跳至正文

NetApp ONTAP Integration

Overview

NetApp ONTAP provides enterprise storage with comprehensive audit logging. KYRA MDR collects NetApp audit logs for monitoring data access and detecting ransomware. Supports ONTAP 9.x.

Prerequisites

  • A KYRA MDR Collector installed and running
  • NetApp ONTAP storage system with admin access
  • ONTAP 9.8 or later
  • Network connectivity from the ONTAP cluster to the collector

Configuration

Configure NetApp ONTAP audit logging:

  1. Enable audit logging on the SVM:
vserver audit create -vserver <svm-name> -destination /vol/audit_log \
-events file-ops,cifs-logon-logoff,authorization-policy-change -format evtx
vserver audit enable -vserver <svm-name>
  1. Configure syslog forwarding:
event notification destination create -name kyra-mdr \
-syslog <collector-ip> -syslog-port 514 -syslog-transport tcp
event notification create -filter-name important-events -destinations kyra-mdr
  1. Configure FPolicy for file access monitoring:
fpolicy policy event create -vserver <svm-name> \
-event-name kyra-monitor -protocol cifs \
-file-operations create,write,rename,delete

Collected Log Types

Log TypeDescriptionSecurity Use
File OperationsFile create, read, write, deleteData access monitoring
CIFS LogonSMB authentication eventsAccess monitoring
NFS AccessNFS file access eventsUnix file access auditing
Admin OperationsStorage management commandsChange management
FPolicyFile policy eventsRansomware detection
SnapMirrorReplication eventsData protection monitoring

Troubleshooting

No audit events: Verify audit is enabled with vserver audit show.

Missing file operations: Ensure the -events parameter includes the desired types.

FPolicy external mode: Configure for real-time file event monitoring.

Contact kyra@seekerslab.com for support.