[gpfsug-discuss] FAL audit events not always triggered

Dave Bond davebond7787 at gmail.com
Thu May 20 13:56:51 BST 2021


Hello

I am currently testing out the FAL and watch folders auditing mechanism in
5.1.0.  I have noticed that audit events such as file access or creation
are not always recorded in the FAL log on the filesystem.  It would seem
necessary to disable and re enable FAL auditing for the same file access to
be recorded.  I have only triggered this condition twice so far, but it has
set in my mind a few questions.

1) Have others seen this?  If so what is the trigger, as I do not yet have
a reproducer.
2) Is it intended for the audit mechanism to be a soft audit?  i.e the
audit is best effort, and non blocking for file access.

This is using a single NSD and a single remote cluster doing the file
writing.  FAL is running on the NSD node.

Regards

Dave
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://gpfsug.org/pipermail/gpfsug-discuss_gpfsug.org/attachments/20210520/c4895935/attachment-0001.htm>


More information about the gpfsug-discuss mailing list