An audit log record can include the following fields:
Field Name | Description |
|---|---|
| The SMB Alternative Data Stream (ADS) name, including information about affected internal handles. |
| The S3 bucket name. |
| The IP from which the RPC was received. |
| The name of the cluster. |
| The virtual IP on which the RPC was received. |
| The CNode name. |
| Connection type for S3 requests: HTTP or HTTPS. |
| Indicates the SMB type of action, such as create, open, overwrite, or supersede a file. |
| SMB action to perform if the file specified in a create request already exists. |
| SMB options applied when creating or opening the file. |
| Whether the SMB request required the file to be deleted after all its handles were closed. |
| Permissions granted as a result of the NFSv4 access check. |
| Permissions granted as a result of the NFSv3 access check. |
| The class of information obtained with the SMB GET_INFO request. |
| The type of information set with the SMB SET_INFO request. |
| The user name. Appears only if you configured VAST Cluster to log user login names and when this information could be retrieved from the authorization provider. |
| The name of the file or directory, including information about affected internal handles. |
| The type of object the request acts upon: The object type of |
| The full Element Store path, including information about affected internal handles. This field appears only when VAST Cluster is configured to log full path. |
| The client protocol that sent the RPC. |
| The target name in an NFSv4 rename or move operation. |
| The target path in an NFSv4 rename or move operation. |
| The ID of the S3 request. |
| Permissions required to perform the requested NFSv4 operation. |
| Permissions required to perform the requested NFSv3 operation. |
| One or more attributes that are set with the requested NFSv3 or NFSv4 operation. |
| The requested operation. |
| The user's S3 access keys, if applicable. |
| The user's SMB user SID. |
| This structure contains the name of the S3 source bucket and the name of the source object, including information about its version (if applicable) and affected internal handles. |
| Indicates if the operation was successful or not. |
| The symlink name. |
| The tenant to which access was requested. |
| The RPC time. |
| The S3 object version ID. |
| The internal handle for the S3 object version. |
| The path relative to the view. This field appears only when VAST Cluster is not configured to log full paths. |
| The user's NFS UID. |
| The S3 multipart upload ID. |
| The S3 access key that was used in the request. |