similar to: No Logging for most VFS Operations with full_audit on smbd 4.9.5-Debian

Displaying 20 results from an estimated 5000 matches similar to: "No Logging for most VFS Operations with full_audit on smbd 4.9.5-Debian"

2013 Nov 05
1
4.1.0 auditing : can't get only wanted vfs operations to log
HI all, So I'd like to log the user's operations on some shares. As I need to know who made what when. I'd read a previous answer from Andrew about auditing, so I can see loggued operations. Modified smb.conf : > [global] > vfs objects = dfs_samba4, acl_xattr, full_audit > full_audit:success =none > full_audit:failure = none share is : > [journal] > path =
2010 Jun 15
1
Logging file creation with full_audit
I'm trying to set up a samba server to audit only the file operations that I care about, which are create, modify, delete, and rename (for files and folders). I've got the full_audit vfs module working well, except that I haven't been able to figure out what to set it to log (in the "full_audit:success" setting) to include file creation and modification. If I log
2023 Mar 10
1
full_audit syslog logging question
Running Samba 4.16.4 and having problems getting the vfs_full_audit module to send anything to syslog. I can get it to log to a file, but nothing happens when using syslog only. Configuration looks like: [global] ... log level = 4 log file = /var/log/samba/log.%m logging = syslog at 4 ... [foobar] path = /foobar vfs objects = full_audit streams_xattr acl_xattr full_audit:priority = INFO
2023 Mar 13
1
full_audit syslog logging question
In case anyone is interested, I found the problem. I was running samba in a container that did not have any syslog service (rsyslogd or syslog-ng) running. By default, samba syslog only sends messages to the system's syslog socket and there was nothing listening on it so the messages just got dropped. I put rsyslogd in the container and configured it to listen on the syslog socket and am
2016 Jul 23
2
permission problem with vfs object recycle:directory_mode
Well, Despite I've recently answered about vfs object recycle on this list, it seems that it isn't working as excepted. Using Samba 4.4.5, compiled from sources Here is the conf for a share: [musique] path = /media/data/musique read only = No vfs objects = acl_xattr recycle recycle:directory_mode = 0770 recycle:subdir_mode = 0700
2010 Nov 29
0
VFS full_audit sending spurious messages to syslog?
Hi, I'm currently running Samba 3.0.22 (on an Ubuntu 6.06 [Dapper] server). I have VFS full_audit set up successfully to log user activity using the LOCAL6 facility. I also have syslog configured to redirect all messages from this facility to /var/log/samba/log.audit This is working fine. However, I've recently been getting lines in /var/log/syslog that look like they're coming
2009 Mar 20
1
vfs full_audit panic
Folks, I tried using full_audit on Samba 3.0.28 by putting the following lines on smb.conf (global section): vfs objects = full_audit full_audit:facility = LOCAL2 full_audit:priority = WARN full_audit:prefix = %u|%m|%S full_audit:success = rename rmdir unlink write full_audit:failure = none My log says: Dec 29 13:57:07 lua smbd_audit: [2008/12/29 13:57:07, 0] lib/fault.c:fault_report(45) Dec
2016 Jul 23
0
permission problem with vfs object recycle:directory_mode
On 23/07/16 07:58, Nicolas wrote: > Well, > > Despite I've recently answered about vfs object recycle on this list, > it seems that it isn't working as excepted. > > Using Samba 4.4.5, compiled from sources > > Here is the conf for a share: > [musique] > path = /media/data/musique > read only = No > vfs objects = acl_xattr
2018 May 06
0
Samba Audit Logs
Hi Rowland, Thank you. I tried both options. The following is using option 2 [global] vfs objects = full_audit [homes] create mask = 0700 directory mask = 0700 browseable = No read only = No path = %H full_audit:prefix = %u|%I|%S full_audit:failure = none full_audit:success = mkdir rmdir read pread write pwrite rename unlink
2018 May 06
1
Samba Audit Logs
I think the issue is permissions related. I changed the log location to /tmp/audit.log and now it is populating. What should be the permissions for /var/log/samba/audit.log? On Mon, May 7, 2018 at 12:29 AM, Robin G <robinghere3 at gmail.com> wrote: > Hi Rowland, > > Thank you. > > I tried both options. The following is using option 2 > [global] > vfs objects =
2020 Apr 02
2
Samba 4.12 python3 and vfs object full_audit (centos7)
Hallo, I?m using samba 4.11 from sernet and the vfs object full_audit. After update samba to 4.12 from sernet full_audit is broken and the shares with full_audit are not accessible. Can anyone tell me please how to install python 3 on centos7 while the Centos system needs python 2 but samba sould use python3? Thanks in advance, Peter
2018 May 06
0
Samba Audit Logs
Hi Rowland, here is the smb.conf. All shares have the full_audit [global] workgroup = RESOLVS netbios name = DC1 security = USER obey pam restrictions = yes local master = yes domain master = yes preferred master = yes domain logons = yes os level = 50 #### LDAP definitions #### ### Logging syslog = 0 log file =
2009 Dec 09
1
VFS full_audit problem
Hi all, I had implemented on one of my shares vfs full_audit module. It was working with Samba 3.0.x without any problems. After migration to Samba 3.4.3 this function doesn't work anymore - when it's enabled then share isn't accessible from users (it's visible but getting error when trying to connect to it). Audit and extd_audit vfs's are working fine, but they
2018 May 05
2
Samba Audit Logs
Hi, My apologies if this isn't the right place to ask this question. We have trying to setup auditing in Samba but can't seem to get it to work. The audit log file is empty and we see some entries about file/folders in the /var/log/samba/%m but not the actual audit bits. Can someone please assist or point in the correct direction? syslog = 0 log file = /var/log/samba/%m Log level = 0
2018 May 05
2
Samba Audit Logs
On Sat, 5 May 2018 11:11:21 -0300 "Ethy H. Brito via samba" <samba at lists.samba.org> wrote: > On Sat, 5 May 2018 23:40:47 +1000 > Robin G via samba <samba at lists.samba.org> wrote: > > ... > > > > full_audit:prefix = %u|%I|%S > > full_audit:failure = none > > full_audit:success = mkdir rmdir read pread write pwrite
2018 May 06
2
Samba Audit Logs
On Sun, 6 May 2018 20:05:20 +1000 Robin G <robinghere3 at gmail.com> wrote: > Hi Rowland, > here is the smb.conf. All shares have the full_audit > > [global] > workgroup = RESOLVS > netbios name = DC1 > security = USER > obey pam restrictions = yes > local master = yes > domain master = yes > preferred
2010 Dec 02
0
samba3x troubles
Hi all, I get troubles with samba3x server: samba3x-winbind-3.3.8-0.52.el5_5.2 samba3x-3.3.8-0.52.el5_5.2 samba3x-common-3.3.8-0.52.el5_5.2 Some times, users call and ask of any folder in any share sleep. Locked not _all_ share, only one of it's folder. In logs i don't see any errors(for time of user call, may be errors in log was some times before). I use
2011 Jun 10
1
known incompatibility with msdfs and vfs full_audit combination?
Hi all, I'm running debian 6, x64, stock samba 3.5.6, various clients. As soon as I enable the full_audit vfs object in smb.conf, my msdfs links stop working with: - INTERNAL ERROR: Signal 11 and - failed to get vfs_handle->data! in the samba logfiles. Is there a known problem with this combination? I'm guessing that this combination is supposed to work..? I have a level 10 log
2020 Apr 16
0
Crash after Update to 4.12.1 with vfs full_audit
Forgot to mention that this is on Centos 8. So maybe something different than this: https://www.spinics.net/lists/samba/msg163085.html Regards Christian Am 16.04.20 um 13:45 schrieb Christian Naumer via samba: > Hello alAl, > after update of our test server to 4.12.1 from 4.11 it crashes. If the > vfs module is removed from the config everthing works as before. Logs > from the
2013 Mar 15
1
There are no currently logon servers available when mapping with "net use"
Hi people, I have a problem and I need so much of your help. I have a login script in \\server1\netlogon\script.bat (on my PDC and BDC) that runs "net use" commands to map some shares in time of the logon. This login tries to map share in another server (samba member of domain \\server2). So, I put the result at a log and appears these lines: " System error 1311 has occurred.