System
cert-add
cert-add [options]
Add a certificate or certificate chain to the system’s trust store
Adds a certificate or CA to the Hammerspace trust store. By default, cert-add accepts only root CA certificates. You do not need to add the Hammerspace system root CA — it is generated and distributed automatically.
Options
--help
Display this help and exit
--pem
The certificate or certificate chain in PEM format (Required)
PEM-format certificate content to add. Accepts a multi-line, quoted PEM string.
--pem "<pem_content>"
--trust-intermediate-ca
Allow adding intermediate CA certificates to the trust store (defaults to only adding root CA certificates)
Adds an intermediate CA certificate (rather than a root CA).
--trust-self-signed-certificate
Allow adding self-signed non-CA certificates to the trust store (defaults to only adding root CA certificates)
Adds a self-signed, non-CA certificate (for example, a pinned server certificate).
cert-ca-list
cert-ca-list [options]
List the system root CA certificate(s)
Lists the Hammerspace-generated system root CA certificate(s). The active CA is used to sign all internal node certificates.
Options
--help
Display this help and exit
--role
List a specific CA by role. Possible values: SYSTEM_ACTIVE | SYSTEM_OLD.
Lists a specific CA by role. Valid values: SYSTEM_ACTIVE (the CA that signs node certificates and CSR-signed certificates) and SYSTEM_OLD (reserved for a CA that has been replaced; Hammerspace 5.3 provides no way to replace the system CA).
cert-csr-sign
cert-csr-sign [options]
Sign a certificate signing request (CSR) with the system root CA certificate
Signs a Certificate Signing Request (CSR) using the Hammerspace system CA and returns a signed certificate that a client can install. The certificate is valid for 365 days and supports client authentication (clientAuth) only, so it cannot be used by a storage server. Include at least one IP address in the CSR’s Subject Alternative Name (SAN) field: the command does not require it, but peers that check the certificate generally match against the SAN.
Options
--help
Display this help and exit
--pem
The certificate signing request in PEM format
PEM-format CSR content to sign. Accepts a multi-line, quoted PEM string.
--pem "<csr_pem_content>"
--track
Add the certificate to the system’s inventory of known certificates
Adds the signed certificate to the Hammerspace certificate inventory, where its expiration date is shown. Hammerspace does not alert you before the certificate expires. Recommended.
cert-list
cert-list [options]
List the known certificate(s)
Lists all certificates known to the system, including the system root CA and the per-node certificates signed by it.
Options
--full
Print extra information for each element
Displays detailed output, including validity dates and subject information.
--help
Display this help and exit
--id
The ID of the certificate to list
Retrieves a specific certificate by its ID.
--origin
List certificates that have this origin. Possible values: SYSTEM_CA | SYSTEM_ISSUED | CSR_SIGNED_BY_CA | UPLOADED_ROOT_CA | UPLOADED_INTERMEDIATE_CA | UPLOADED_PINNED_CERT.
Filters the list by how a certificate was added to the system. Valid values: SYSTEM_CA (the Hammerspace root CA), SYSTEM_ISSUED (the certificate issued to each Anvil and DSX node), CSR_SIGNED_BY_CA (certificates created by signing a CSR with the system CA), UPLOADED_ROOT_CA (an uploaded self-signed CA certificate), UPLOADED_INTERMEDIATE_CA (an uploaded intermediate CA certificate, added with --trust-intermediate-ca), and UPLOADED_PINNED_CERT (an uploaded self-signed certificate that is not a CA, added with --trust-self-signed-certificate).
cert-remove
cert-remove [options]
Remove a certificate from the system’s trust store
Removes an uploaded CA certificate or pinned certificate, or a certificate signed from a CSR, from the trust store. Retrieve the certificate ID with cert-list first. SYSTEM_CA and SYSTEM_ISSUED certificates are managed by Hammerspace and cannot be removed.
Options
--help
Display this help and exit
--id
The ID of the certificate to remove (Required)
cluster-config
cluster-config [options]
Update cluster configuration
Options
--async
Causes the command to be executed asynchronously. A reference task identifier will be returned
--gfs-participant-max-suspected-time
The amount of time any GFS participant may remain in a SUSPECTED operational state before that state automatically transitioned to DOWN. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, minutes are assumed
--help
Display this help and exit
--nfs-tls-forbidden
Disallow TLS for all external and internal NFS connections
--nfs-tls-required
Require TLS with mutual authentication for all external and internal NFS connections
--no-timeout
When running a task-based command synchronously, monitor for task completion indefinitely
--online-activation-support
Determines whether online license activation is allowed. Allowed values:[YES, NO]
--prometheus-exporters-disable
Disable Prometheus exporters
--prometheus-exporters-enable
Enable Prometheus exporters
--proxy-url
The URL of the HTTP proxy server (in the form http://a.b.c.d:pp)
--proxy-url-clear
Clear the HTTP proxy server configuration
--server-certificate-chain
An X.509 certificate, with an optional CA chain, in certificate PEM format that identifies the management server to the client
--server-certificate-reset
Reset the server to use an internally-generated self-signed certificate
--server-private-key
An unencrypted RSA private key in PKCS#1 or PKCS#8 PEM format that is paired with the server certificate in the server-certificate-chain bundle
--timezone
Specifies the timezone
--view
View the cluster configuration
dns-config
dns-config [options]
Configure DNS
Options
--force
Skip validation of new DNS server configuration
--help
Display this help and exit
--servers
Set DNS server(s)
--servers-clear
Clear DNS servers
--view
View the DNS configuration
dp-update
dp-update [options]
Update data portal
Options
--data-portal-id
The data portal UUID. Required unless any of the following is specified: --data-portal-type, --node-name
--data-portal-type
The data portal type. Required unless any of the following is specified: --data-portal-id, --node-name Possible values: SMB | NFS_V3 | NFS_V4_1 | S3.
--disable
Set the data portal admin state to DOWN
--enable
Set the data portal admin state to UP
--help
Display this help and exit
--node-name
The node name. Required unless any of the following is specified: --data-portal-type, --data-portal-id
email-config
email-config [options]
Add an SMTP gateway which will be used for events and call home through a mail server
Options
--connection-security
The type of connection security to use (default: NONE). Possible values: NONE | TLS | STARTTLS.
The connection security mode used for the SMTP connection. Choose the mode that matches what your mail server expects:
-
NONE— Connect without encryption. -
TLS— Use implicit TLS. The connection is encrypted immediately on connect. Typically used with port 465. -
STARTTLS— Connect unencrypted, then upgrade the connection to TLS using the STARTTLS command. Typically used with port 587.
--disable
Disable SMTP email
--enable
Enable SMTP email
--from-address
Source email address from which the events will be sent
--help
Display this help and exit
--host
SMTP host
--password
SMTP password
--port
SMTP port
--username
SMTP username
--view
View current configuration
event-list
event-list [options]
List events generated by the system
Options
--cleared
Include only cleared events
--from-date
List events after "from-date", in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"
--full
Print extra information for each element
--help
Display this help and exit
--id
The ID of the event to list
--last-emitted
The number of last-emitted events to list
--severity
List all events with severity greater than or equal to the given severity. Possible values: DEBUG | INFORMATIONAL | NOTICE | WARNING | ERROR | CRITICAL | ALERT | EMERGENCY.
--type
List all events of a given type.
Possible values
ACTUAL_ALLOCATED_CAPACITY_EXCEEDED | ADDED | ADD_FAILED | AD_CACHE_FLUSH_FAILED | AD_CACHE_FLUSH_SUCCESS | AD_COMPUTER_ISSUE | AD_DC_OUT_OF_TIME_SYNC | AD_SERVER_ISSUE | AD_WITHOUT_NTP | ALLOCATED_CAPACITY_APPROACHING_LIMIT | ALLOCATED_CAPACITY_EXCEEDED | ASSIMILATION_CANCELLED | ASSIMILATION_FAILED | ASSIMILATION_STOPPED | ASSIMILATION_SUCCESS | AUDIT | BACKUP_COMPLETED | BACKUP_CREATION_FAILED | BACKUP_FAILED | BACKUP_NOT_SCHEDULED | BORROWING_LICENSE_ABOUT_TO_EXPIRE | BORROWING_LICENSE_EXPIRED | CANCELLED | CAPACITY_HEARTBEAT_DISABLED | CAPACITY_THRESHOLD_PASSED | CLUSTER_DEGRADED | CLUSTER_FAILOVER | CLUSTER_MISCONFIGURED | CLUSTER_REPLICATION_EVENT | CLUSTER_SPLIT_BRAIN | COLLECTIONS_ENTER | COLLECTIONS_LEAVE | COMB_MIGRATION_INCOMPLETE | COMPONENT_MISSING | CREATED | CREATE_FAILED | CTDB_IN_RECOVERY | CTDB_NODES_FILE_SYNC_FAILED | CTDB_NODE_FAILURE | CTDB_NOT_RESPONDING | DATA_COPY_TO_OBJECT_FAILED | DATA_COPY_TO_OBJECT_SUCCESS | DATA_REPLICATION_ISSUE | DD_CLUSTER_PLANNED_SHUTDOWN | DD_CLUSTER_PLANNED_SHUTDOWN_FAILED | DELETED | DELETE_FAILED | DISK_USAGE_LIMIT_EXCEEDED | DISK_USAGE_LIMIT_WARNING | DNS_ISSUE | ECGROUP_ARRAY | ECGROUP_MOUNTPOINT | ECGROUP_STORAGE | EVAL_ABOUT_TO_EXPIRE | EVAL_EXPIRED | EXPIRED_LICENSE_IN_GRACE | FAILURE_REPORTING_LICENSED_USAGE | GFS_PARTICIPANT_ADDED | GFS_PARTICIPANT_ADD_FAILED | GFS_PARTICIPANT_OPER_STATE_CHANGED | GFS_PARTICIPANT_REMOVED | GFS_PARTICIPANT_REMOVE_FAILED | HW_DRIVE_FAILED | HW_FAN_FAILED | HW_FRU_EVENT | HW_NIC_LINK_EVENT | HW_PSU_FAILED | HW_RAID_EVENT | IDMAPD_SYNC_ISSUE | INDEXING_SENT | INVALID_ADDITIONAL_ADDRESS | INVALID_COMB_STRUCTURE | KERBEROS_CLUSTER_UNHEALTHY | KERBEROS_REQUIRED_NFS_SPNS_MISSING | KERBEROS_SHARE_WITH_NO_NFS_SPNS | KERBEROS_SHARE_WITH_UNJOINED_AD | KERBEROS_SYNC_FAILURE | KERBEROS_USER_MAPPING_NONFUNCTIONAL | KEYTAB_MISMATCH | KMS_OPERATION_CHECK_FAILED | LICENSE_ABOUT_TO_ENTER_GRACE | LICENSE_ABOUT_TO_EXPIRE | LICENSE_ACTIVATED | LICENSE_ACTIVATION_FAILED | LICENSE_EXPIRED | LICENSE_IN_GRACE_ABOUT_TO_EXPIRE | LICENSE_STATE_CHANGED | LICENSING_MISCONFIGURED | METADATA_REPLICATION_ISSUE | METERED_LICENSE_IN_GRACE | METRIC_COLLECTION_DEGRADED | MGMT_GENERIC_EVENT | MGMT_STARTED | MGMT_STARTED_FROM_RESTORE | MISSING_CLOUD_MOVER | MISSING_COMB_STRUCTURE | MISSING_DATA_MOVER | MISSING_SHARED_OBJECT_STORAGE_VOLUME | MISSING_STORAGE_VOLUME | MODELER_SHARE_SWEEP_COMPLETED | MOVER_AT_CAPACITY | MOVER_BAD_IP | MOVER_CONNECTED | MOVER_DROPPED | MOVER_UNKNOWN | NAME_SERVICE_UNHEALTHY | NETWORK_LDAP_UNREACHABLE | NETWORK_NTP_UNREACHABLE | NFS_LAYOUT_ERROR_ACCESS | NFS_LAYOUT_ERROR_IO | NFS_LAYOUT_ERROR_NXIO | NFS_LAYOUT_ERROR_STALE | NFS_TLS_CONFIGURATION_UNHEALTHY | NODE_MODE_ISSUE | NONE | NO_AVAILABLE_STORAGE_ON_NODE | NO_REGISTERED_MOVER | NO_REGISTERED_STORAGE_VOLUME | NTP_NOT_SYNCHRONIZED | NVMEOF_PATH_DEGRADED | NVMEOF_PATH_LOST | OBJECT_VOLUME_GC_BLOCKED | OBJECT_VOLUME_GC_CANCELLED | OBJECT_VOLUME_GC_COMPLETED | OBJECT_VOLUME_GC_FAILED | OBJECT_VOLUME_IO_TEST_ALL_FAILED | OBJECT_VOLUME_IO_TEST_FAILED | OBJECT_VOLUME_RESERVATION_OLD | OSV_CSP_CONN_FAILED | OSV_HMDB_CLOUD_DELETES_FAILING | OSV_HMDB_DEGRADED_BLOOM_FILTER_ALLOCATED | OSV_HMDB_INSUFFICIENT_GC_MEMORY | OSV_HMDB_REPLICATION_OUT_OF_SYNC | OSV_QUORUM_IN_FLUX | OSV_SITE_TO_SITE_CONN_FAILED | OVER_CAPACITY_GRACE_ABOUT_TO_EXPIRE | OVER_CAPACITY_LICENSE_VIOLATION | PDDM_EXITED | PDDM_KILLED_DI | PDDM_RESTART | PKI_CA_CREATION_FAILED | PKI_NODE_CERT_CREATION_FAILED | PKI_NODE_CERT_SYNC_FAILED | PKI_NODE_CHECK_FAILED | PKI_TRUST_SYNC_FAILED | PORTAL_EXPORT_FAILED | PORTAL_FLOATING_IP_SYNC_FAILED | PORTAL_UNEXPORT_FAILED | PROMETHEUS_DEGRADED | QUORUM_DEVICE_CONFIGURED | QUORUM_DEVICE_UNCONFIGURED | QUORUM_DEVICE_UNHEALTHY | READ_LATENCY_THRESHOLD_CROSSED | REMOVED | REMOVE_FAILED | REPLICATION_CLOCK_OUT_OF_SYNC | REPLICATION_LATENCY_THRESHOLD_EXCEEDED | REPLICATION_PORT_CHECK_FAILED | REPLICATION_WITHOUT_NTP | S3_MULTIPART_UPLOAD_ABORTED | S3_SERVICE_RELOADED | S3_SERVICE_RELOAD_ERROR | SALT_NOT_FUNCTIONAL | SERVICE_OPER_STATE_ISSUE | SHARE_CLONED | SHARE_CLONE_FAILED | SHARE_EVENTS_PROCESSED | SHARE_EVENTS_PROCESSING | SHARE_EVENT_PROCESSING_BLOCKED | SHARE_PRUNING | SHARE_PRUNING_BLOCKED | SHARE_QUOTA_EXCEEDED | SHARE_QUOTA_WARNING | SHARE_RESTORED | SHARE_RESTORE_FAILED | SHARE_SNAPSHOT_CREATED | SHARE_SNAPSHOT_CREATE_FAILED | SHARE_SNAPSHOT_DELETED | SHARE_SNAPSHOT_DELETE_FAILED | SOFTWARE_UPDATE_FAILED | SOFTWARE_UPDATE_STARTED | SOFTWARE_UPDATE_SUCCESS | SOFTWARE_VERSION_CHANGED | SSSD_CONFIG_SYNC_FAILED | SUPPORT_CALL_HOME_EVENT | SYSTEM | UPDATED | UPDATE_FAILED | USER_PASSWORD_CHANGED | VASA_VAAI_PROVIDER_EVENT | VOLUME_ASSIMILATION_EVENT | VOLUME_CLONE_TEST_FAILED | VOLUME_CONFIG_TEST_ALL_FAILED | VOLUME_CONFIG_TEST_FAILED | VOLUME_DECOMMISSION_EVENT | VOLUME_EVICTION_FAILED | VOLUME_STATE_CHANGED | WRITE_LATENCY_THRESHOLD_CROSSED
--uncleared
Include only uncleared events
--until-date
List events before "until-date", in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"
event-update
event-update [options]
Clear events generated by the system
Options
--all
Clear all events. Required unless any of the following is specified: --type, --created-before, --created-after, --id
--clear
Clear events (Required)
--created-after
Clear events after "created-after", in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30". Required unless any of the following is specified: --type, --all, --created-before, --id
--created-before
Clear events before "created-before", in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30". Required unless any of the following is specified: --type, --all, --created-after, --id
--help
Display this help and exit
--id
The ID of the event to clear. Required unless any of the following is specified: --type, --all, --created-before, --created-after
--type
Clear all events of a given type. Required unless any of the following is specified: --all, --created-before, --created-after, --id
Possible values
ACTUAL_ALLOCATED_CAPACITY_EXCEEDED | ADDED | ADD_FAILED | AD_CACHE_FLUSH_FAILED | AD_CACHE_FLUSH_SUCCESS | AD_COMPUTER_ISSUE | AD_DC_OUT_OF_TIME_SYNC | AD_SERVER_ISSUE | AD_WITHOUT_NTP | ALLOCATED_CAPACITY_APPROACHING_LIMIT | ALLOCATED_CAPACITY_EXCEEDED | ASSIMILATION_CANCELLED | ASSIMILATION_FAILED | ASSIMILATION_STOPPED | ASSIMILATION_SUCCESS | AUDIT | BACKUP_COMPLETED | BACKUP_CREATION_FAILED | BACKUP_FAILED | BACKUP_NOT_SCHEDULED | BORROWING_LICENSE_ABOUT_TO_EXPIRE | BORROWING_LICENSE_EXPIRED | CANCELLED | CAPACITY_HEARTBEAT_DISABLED | CAPACITY_THRESHOLD_PASSED | CLUSTER_DEGRADED | CLUSTER_FAILOVER | CLUSTER_MISCONFIGURED | CLUSTER_REPLICATION_EVENT | CLUSTER_SPLIT_BRAIN | COLLECTIONS_ENTER | COLLECTIONS_LEAVE | COMB_MIGRATION_INCOMPLETE | COMPONENT_MISSING | CREATED | CREATE_FAILED | CTDB_IN_RECOVERY | CTDB_NODES_FILE_SYNC_FAILED | CTDB_NODE_FAILURE | CTDB_NOT_RESPONDING | DATA_COPY_TO_OBJECT_FAILED | DATA_COPY_TO_OBJECT_SUCCESS | DATA_REPLICATION_ISSUE | DD_CLUSTER_PLANNED_SHUTDOWN | DD_CLUSTER_PLANNED_SHUTDOWN_FAILED | DELETED | DELETE_FAILED | DISK_USAGE_LIMIT_EXCEEDED | DISK_USAGE_LIMIT_WARNING | DNS_ISSUE | ECGROUP_ARRAY | ECGROUP_MOUNTPOINT | ECGROUP_STORAGE | EVAL_ABOUT_TO_EXPIRE | EVAL_EXPIRED | EXPIRED_LICENSE_IN_GRACE | FAILURE_REPORTING_LICENSED_USAGE | GFS_PARTICIPANT_ADDED | GFS_PARTICIPANT_ADD_FAILED | GFS_PARTICIPANT_OPER_STATE_CHANGED | GFS_PARTICIPANT_REMOVED | GFS_PARTICIPANT_REMOVE_FAILED | HW_DRIVE_FAILED | HW_FAN_FAILED | HW_FRU_EVENT | HW_NIC_LINK_EVENT | HW_PSU_FAILED | HW_RAID_EVENT | IDMAPD_SYNC_ISSUE | INDEXING_SENT | INVALID_ADDITIONAL_ADDRESS | INVALID_COMB_STRUCTURE | KERBEROS_CLUSTER_UNHEALTHY | KERBEROS_REQUIRED_NFS_SPNS_MISSING | KERBEROS_SHARE_WITH_NO_NFS_SPNS | KERBEROS_SHARE_WITH_UNJOINED_AD | KERBEROS_SYNC_FAILURE | KERBEROS_USER_MAPPING_NONFUNCTIONAL | KEYTAB_MISMATCH | KMS_OPERATION_CHECK_FAILED | LICENSE_ABOUT_TO_ENTER_GRACE | LICENSE_ABOUT_TO_EXPIRE | LICENSE_ACTIVATED | LICENSE_ACTIVATION_FAILED | LICENSE_EXPIRED | LICENSE_IN_GRACE_ABOUT_TO_EXPIRE | LICENSE_STATE_CHANGED | LICENSING_MISCONFIGURED | METADATA_REPLICATION_ISSUE | METERED_LICENSE_IN_GRACE | METRIC_COLLECTION_DEGRADED | MGMT_GENERIC_EVENT | MGMT_STARTED | MGMT_STARTED_FROM_RESTORE | MISSING_CLOUD_MOVER | MISSING_COMB_STRUCTURE | MISSING_DATA_MOVER | MISSING_SHARED_OBJECT_STORAGE_VOLUME | MISSING_STORAGE_VOLUME | MODELER_SHARE_SWEEP_COMPLETED | MOVER_AT_CAPACITY | MOVER_BAD_IP | MOVER_CONNECTED | MOVER_DROPPED | MOVER_UNKNOWN | NAME_SERVICE_UNHEALTHY | NETWORK_LDAP_UNREACHABLE | NETWORK_NTP_UNREACHABLE | NFS_LAYOUT_ERROR_ACCESS | NFS_LAYOUT_ERROR_IO | NFS_LAYOUT_ERROR_NXIO | NFS_LAYOUT_ERROR_STALE | NFS_TLS_CONFIGURATION_UNHEALTHY | NODE_MODE_ISSUE | NONE | NO_AVAILABLE_STORAGE_ON_NODE | NO_REGISTERED_MOVER | NO_REGISTERED_STORAGE_VOLUME | NTP_NOT_SYNCHRONIZED | NVMEOF_PATH_DEGRADED | NVMEOF_PATH_LOST | OBJECT_VOLUME_GC_BLOCKED | OBJECT_VOLUME_GC_CANCELLED | OBJECT_VOLUME_GC_COMPLETED | OBJECT_VOLUME_GC_FAILED | OBJECT_VOLUME_IO_TEST_ALL_FAILED | OBJECT_VOLUME_IO_TEST_FAILED | OBJECT_VOLUME_RESERVATION_OLD | OSV_CSP_CONN_FAILED | OSV_HMDB_CLOUD_DELETES_FAILING | OSV_HMDB_DEGRADED_BLOOM_FILTER_ALLOCATED | OSV_HMDB_INSUFFICIENT_GC_MEMORY | OSV_HMDB_REPLICATION_OUT_OF_SYNC | OSV_QUORUM_IN_FLUX | OSV_SITE_TO_SITE_CONN_FAILED | OVER_CAPACITY_GRACE_ABOUT_TO_EXPIRE | OVER_CAPACITY_LICENSE_VIOLATION | PDDM_EXITED | PDDM_KILLED_DI | PDDM_RESTART | PKI_CA_CREATION_FAILED | PKI_NODE_CERT_CREATION_FAILED | PKI_NODE_CERT_SYNC_FAILED | PKI_NODE_CHECK_FAILED | PKI_TRUST_SYNC_FAILED | PORTAL_EXPORT_FAILED | PORTAL_FLOATING_IP_SYNC_FAILED | PORTAL_UNEXPORT_FAILED | PROMETHEUS_DEGRADED | QUORUM_DEVICE_CONFIGURED | QUORUM_DEVICE_UNCONFIGURED | QUORUM_DEVICE_UNHEALTHY | READ_LATENCY_THRESHOLD_CROSSED | REMOVED | REMOVE_FAILED | REPLICATION_CLOCK_OUT_OF_SYNC | REPLICATION_LATENCY_THRESHOLD_EXCEEDED | REPLICATION_PORT_CHECK_FAILED | REPLICATION_WITHOUT_NTP | S3_MULTIPART_UPLOAD_ABORTED | S3_SERVICE_RELOADED | S3_SERVICE_RELOAD_ERROR | SALT_NOT_FUNCTIONAL | SERVICE_OPER_STATE_ISSUE | SHARE_CLONED | SHARE_CLONE_FAILED | SHARE_EVENTS_PROCESSED | SHARE_EVENTS_PROCESSING | SHARE_EVENT_PROCESSING_BLOCKED | SHARE_PRUNING | SHARE_PRUNING_BLOCKED | SHARE_QUOTA_EXCEEDED | SHARE_QUOTA_WARNING | SHARE_RESTORED | SHARE_RESTORE_FAILED | SHARE_SNAPSHOT_CREATED | SHARE_SNAPSHOT_CREATE_FAILED | SHARE_SNAPSHOT_DELETED | SHARE_SNAPSHOT_DELETE_FAILED | SOFTWARE_UPDATE_FAILED | SOFTWARE_UPDATE_STARTED | SOFTWARE_UPDATE_SUCCESS | SOFTWARE_VERSION_CHANGED | SSSD_CONFIG_SYNC_FAILED | SUPPORT_CALL_HOME_EVENT | SYSTEM | UPDATED | UPDATE_FAILED | USER_PASSWORD_CHANGED | VASA_VAAI_PROVIDER_EVENT | VOLUME_ASSIMILATION_EVENT | VOLUME_CLONE_TEST_FAILED | VOLUME_CONFIG_TEST_ALL_FAILED | VOLUME_CONFIG_TEST_FAILED | VOLUME_DECOMMISSION_EVENT | VOLUME_EVICTION_FAILED | VOLUME_STATE_CHANGED | WRITE_LATENCY_THRESHOLD_CROSSED
heartbeat-list
heartbeat-list [options]
List the configured heartbeats
Options
--help
Display this help and exit
heartbeat-send
heartbeat-send [options]
Sends the specified heartbeat type to support
Options
--help
Display this help and exit
--id
The ID of the heartbeat to send. Required unless any of the following is specified: --type, --name
--name
The name of the heartbeat to send. Required unless any of the following is specified: --type, --id
--type
The type of the heartbeat to send. Required unless any of the following is specified: --name, --id Possible values: HEALTH | CAPACITY.
heartbeat-update
heartbeat-update [options]
Update the heartbeat configuration
Options
--disable
Disables periodic heartbeat sending. Required unless any of the following is specified: --enable, --interval
--enable
Enables periodic heartbeat sending. Required unless any of the following is specified: --disable, --interval
--help
Display this help and exit
--id
The ID of the heartbeat configuration to be updated. Required unless any of the following is specified: --type, --name
--interval
Periodic heartbeat sending interval (default units: seconds, otherwise specify units, e.g. "5 minutes"). Required unless any of the following is specified: --enable, --disable
--name
The name of the heartbeat configuration to be updated. Required unless any of the following is specified: --type, --id
--type
The type of the heartbeat configuration to be updated. Required unless any of the following is specified: --name, --id Possible values: HEALTH | CAPACITY.
identity-group-mapping-create
identity-group-mapping-create [options]
Map a federated user’s group to an internal Role. For example, map the members of a particular Active Directory group to the admin Role
Options
--group
Name of the group to map to the internal role (Required)
--help
Display this help and exit
--mgmt-role-id
The ID of an internal role. Required unless "--mgmt-role-name" is specified
--mgmt-role-name
The name of an internal role. Required unless "--mgmt-role-id" is specified
--name
A name for the group to role mapping. If missing, group::role is used. (Required)
identity-group-mapping-delete
identity-group-mapping-delete [options]
Delete an identity group mapping
Options
--help
Display this help and exit
--id
The ID of the identity group mapping to delete. Required unless "--name" is specified
--name
The name of the identity group mapping to delete. Required unless "--id" is specified
identity-group-mapping-list
identity-group-mapping-list [options]
List the identity group mappings
Options
--full
Print extra information for each element
--help
Display this help and exit
--id
List a specific identity group mapping by ID
--name
List a specific identity group mapping by name
identity-group-mapping-update
identity-group-mapping-update [options]
Update an identity group mapping
Options
--group
The name of a new identity group to associate with the role
--help
Display this help and exit
--id
The ID of the identity group mapping to update. Required unless "--name" is specified
--mgmt-role-id
The ID the role to associate with the identity group
--mgmt-role-name
The name the role to associate with the identity group
--name
The name of the identity group mapping to update. Required unless "--id" is specified
idp-add
idp-add [options]
Add an Identity Provider (IdP) such as Active Directory for purposes of federated authentication and authorization. See also the identity-group-mapping commands
Options
--connect-timeout
The amount of time to wait for the system to connect to the IdP. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, seconds are assumed
--connection-security
The type of connection security to use (default: NONE). Possible values: NONE | TLS | STARTTLS.
The connection security mode used for the LDAP connection to the identity provider. NONE connects in cleartext (normally port 389). TLS uses LDAPS, negotiating TLS immediately on connect (normally port 636). STARTTLS connects in cleartext and then upgrades the connection in place with the STARTTLS command. SSL is accepted as a synonym for TLS.
--domain
The name of an IdP domain. When adding an AD IdP, this specifies the AD domain (Required)
--follow-referrals
Instructs the system to follow referrals when resolving usernames. Typically, only required when there are cross-domain memberships
--help
Display this help and exit
--name
The name of this IdP (Required)
--read-timeout
The amount of time to wait for the system to read from the IdP. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, seconds are assumed
--servers
A comma-separated list of fully-qualified domain names or IP addresses, optionally followed by a colon-separated TCP port. The list may not contain spaces.
--servers server1.example.com
--servers server1.example.com,server2.example.com
--servers 127.0.0.5:8389
(Required)
A comma-separated list of fully-qualified domain names or IP addresses. The list may not contain spaces. To use a non-standard port, append it to a server entry, for example dc1.example.com:636
--type
The type of IdP being added. Possible values: AD.
--validate-server-certs-enable
Enable validation of server certificates for SSL/TLS connections.
Enable validation of the identity provider’s server certificate. Applies when --connection-security is TLS or STARTTLS. Before enabling validation, install the issuing CA (and any intermediates) so Hammerspace trusts the server certificate, from the GUI under or with cert-add; otherwise logins fail during the TLS handshake.
If you omit this option, certificate validation is disabled. idp-add has no option to disable validation; to turn validation off after enabling it, use idp-update --validate-server-certs-disable.
idp-list
idp-list [options]
List the federated Identity Providers (IdPs)
Options
--full
Print extra information for each element
--help
Display this help and exit
--id
List a specific IdP by ID
--name
List a specific IdP by name
idp-remove
idp-remove [options]
Remove a federated Identity Provider (IdP)
Options
--help
Display this help and exit
--id
The ID of the IdP to remove. Required unless "--name" is specified
--name
The name of the IdP to remove. Required unless "--id" is specified
idp-update
idp-update [options]
Update a federated Identity Provider (IdP)
Options
--connect-timeout
The amount of time to wait for the system to connect to the IdP. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, seconds are assumed
--connection-security
The type of connection security to use. Possible values: NONE | TLS | STARTTLS.
--domain
A domain name
--follow-referrals
Instructs the system to follow referrals when resolving usernames. Typically, only required when there are cross-domain memberships
--help
Display this help and exit
--id
The ID of the IdP to update. Required unless "--name" is specified
--ignore-referrals
Instructs the system to not follow referrals when resolving usernames
--name
The name of the IdP to update. Required unless "--id" is specified
--read-timeout
The amount of time to wait for the system to read from the IdP. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, seconds are assumed
--servers
A comma-separated list of fully-qualified domain names or IP addresses, optionally followed by a colon-separated TCP port. The list may not contain spaces.
--servers server1.example.com
--servers server1.example.com,server2.example.com
--servers 127.0.0.5:8389
--validate-server-certs-disable
Disable validation of server certificates for SSL/TLS connections.
--validate-server-certs-enable
Enable validation of server certificates for SSL/TLS connections.
kms-add
kms-add [options]
Add a key management system (KMS)
Options
--access-id
Authentication username (* required for AWS_KMS)
--client-certificate
An X.509 certificate in certificate PEM format that identifies the client to the server (* required for NCIPHER_WSOP)
--client-private-key
An RSA private key in PKCS#1 or PKCS#8 PEM format that is paired with the client-certificate (* required for NCIPHER_WSOP)
--comment
Any comment to be associated with the KMS
--endpoint
The endpoint (URI or host:port) of the KMS (* required for and exclusive to NCIPHER_WSOP)
--help
Display this help and exit
--key-id
The key identifier to use with the KMS (* required for AWS_KMS and NCIPHER_WSOP)
--name
A name for the KMS (Required)
--passphrase
The passphrase (* required for and exclusive to PASSPHRASE). If not specified, it will be prompted for.
--secret
Authentication password (* required for AWS_KMS)
--server-certificate-chain
An X.509 certificate, with optional CA chain, in certificate PEM format that identifies the KMS server to the client (* required for and exclusive to NCIPHER_WSOP)
--type
The type of KMS system being added. Possible values: NCIPHER_WSOP | AWS_KMS | PASSPHRASE. (Required)
kms-list
kms-list [options]
List the key management systems (KMS)s
Options
--full
Print extra information for each element
--help
Display this help and exit
--id
The ID of the KMS to list
--internal-id
The internal ID of the KMS to list
--name
The name of the KMS to list
kms-remove
kms-remove [options]
Remove a key management system
Options
--force
Force the removal of a KMS, even if object storage volumes exist
--help
Display this help and exit
--id
The ID of the KMS to remove. Required unless any of the following is specified: --internal-id, --name
--internal-id
The internal ID of the KMS to remove. Required unless any of the following is specified: --name, --id
--name
The name of the KMS to remove. Required unless any of the following is specified: --internal-id, --id
kms-update
kms-update [options]
Update a key management system (KMS)
Options
--access-id
Authentication username (exclusive to AWS_KMS)
--add-passphrase
Prompt for a new passphrase for the PASSPHRASE KMS
--client-certificate
An X.509 certificate in Base64-encoded PEM format (with the BEGIN and END tags) that identifies the client to the server (exclusive to NCIPHER_WSOP)
--client-private-key
An RSA private key in Base64-encoded PEM format (with the BEGIN and END tags) that is paired with the client-certificate (exclusive to NCIPHER_WSOP)
--comment
Any comment to be associated with the KMS
--endpoint
The endpoint (URI or host:port) of the NCIPHER_WSOP KMS
--help
Display this help and exit
--id
The ID of the KMS to update. Required unless any of the following is specified: --internal-id, --name
--internal-id
The internal ID of the KMS to update. Required unless any of the following is specified: --name, --id
--key-id
The key identifier to use with the KMS
--name
The name of the KMS to update. Required unless any of the following is specified: --internal-id, --id
--new-name
A new name for the KMS
--passphrase
A new passphrase for the PASSPHRASE KMS
--secret
Authentication password (exclusive to AWS_KMS)
--server-certificate-chain
An X.509 certificate with optional CA chain in Base64-encoded PEM format (with the BEGIN and END tags) that identifies the NCIPHER_WSOP KMS server to the client
local-site-config
local-site-config [options]
Update information for the local site.
Options
--data-center
The name of the data center location of the site
--data-center-clear
Clears the data center location
--geo-coordinates
Alternate specification of the location in <latitude>,<longitude> format
--geo-coordinates-clear
Clears both the latitude and longitude
--help
Display this help and exit
--latitude
The latitude (-90.0 to 90.0) of the site
--latitude-clear
Clears the latitude
--longitude
The longitude (-180.0 to 180.0) of the site
--longitude-clear
Clears the longitude
--name
The new name of the local site
--override-data-address
An address which overrides the site’s data address. When specified, this address will be used as the effective data address advertised to other sites. When not specified, the cluster’s data address will be used as the effective address
--override-data-address-clear
Clears the override-data-address
--override-mgmt-address
An address which overrides the site’s mgmt address. When specified, this address will be used as the effective mgmt address advertised to other sites. When not specified, the cluster’s mgmt address will be used as the effective address
--override-mgmt-address-clear
Clears the override-mgmt-address
--plus-code
Alternate specification of the location in Plus Code format
--view
View the local site
license-add
license-add [options]
Add and activate a license
Options
--activation-id
The license activation ID
--async
Causes the command to be executed asynchronously. A reference task identifier will be returned
--capacity
Number of 1TB units of storage capacity to allocate to this license. Only applicable with capacity-based licenses
--help
Display this help and exit
--license-server-ip
A management IP of a metered license server
--license-server-password
The password for the user named by the license-server-username parameter
--license-server-username
A user who has administrative rights on the metered license server
--no-timeout
When running a task-based command synchronously, monitor for task completion indefinitely
--type
The type of license to add. Possible values: NODE | FILE_CAPACITY | OBJECT_CAPACITY | METERED. (Required)
license-list
license-list [options]
List all licenses
Options
--activation-id
The activation ID of the license to list
--help
Display this help and exit
license-offline-add
license-offline-add [options]
Add and activate a license via an offline process. A request file is generated and obtained via one of the export parameters. The request file is then exchanged for a response file by the license administrator or at the license portal. The response file is then uploaded to complete the process.
Options
--activation-id
The license activation ID (Required)
--capacity
Number of 1TB units of storage capacity to allocate to this license. Only applicable with capacity-based licenses
--export-uri
Causes an activation request to be copied to an ftp, scp, or mailto location. Examples: ftp://example.com/uploads, scp://example.com/uploads, mailTo:john.doe@example.com. Required unless "--import-uri" is specified
--help
Display this help and exit
--import-uri
The location of the activation response file to be uploaded which will complete the offline license add process. Examples: ftp://example.com/uploads/capabilityResponse.bin, scp://example.com/uploads/capabilityResponse.bin. Required unless any of the following is specified: --export-uri, --type
--type
The type of license to add. Required unless "--import-uri" is specified. Possible values: NODE | FILE_CAPACITY | OBJECT_CAPACITY.
license-offline-cancel
license-offline-cancel [options]
Cancel a pending offline license operation for a given activation ID. If the initial request has already been uploaded to the license server, use the appropriate license-offline command to complete the operation.
Options
--activation-id
The license activation ID associated with the pending offline request (Required)
--help
Display this help and exit
license-offline-remove
license-offline-remove [options]
Deactivate and remove a license via an offline process. A request file is generated and obtained via one of the export parameters. The request file is then exchanged for a response file by the license administrator or at the license portal. The response file is then uploaded to complete the update process.
Options
--activation-id
The license activation ID (Required)
--export-uri
Causes a remove request file to be copied to an ftp, scp, or mailto location. Examples: ftp://example.com/uploads, scp://example.com/uploads, mailTo:john.doe@example.com. Required unless "--import-uri" is specified
--help
Display this help and exit
--import-uri
The location of the activation response file to be uploaded which will complete the offline license add process. Examples: ftp://example.com/uploads/capabilityResponse.bin, scp://example.com/uploads/capabilityResponse.bin. Required unless "--export-uri" is specified
license-offline-update
license-offline-update [options]
Update a license via an offline process. This supports administrative changes that do not affect capacity, such as expiration date extensions. A request file is generated and obtained via one of the export parameters. The request file is then exchanged for a response file by the license administrator or at the license portal. The response file is then uploaded to complete the update process.
Options
--activation-id
The license activation ID (Required)
--capacity
New number of 1TB units of storage capacity to allocate to this license
--export-uri
Causes an update request file to be copied to an ftp, scp, or mailto location. Examples: ftp://example.com/uploads, scp://example.com/uploads, mailTo:john.doe@example.com. Required unless "--import-uri" is specified
--help
Display this help and exit
--import-uri
The location of the activation response file to be uploaded which will complete the offline license add process. Examples: ftp://example.com/uploads/capabilityResponse.bin, scp://example.com/uploads/capabilityResponse.bin. Required unless "--export-uri" is specified
license-remove
license-remove [options]
Deactivate and remove a license
Options
--activation-id
The license activation ID (Required)
--async
Causes the command to be executed asynchronously. A reference task identifier will be returned
--force
When license-remove is invoked from the licensed client, the presence of the force parameter will cause the license to be removed from the client even if the license server can not be reached. When invoked from the license server, the force parameter is required and will cause the license server’s record of the license to be deleted.
--help
Display this help and exit
--no-timeout
When running a task-based command synchronously, monitor for task completion indefinitely
license-update
license-update [options]
Update the allocated capacity for a capacity-based license
Options
--activation-id
The license activation ID (Required)
--async
Causes the command to be executed asynchronously. A reference task identifier will be returned
--capacity
New number of 1TB units of storage capacity to allocate to this license
--help
Display this help and exit
--license-server-ip
For a metered license, update the IP of server to which usage reporting is sent. The IP must identify the license server which originally granted the client license.
--no-timeout
When running a task-based command synchronously, monitor for task completion indefinitely
metric-list
metric-list [options]
List metrics
Options
--field
Field names in the format: <table-name>.<column-name> (e.g., network.bytesSent) (Required)
--from-date
Shows metrics after date "from-date" (default: now - 1h)
--func
Computational aggregate function. Possible values: MIN | MAX | MEAN | MEDIAN.
--group-by
Time grouping interval. For example, 60s (seconds), 60m (minutes), 24h (hours), 7d (days), 52w (weeks)
--help
Display this help and exit
--limit
Total number of samples per column (default: 1000)
--name
Name criteria on the metrics
--object-type
Object type criteria on the metrics
--until-date
Shows metrics before date "until-date"
--uuid
Shows metrics on an object with the specified UUID
name-service-config
name-service-config [options]
Manage configured Name Services
Configures and manages LDAP name services used for user and group resolution on the NFS data path. When called without an operation flag, name-service-config defaults to --list. Operations (--add, --list, --update, --remove, --resolution-order, --resolve-user, --resolve-group, --resolve-user-groups, --test-connect) cannot be combined in one command.
Options
--add
Add a new LDAP Name Service
--address
The network address of the LDAP server in the form <host>[:port]. Host can be an IP address or a DNS name. Port is optional. Can be repeated. Required when adding, optional for update
IP address or DNS hostname of the LDAP server, with an optional :port suffix (1–65535). Required for --add, optional for --update. If the port is omitted, the connection test tries port 389 and then 636; a port is required if --no-connection-test is used. Repeat --address once per server; do not separate addresses with commas. On --update, the addresses given replace all existing addresses. More than one address works only with --no-connection-test, --transport-mode, and a port on every address.
--bind-clear
Clear both the Bind Distinguished Name (Bind DN) and the Bind Secret/password
Removes the Bind DN and Bind Secret from the name service. Used with --update.
--bind-dn
The Bind Distinguished Name used to authenticate and search the directory. Example: cn=search-user,ou=people,dc=example,dc=com
Bind distinguished name for authenticated access. Must be used with --bind-secret. On --add, a plain account name is expanded to cn=<name>,<domain in dc= form>; on --update, give a full DN.
--bind-secret
The Bind Secret/password of the LDAP user described by the Bind Distinguished Name (Bind DN)
Password for the Bind DN. Must be used with --bind-dn when adding a name service; on --update, give it alone to change only the secret. The CLI does not prompt for the secret; it is given on the command line.
In 5.3, --bind-secret is also required on every --update of a name service that has a Bind DN, except with --bind-clear.
--domain
The domain name of the LDAP Name Service. Optional: the management name will be used if not provided. Add only
Domain name (for example, corp.example.com). If omitted on --add, the --name value is used as the domain name and must be a valid domain name. Must be unique (case-insensitive) and is immutable after creation. The LDAP server must serve a naming context for the domain (dc=corp,dc=example,dc=com).
--help
Display this help and exit
--id
The ID (UUID) of the Name Service
UUID of the name service. Valid on --list, --update, and --remove. Illegal on --add.
--internal-id
The internal ID of the Name Service
Integer ID of the name service. Valid on --list, --update, and --remove. Illegal on --add.
--list
List configured Name Services
Lists all configured name services in resolution order.
--name
The management name of the Name Service
Management name of the name service. Maximum 255 characters; must be unique (case-insensitive). Required for --add; optional for --list, --update, and --remove.
--new-name
The new management name of the LDAP Name Service. Update only
--no-connection-test
Skip the pre-add or pre-update connectivity validation test
Skips the connection test. Requires --transport-mode and a port in each --address value. On --update, the connection test runs only when the addresses, ports, transport mode, or search base change, even without this option.
--remove
Remove a configured LDAP Name Service
--resolution-order
A comma-separated list of Name Service identifiers (names, UUIDs, or internal IDs)
describing the order in which they will be used for name resolution.
Any configured Name Services not provided will be sorted to the end of the list in indeterminate order
Reorders existing name services. Provide a comma-separated list of names, UUIDs, or internal IDs (all identifiers must be of the same type). Any name service whose identifier is not listed is sorted to the end with no guaranteed order.
--resolve-group
Supply a group name to test how Hammerspace resolves it. Can be qualified or unqualified
Looks up a group. Uses the same qualified/unqualified domain behavior as --resolve-user.
--resolve-user
Supply a username to test how Hammerspace resolves it. Can be qualified or unqualified
Looks up a user against configured name services via SSSD. Unqualified names (for example, jsmith) are looked up in every configured domain, with a result for each domain; qualified names (for example, jsmith@corp.example.com) are looked up only in the specified domain, and a domain that is not configured returns an error.
--resolve-user-groups
Supply a username to test how Hammerspace resolves its groups. Can be qualified or unqualified
Lists all groups a user belongs to. Uses the same qualified/unqualified domain behavior as --resolve-user.
--schema
The LDAP schema. Defaults to RFC2307. Possible values: RFC2307 | RFC2307BIS.
--search-base
The LDAP search base. Defaults to the domain’s root if not provided.
(default) dc=example,dc=com; (custom) ou=people,dc=example,dc=com
LDAP search base in domain-component syntax, for example dc=corp,dc=example,dc=com. Pass "" to set a blank search base.
--search-base-reset
Reset the LDAP search base to the domain’s root. Update only
Resets the search base to the domain’s root (for example, dc=corp,dc=example,dc=com). Used with --update.
--test-connect
Test connectivity to provided Name Service(s). Provide a single identifier, or a comma-separated
list of Name Service identifiers (names, UUIDs, or internal IDs) describing the Name Service(s) to test
Reruns the connection test for configured name services, using their saved address, port, transport mode, search base, and bind credentials. All identifiers in a list must be of the same type. The test checks that an LDAPS or StartTLS certificate names the configured address, but not that it is trusted.
--transport-mode
The Transport to use for connections. Optional: a connection test will determine
the most secure supported transport if not provided. Possible values: STARTTLS | LDAPS | LDAP.
Connection transport mode: LDAP, LDAPS, or STARTTLS (not case-sensitive). If omitted, the connection test tries STARTTLS, then LDAPS, then LDAP, and keeps the first that works. Required if --no-connection-test is used.
--transport-mode-reset
Reset the transport mode to use the default (discovered) value for the LDAP server
Clears the transport mode so it is re-determined. Used with --update. Cannot be used with --no-connection-test.
--update
Update a configured LDAP Name Service
nis-config
nis-config [options]
Configure NIS servers
Options
--disable
Disable NIS service, clear NIS servers
--enable
Enable NIS service
--help
Display this help and exit
--servers
NIS servers configuration in the form domain:server, example: --servers somedomain.local:192.168.3.17. This parameter may be repeated.
--view
View NIS configuration
notification-rule-create
notification-rule-create [options]
Create a notification rule
Options
--format
Notification format. Possible values: PLAIN | XML. (Required)
--help
Display this help and exit
--name
Rule name (Required)
--threshold
Severity threshold. Selecting a threshold means that users will be notified on any events with severity greater than or equal to the selected threshold. Possible values: DEBUG | INFORMATIONAL | NOTICE | WARNING | ERROR | CRITICAL | ALERT | EMERGENCY. (Required)
--users
Destination users (each must have an email address)
notification-rule-list
notification-rule-list [options]
List notification rules
Options
--full
Print extra information for each element
--help
Display this help and exit
--id
Notification rule identifier
--name
Notification rule name
notification-rule-remove
notification-rule-remove [options]
Remove a notification rule
Options
--help
Display this help and exit
--id
Notification rule identifier. Required unless "--name" is specified
--name
Notification rule name. Required unless "--id" is specified
notification-rule-update
notification-rule-update [options]
Update a notification rule
Options
--help
Display this help and exit
--id
Notification rule identifier. Required unless "--name" is specified
--name
Notification rule name. Required unless "--id" is specified
--new-format
New notification format. Required unless any of the following is specified: --new-threshold, --new-name Possible values: PLAIN | XML.
--new-name
New name. Required unless any of the following is specified: --new-format, --new-threshold
--new-threshold
New severity threshold. Required unless any of the following is specified: --new-format, --new-name Possible values: DEBUG | INFORMATIONAL | NOTICE | WARNING | ERROR | CRITICAL | ALERT | EMERGENCY.
ntp-config
ntp-config [options]
Configure NTP
Options
--help
Display this help and exit
--servers
Comma-separated list of NTP server hostnames or IP addresses.
--servers time1.google.com,time2.google.com,192.168.1.10
--servers-clear
Clear all NTP servers
--view
View NTP configuration
support-bundle
support-bundle [options]
Collect logs and information from all nodes
Options
--all
Collect from all available nodes. Required unless any of the following is specified: --current, --push, --node
--async
Causes the command to be executed asynchronously. A reference task identifier will be returned
--current
Collect from current node. For push requests, use this option to send only the current node. Required unless any of the following is specified: --all, --push, --node
--help
Display this help and exit
--local
Collect locally
--message
Optional message to include with the support bundle request. Use quotes if the message contains spaces
Optional message to include with the support bundle request. Use quotes if the message contains spaces. Do not include passwords or other secrets.
The message is recorded in the System Management logs, which are collected in the generated bundle. For example:
support-bundle --push --message "Case 12345, issue after failover"
--no-timeout
When running a task-based command synchronously, monitor for task completion indefinitely
--node
Collect from specific node. Required unless any of the following is specified: --current, --all, --push
--push
Collect and push to Support Center. Defaults to all nodes unless --current, --all, or --node is specified. Required unless any of the following is specified: --current, --all, --node
remote-site-add
remote-site-add [options]
Add a remote site
Options
--help
Display this help and exit
--mgmt-address
The management address of the remote site (Required)
--trust-client-certificate
Automatically trust the remote site’s client certificate
remote-site-discover
remote-site-discover [options]
Discover a remote site and, optionally, synchronize data on the local instance of the remote site
Options
--help
Display this help and exit
--mgmt-address
The management address (IP or DNS) of the remote site (Required)
--sync
Synchronize data on the local site instance with discovered remote values
remote-site-list
remote-site-list [options]
List known remote sites
Options
--full
Print extra information for each element
--help
Display this help and exit
--id
The ID of the site to be listed
--internal-id
The internal ID of the site to be listed
--name
The name of the site to be listed
remote-site-remove
remote-site-remove [options]
Remove a remote site. Note that if the site is sharing an object volume with this site, it will automatically be re-added
Options
--help
Display this help and exit
--id
The ID of the site to be removed. Required unless any of the following is specified: --internal-id, --name
--internal-id
The internal ID of the site to be removed. Required unless any of the following is specified: --name, --id
--name
The name of the site to be removed. Required unless any of the following is specified: --internal-id, --id
remote-site-update
remote-site-update [options]
Update a remote site. Use this to override the management and data address when configuring a Global File System. Overriding addresses is commonly used when network topologies are using NAT.
Options
--help
Display this help and exit
--id
The ID of the site to be updated. Required unless any of the following is specified: --internal-id, --name
--internal-id
The internal ID of the site to be updated. Required unless any of the following is specified: --name, --id
--name
The remote site’s name. Required unless any of the following is specified: --internal-id, --id
--no-trust-client-certificate
Do not automatically trust the remote site’s client certificate
--override-data-address
An address which overrides the remote site’s data address. When specified, this will be the effective data address used to communicate with the remote site
--override-data-address-clear
Clears the override-data-address
--override-mgmt-address
An address which overrides the remote site’s mgmt address. When specified, this will be the effective mgmt address used to communicate with the remote site
--override-mgmt-address-clear
Clears the override-mgmt-address
--trust-client-certificate
Automatically trust the remote site’s client certificate
schedule-create
schedule-create [options]
Create a schedule
Expression values follow cron syntax where:
',' Commas separate lists
'-' Hyphens define ranges
'*' Wildcard matches all cases
'/' Slashes define step values i.e. */5 = every 5 minutes
To create a schedule at 1:30 AM, 12:30 PM and 6:30 PM, Monday-Friday
schedule-create --name schedule_name --minute 30 --hour 1,12,18 --day-of-week MON-FRI
Options
--day-of-month
The day of month for schedule. Allowed values are: 1-31,-*/ (default value: *)
--day-of-week
The day of week for schedule. Allowed values are: 1-7,SUN-SAT-*/ (default value: *)
--help
Display this help and exit
--hour
The hour for schedule. Allowed values are: 0-23,-*/ (default value: *)
--minute
The minute for schedule. Allowed values are: 0-59,-*/ (default value: *)
--month
The month for schedule. Allowed values are: 1-12,-*/ (default value: *)
--name
The name of the schedule (Required)
schedule-delete
schedule-delete [options]
Delete a schedule
Options
--help
Display this help and exit
--id
The ID of the schedule to delete. Required unless "--name" is specified
--name
The name of the schedule to delete. Required unless "--id" is specified
schedule-list
schedule-list [options]
List schedules
Options
--full
Print extra information for each element
--help
Display this help and exit
--id
The ID of the schedule to list
--name
The name of the schedule to list
schedule-update
schedule-update [options]
Update a schedule
Expression values follow cron syntax where:
',' Commas separate lists
'-' Hyphens define ranges
'*' Wildcard matches all cases
'/' Slashes define step values i.e. */5 = every 5 minutes
To update a schedule to 1:30 AM, 12:30 PM and 6:30 PM, Monday-Friday
schedule-update --name schedule_name --minute 30 --hour 1,12,18 --day-of-week MON-FRI
Options
--day-of-month
The day of month for schedule. Allowed values are: 1-31,-*/ (default value: *)
--day-of-week
The day of week for schedule. Allowed values are: 1-7,SUN-SAT-*/ (default value: *)
--help
Display this help and exit
--hour
The hour for schedule. Allowed values are: 0-23,-*/ (default value: *)
--id
ID to identify the schedule. Required unless "--name" is specified
--minute
The minute for schedule. Allowed values are: 0-59,-*/ (default value: *)
--month
The month for schedule. Allowed values are: 1-12,-*/ (default value: *)
--name
Name to identify the schedule. Required unless "--id" is specified
snmp-config
snmp-config [options]
Configure SNMP service
Options
--contact
The textual identification of the contact person for this managed node, together with information on how to contact this person
--description
A textual description of the entity
--dest
SNMP trap destination configuration. A 3-tuple including <IP>,<version>,<community>. For example: 172.31.12.216,V2C,public
--disable
Disable SNMP service. Required unless any of the following is specified: --enable, --view
--enable
Enable SNMP service. Required unless any of the following is specified: --disable, --view
--help
Display this help and exit
--location
The physical location of this node
--manager
SNMP manager configuration. A 3-tuple including <subnet>,<version (V1|V2C)>,<community>. For example: 172.31.0.0/16,V2C,public
--name
An administratively-assigned name for this managed node
--view
View SNMP configuration. Required unless any of the following is specified: --enable, --disable
software-apply
software-apply [options]
Apply software version
Options
--all
Update all nodes, mutually exclusive with "--node-name". Required unless "--node-name" is specified
--help
Display this help and exit
--node-name
Node name, mutually exclusive with "--all". Required unless "--all" is specified
--skip-order-validation
Bypass software update ordering and versioning validation
--version
Version (Required)
software-list
software-list [options]
List software versions
Options
--full
Print extra information for each element
--help
Display this help and exit
software-package-delete
software-package-delete [options]
Delete software update packages
Options
--help
Display this help and exit
--package-name
Package name to delete (Required)
software-update-cancel
software-update-cancel [options]
Cancel software update task
Options
--help
Display this help and exit
--task-id
Task ID (Required)
software-update-status
software-update-status [options]
Monitor update status
Options
--full
Print extra information for each element
--help
Display this help and exit
--last
The number of last-started software updates to list
--task-id
Update task id
software-upload
software-upload [options]
Upload a software package with UPD format
Options
--help
Display this help and exit
--package-location
The path to the UPD software package (Required)
syslog-config
syslog-config [options]
Configure syslog servers
Options
--disable
Disable syslog event forwarding, clear syslog configuration. Required unless any of the following is specified: --enable, --view
--enable
Enable syslog event forwarding. Required unless any of the following is specified: --disable, --view
--help
Display this help and exit
--server
Syslog server configuration. A 3 or 4-tuple including <server>,<port>,<transport>,[<message types delimited by |>].
Server may be an IP address or a hostname (requires DNS).
Transport values may be tcp, udp, or relp.
Message types may be event and/or filesystem. When the relp transport is specified, only filesystem is allowed.
'event' causes system events to be forwarded to the remote syslog server.
'filesystem' causes filesystem access audit records to be forwarded.
When both are present, they are separated by a |.
The message type defaults to event|filesystem for udp and tcp, and filesystem for relp.
The entire --server param can be used multiple times.
--server 192.168.1.23,601,tcp
--server syslog-server.hostname,514,udp
--server 192.168.1.24,20514,relp,filesystem
--server 192.168.1.24,514,udp,event --server syslog-server.hostname,514,tcp,event|filesystem
--view
View syslog configuration. Required unless any of the following is specified: --enable, --disable
system-backup-config
system-backup-config [options]
Configure product configuration and metadata backups. Optionally create a backup now
Options
--async
Causes the command to be executed asynchronously. A reference task identifier will be returned
--help
Display this help and exit
--ip
IP address of the backup volume
--no-timeout
When running a task-based command synchronously, monitor for task completion indefinitely
--now
Create an immediate system backup of configuration and metadata (--ip and --path parameters are required if specified). Required unless any of the following is specified: --schedule-remove, --schedule-name, --view
--path
The NFS export path to the backup volume
--schedule-name
Name for the periodic backup schedule. Required unless any of the following is specified: --now, --schedule-remove, --view
--schedule-remove
Remove the scheduled backup configuration. Required unless any of the following is specified: --now, --schedule-name, --view
--view
View the system backup configuration. Required unless any of the following is specified: --now, --schedule-remove, --schedule-name
system-backup-list
system-backup-list [options]
List the names of the product configuration and metadata backups in the backup volume
Options
--help
Display this help and exit
--ip
IP address of the backup volume (Required)
--path
The NFS export path to the backup volume (Required)
system-backup-restore
system-backup-restore [options]
Restore product configuration and metadata backup
Options
--async
Causes the command to be executed asynchronously. A reference task identifier will be returned
--backup-name
The name of the backup. If not specified, the most recent backup is restored
--cluster-uuid
The UUID of the cluster that created the backup from which you would like to restore
--help
Display this help and exit
--ip
IP address of the backup volume (Required)
--no-timeout
When running a task-based command synchronously, monitor for task completion indefinitely
--path
The NFS export path to the backup volume (Required)
system-shutdown
system-shutdown [options]
Use this command to cleanly shut down all product nodes.
Options
--force
Confirm shutdown execution (Required)
--help
Display this help and exit
--reason
Shutdown reason
system-view
system-view [options]
Show an overview of the system
Options
--help
Display this help and exit
--timeout
A timeout in seconds to use when executing the command
task-cancel
task-cancel [options]
Attempt to cancel a task. If the task is HALTED, it will be restarted and the new task will be cancelled.
Options
--help
Display this help and exit
--id
The task ID
task-list
task-list [options]
List all running tasks in the system. The command can also be used to list completed tasks using the status filter, showing both successful and failed tasks. When no time-based filter is specified, tasks created over the past 31 days are returned.
Options
--created-after
List tasks that were created at or after (>=) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"
--created-before
List tasks that were created before (<) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"
--ended-after
List tasks that ended at or after (>=) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"
--ended-before
List tasks that ended before (<) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"
--full
Print extra information for each element
--help
Display this help and exit
--id
The task ID
--last-created
The number of last-created tasks to list
--name
The task name
--started-after
List tasks that started at or after (>=) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"
--started-before
List tasks that started before (<) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"
--status
Filter by the status of the task. Possible values: NONE | QUEUED | VALIDATING | VALIDATED | VALIDATION_FAILED | EXECUTING | CANCELLING | HALTED | RECOVERING | RESUMED | FAILED | CANCELLED | COMPLETED.
task-resume
task-resume [options]
Resume a task that is HALTED, or retry a task that is FAILED
Options
--help
Display this help and exit
--id
The task ID