Audit log records include these attributes. Some are applicable to all protocols, some for specific ones.
VAST DataBase Table attribute | JSON-formatted Files attribute | Protocols | Description | Example |
|---|---|---|---|---|
|
| ALL | The IP from which the RPC was received. |
|
|
| ALL | The name of the cluster. |
|
|
| ALL | The virtual IP on which the RPC was received. |
|
|
| ALL | The CNode name. |
|
|
| ALL | The target destination path pointed to by a file or directory link. | |
|
| ALL | The user name. Appears only if you configured VAST Cluster to log user login names and when this information could be retrieved from the authorization provider. |
|
|
| ALL | The name of the file or directory, including information about affected internal handles. | |
|
| ALL | The total number of bytes transferred (read or written) during the operation. |
|
| None | ALL | The cumulative count of internal sub-operations executed for the request. | |
|
| ALL | The type of object the request acts upon: The object type of |
|
|
| ALL | The full Element Store path, including information about affected internal handles. This field appears only when VAST Cluster is configured to log full path. |
|
|
| ALL | The client protocol that sent the RPC. |
|
|
| ALL | The requested operation. |
|
|
| ALL | The user's SMB user SID. | |
|
| ALL | Indicates if the operation was successful or not. |
|
|
| ALL | The tenant to which access was requested. |
|
|
| ALL | The RPC time. |
|
|
| ALL | The RPC time. |
|
|
| ALL | The user's NFS UID. |
|
|
| ALL | The path relative to the view. This field appears only when VAST Cluster is not configured to log full paths. | |
|
| ALL | The name of the Virtual IP (VIP) pool servicing the connection. |
|
|
| NFS | Mutual TLS (mTLS) client certificate details used to authenticate the NFS connection. | |
|
| NFS | Permissions granted as a result of the NFSv3 access check. | |
|
| NFS | Permissions required to perform the requested NFSv3 operation. | |
|
| NFS | The structural NFSv4 object file type attribute (e.g., regular file, directory, symbolic link). | |
|
| NFS | Permissions granted as a result of the NFSv4 access check. | |
|
| NFS | Permissions required to perform the requested NFSv4 operation. | |
|
| NFS | The filename/alias targeted during an NFS link creation or modification. | |
|
| NFS | The target path destination pointed to in NFS link operations. | |
|
| NFS | One or more attributes that are set with the requested NFSv3 or NFSv4 operation. |
|
|
| NFS | The symlink name. | |
|
| NFS | The target name in an NFSv4 rename or move operation. | |
|
| NFS | The target path in an NFSv4 rename or move operation. | |
|
| S3 | Connection type for S3 requests: HTTP or HTTPS. |
|
|
| S3 | Human-readable text describing the error or failure reason for an unsuccessful request. | |
|
| S3 | The HTTP |
|
|
| S3 | The standard HTTP status/error code returned for an S3 request (e.g., 200, 403, 404). |
|
|
| S3 | The user's S3 access keys, if applicable. |
|
|
| S3 | The S3 bucket name. |
|
|
| S3 | The S3 multipart upload ID. | |
|
| S3 | The ID of the S3 request. |
|
|
| S3 | This structure contains the name of the S3 source bucket and the name of the source object, including information about its version (if applicable) and affected internal handles. | |
|
| S3 | The S3 access key that was used in the request. |
|
|
| S3 | The S3 object version ID. |
|
|
| S3 | The internal handle for the S3 object version. | |
|
| S3 | A unique sequential correlation key mapping the request down to lower-level system transaction logs. | |
|
| S3 | The original client IP address preserved when requests pass through proxies or load balancers. | |
|
| SMB | The SMB Alternative Data Stream (ADS) name, including information about affected internal handles. | |
|
| SMB | Indicates the SMB type of action, such as create, open, overwrite, or supersede a file. | |
|
| SMB | SMB action to perform if the file specified in a create request already exists. | |
|
| SMB | SMB options applied when creating or opening the file. | |
|
| SMB | Whether the SMB request required the file to be deleted after all its handles were closed. | |
|
| SMB | The class of information obtained with the SMB GET_INFO request. | |
|
| SMB | The type of information set with the SMB SET_INFO request. | |
|
| SMB | Structural properties and metadata layout describing SMB move or rename operations. |