Search the docs

System

cert-add

cert-add [options]

Add a certificate or certificate chain to the system’s trust store

Adds a certificate or CA to the Hammerspace trust store. By default, cert-add accepts only root CA certificates. You do not need to add the Hammerspace system root CA — it is generated and distributed automatically.

Options

--help

Display this help and exit

--pem

The certificate or certificate chain in PEM format (Required)

PEM-format certificate content to add. Accepts a multi-line, quoted PEM string.

--pem "<pem_content>"
--trust-intermediate-ca

Allow adding intermediate CA certificates to the trust store (defaults to only adding root CA certificates)

Adds an intermediate CA certificate (rather than a root CA).

--trust-self-signed-certificate

Allow adding self-signed non-CA certificates to the trust store (defaults to only adding root CA certificates)

Adds a self-signed, non-CA certificate (for example, a pinned server certificate).


cert-ca-list

cert-ca-list [options]

List the system root CA certificate(s)

Lists the Hammerspace-generated system root CA certificate(s). The active CA is used to sign all internal node certificates.

Options

--help

Display this help and exit

--role

List a specific CA by role. Possible values: SYSTEM_ACTIVE | SYSTEM_OLD.

Lists a specific CA by role. Valid values: SYSTEM_ACTIVE (the CA that signs node certificates and CSR-signed certificates) and SYSTEM_OLD (reserved for a CA that has been replaced; Hammerspace 5.3 provides no way to replace the system CA).


cert-csr-sign

cert-csr-sign [options]

Sign a certificate signing request (CSR) with the system root CA certificate

Signs a Certificate Signing Request (CSR) using the Hammerspace system CA and returns a signed certificate that a client can install. The certificate is valid for 365 days and supports client authentication (clientAuth) only, so it cannot be used by a storage server. Include at least one IP address in the CSR’s Subject Alternative Name (SAN) field: the command does not require it, but peers that check the certificate generally match against the SAN.

Options

--help

Display this help and exit

--pem

The certificate signing request in PEM format

PEM-format CSR content to sign. Accepts a multi-line, quoted PEM string.

--pem "<csr_pem_content>"
--track

Add the certificate to the system’s inventory of known certificates

Adds the signed certificate to the Hammerspace certificate inventory, where its expiration date is shown. Hammerspace does not alert you before the certificate expires. Recommended.


cert-list

cert-list [options]

List the known certificate(s)

Lists all certificates known to the system, including the system root CA and the per-node certificates signed by it.

Options

--full

Print extra information for each element

Displays detailed output, including validity dates and subject information.

--help

Display this help and exit

--id

The ID of the certificate to list

Retrieves a specific certificate by its ID.

--origin

List certificates that have this origin. Possible values: SYSTEM_CA | SYSTEM_ISSUED | CSR_SIGNED_BY_CA | UPLOADED_ROOT_CA | UPLOADED_INTERMEDIATE_CA | UPLOADED_PINNED_CERT.

Filters the list by how a certificate was added to the system. Valid values: SYSTEM_CA (the Hammerspace root CA), SYSTEM_ISSUED (the certificate issued to each Anvil and DSX node), CSR_SIGNED_BY_CA (certificates created by signing a CSR with the system CA), UPLOADED_ROOT_CA (an uploaded self-signed CA certificate), UPLOADED_INTERMEDIATE_CA (an uploaded intermediate CA certificate, added with --trust-intermediate-ca), and UPLOADED_PINNED_CERT (an uploaded self-signed certificate that is not a CA, added with --trust-self-signed-certificate).


cert-remove

cert-remove [options]

Remove a certificate from the system’s trust store

Removes an uploaded CA certificate or pinned certificate, or a certificate signed from a CSR, from the trust store. Retrieve the certificate ID with cert-list first. SYSTEM_CA and SYSTEM_ISSUED certificates are managed by Hammerspace and cannot be removed.

Options

--help

Display this help and exit

--id

The ID of the certificate to remove (Required)


cluster-config

cluster-config [options]

Update cluster configuration

Options

--async

Causes the command to be executed asynchronously. A reference task identifier will be returned

--gfs-participant-max-suspected-time

The amount of time any GFS participant may remain in a SUSPECTED operational state before that state automatically transitioned to DOWN. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, minutes are assumed

--help

Display this help and exit

--nfs-tls-forbidden

Disallow TLS for all external and internal NFS connections

--nfs-tls-required

Require TLS with mutual authentication for all external and internal NFS connections

--no-timeout

When running a task-based command synchronously, monitor for task completion indefinitely

--online-activation-support

Determines whether online license activation is allowed. Allowed values:[YES, NO]

--prometheus-exporters-disable

Disable Prometheus exporters

--prometheus-exporters-enable

Enable Prometheus exporters

--proxy-url

The URL of the HTTP proxy server (in the form http://a.b.c.d:pp)

--proxy-url-clear

Clear the HTTP proxy server configuration

--server-certificate-chain

An X.509 certificate, with an optional CA chain, in certificate PEM format that identifies the management server to the client

--server-certificate-reset

Reset the server to use an internally-generated self-signed certificate

--server-private-key

An unencrypted RSA private key in PKCS#1 or PKCS#8 PEM format that is paired with the server certificate in the server-certificate-chain bundle

--timezone

Specifies the timezone

--view

View the cluster configuration


dns-config

dns-config [options]

Configure DNS

Options

--force

Skip validation of new DNS server configuration

--help

Display this help and exit

--servers

Set DNS server(s)

--servers-clear

Clear DNS servers

--view

View the DNS configuration


dp-update

dp-update [options]

Update data portal

Options

--data-portal-id

The data portal UUID. Required unless any of the following is specified: --data-portal-type, --node-name

--data-portal-type

The data portal type. Required unless any of the following is specified: --data-portal-id, --node-name Possible values: SMB | NFS_V3 | NFS_V4_1 | S3.

--disable

Set the data portal admin state to DOWN

--enable

Set the data portal admin state to UP

--help

Display this help and exit

--node-name

The node name. Required unless any of the following is specified: --data-portal-type, --data-portal-id


email-config

email-config [options]

Add an SMTP gateway which will be used for events and call home through a mail server

Options

--connection-security

The type of connection security to use (default: NONE). Possible values: NONE | TLS | STARTTLS.

The connection security mode used for the SMTP connection. Choose the mode that matches what your mail server expects:

  • NONE — Connect without encryption.

  • TLS — Use implicit TLS. The connection is encrypted immediately on connect. Typically used with port 465.

  • STARTTLS — Connect unencrypted, then upgrade the connection to TLS using the STARTTLS command. Typically used with port 587.

--disable

Disable SMTP email

--enable

Enable SMTP email

--from-address

Source email address from which the events will be sent

--help

Display this help and exit

--host

SMTP host

--password

SMTP password

--port

SMTP port

--username

SMTP username

--view

View current configuration


event-list

event-list [options]

List events generated by the system

Options

--cleared

Include only cleared events

--from-date

List events after "from-date", in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"

--full

Print extra information for each element

--help

Display this help and exit

--id

The ID of the event to list

--last-emitted

The number of last-emitted events to list

--severity

List all events with severity greater than or equal to the given severity. Possible values: DEBUG | INFORMATIONAL | NOTICE | WARNING | ERROR | CRITICAL | ALERT | EMERGENCY.

--type

List all events of a given type.

Possible values

ACTUAL_ALLOCATED_CAPACITY_EXCEEDED | ADDED | ADD_FAILED | AD_CACHE_FLUSH_FAILED | AD_CACHE_FLUSH_SUCCESS | AD_COMPUTER_ISSUE | AD_DC_OUT_OF_TIME_SYNC | AD_SERVER_ISSUE | AD_WITHOUT_NTP | ALLOCATED_CAPACITY_APPROACHING_LIMIT | ALLOCATED_CAPACITY_EXCEEDED | ASSIMILATION_CANCELLED | ASSIMILATION_FAILED | ASSIMILATION_STOPPED | ASSIMILATION_SUCCESS | AUDIT | BACKUP_COMPLETED | BACKUP_CREATION_FAILED | BACKUP_FAILED | BACKUP_NOT_SCHEDULED | BORROWING_LICENSE_ABOUT_TO_EXPIRE | BORROWING_LICENSE_EXPIRED | CANCELLED | CAPACITY_HEARTBEAT_DISABLED | CAPACITY_THRESHOLD_PASSED | CLUSTER_DEGRADED | CLUSTER_FAILOVER | CLUSTER_MISCONFIGURED | CLUSTER_REPLICATION_EVENT | CLUSTER_SPLIT_BRAIN | COLLECTIONS_ENTER | COLLECTIONS_LEAVE | COMB_MIGRATION_INCOMPLETE | COMPONENT_MISSING | CREATED | CREATE_FAILED | CTDB_IN_RECOVERY | CTDB_NODES_FILE_SYNC_FAILED | CTDB_NODE_FAILURE | CTDB_NOT_RESPONDING | DATA_COPY_TO_OBJECT_FAILED | DATA_COPY_TO_OBJECT_SUCCESS | DATA_REPLICATION_ISSUE | DD_CLUSTER_PLANNED_SHUTDOWN | DD_CLUSTER_PLANNED_SHUTDOWN_FAILED | DELETED | DELETE_FAILED | DISK_USAGE_LIMIT_EXCEEDED | DISK_USAGE_LIMIT_WARNING | DNS_ISSUE | ECGROUP_ARRAY | ECGROUP_MOUNTPOINT | ECGROUP_STORAGE | EVAL_ABOUT_TO_EXPIRE | EVAL_EXPIRED | EXPIRED_LICENSE_IN_GRACE | FAILURE_REPORTING_LICENSED_USAGE | GFS_PARTICIPANT_ADDED | GFS_PARTICIPANT_ADD_FAILED | GFS_PARTICIPANT_OPER_STATE_CHANGED | GFS_PARTICIPANT_REMOVED | GFS_PARTICIPANT_REMOVE_FAILED | HW_DRIVE_FAILED | HW_FAN_FAILED | HW_FRU_EVENT | HW_NIC_LINK_EVENT | HW_PSU_FAILED | HW_RAID_EVENT | IDMAPD_SYNC_ISSUE | INDEXING_SENT | INVALID_ADDITIONAL_ADDRESS | INVALID_COMB_STRUCTURE | KERBEROS_CLUSTER_UNHEALTHY | KERBEROS_REQUIRED_NFS_SPNS_MISSING | KERBEROS_SHARE_WITH_NO_NFS_SPNS | KERBEROS_SHARE_WITH_UNJOINED_AD | KERBEROS_SYNC_FAILURE | KERBEROS_USER_MAPPING_NONFUNCTIONAL | KEYTAB_MISMATCH | KMS_OPERATION_CHECK_FAILED | LICENSE_ABOUT_TO_ENTER_GRACE | LICENSE_ABOUT_TO_EXPIRE | LICENSE_ACTIVATED | LICENSE_ACTIVATION_FAILED | LICENSE_EXPIRED | LICENSE_IN_GRACE_ABOUT_TO_EXPIRE | LICENSE_STATE_CHANGED | LICENSING_MISCONFIGURED | METADATA_REPLICATION_ISSUE | METERED_LICENSE_IN_GRACE | METRIC_COLLECTION_DEGRADED | MGMT_GENERIC_EVENT | MGMT_STARTED | MGMT_STARTED_FROM_RESTORE | MISSING_CLOUD_MOVER | MISSING_COMB_STRUCTURE | MISSING_DATA_MOVER | MISSING_SHARED_OBJECT_STORAGE_VOLUME | MISSING_STORAGE_VOLUME | MODELER_SHARE_SWEEP_COMPLETED | MOVER_AT_CAPACITY | MOVER_BAD_IP | MOVER_CONNECTED | MOVER_DROPPED | MOVER_UNKNOWN | NAME_SERVICE_UNHEALTHY | NETWORK_LDAP_UNREACHABLE | NETWORK_NTP_UNREACHABLE | NFS_LAYOUT_ERROR_ACCESS | NFS_LAYOUT_ERROR_IO | NFS_LAYOUT_ERROR_NXIO | NFS_LAYOUT_ERROR_STALE | NFS_TLS_CONFIGURATION_UNHEALTHY | NODE_MODE_ISSUE | NONE | NO_AVAILABLE_STORAGE_ON_NODE | NO_REGISTERED_MOVER | NO_REGISTERED_STORAGE_VOLUME | NTP_NOT_SYNCHRONIZED | NVMEOF_PATH_DEGRADED | NVMEOF_PATH_LOST | OBJECT_VOLUME_GC_BLOCKED | OBJECT_VOLUME_GC_CANCELLED | OBJECT_VOLUME_GC_COMPLETED | OBJECT_VOLUME_GC_FAILED | OBJECT_VOLUME_IO_TEST_ALL_FAILED | OBJECT_VOLUME_IO_TEST_FAILED | OBJECT_VOLUME_RESERVATION_OLD | OSV_CSP_CONN_FAILED | OSV_HMDB_CLOUD_DELETES_FAILING | OSV_HMDB_DEGRADED_BLOOM_FILTER_ALLOCATED | OSV_HMDB_INSUFFICIENT_GC_MEMORY | OSV_HMDB_REPLICATION_OUT_OF_SYNC | OSV_QUORUM_IN_FLUX | OSV_SITE_TO_SITE_CONN_FAILED | OVER_CAPACITY_GRACE_ABOUT_TO_EXPIRE | OVER_CAPACITY_LICENSE_VIOLATION | PDDM_EXITED | PDDM_KILLED_DI | PDDM_RESTART | PKI_CA_CREATION_FAILED | PKI_NODE_CERT_CREATION_FAILED | PKI_NODE_CERT_SYNC_FAILED | PKI_NODE_CHECK_FAILED | PKI_TRUST_SYNC_FAILED | PORTAL_EXPORT_FAILED | PORTAL_FLOATING_IP_SYNC_FAILED | PORTAL_UNEXPORT_FAILED | PROMETHEUS_DEGRADED | QUORUM_DEVICE_CONFIGURED | QUORUM_DEVICE_UNCONFIGURED | QUORUM_DEVICE_UNHEALTHY | READ_LATENCY_THRESHOLD_CROSSED | REMOVED | REMOVE_FAILED | REPLICATION_CLOCK_OUT_OF_SYNC | REPLICATION_LATENCY_THRESHOLD_EXCEEDED | REPLICATION_PORT_CHECK_FAILED | REPLICATION_WITHOUT_NTP | S3_MULTIPART_UPLOAD_ABORTED | S3_SERVICE_RELOADED | S3_SERVICE_RELOAD_ERROR | SALT_NOT_FUNCTIONAL | SERVICE_OPER_STATE_ISSUE | SHARE_CLONED | SHARE_CLONE_FAILED | SHARE_EVENTS_PROCESSED | SHARE_EVENTS_PROCESSING | SHARE_EVENT_PROCESSING_BLOCKED | SHARE_PRUNING | SHARE_PRUNING_BLOCKED | SHARE_QUOTA_EXCEEDED | SHARE_QUOTA_WARNING | SHARE_RESTORED | SHARE_RESTORE_FAILED | SHARE_SNAPSHOT_CREATED | SHARE_SNAPSHOT_CREATE_FAILED | SHARE_SNAPSHOT_DELETED | SHARE_SNAPSHOT_DELETE_FAILED | SOFTWARE_UPDATE_FAILED | SOFTWARE_UPDATE_STARTED | SOFTWARE_UPDATE_SUCCESS | SOFTWARE_VERSION_CHANGED | SSSD_CONFIG_SYNC_FAILED | SUPPORT_CALL_HOME_EVENT | SYSTEM | UPDATED | UPDATE_FAILED | USER_PASSWORD_CHANGED | VASA_VAAI_PROVIDER_EVENT | VOLUME_ASSIMILATION_EVENT | VOLUME_CLONE_TEST_FAILED | VOLUME_CONFIG_TEST_ALL_FAILED | VOLUME_CONFIG_TEST_FAILED | VOLUME_DECOMMISSION_EVENT | VOLUME_EVICTION_FAILED | VOLUME_STATE_CHANGED | WRITE_LATENCY_THRESHOLD_CROSSED

--uncleared

Include only uncleared events

--until-date

List events before "until-date", in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"


event-update

event-update [options]

Clear events generated by the system

Options

--all

Clear all events. Required unless any of the following is specified: --type, --created-before, --created-after, --id

--clear

Clear events (Required)

--created-after

Clear events after "created-after", in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30". Required unless any of the following is specified: --type, --all, --created-before, --id

--created-before

Clear events before "created-before", in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30". Required unless any of the following is specified: --type, --all, --created-after, --id

--help

Display this help and exit

--id

The ID of the event to clear. Required unless any of the following is specified: --type, --all, --created-before, --created-after

--type

Clear all events of a given type. Required unless any of the following is specified: --all, --created-before, --created-after, --id

Possible values

ACTUAL_ALLOCATED_CAPACITY_EXCEEDED | ADDED | ADD_FAILED | AD_CACHE_FLUSH_FAILED | AD_CACHE_FLUSH_SUCCESS | AD_COMPUTER_ISSUE | AD_DC_OUT_OF_TIME_SYNC | AD_SERVER_ISSUE | AD_WITHOUT_NTP | ALLOCATED_CAPACITY_APPROACHING_LIMIT | ALLOCATED_CAPACITY_EXCEEDED | ASSIMILATION_CANCELLED | ASSIMILATION_FAILED | ASSIMILATION_STOPPED | ASSIMILATION_SUCCESS | AUDIT | BACKUP_COMPLETED | BACKUP_CREATION_FAILED | BACKUP_FAILED | BACKUP_NOT_SCHEDULED | BORROWING_LICENSE_ABOUT_TO_EXPIRE | BORROWING_LICENSE_EXPIRED | CANCELLED | CAPACITY_HEARTBEAT_DISABLED | CAPACITY_THRESHOLD_PASSED | CLUSTER_DEGRADED | CLUSTER_FAILOVER | CLUSTER_MISCONFIGURED | CLUSTER_REPLICATION_EVENT | CLUSTER_SPLIT_BRAIN | COLLECTIONS_ENTER | COLLECTIONS_LEAVE | COMB_MIGRATION_INCOMPLETE | COMPONENT_MISSING | CREATED | CREATE_FAILED | CTDB_IN_RECOVERY | CTDB_NODES_FILE_SYNC_FAILED | CTDB_NODE_FAILURE | CTDB_NOT_RESPONDING | DATA_COPY_TO_OBJECT_FAILED | DATA_COPY_TO_OBJECT_SUCCESS | DATA_REPLICATION_ISSUE | DD_CLUSTER_PLANNED_SHUTDOWN | DD_CLUSTER_PLANNED_SHUTDOWN_FAILED | DELETED | DELETE_FAILED | DISK_USAGE_LIMIT_EXCEEDED | DISK_USAGE_LIMIT_WARNING | DNS_ISSUE | ECGROUP_ARRAY | ECGROUP_MOUNTPOINT | ECGROUP_STORAGE | EVAL_ABOUT_TO_EXPIRE | EVAL_EXPIRED | EXPIRED_LICENSE_IN_GRACE | FAILURE_REPORTING_LICENSED_USAGE | GFS_PARTICIPANT_ADDED | GFS_PARTICIPANT_ADD_FAILED | GFS_PARTICIPANT_OPER_STATE_CHANGED | GFS_PARTICIPANT_REMOVED | GFS_PARTICIPANT_REMOVE_FAILED | HW_DRIVE_FAILED | HW_FAN_FAILED | HW_FRU_EVENT | HW_NIC_LINK_EVENT | HW_PSU_FAILED | HW_RAID_EVENT | IDMAPD_SYNC_ISSUE | INDEXING_SENT | INVALID_ADDITIONAL_ADDRESS | INVALID_COMB_STRUCTURE | KERBEROS_CLUSTER_UNHEALTHY | KERBEROS_REQUIRED_NFS_SPNS_MISSING | KERBEROS_SHARE_WITH_NO_NFS_SPNS | KERBEROS_SHARE_WITH_UNJOINED_AD | KERBEROS_SYNC_FAILURE | KERBEROS_USER_MAPPING_NONFUNCTIONAL | KEYTAB_MISMATCH | KMS_OPERATION_CHECK_FAILED | LICENSE_ABOUT_TO_ENTER_GRACE | LICENSE_ABOUT_TO_EXPIRE | LICENSE_ACTIVATED | LICENSE_ACTIVATION_FAILED | LICENSE_EXPIRED | LICENSE_IN_GRACE_ABOUT_TO_EXPIRE | LICENSE_STATE_CHANGED | LICENSING_MISCONFIGURED | METADATA_REPLICATION_ISSUE | METERED_LICENSE_IN_GRACE | METRIC_COLLECTION_DEGRADED | MGMT_GENERIC_EVENT | MGMT_STARTED | MGMT_STARTED_FROM_RESTORE | MISSING_CLOUD_MOVER | MISSING_COMB_STRUCTURE | MISSING_DATA_MOVER | MISSING_SHARED_OBJECT_STORAGE_VOLUME | MISSING_STORAGE_VOLUME | MODELER_SHARE_SWEEP_COMPLETED | MOVER_AT_CAPACITY | MOVER_BAD_IP | MOVER_CONNECTED | MOVER_DROPPED | MOVER_UNKNOWN | NAME_SERVICE_UNHEALTHY | NETWORK_LDAP_UNREACHABLE | NETWORK_NTP_UNREACHABLE | NFS_LAYOUT_ERROR_ACCESS | NFS_LAYOUT_ERROR_IO | NFS_LAYOUT_ERROR_NXIO | NFS_LAYOUT_ERROR_STALE | NFS_TLS_CONFIGURATION_UNHEALTHY | NODE_MODE_ISSUE | NONE | NO_AVAILABLE_STORAGE_ON_NODE | NO_REGISTERED_MOVER | NO_REGISTERED_STORAGE_VOLUME | NTP_NOT_SYNCHRONIZED | NVMEOF_PATH_DEGRADED | NVMEOF_PATH_LOST | OBJECT_VOLUME_GC_BLOCKED | OBJECT_VOLUME_GC_CANCELLED | OBJECT_VOLUME_GC_COMPLETED | OBJECT_VOLUME_GC_FAILED | OBJECT_VOLUME_IO_TEST_ALL_FAILED | OBJECT_VOLUME_IO_TEST_FAILED | OBJECT_VOLUME_RESERVATION_OLD | OSV_CSP_CONN_FAILED | OSV_HMDB_CLOUD_DELETES_FAILING | OSV_HMDB_DEGRADED_BLOOM_FILTER_ALLOCATED | OSV_HMDB_INSUFFICIENT_GC_MEMORY | OSV_HMDB_REPLICATION_OUT_OF_SYNC | OSV_QUORUM_IN_FLUX | OSV_SITE_TO_SITE_CONN_FAILED | OVER_CAPACITY_GRACE_ABOUT_TO_EXPIRE | OVER_CAPACITY_LICENSE_VIOLATION | PDDM_EXITED | PDDM_KILLED_DI | PDDM_RESTART | PKI_CA_CREATION_FAILED | PKI_NODE_CERT_CREATION_FAILED | PKI_NODE_CERT_SYNC_FAILED | PKI_NODE_CHECK_FAILED | PKI_TRUST_SYNC_FAILED | PORTAL_EXPORT_FAILED | PORTAL_FLOATING_IP_SYNC_FAILED | PORTAL_UNEXPORT_FAILED | PROMETHEUS_DEGRADED | QUORUM_DEVICE_CONFIGURED | QUORUM_DEVICE_UNCONFIGURED | QUORUM_DEVICE_UNHEALTHY | READ_LATENCY_THRESHOLD_CROSSED | REMOVED | REMOVE_FAILED | REPLICATION_CLOCK_OUT_OF_SYNC | REPLICATION_LATENCY_THRESHOLD_EXCEEDED | REPLICATION_PORT_CHECK_FAILED | REPLICATION_WITHOUT_NTP | S3_MULTIPART_UPLOAD_ABORTED | S3_SERVICE_RELOADED | S3_SERVICE_RELOAD_ERROR | SALT_NOT_FUNCTIONAL | SERVICE_OPER_STATE_ISSUE | SHARE_CLONED | SHARE_CLONE_FAILED | SHARE_EVENTS_PROCESSED | SHARE_EVENTS_PROCESSING | SHARE_EVENT_PROCESSING_BLOCKED | SHARE_PRUNING | SHARE_PRUNING_BLOCKED | SHARE_QUOTA_EXCEEDED | SHARE_QUOTA_WARNING | SHARE_RESTORED | SHARE_RESTORE_FAILED | SHARE_SNAPSHOT_CREATED | SHARE_SNAPSHOT_CREATE_FAILED | SHARE_SNAPSHOT_DELETED | SHARE_SNAPSHOT_DELETE_FAILED | SOFTWARE_UPDATE_FAILED | SOFTWARE_UPDATE_STARTED | SOFTWARE_UPDATE_SUCCESS | SOFTWARE_VERSION_CHANGED | SSSD_CONFIG_SYNC_FAILED | SUPPORT_CALL_HOME_EVENT | SYSTEM | UPDATED | UPDATE_FAILED | USER_PASSWORD_CHANGED | VASA_VAAI_PROVIDER_EVENT | VOLUME_ASSIMILATION_EVENT | VOLUME_CLONE_TEST_FAILED | VOLUME_CONFIG_TEST_ALL_FAILED | VOLUME_CONFIG_TEST_FAILED | VOLUME_DECOMMISSION_EVENT | VOLUME_EVICTION_FAILED | VOLUME_STATE_CHANGED | WRITE_LATENCY_THRESHOLD_CROSSED


heartbeat-list

heartbeat-list [options]

List the configured heartbeats

Options

--help

Display this help and exit


heartbeat-send

heartbeat-send [options]

Sends the specified heartbeat type to support

Options

--help

Display this help and exit

--id

The ID of the heartbeat to send. Required unless any of the following is specified: --type, --name

--name

The name of the heartbeat to send. Required unless any of the following is specified: --type, --id

--type

The type of the heartbeat to send. Required unless any of the following is specified: --name, --id Possible values: HEALTH | CAPACITY.


heartbeat-update

heartbeat-update [options]

Update the heartbeat configuration

Options

--disable

Disables periodic heartbeat sending. Required unless any of the following is specified: --enable, --interval

--enable

Enables periodic heartbeat sending. Required unless any of the following is specified: --disable, --interval

--help

Display this help and exit

--id

The ID of the heartbeat configuration to be updated. Required unless any of the following is specified: --type, --name

--interval

Periodic heartbeat sending interval (default units: seconds, otherwise specify units, e.g. "5 minutes"). Required unless any of the following is specified: --enable, --disable

--name

The name of the heartbeat configuration to be updated. Required unless any of the following is specified: --type, --id

--type

The type of the heartbeat configuration to be updated. Required unless any of the following is specified: --name, --id Possible values: HEALTH | CAPACITY.


identity-group-mapping-create

identity-group-mapping-create [options]

Map a federated user’s group to an internal Role. For example, map the members of a particular Active Directory group to the admin Role

Options

--group

Name of the group to map to the internal role (Required)

--help

Display this help and exit

--mgmt-role-id

The ID of an internal role. Required unless "--mgmt-role-name" is specified

--mgmt-role-name

The name of an internal role. Required unless "--mgmt-role-id" is specified

--name

A name for the group to role mapping. If missing, group::role is used. (Required)


identity-group-mapping-delete

identity-group-mapping-delete [options]

Delete an identity group mapping

Options

--help

Display this help and exit

--id

The ID of the identity group mapping to delete. Required unless "--name" is specified

--name

The name of the identity group mapping to delete. Required unless "--id" is specified


identity-group-mapping-list

identity-group-mapping-list [options]

List the identity group mappings

Options

--full

Print extra information for each element

--help

Display this help and exit

--id

List a specific identity group mapping by ID

--name

List a specific identity group mapping by name


identity-group-mapping-update

identity-group-mapping-update [options]

Update an identity group mapping

Options

--group

The name of a new identity group to associate with the role

--help

Display this help and exit

--id

The ID of the identity group mapping to update. Required unless "--name" is specified

--mgmt-role-id

The ID the role to associate with the identity group

--mgmt-role-name

The name the role to associate with the identity group

--name

The name of the identity group mapping to update. Required unless "--id" is specified


idp-add

idp-add [options]

Add an Identity Provider (IdP) such as Active Directory for purposes of federated authentication and authorization. See also the identity-group-mapping commands

Options

--connect-timeout

The amount of time to wait for the system to connect to the IdP. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, seconds are assumed

--connection-security

The type of connection security to use (default: NONE). Possible values: NONE | TLS | STARTTLS.

The connection security mode used for the LDAP connection to the identity provider. NONE connects in cleartext (normally port 389). TLS uses LDAPS, negotiating TLS immediately on connect (normally port 636). STARTTLS connects in cleartext and then upgrades the connection in place with the STARTTLS command. SSL is accepted as a synonym for TLS.

--domain

The name of an IdP domain. When adding an AD IdP, this specifies the AD domain (Required)

--follow-referrals

Instructs the system to follow referrals when resolving usernames. Typically, only required when there are cross-domain memberships

--help

Display this help and exit

--name

The name of this IdP (Required)

--read-timeout

The amount of time to wait for the system to read from the IdP. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, seconds are assumed

--servers

A comma-separated list of fully-qualified domain names or IP addresses, optionally followed by a colon-separated TCP port. The list may not contain spaces.

--servers server1.example.com
--servers server1.example.com,server2.example.com
--servers 127.0.0.5:8389

(Required)

A comma-separated list of fully-qualified domain names or IP addresses. The list may not contain spaces. To use a non-standard port, append it to a server entry, for example dc1.example.com:636

--type

The type of IdP being added. Possible values: AD.

--validate-server-certs-enable

Enable validation of server certificates for SSL/TLS connections.

Enable validation of the identity provider’s server certificate. Applies when --connection-security is TLS or STARTTLS. Before enabling validation, install the issuing CA (and any intermediates) so Hammerspace trusts the server certificate, from the GUI under Administration  TLS  Trusted Certificates or with cert-add; otherwise logins fail during the TLS handshake.

If you omit this option, certificate validation is disabled. idp-add has no option to disable validation; to turn validation off after enabling it, use idp-update --validate-server-certs-disable.


idp-list

idp-list [options]

List the federated Identity Providers (IdPs)

Options

--full

Print extra information for each element

--help

Display this help and exit

--id

List a specific IdP by ID

--name

List a specific IdP by name


idp-remove

idp-remove [options]

Remove a federated Identity Provider (IdP)

Options

--help

Display this help and exit

--id

The ID of the IdP to remove. Required unless "--name" is specified

--name

The name of the IdP to remove. Required unless "--id" is specified


idp-update

idp-update [options]

Update a federated Identity Provider (IdP)

Options

--connect-timeout

The amount of time to wait for the system to connect to the IdP. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, seconds are assumed

--connection-security

The type of connection security to use. Possible values: NONE | TLS | STARTTLS.

--domain

A domain name

--follow-referrals

Instructs the system to follow referrals when resolving usernames. Typically, only required when there are cross-domain memberships

--help

Display this help and exit

--id

The ID of the IdP to update. Required unless "--name" is specified

--ignore-referrals

Instructs the system to not follow referrals when resolving usernames

--name

The name of the IdP to update. Required unless "--id" is specified

--read-timeout

The amount of time to wait for the system to read from the IdP. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, seconds are assumed

--servers

A comma-separated list of fully-qualified domain names or IP addresses, optionally followed by a colon-separated TCP port. The list may not contain spaces.

--servers server1.example.com
--servers server1.example.com,server2.example.com
--servers 127.0.0.5:8389
--validate-server-certs-disable

Disable validation of server certificates for SSL/TLS connections.

--validate-server-certs-enable

Enable validation of server certificates for SSL/TLS connections.


kms-add

kms-add [options]

Add a key management system (KMS)

Options

--access-id

Authentication username (* required for AWS_KMS)

--client-certificate

An X.509 certificate in certificate PEM format that identifies the client to the server (* required for NCIPHER_WSOP)

--client-private-key

An RSA private key in PKCS#1 or PKCS#8 PEM format that is paired with the client-certificate (* required for NCIPHER_WSOP)

--comment

Any comment to be associated with the KMS

--endpoint

The endpoint (URI or host:port) of the KMS (* required for and exclusive to NCIPHER_WSOP)

--help

Display this help and exit

--key-id

The key identifier to use with the KMS (* required for AWS_KMS and NCIPHER_WSOP)

--name

A name for the KMS (Required)

--passphrase

The passphrase (* required for and exclusive to PASSPHRASE). If not specified, it will be prompted for.

--secret

Authentication password (* required for AWS_KMS)

--server-certificate-chain

An X.509 certificate, with optional CA chain, in certificate PEM format that identifies the KMS server to the client (* required for and exclusive to NCIPHER_WSOP)

--type

The type of KMS system being added. Possible values: NCIPHER_WSOP | AWS_KMS | PASSPHRASE. (Required)


kms-list

kms-list [options]

List the key management systems (KMS)s

Options

--full

Print extra information for each element

--help

Display this help and exit

--id

The ID of the KMS to list

--internal-id

The internal ID of the KMS to list

--name

The name of the KMS to list


kms-remove

kms-remove [options]

Remove a key management system

Options

--force

Force the removal of a KMS, even if object storage volumes exist

--help

Display this help and exit

--id

The ID of the KMS to remove. Required unless any of the following is specified: --internal-id, --name

--internal-id

The internal ID of the KMS to remove. Required unless any of the following is specified: --name, --id

--name

The name of the KMS to remove. Required unless any of the following is specified: --internal-id, --id


kms-update

kms-update [options]

Update a key management system (KMS)

Options

--access-id

Authentication username (exclusive to AWS_KMS)

--add-passphrase

Prompt for a new passphrase for the PASSPHRASE KMS

--client-certificate

An X.509 certificate in Base64-encoded PEM format (with the BEGIN and END tags) that identifies the client to the server (exclusive to NCIPHER_WSOP)

--client-private-key

An RSA private key in Base64-encoded PEM format (with the BEGIN and END tags) that is paired with the client-certificate (exclusive to NCIPHER_WSOP)

--comment

Any comment to be associated with the KMS

--endpoint

The endpoint (URI or host:port) of the NCIPHER_WSOP KMS

--help

Display this help and exit

--id

The ID of the KMS to update. Required unless any of the following is specified: --internal-id, --name

--internal-id

The internal ID of the KMS to update. Required unless any of the following is specified: --name, --id

--key-id

The key identifier to use with the KMS

--name

The name of the KMS to update. Required unless any of the following is specified: --internal-id, --id

--new-name

A new name for the KMS

--passphrase

A new passphrase for the PASSPHRASE KMS

--secret

Authentication password (exclusive to AWS_KMS)

--server-certificate-chain

An X.509 certificate with optional CA chain in Base64-encoded PEM format (with the BEGIN and END tags) that identifies the NCIPHER_WSOP KMS server to the client


local-site-config

local-site-config [options]

Update information for the local site.

Options

--data-center

The name of the data center location of the site

--data-center-clear

Clears the data center location

--geo-coordinates

Alternate specification of the location in <latitude>,<longitude> format

--geo-coordinates-clear

Clears both the latitude and longitude

--help

Display this help and exit

--latitude

The latitude (-90.0 to 90.0) of the site

--latitude-clear

Clears the latitude

--longitude

The longitude (-180.0 to 180.0) of the site

--longitude-clear

Clears the longitude

--name

The new name of the local site

--override-data-address

An address which overrides the site’s data address. When specified, this address will be used as the effective data address advertised to other sites. When not specified, the cluster’s data address will be used as the effective address

--override-data-address-clear

Clears the override-data-address

--override-mgmt-address

An address which overrides the site’s mgmt address. When specified, this address will be used as the effective mgmt address advertised to other sites. When not specified, the cluster’s mgmt address will be used as the effective address

--override-mgmt-address-clear

Clears the override-mgmt-address

--plus-code

Alternate specification of the location in Plus Code format

--view

View the local site


license-add

license-add [options]

Add and activate a license

Options

--activation-id

The license activation ID

--async

Causes the command to be executed asynchronously. A reference task identifier will be returned

--capacity

Number of 1TB units of storage capacity to allocate to this license. Only applicable with capacity-based licenses

--help

Display this help and exit

--license-server-ip

A management IP of a metered license server

--license-server-password

The password for the user named by the license-server-username parameter

--license-server-username

A user who has administrative rights on the metered license server

--no-timeout

When running a task-based command synchronously, monitor for task completion indefinitely

--type

The type of license to add. Possible values: NODE | FILE_CAPACITY | OBJECT_CAPACITY | METERED. (Required)


license-list

license-list [options]

List all licenses

Options

--activation-id

The activation ID of the license to list

--help

Display this help and exit


license-offline-add

license-offline-add [options]

Add and activate a license via an offline process. A request file is generated and obtained via one of the export parameters. The request file is then exchanged for a response file by the license administrator or at the license portal. The response file is then uploaded to complete the process.

Options

--activation-id

The license activation ID (Required)

--capacity

Number of 1TB units of storage capacity to allocate to this license. Only applicable with capacity-based licenses

--export-uri

Causes an activation request to be copied to an ftp, scp, or mailto location. Examples: ftp://example.com/uploads, scp://example.com/uploads, mailTo:john.doe@example.com. Required unless "--import-uri" is specified

--help

Display this help and exit

--import-uri

The location of the activation response file to be uploaded which will complete the offline license add process. Examples: ftp://example.com/uploads/capabilityResponse.bin, scp://example.com/uploads/capabilityResponse.bin. Required unless any of the following is specified: --export-uri, --type

--type

The type of license to add. Required unless "--import-uri" is specified. Possible values: NODE | FILE_CAPACITY | OBJECT_CAPACITY.


license-offline-cancel

license-offline-cancel [options]

Cancel a pending offline license operation for a given activation ID. If the initial request has already been uploaded to the license server, use the appropriate license-offline command to complete the operation.

Options

--activation-id

The license activation ID associated with the pending offline request (Required)

--help

Display this help and exit


license-offline-remove

license-offline-remove [options]

Deactivate and remove a license via an offline process. A request file is generated and obtained via one of the export parameters. The request file is then exchanged for a response file by the license administrator or at the license portal. The response file is then uploaded to complete the update process.

Options

--activation-id

The license activation ID (Required)

--export-uri

Causes a remove request file to be copied to an ftp, scp, or mailto location. Examples: ftp://example.com/uploads, scp://example.com/uploads, mailTo:john.doe@example.com. Required unless "--import-uri" is specified

--help

Display this help and exit

--import-uri

The location of the activation response file to be uploaded which will complete the offline license add process. Examples: ftp://example.com/uploads/capabilityResponse.bin, scp://example.com/uploads/capabilityResponse.bin. Required unless "--export-uri" is specified


license-offline-update

license-offline-update [options]

Update a license via an offline process. This supports administrative changes that do not affect capacity, such as expiration date extensions. A request file is generated and obtained via one of the export parameters. The request file is then exchanged for a response file by the license administrator or at the license portal. The response file is then uploaded to complete the update process.

Options

--activation-id

The license activation ID (Required)

--capacity

New number of 1TB units of storage capacity to allocate to this license

--export-uri

Causes an update request file to be copied to an ftp, scp, or mailto location. Examples: ftp://example.com/uploads, scp://example.com/uploads, mailTo:john.doe@example.com. Required unless "--import-uri" is specified

--help

Display this help and exit

--import-uri

The location of the activation response file to be uploaded which will complete the offline license add process. Examples: ftp://example.com/uploads/capabilityResponse.bin, scp://example.com/uploads/capabilityResponse.bin. Required unless "--export-uri" is specified


license-remove

license-remove [options]

Deactivate and remove a license

Options

--activation-id

The license activation ID (Required)

--async

Causes the command to be executed asynchronously. A reference task identifier will be returned

--force

When license-remove is invoked from the licensed client, the presence of the force parameter will cause the license to be removed from the client even if the license server can not be reached. When invoked from the license server, the force parameter is required and will cause the license server’s record of the license to be deleted.

--help

Display this help and exit

--no-timeout

When running a task-based command synchronously, monitor for task completion indefinitely


license-update

license-update [options]

Update the allocated capacity for a capacity-based license

Options

--activation-id

The license activation ID (Required)

--async

Causes the command to be executed asynchronously. A reference task identifier will be returned

--capacity

New number of 1TB units of storage capacity to allocate to this license

--help

Display this help and exit

--license-server-ip

For a metered license, update the IP of server to which usage reporting is sent. The IP must identify the license server which originally granted the client license.

--no-timeout

When running a task-based command synchronously, monitor for task completion indefinitely


metric-list

metric-list [options]

List metrics

Options

--field

Field names in the format: <table-name>.<column-name> (e.g., network.bytesSent) (Required)

--from-date

Shows metrics after date "from-date" (default: now - 1h)

--func

Computational aggregate function. Possible values: MIN | MAX | MEAN | MEDIAN.

--group-by

Time grouping interval. For example, 60s (seconds), 60m (minutes), 24h (hours), 7d (days), 52w (weeks)

--help

Display this help and exit

--limit

Total number of samples per column (default: 1000)

--name

Name criteria on the metrics

--object-type

Object type criteria on the metrics

--until-date

Shows metrics before date "until-date"

--uuid

Shows metrics on an object with the specified UUID


name-service-config

name-service-config [options]

Manage configured Name Services

Configures and manages LDAP name services used for user and group resolution on the NFS data path. When called without an operation flag, name-service-config defaults to --list. Operations (--add, --list, --update, --remove, --resolution-order, --resolve-user, --resolve-group, --resolve-user-groups, --test-connect) cannot be combined in one command.

Options

--add

Add a new LDAP Name Service

--address

The network address of the LDAP server in the form <host>[:port]. Host can be an IP address or a DNS name. Port is optional. Can be repeated. Required when adding, optional for update

IP address or DNS hostname of the LDAP server, with an optional :port suffix (1–65535). Required for --add, optional for --update. If the port is omitted, the connection test tries port 389 and then 636; a port is required if --no-connection-test is used. Repeat --address once per server; do not separate addresses with commas. On --update, the addresses given replace all existing addresses. More than one address works only with --no-connection-test, --transport-mode, and a port on every address.

--bind-clear

Clear both the Bind Distinguished Name (Bind DN) and the Bind Secret/password

Removes the Bind DN and Bind Secret from the name service. Used with --update.

--bind-dn

The Bind Distinguished Name used to authenticate and search the directory. Example: cn=search-user,ou=people,dc=example,dc=com

Bind distinguished name for authenticated access. Must be used with --bind-secret. On --add, a plain account name is expanded to cn=<name>,<domain in dc= form>; on --update, give a full DN.

--bind-secret

The Bind Secret/password of the LDAP user described by the Bind Distinguished Name (Bind DN)

Password for the Bind DN. Must be used with --bind-dn when adding a name service; on --update, give it alone to change only the secret. The CLI does not prompt for the secret; it is given on the command line. In 5.3, --bind-secret is also required on every --update of a name service that has a Bind DN, except with --bind-clear.

--domain

The domain name of the LDAP Name Service. Optional: the management name will be used if not provided. Add only

Domain name (for example, corp.example.com). If omitted on --add, the --name value is used as the domain name and must be a valid domain name. Must be unique (case-insensitive) and is immutable after creation. The LDAP server must serve a naming context for the domain (dc=corp,dc=example,dc=com).

--help

Display this help and exit

--id

The ID (UUID) of the Name Service

UUID of the name service. Valid on --list, --update, and --remove. Illegal on --add.

--internal-id

The internal ID of the Name Service

Integer ID of the name service. Valid on --list, --update, and --remove. Illegal on --add.

--list

List configured Name Services

Lists all configured name services in resolution order.

--name

The management name of the Name Service

Management name of the name service. Maximum 255 characters; must be unique (case-insensitive). Required for --add; optional for --list, --update, and --remove.

--new-name

The new management name of the LDAP Name Service. Update only

--no-connection-test

Skip the pre-add or pre-update connectivity validation test

Skips the connection test. Requires --transport-mode and a port in each --address value. On --update, the connection test runs only when the addresses, ports, transport mode, or search base change, even without this option.

--remove

Remove a configured LDAP Name Service

--resolution-order

A comma-separated list of Name Service identifiers (names, UUIDs, or internal IDs)
describing the order in which they will be used for name resolution.
Any configured Name Services not provided will be sorted to the end of the list in indeterminate order

Reorders existing name services. Provide a comma-separated list of names, UUIDs, or internal IDs (all identifiers must be of the same type). Any name service whose identifier is not listed is sorted to the end with no guaranteed order.

--resolve-group

Supply a group name to test how Hammerspace resolves it. Can be qualified or unqualified

Looks up a group. Uses the same qualified/unqualified domain behavior as --resolve-user.

--resolve-user

Supply a username to test how Hammerspace resolves it. Can be qualified or unqualified

Looks up a user against configured name services via SSSD. Unqualified names (for example, jsmith) are looked up in every configured domain, with a result for each domain; qualified names (for example, jsmith@corp.example.com) are looked up only in the specified domain, and a domain that is not configured returns an error.

--resolve-user-groups

Supply a username to test how Hammerspace resolves its groups. Can be qualified or unqualified

Lists all groups a user belongs to. Uses the same qualified/unqualified domain behavior as --resolve-user.

--schema

The LDAP schema. Defaults to RFC2307. Possible values: RFC2307 | RFC2307BIS.

--search-base

The LDAP search base. Defaults to the domain’s root if not provided.

(default) dc=example,dc=com; (custom) ou=people,dc=example,dc=com

LDAP search base in domain-component syntax, for example dc=corp,dc=example,dc=com. Pass "" to set a blank search base.

--search-base-reset

Reset the LDAP search base to the domain’s root. Update only

Resets the search base to the domain’s root (for example, dc=corp,dc=example,dc=com). Used with --update.

--test-connect

Test connectivity to provided Name Service(s). Provide a single identifier, or a comma-separated
list of Name Service identifiers (names, UUIDs, or internal IDs) describing the Name Service(s) to test

Reruns the connection test for configured name services, using their saved address, port, transport mode, search base, and bind credentials. All identifiers in a list must be of the same type. The test checks that an LDAPS or StartTLS certificate names the configured address, but not that it is trusted.

--transport-mode

The Transport to use for connections. Optional: a connection test will determine
the most secure supported transport if not provided. Possible values: STARTTLS | LDAPS | LDAP.

Connection transport mode: LDAP, LDAPS, or STARTTLS (not case-sensitive). If omitted, the connection test tries STARTTLS, then LDAPS, then LDAP, and keeps the first that works. Required if --no-connection-test is used.

--transport-mode-reset

Reset the transport mode to use the default (discovered) value for the LDAP server

Clears the transport mode so it is re-determined. Used with --update. Cannot be used with --no-connection-test.

--update

Update a configured LDAP Name Service


nis-config

nis-config [options]

Configure NIS servers

Options

--disable

Disable NIS service, clear NIS servers

--enable

Enable NIS service

--help

Display this help and exit

--servers

NIS servers configuration in the form domain:server, example: --servers somedomain.local:192.168.3.17. This parameter may be repeated.

--view

View NIS configuration


notification-rule-create

notification-rule-create [options]

Create a notification rule

Options

--format

Notification format. Possible values: PLAIN | XML. (Required)

--help

Display this help and exit

--name

Rule name (Required)

--threshold

Severity threshold. Selecting a threshold means that users will be notified on any events with severity greater than or equal to the selected threshold. Possible values: DEBUG | INFORMATIONAL | NOTICE | WARNING | ERROR | CRITICAL | ALERT | EMERGENCY. (Required)

--users

Destination users (each must have an email address)


notification-rule-list

notification-rule-list [options]

List notification rules

Options

--full

Print extra information for each element

--help

Display this help and exit

--id

Notification rule identifier

--name

Notification rule name


notification-rule-remove

notification-rule-remove [options]

Remove a notification rule

Options

--help

Display this help and exit

--id

Notification rule identifier. Required unless "--name" is specified

--name

Notification rule name. Required unless "--id" is specified


notification-rule-update

notification-rule-update [options]

Update a notification rule

Options

--help

Display this help and exit

--id

Notification rule identifier. Required unless "--name" is specified

--name

Notification rule name. Required unless "--id" is specified

--new-format

New notification format. Required unless any of the following is specified: --new-threshold, --new-name Possible values: PLAIN | XML.

--new-name

New name. Required unless any of the following is specified: --new-format, --new-threshold

--new-threshold

New severity threshold. Required unless any of the following is specified: --new-format, --new-name Possible values: DEBUG | INFORMATIONAL | NOTICE | WARNING | ERROR | CRITICAL | ALERT | EMERGENCY.


ntp-config

ntp-config [options]

Configure NTP

Options

--help

Display this help and exit

--servers

Comma-separated list of NTP server hostnames or IP addresses.

--servers time1.google.com,time2.google.com,192.168.1.10
--servers-clear

Clear all NTP servers

--view

View NTP configuration


support-bundle

support-bundle [options]

Collect logs and information from all nodes

Options

--all

Collect from all available nodes. Required unless any of the following is specified: --current, --push, --node

--async

Causes the command to be executed asynchronously. A reference task identifier will be returned

--current

Collect from current node. For push requests, use this option to send only the current node. Required unless any of the following is specified: --all, --push, --node

--help

Display this help and exit

--local

Collect locally

--message

Optional message to include with the support bundle request. Use quotes if the message contains spaces

Optional message to include with the support bundle request. Use quotes if the message contains spaces. Do not include passwords or other secrets.

The message is recorded in the System Management logs, which are collected in the generated bundle. For example:

support-bundle --push --message "Case 12345, issue after failover"
--no-timeout

When running a task-based command synchronously, monitor for task completion indefinitely

--node

Collect from specific node. Required unless any of the following is specified: --current, --all, --push

--push

Collect and push to Support Center. Defaults to all nodes unless --current, --all, or --node is specified. Required unless any of the following is specified: --current, --all, --node


remote-site-add

remote-site-add [options]

Add a remote site

Options

--help

Display this help and exit

--mgmt-address

The management address of the remote site (Required)

--trust-client-certificate

Automatically trust the remote site’s client certificate


remote-site-discover

remote-site-discover [options]

Discover a remote site and, optionally, synchronize data on the local instance of the remote site

Options

--help

Display this help and exit

--mgmt-address

The management address (IP or DNS) of the remote site (Required)

--sync

Synchronize data on the local site instance with discovered remote values


remote-site-list

remote-site-list [options]

List known remote sites

Options

--full

Print extra information for each element

--help

Display this help and exit

--id

The ID of the site to be listed

--internal-id

The internal ID of the site to be listed

--name

The name of the site to be listed


remote-site-remove

remote-site-remove [options]

Remove a remote site. Note that if the site is sharing an object volume with this site, it will automatically be re-added

Options

--help

Display this help and exit

--id

The ID of the site to be removed. Required unless any of the following is specified: --internal-id, --name

--internal-id

The internal ID of the site to be removed. Required unless any of the following is specified: --name, --id

--name

The name of the site to be removed. Required unless any of the following is specified: --internal-id, --id


remote-site-update

remote-site-update [options]

Update a remote site. Use this to override the management and data address when configuring a Global File System. Overriding addresses is commonly used when network topologies are using NAT.

Options

--help

Display this help and exit

--id

The ID of the site to be updated. Required unless any of the following is specified: --internal-id, --name

--internal-id

The internal ID of the site to be updated. Required unless any of the following is specified: --name, --id

--name

The remote site’s name. Required unless any of the following is specified: --internal-id, --id

--no-trust-client-certificate

Do not automatically trust the remote site’s client certificate

--override-data-address

An address which overrides the remote site’s data address. When specified, this will be the effective data address used to communicate with the remote site

--override-data-address-clear

Clears the override-data-address

--override-mgmt-address

An address which overrides the remote site’s mgmt address. When specified, this will be the effective mgmt address used to communicate with the remote site

--override-mgmt-address-clear

Clears the override-mgmt-address

--trust-client-certificate

Automatically trust the remote site’s client certificate


schedule-create

schedule-create [options]

Create a schedule

Expression values follow cron syntax where:
',' Commas separate lists
'-' Hyphens define ranges
'*' Wildcard matches all cases
'/' Slashes define step values i.e. */5 = every 5 minutes

To create a schedule at 1:30 AM, 12:30 PM and 6:30 PM, Monday-Friday

schedule-create --name schedule_name --minute 30 --hour 1,12,18 --day-of-week MON-FRI

Options

--day-of-month

The day of month for schedule. Allowed values are: 1-31,-*/ (default value: *)

--day-of-week

The day of week for schedule. Allowed values are: 1-7,SUN-SAT-*/ (default value: *)

--help

Display this help and exit

--hour

The hour for schedule. Allowed values are: 0-23,-*/ (default value: *)

--minute

The minute for schedule. Allowed values are: 0-59,-*/ (default value: *)

--month

The month for schedule. Allowed values are: 1-12,-*/ (default value: *)

--name

The name of the schedule (Required)


schedule-delete

schedule-delete [options]

Delete a schedule

Options

--help

Display this help and exit

--id

The ID of the schedule to delete. Required unless "--name" is specified

--name

The name of the schedule to delete. Required unless "--id" is specified


schedule-list

schedule-list [options]

List schedules

Options

--full

Print extra information for each element

--help

Display this help and exit

--id

The ID of the schedule to list

--name

The name of the schedule to list


schedule-update

schedule-update [options]

Update a schedule

Expression values follow cron syntax where:
',' Commas separate lists
'-' Hyphens define ranges
'*' Wildcard matches all cases
'/' Slashes define step values i.e. */5 = every 5 minutes

To update a schedule to 1:30 AM, 12:30 PM and 6:30 PM, Monday-Friday

schedule-update --name schedule_name --minute 30 --hour 1,12,18 --day-of-week MON-FRI

Options

--day-of-month

The day of month for schedule. Allowed values are: 1-31,-*/ (default value: *)

--day-of-week

The day of week for schedule. Allowed values are: 1-7,SUN-SAT-*/ (default value: *)

--help

Display this help and exit

--hour

The hour for schedule. Allowed values are: 0-23,-*/ (default value: *)

--id

ID to identify the schedule. Required unless "--name" is specified

--minute

The minute for schedule. Allowed values are: 0-59,-*/ (default value: *)

--month

The month for schedule. Allowed values are: 1-12,-*/ (default value: *)

--name

Name to identify the schedule. Required unless "--id" is specified


snmp-config

snmp-config [options]

Configure SNMP service

Options

--contact

The textual identification of the contact person for this managed node, together with information on how to contact this person

--description

A textual description of the entity

--dest

SNMP trap destination configuration. A 3-tuple including <IP>,<version>,<community>. For example: 172.31.12.216,V2C,public

--disable

Disable SNMP service. Required unless any of the following is specified: --enable, --view

--enable

Enable SNMP service. Required unless any of the following is specified: --disable, --view

--help

Display this help and exit

--location

The physical location of this node

--manager

SNMP manager configuration. A 3-tuple including <subnet>,<version (V1|V2C)>,<community>. For example: 172.31.0.0/16,V2C,public

--name

An administratively-assigned name for this managed node

--view

View SNMP configuration. Required unless any of the following is specified: --enable, --disable


software-apply

software-apply [options]

Apply software version

Options

--all

Update all nodes, mutually exclusive with "--node-name". Required unless "--node-name" is specified

--help

Display this help and exit

--node-name

Node name, mutually exclusive with "--all". Required unless "--all" is specified

--skip-order-validation

Bypass software update ordering and versioning validation

--version

Version (Required)


software-list

software-list [options]

List software versions

Options

--full

Print extra information for each element

--help

Display this help and exit


software-package-delete

software-package-delete [options]

Delete software update packages

Options

--help

Display this help and exit

--package-name

Package name to delete (Required)


software-update-cancel

software-update-cancel [options]

Cancel software update task

Options

--help

Display this help and exit

--task-id

Task ID (Required)


software-update-status

software-update-status [options]

Monitor update status

Options

--full

Print extra information for each element

--help

Display this help and exit

--last

The number of last-started software updates to list

--task-id

Update task id


software-upload

software-upload [options]

Upload a software package with UPD format

Options

--help

Display this help and exit

--package-location

The path to the UPD software package (Required)


syslog-config

syslog-config [options]

Configure syslog servers

Options

--disable

Disable syslog event forwarding, clear syslog configuration. Required unless any of the following is specified: --enable, --view

--enable

Enable syslog event forwarding. Required unless any of the following is specified: --disable, --view

--help

Display this help and exit

--server

Syslog server configuration. A 3 or 4-tuple including <server>,<port>,<transport>,[<message types delimited by |>].
Server may be an IP address or a hostname (requires DNS).
Transport values may be tcp, udp, or relp.
Message types may be event and/or filesystem. When the relp transport is specified, only filesystem is allowed.
'event' causes system events to be forwarded to the remote syslog server.
'filesystem' causes filesystem access audit records to be forwarded.
When both are present, they are separated by a |.
The message type defaults to event|filesystem for udp and tcp, and filesystem for relp.
The entire --server param can be used multiple times.

--server 192.168.1.23,601,tcp
--server syslog-server.hostname,514,udp
--server 192.168.1.24,20514,relp,filesystem
--server 192.168.1.24,514,udp,event --server syslog-server.hostname,514,tcp,event|filesystem
--view

View syslog configuration. Required unless any of the following is specified: --enable, --disable


system-backup-config

system-backup-config [options]

Configure product configuration and metadata backups. Optionally create a backup now

Options

--async

Causes the command to be executed asynchronously. A reference task identifier will be returned

--help

Display this help and exit

--ip

IP address of the backup volume

--no-timeout

When running a task-based command synchronously, monitor for task completion indefinitely

--now

Create an immediate system backup of configuration and metadata (--ip and --path parameters are required if specified). Required unless any of the following is specified: --schedule-remove, --schedule-name, --view

--path

The NFS export path to the backup volume

--schedule-name

Name for the periodic backup schedule. Required unless any of the following is specified: --now, --schedule-remove, --view

--schedule-remove

Remove the scheduled backup configuration. Required unless any of the following is specified: --now, --schedule-name, --view

--view

View the system backup configuration. Required unless any of the following is specified: --now, --schedule-remove, --schedule-name


system-backup-list

system-backup-list [options]

List the names of the product configuration and metadata backups in the backup volume

Options

--help

Display this help and exit

--ip

IP address of the backup volume (Required)

--path

The NFS export path to the backup volume (Required)


system-backup-restore

system-backup-restore [options]

Restore product configuration and metadata backup

Options

--async

Causes the command to be executed asynchronously. A reference task identifier will be returned

--backup-name

The name of the backup. If not specified, the most recent backup is restored

--cluster-uuid

The UUID of the cluster that created the backup from which you would like to restore

--help

Display this help and exit

--ip

IP address of the backup volume (Required)

--no-timeout

When running a task-based command synchronously, monitor for task completion indefinitely

--path

The NFS export path to the backup volume (Required)


system-shutdown

system-shutdown [options]

Use this command to cleanly shut down all product nodes.

Options

--force

Confirm shutdown execution (Required)

--help

Display this help and exit

--reason

Shutdown reason


system-view

system-view [options]

Show an overview of the system

Options

--help

Display this help and exit

--timeout

A timeout in seconds to use when executing the command


task-cancel

task-cancel [options]

Attempt to cancel a task. If the task is HALTED, it will be restarted and the new task will be cancelled.

Options

--help

Display this help and exit

--id

The task ID


task-list

task-list [options]

List all running tasks in the system. The command can also be used to list completed tasks using the status filter, showing both successful and failed tasks. When no time-based filter is specified, tasks created over the past 31 days are returned.

Options

--created-after

List tasks that were created at or after (>=) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"

--created-before

List tasks that were created before (<) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"

--ended-after

List tasks that ended at or after (>=) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"

--ended-before

List tasks that ended before (<) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"

--full

Print extra information for each element

--help

Display this help and exit

--id

The task ID

--last-created

The number of last-created tasks to list

--name

The task name

--started-after

List tasks that started at or after (>=) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"

--started-before

List tasks that started before (<) the specified time, in the format [yyyy-MM-dd|dd-MMM-yyyy] [HH:mm:ss] Examples: "2025-06-21 02:42", "25-FEB-2025 19:25:30"

--status

Filter by the status of the task. Possible values: NONE | QUEUED | VALIDATING | VALIDATED | VALIDATION_FAILED | EXECUTING | CANCELLING | HALTED | RECOVERING | RESUMED | FAILED | CANCELLED | COMPLETED.


task-resume

task-resume [options]

Resume a task that is HALTED, or retry a task that is FAILED

Options

--help

Display this help and exit

--id

The task ID