NetApp ONTAP Integration
Overview
NetApp ONTAP provides enterprise storage with comprehensive audit logging. KYRA MDR collects NetApp audit logs for monitoring data access and detecting ransomware. Supports ONTAP 9.x.
Prerequisites
- A KYRA MDR Collector installed and running
- NetApp ONTAP storage system with admin access
- ONTAP 9.8 or later
- Network connectivity from the ONTAP cluster to the collector
Configuration
Configure NetApp ONTAP audit logging:
- Enable audit logging on the SVM:
vserver audit create -vserver <svm-name> -destination /vol/audit_log \ -events file-ops,cifs-logon-logoff,authorization-policy-change -format evtxvserver audit enable -vserver <svm-name>- Configure syslog forwarding:
event notification destination create -name kyra-mdr \ -syslog <collector-ip> -syslog-port 514 -syslog-transport tcpevent notification create -filter-name important-events -destinations kyra-mdr- Configure FPolicy for file access monitoring:
fpolicy policy event create -vserver <svm-name> \ -event-name kyra-monitor -protocol cifs \ -file-operations create,write,rename,deleteCollected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| File Operations | File create, read, write, delete | Data access monitoring |
| CIFS Logon | SMB authentication events | Access monitoring |
| NFS Access | NFS file access events | Unix file access auditing |
| Admin Operations | Storage management commands | Change management |
| FPolicy | File policy events | Ransomware detection |
| SnapMirror | Replication events | Data protection monitoring |
Troubleshooting
No audit events: Verify audit is enabled with vserver audit show.
Missing file operations: Ensure the -events parameter includes the desired types.
FPolicy external mode: Configure for real-time file event monitoring.
Contact kyra@seekerslab.com for support.