node7 Utilization before Audit enabled:
-----------------------------------------------------------------------------------------------------------------
Observations:
1. Only enable audit on required volumes, do not enable it on landing zone or users
profile, otherwise it will be impossible to manage the log files.
2. we need to have another common volume where we must copy all log files on
common location in every week, based on SVM name.
3. need to monitor log location as files will be overwritten after 30 count .
Currently Enabled on two vservers in IRV:
1. IRV_CIFS01for log we have created Audit_IRV_CIFS01 volume allocated
100GBusage 5%  number of log files on the volume  30 log files.
2. IRV_APPS_DEV for log we have created Audit_test volume allocated
100GBusage 5%  number of log files on the volume 4 log files (as there is no
data deleted/moved so files will be less)
-----------------------------------------------------------------------------------------------------------------
Current Utilization of Atlanta Nodes:
Node 8:
We have captured last 3 months’ data and below are the details
CPU utilization is around 23%
Detailed IOPs, in this screen shot we can see Avg Iops is 1672 for last 3 months.
Expectations after implementing CIFS AUDIT for Node 8
Average IOPs should reach up to 2000-2200 and CPU utilization will go up to 30% as current
is 23%.
Note: there will be other factors needs to consider, for CPU and IOPs not just AUDIT.
-------------------------------------------------------------------- ---------------------------------------------
Node 7:
Average CPU utilization is around 23% for last 3 months
Detailed IOPs, in this screen shot we can see Avg Iops is 2000 for last 3 months.
Expectations after implementing CIFS AUDIT for Node 7
Average IOPs should reach up to 2000-2500 and CPU utilization will go up to 30% as current
is 23%.
Note: there will be other factors needs to consider, for CPU and IOPs not just AUDIT.
Conclusion:
We should .
OC_SComsh
OC_SComsh1
OC_SComsh2
OC_SComsh3
OC_SComsh4
OC_SComsh5
OC_SComsh6
OC_SComsh7
OC_SComsh8
OC_SComsh9
OC_SComsh10
OC_SComsh11
OC_SComsh12
OC_SComsh13
Ocwen_Share1
Ocwen_Share2
Phase I: enable AUDIT on 5 common share, observe the Iops and node utilization and then
proceed with next phases until we are satisfied with IOPS and Utilization of nodes.
How to access Audit logs:
TXIRVNAPSTG01-08_IRV_CIFSAudit_IRV_CIFS01
You can access share and view those in windows event viewer application.
Volumes included in Audit:
For example:
Vserver Volume Aggregate State Type Size Available Used%
--------- ------------ ------------ ---------- ---- ---------- ---------- -----
TXIRVNAPSTG01
MDV_aud_fdf16480ceb740f6ac0d320a7ea0f4ff
aggr0_TXIRVNAPSTG01_07_0
online RW 2GB 1.90GB 5%
we should be monitoring these volumes as these will be used to

More Related Content

Similar to NetApp CIFS Audit.docx

On-Demand Image Resizing Extended - External Meet-up
On-Demand Image Resizing Extended - External Meet-upOn-Demand Image Resizing Extended - External Meet-up
On-Demand Image Resizing Extended - External Meet-upJonathan Lee
 
linux monitoring and performance tunning
linux monitoring and performance tunning linux monitoring and performance tunning
linux monitoring and performance tunning iman darabi
 
Ceph Day Beijing - Ceph all-flash array design based on NUMA architecture
Ceph Day Beijing - Ceph all-flash array design based on NUMA architectureCeph Day Beijing - Ceph all-flash array design based on NUMA architecture
Ceph Day Beijing - Ceph all-flash array design based on NUMA architectureCeph Community
 
Ceph Day Beijing - Ceph All-Flash Array Design Based on NUMA Architecture
Ceph Day Beijing - Ceph All-Flash Array Design Based on NUMA ArchitectureCeph Day Beijing - Ceph All-Flash Array Design Based on NUMA Architecture
Ceph Day Beijing - Ceph All-Flash Array Design Based on NUMA ArchitectureDanielle Womboldt
 
Optimize MySQL Workloads with Amazon Elastic Block Store - February 2017 AWS ...
Optimize MySQL Workloads with Amazon Elastic Block Store - February 2017 AWS ...Optimize MySQL Workloads with Amazon Elastic Block Store - February 2017 AWS ...
Optimize MySQL Workloads with Amazon Elastic Block Store - February 2017 AWS ...Amazon Web Services
 
Increase density and performance with upgrades from Intel and Microsoft
Increase density and performance with upgrades from Intel and MicrosoftIncrease density and performance with upgrades from Intel and Microsoft
Increase density and performance with upgrades from Intel and MicrosoftPrincipled Technologies
 
Stream processing with Apache Flink @ OfferUp
Stream processing with Apache Flink @ OfferUpStream processing with Apache Flink @ OfferUp
Stream processing with Apache Flink @ OfferUpBowen Li
 
Performance Tuning Oracle Weblogic Server 12c
Performance Tuning Oracle Weblogic Server 12cPerformance Tuning Oracle Weblogic Server 12c
Performance Tuning Oracle Weblogic Server 12cAjith Narayanan
 
What’s New in UniVerse 11.2
What’s New in UniVerse 11.2What’s New in UniVerse 11.2
What’s New in UniVerse 11.2Rocket Software
 
Big Lab Problems Solved with Spectrum Scale: Innovations for the Coral Program
Big Lab Problems Solved with Spectrum Scale: Innovations for the Coral ProgramBig Lab Problems Solved with Spectrum Scale: Innovations for the Coral Program
Big Lab Problems Solved with Spectrum Scale: Innovations for the Coral Programinside-BigData.com
 
Let the Tiger Roar! - MongoDB 3.0 + WiredTiger
Let the Tiger Roar! - MongoDB 3.0 + WiredTigerLet the Tiger Roar! - MongoDB 3.0 + WiredTiger
Let the Tiger Roar! - MongoDB 3.0 + WiredTigerJon Rangel
 
HeroLympics Eng V03 Henk Vd Valk
HeroLympics  Eng V03 Henk Vd ValkHeroLympics  Eng V03 Henk Vd Valk
HeroLympics Eng V03 Henk Vd Valkhvdvalk
 
Database Performance of Intel Cache Acceleration Software
Database Performance of Intel Cache Acceleration SoftwareDatabase Performance of Intel Cache Acceleration Software
Database Performance of Intel Cache Acceleration SoftwarePrincipled Technologies
 
Alfresco benchmark report_bl100093
Alfresco benchmark report_bl100093Alfresco benchmark report_bl100093
Alfresco benchmark report_bl100093ECNU
 
Benchmark of Alibaba Cloud capabilities
Benchmark of Alibaba Cloud capabilitiesBenchmark of Alibaba Cloud capabilities
Benchmark of Alibaba Cloud capabilitiesHuxi LI
 
Data Science in the Cloud @StitchFix
Data Science in the Cloud @StitchFixData Science in the Cloud @StitchFix
Data Science in the Cloud @StitchFixC4Media
 
Oracle Performance On Linux X86 systems
Oracle  Performance On Linux  X86 systems Oracle  Performance On Linux  X86 systems
Oracle Performance On Linux X86 systems Baruch Osoveskiy
 

Similar to NetApp CIFS Audit.docx (20)

On-Demand Image Resizing Extended - External Meet-up
On-Demand Image Resizing Extended - External Meet-upOn-Demand Image Resizing Extended - External Meet-up
On-Demand Image Resizing Extended - External Meet-up
 
linux monitoring and performance tunning
linux monitoring and performance tunning linux monitoring and performance tunning
linux monitoring and performance tunning
 
Ceph Day Beijing - Ceph all-flash array design based on NUMA architecture
Ceph Day Beijing - Ceph all-flash array design based on NUMA architectureCeph Day Beijing - Ceph all-flash array design based on NUMA architecture
Ceph Day Beijing - Ceph all-flash array design based on NUMA architecture
 
Ceph Day Beijing - Ceph All-Flash Array Design Based on NUMA Architecture
Ceph Day Beijing - Ceph All-Flash Array Design Based on NUMA ArchitectureCeph Day Beijing - Ceph All-Flash Array Design Based on NUMA Architecture
Ceph Day Beijing - Ceph All-Flash Array Design Based on NUMA Architecture
 
Optimize MySQL Workloads with Amazon Elastic Block Store - February 2017 AWS ...
Optimize MySQL Workloads with Amazon Elastic Block Store - February 2017 AWS ...Optimize MySQL Workloads with Amazon Elastic Block Store - February 2017 AWS ...
Optimize MySQL Workloads with Amazon Elastic Block Store - February 2017 AWS ...
 
Increase density and performance with upgrades from Intel and Microsoft
Increase density and performance with upgrades from Intel and MicrosoftIncrease density and performance with upgrades from Intel and Microsoft
Increase density and performance with upgrades from Intel and Microsoft
 
10Gbps transfers
10Gbps transfers10Gbps transfers
10Gbps transfers
 
Stream processing with Apache Flink @ OfferUp
Stream processing with Apache Flink @ OfferUpStream processing with Apache Flink @ OfferUp
Stream processing with Apache Flink @ OfferUp
 
Performance Tuning Oracle Weblogic Server 12c
Performance Tuning Oracle Weblogic Server 12cPerformance Tuning Oracle Weblogic Server 12c
Performance Tuning Oracle Weblogic Server 12c
 
What’s New in UniVerse 11.2
What’s New in UniVerse 11.2What’s New in UniVerse 11.2
What’s New in UniVerse 11.2
 
Refining Linux
Refining LinuxRefining Linux
Refining Linux
 
Big Lab Problems Solved with Spectrum Scale: Innovations for the Coral Program
Big Lab Problems Solved with Spectrum Scale: Innovations for the Coral ProgramBig Lab Problems Solved with Spectrum Scale: Innovations for the Coral Program
Big Lab Problems Solved with Spectrum Scale: Innovations for the Coral Program
 
Let the Tiger Roar! - MongoDB 3.0 + WiredTiger
Let the Tiger Roar! - MongoDB 3.0 + WiredTigerLet the Tiger Roar! - MongoDB 3.0 + WiredTiger
Let the Tiger Roar! - MongoDB 3.0 + WiredTiger
 
HeroLympics Eng V03 Henk Vd Valk
HeroLympics  Eng V03 Henk Vd ValkHeroLympics  Eng V03 Henk Vd Valk
HeroLympics Eng V03 Henk Vd Valk
 
Database Performance of Intel Cache Acceleration Software
Database Performance of Intel Cache Acceleration SoftwareDatabase Performance of Intel Cache Acceleration Software
Database Performance of Intel Cache Acceleration Software
 
Alfresco benchmark report_bl100093
Alfresco benchmark report_bl100093Alfresco benchmark report_bl100093
Alfresco benchmark report_bl100093
 
Benchmark of Alibaba Cloud capabilities
Benchmark of Alibaba Cloud capabilitiesBenchmark of Alibaba Cloud capabilities
Benchmark of Alibaba Cloud capabilities
 
Data Science in the Cloud @StitchFix
Data Science in the Cloud @StitchFixData Science in the Cloud @StitchFix
Data Science in the Cloud @StitchFix
 
Openstack summit 2015
Openstack summit 2015Openstack summit 2015
Openstack summit 2015
 
Oracle Performance On Linux X86 systems
Oracle  Performance On Linux  X86 systems Oracle  Performance On Linux  X86 systems
Oracle Performance On Linux X86 systems
 

More from ssuser2dbaee

AZ900-AzureFundamentals-part-11.pdf
AZ900-AzureFundamentals-part-11.pdfAZ900-AzureFundamentals-part-11.pdf
AZ900-AzureFundamentals-part-11.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-5.pdf
AZ900-AzureFundamentals-part-5.pdfAZ900-AzureFundamentals-part-5.pdf
AZ900-AzureFundamentals-part-5.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-7.pdf
AZ900-AzureFundamentals-part-7.pdfAZ900-AzureFundamentals-part-7.pdf
AZ900-AzureFundamentals-part-7.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-8.pdf
AZ900-AzureFundamentals-part-8.pdfAZ900-AzureFundamentals-part-8.pdf
AZ900-AzureFundamentals-part-8.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-6.pdf
AZ900-AzureFundamentals-part-6.pdfAZ900-AzureFundamentals-part-6.pdf
AZ900-AzureFundamentals-part-6.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-2.pdf
AZ900-AzureFundamentals-part-2.pdfAZ900-AzureFundamentals-part-2.pdf
AZ900-AzureFundamentals-part-2.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-9.pdf
AZ900-AzureFundamentals-part-9.pdfAZ900-AzureFundamentals-part-9.pdf
AZ900-AzureFundamentals-part-9.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-3.pdf
AZ900-AzureFundamentals-part-3.pdfAZ900-AzureFundamentals-part-3.pdf
AZ900-AzureFundamentals-part-3.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-10.pdf
AZ900-AzureFundamentals-part-10.pdfAZ900-AzureFundamentals-part-10.pdf
AZ900-AzureFundamentals-part-10.pdfssuser2dbaee
 
AZ900-AzureFundamentals-part-4.pdf
AZ900-AzureFundamentals-part-4.pdfAZ900-AzureFundamentals-part-4.pdf
AZ900-AzureFundamentals-part-4.pdfssuser2dbaee
 
Netapp_Aggregates.docx
Netapp_Aggregates.docxNetapp_Aggregates.docx
Netapp_Aggregates.docxssuser2dbaee
 

More from ssuser2dbaee (11)

AZ900-AzureFundamentals-part-11.pdf
AZ900-AzureFundamentals-part-11.pdfAZ900-AzureFundamentals-part-11.pdf
AZ900-AzureFundamentals-part-11.pdf
 
AZ900-AzureFundamentals-part-5.pdf
AZ900-AzureFundamentals-part-5.pdfAZ900-AzureFundamentals-part-5.pdf
AZ900-AzureFundamentals-part-5.pdf
 
AZ900-AzureFundamentals-part-7.pdf
AZ900-AzureFundamentals-part-7.pdfAZ900-AzureFundamentals-part-7.pdf
AZ900-AzureFundamentals-part-7.pdf
 
AZ900-AzureFundamentals-part-8.pdf
AZ900-AzureFundamentals-part-8.pdfAZ900-AzureFundamentals-part-8.pdf
AZ900-AzureFundamentals-part-8.pdf
 
AZ900-AzureFundamentals-part-6.pdf
AZ900-AzureFundamentals-part-6.pdfAZ900-AzureFundamentals-part-6.pdf
AZ900-AzureFundamentals-part-6.pdf
 
AZ900-AzureFundamentals-part-2.pdf
AZ900-AzureFundamentals-part-2.pdfAZ900-AzureFundamentals-part-2.pdf
AZ900-AzureFundamentals-part-2.pdf
 
AZ900-AzureFundamentals-part-9.pdf
AZ900-AzureFundamentals-part-9.pdfAZ900-AzureFundamentals-part-9.pdf
AZ900-AzureFundamentals-part-9.pdf
 
AZ900-AzureFundamentals-part-3.pdf
AZ900-AzureFundamentals-part-3.pdfAZ900-AzureFundamentals-part-3.pdf
AZ900-AzureFundamentals-part-3.pdf
 
AZ900-AzureFundamentals-part-10.pdf
AZ900-AzureFundamentals-part-10.pdfAZ900-AzureFundamentals-part-10.pdf
AZ900-AzureFundamentals-part-10.pdf
 
AZ900-AzureFundamentals-part-4.pdf
AZ900-AzureFundamentals-part-4.pdfAZ900-AzureFundamentals-part-4.pdf
AZ900-AzureFundamentals-part-4.pdf
 
Netapp_Aggregates.docx
Netapp_Aggregates.docxNetapp_Aggregates.docx
Netapp_Aggregates.docx
 

Recently uploaded

Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 

Recently uploaded (20)

Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 

NetApp CIFS Audit.docx

  • 1. NetApp CIFS Audit Recommendations: Every aggregate should have minimum 2GB of space in order to enable the Audit including aggr0. NetApp recommends to use vserver security file-directory command to configure SACLS but in our environment we cannot do it as it will replace existing permission. Need to follow process for new volumes. (Required inputs from Harry/Karthik) . NetApp recommends the following to configure a destination volume The destination volume holds the consolidated audit log files. The destination volume must be set while configuring the audit policy. The destination volume should never be filled up to more than 90% at any point in time, this rule should be followed in each SVM in the cluster. To prevent it we need hourly monitoring for destination volume. The optimal size of the destination volume depends on the generated log size, which in turn depends on: Destination volume size = generated log size x [rotate limit + 1]. In our case: 7-8GB (approx.) = 240MB x [30 + 1]. NetApp recommends keeping an additional buffer of 10% to 15% in the destination volume . Currently we have 100GB volume. NetApp recommends the following to configure guaranteed auditing: Guaranteed auditing is a new feature enabled by default in clustered Data ONTAP , so audit event recorded for each and every operation, thus provide highly reliable audit for compliance. When guaranteed audit is enabled and the destination and staging volume is full cifs client operation are blocked. NetApp recommends turning off this feature if regulatory requirements do not mandate guaranteed auditing.
  • 2. Testing: Test Suite 1 Consider 1000 users are moving files at a given time(PDF File Only) Current Size of Evtx file After Move size of evtx file size Size of files moved Rotation Identifications Observation 4.94MB 6.94MB 1.39GB 1 evtx file size increased by 2MB for moving 1.39GB files Move will generate two events one for delete and one for move Test Suite 2 Consider 1000 users are deleting files at a given time(PDF File Only) Current Size of Evtx file After Move size of evtx file size Size of files moved Rotation Identifications Observation 6.94MB 8MB 1.39GB 1 evtx file size increased by 1MB for moving 1.39GB files delete will generate one event only Test Suite 3 Consider 5000 users are moving files at a given time(PDF File Only) Current Size of Evtx file After Move size of evtx file size Size of files moved Rotation Identifications Observation 11MB 21.6MB,32.3MB 6.98GB 2 evtx file size increasedby11MB for moving 6.98GB files Move will generate two events one for delete and one for move
  • 3. Test Suite 4 Consider 5000 users are deleting files at a given time(PDF File Only) Current Size of Evtx file After Move size of evtx file size Size of files moved Rotation Identifications Observation 32.3MB 37.6MB 6.98GB 1 evtx file size increased by 5MB for deleting 6.98GB files delete will generate one event only Test Suite 6 Consider 5000 users are deleting files at a given time(Mix file types xls,doc,pdf) Current Size of Evtx file After Move size of evtx file size Size of files moved Rotation Identifications Observation 78.9MB 89.5MB 24.6GB 1 evtx file size increased by 10.6MB for moving 24.6GB files delete will generate one event only Considering 10,000 files being moved and deleted same time, it will generate 30MB of file every hour, accounting that every 8 hour it will generate 240MB evtx file, currently we have 200MB file setup with 30 files rotation which will cause approx. 6-7GB space on audit log volumes, and we have 100GB total space on that volu me. Test Suite 5 Consider 10,000 users are moving files at a given time(Mix file types xls,doc,pdf) Current Size of Evtx file After Move size of evtx file size Size of files moved Rotation Identifications Observation 37.6MB 58.2MB,78.9MB 24.6GB 2 evtx file size increased by 20.6MB for moving 24.6GB files Move will generate two events one for delete and one for move
  • 4. IOPs and CPU utilization report: Vserver: IRV_CIFS01 We have enabled audit on 24/04/2018 and below is the screenshot of statistics for node7 and node8 before enabling audit. Node8 Utilization before Audit enabling: Node7 Utilization before Audit enabling: After enabling the audit below are the observations. Node8 Utilization After Audit enabled:
  • 5. Node7 Utilization before Audit enabled: ----------------------------------------------------------------------------------------------------------------- Observations: 1. Only enable audit on required volumes, do not enable it on landing zone or users profile, otherwise it will be impossible to manage the log files. 2. we need to have another common volume where we must copy all log files on common location in every week, based on SVM name. 3. need to monitor log location as files will be overwritten after 30 count . Currently Enabled on two vservers in IRV: 1. IRV_CIFS01for log we have created Audit_IRV_CIFS01 volume allocated 100GBusage 5%  number of log files on the volume  30 log files. 2. IRV_APPS_DEV for log we have created Audit_test volume allocated 100GBusage 5%  number of log files on the volume 4 log files (as there is no data deleted/moved so files will be less)
  • 6. ----------------------------------------------------------------------------------------------------------------- Current Utilization of Atlanta Nodes: Node 8: We have captured last 3 months’ data and below are the details CPU utilization is around 23% Detailed IOPs, in this screen shot we can see Avg Iops is 1672 for last 3 months. Expectations after implementing CIFS AUDIT for Node 8 Average IOPs should reach up to 2000-2200 and CPU utilization will go up to 30% as current is 23%. Note: there will be other factors needs to consider, for CPU and IOPs not just AUDIT.
  • 7. -------------------------------------------------------------------- --------------------------------------------- Node 7: Average CPU utilization is around 23% for last 3 months Detailed IOPs, in this screen shot we can see Avg Iops is 2000 for last 3 months. Expectations after implementing CIFS AUDIT for Node 7 Average IOPs should reach up to 2000-2500 and CPU utilization will go up to 30% as current is 23%. Note: there will be other factors needs to consider, for CPU and IOPs not just AUDIT.
  • 8. Conclusion: We should . OC_SComsh OC_SComsh1 OC_SComsh2 OC_SComsh3 OC_SComsh4 OC_SComsh5 OC_SComsh6 OC_SComsh7 OC_SComsh8 OC_SComsh9 OC_SComsh10 OC_SComsh11 OC_SComsh12 OC_SComsh13 Ocwen_Share1 Ocwen_Share2 Phase I: enable AUDIT on 5 common share, observe the Iops and node utilization and then proceed with next phases until we are satisfied with IOPS and Utilization of nodes. How to access Audit logs: TXIRVNAPSTG01-08_IRV_CIFSAudit_IRV_CIFS01 You can access share and view those in windows event viewer application. Volumes included in Audit: For example: Vserver Volume Aggregate State Type Size Available Used% --------- ------------ ------------ ---------- ---- ---------- ---------- ----- TXIRVNAPSTG01
  • 9. MDV_aud_fdf16480ceb740f6ac0d320a7ea0f4ff aggr0_TXIRVNAPSTG01_07_0 online RW 2GB 1.90GB 5% we should be monitoring these volumes as these will be used to