Audit Log Record Attributes

Prev Next

Audit log records include these attributes. Some are applicable to all protocols, some for specific ones.

VAST DataBase Table attribute

JSON-formatted Files attribute

Protocols

Description

Example

client_ip

ClientIP

ALL

The IP from which the RPC was received.

'172.27.43.3'

cluster_name

ClusterName

ALL

The name of the cluster.

'loop3043-var'

cluster_vip

ClusterVip

ALL

The virtual IP on which the RPC was received.

'172.27.43.3'

cnode_name

CnodeName

ALL

The CNode name.

'cnode-1'

link_path

LinkPath

ALL

The target destination path pointed to by a file or directory link.

login_name

LoginName

ALL

The user name. Appears only if you configured VAST Cluster to log user login names and when this information could be retrieved from the authorization provider.

'analytical-stonefish'

name

Name

ALL

The name of the file or directory, including information about affected internal handles.

num_bytes

NumBytes

ALL

The total number of bytes transferred (read or written) during the operation.

38

num_ops

None

ALL

The cumulative count of internal sub-operations executed for the request.

object_type

ObjectType

ALL

The type of object the request acts upon: DIRECTORY, FILE, SYMLINK, BUCKET, OBJECT (for S3 objects) or UNKNOWN.

The object type of UNKNOWN is shown for failed requests only. It means that the request had failed before VAST Cluster was able to determine the correct object type from the request.

'OBJECT'

path

Path

ALL

The full Element Store path, including information about affected internal handles. This field appears only when VAST Cluster is configured to log full path.

AuditEntryPath(Path='/d8e16e3e_0-view-71b4/audit-obj-earnest-paca', EHandle='0x89c52a7cda8d189a', CloneID='0x0')

protocol

Protocol

ALL

The client protocol that sent the RPC.

'S3'

rpc_type

RPCType

ALL

The requested operation.

'PUT_OBJECT'

sid

sid

ALL

The user's SMB user SID.

status

Status

ALL

Indicates if the operation was successful or not.

'Success'

tenant

Tenant

ALL

The tenant to which access was requested.

'default'

time

Time

ALL

The RPC time.

'2026-07-27T17:25:22.426Z'

time_str

Time

ALL

The RPC time.

'2026-07-27T17:25:22.426Z'

uid

uid

ALL

The user's NFS UID.

450734677

view_path

ViewPath

ALL

The path relative to the view. This field appears only when VAST Cluster is not configured to log full paths.

vip_pool_name

VipPoolName

ALL

The name of the Virtual IP (VIP) pool servicing the connection.

'vippool-1'

mtls_nfs_client_certificate_info

Client_mTLS_Certificate_Info

NFS

Mutual TLS (mTLS) client certificate details used to authenticate the NFS connection.

nfs3_granted_permissions

GrantedPermissions

NFS

Permissions granted as a result of the NFSv3 access check.

nfs3_required_permissions

RequiredPermissions

NFS

Permissions required to perform the requested NFSv3 operation.

nfs4_ftype

NF4LNK

NFS

The structural NFSv4 object file type attribute (e.g., regular file, directory, symbolic link).

nfs4_granted_access

GrantedAccess

NFS

Permissions granted as a result of the NFSv4 access check.

nfs4_required_access

RequiredAccess

NFS

Permissions required to perform the requested NFSv4 operation.

nfs_link_name

LinkName

NFS

The filename/alias targeted during an NFS link creation or modification.

nfs_link_path

LinkPath

NFS

The target path destination pointed to in NFS link operations.

nfs_rpc_sub_types

RPCSubTypes

NFS

One or more attributes that are set with the requested NFSv3 or NFSv4 operation.

['']

nfs_symlink

Symlink

NFS

The symlink name.

rename_name

RenameName

NFS

The target name in an NFSv4 rename or move operation.

rename_path

RenamePath

NFS

The target path in an NFSv4 rename or move operation.

connection_type

ConnectionType

S3

Connection type for S3 requests: HTTP or HTTPS.

'HTTPS'

error_description

ErrorDescription

S3

Human-readable text describing the error or failure reason for an unsuccessful request.

host

Host

S3

The HTTP Host header value supplied in S3 requests.

'172.27.43.3:9091'

http_error_code

HTTPErrorCode

S3

The standard HTTP status/error code returned for an S3 request (e.g., 200, 403, 404).

'OK'

s3_access_keys

S3AccessKeys

S3

The user's S3 access keys, if applicable.

['U5KVBTGYR27Y8JSB28XR', '', '', '']

s3_bucket_name

BucketName

S3

The S3 bucket name.

'indiscreet-needlefish'

s3_multipart_upload_id

UploadId

S3

The S3 multipart upload ID.

s3_request_id

RequestId

S3

The ID of the S3 request.

'0x40110011aa46'

s3_source_object

SourceObject

S3

This structure contains the name of the S3 source bucket and the name of the source object, including information about its version (if applicable) and affected internal handles.

s3_used_access_key

UsedS3AccessKey

S3

The S3 access key that was used in the request.

'U5KVBTGYR27Y8JSB28XR'

s3_version_id

VersionId

S3

The S3 object version ID.

18446744073709551615

s3_version_phandle

VersionCloneID

VersionEHandle

S3

The internal handle for the S3 object version.

transaction_id

TransactionId

S3

A unique sequential correlation key mapping the request down to lower-level system transaction logs.

true_client_ip

TrueClientIP

S3

The original client IP address preserved when requests pass through proxies or load balancers.

smb_ads_name

AdsName

SMB

The SMB Alternative Data Stream (ADS) name, including information about affected internal handles.

smb_create_action

CreateAction

SMB

Indicates the SMB type of action, such as create, open, overwrite, or supersede a file.

smb_create_disposition

CreateDisposition

SMB

SMB action to perform if the file specified in a create request already exists.

smb_create_option

CreateOptions

SMB

SMB options applied when creating or opening the file.

smb_delete_on_close

DeleteOnClose

SMB

Whether the SMB request required the file to be deleted after all its handles were closed.

smb_info_class

InfoClass

SMB

The class of information obtained with the SMB GET_INFO request.

smb_info_type

InfoType

SMB

The type of information set with the SMB SET_INFO request.

smb_rename_struct

Rename

SMB

Structural properties and metadata layout describing SMB move or rename operations.