Search the docs

Auditing Access to Data

Hammerspace supports sending file-access auditing events to an external syslog server. These audit events include information such as the type of operation, time stamp, path, inode identifier, user/group, and client.

The client details are currently NFSv4.2-specific. This means that for data accessed using a DSX Portal (SMB, NFS v3, NFS 4.1), only the DSX will appear as a client.

Example of audit event

Sample audit event
2025-06-06T15:53:41+00:00 tf-anvil2 filesystem AUDIT [audit_access='dD' audit_access_type='SUCCESSFUL_ACCESS'] [share='Home' path='./mydata/folder1'] [siteid=2 snapid=0 inode=1026

33 inode_64=2251799813787881] [op='RMDIR'] by [uid='S-1-5-21-3011133496-64911139-1301028031-500', gid='S-1-5-21-3011133496-64911139-1301028031-512'] at ['Fri 2025-06-06 15:53:41 U

TC'] from [client=4]

How to Configure Event Forwarding for Auditing Events

Syslog is used to send events from the cluster. The following example shows how to configure syslog for file system auditing events:

Syslog configuration

Command:

syslog-config --server 192.0.2.50,514,tcp,filesystem --enable

Expected output:

Enabled:                 true
Servers:
                         Address:                 192.0.2.50
                         Port:                    514
                         Transport:               TCP
                         Message types:           [Filesystem]

Configuring a Share to Send Auditing Events

Auditing information is configured on a client using the built-in tools.

From a Windows Client Using the Microsoft Management Console

The following example procedure shows how to enable auditing for delete and XX operations on the Home share.

  1. Open the Microsoft Management Console and connect to the cluster.

    admin configuring a share to send auditing events image1
    Figure 1. Connect to the cluster
  2. Select Properties for the Home share and navigate to the Security  Advanced tab and select Auditing.

    admin configuring a share to send auditing events image2
    Figure 2. Advanced security properties
  3. Click Add.

    1. Select Everyone for the principal. This will audit file access for all users.

    2. Select All for type. This will audit successful and failed attempts. Note that if you only want to audit failed attempts, then select failed.

      admin configuring a share to send auditing events image3
      Figure 3. Select auditing specifics
    3. Select the operations to audit. In this example, only delete operations are audited.

  4. Auditing for delete operations has now been configured. Events like this will be logged to the syslog stream.

Syslog Examples

File deletion

Syslog file-delete example
2025-06-06T15:53:41+00:00 tf-anvil2 filesystem AUDIT [audit_access='dD' audit_access_type='SUCCESSFUL_ACCESS'] [share='Home' path='./mydata/folder1/file.txt'] [siteid=2 snapid=0 inode=102636 inode_64=2251799813787884] [op='UNLINK'] by [uid='S-1-5-21-3011133496-64911139-1301028031-500', gid='S-1-5-21-3011133496-64911139-1301028031-512'] at ['Fri 2025-06-06 15:53:41 UTC'] from [client=4]

Directory deletion

Syslog directory-delete example
2025-06-06T15:53:41+00:00 tf-anvil2 filesystem AUDIT [audit_access='dD' audit_access_type='SUCCESSFUL_ACCESS'] [share='Home' path='./mydata/folder1'] [siteid=2 snapid=0 inode=102633 inode_64=2251799813787881] [op='RMDIR'] by [uid='S-1-5-21-3011133496-64911139-1301028031-500', gid='S-1-5-21-3011133496-64911139-1301028031-512'] at ['Fri 2025-06-06 15:53:41 UTC'] from [client=4]