Before you configure and enable auditing on your Storage Virtual Machine (SVM), you need to be aware of certain requirements and considerations.
You can configure and enable auditing even if CIFS and NFS licenses are not installed on the cluster.
When converting ACLs to mode bits, auditing ACEs are skipped. When converting mode bits to ACLs, auditing ACEs are not generated.
If it does not exist, the command to create the auditing configuration fails.
If the directory specified in the auditing configuration contains symbolic links, the command to create the auditing configuration fails.
You should not specify a relative path, for example, /vs1/../.
You must be aware of and have a plan for ensuring that there is sufficient space for the staging volumes in aggregates that contain audited volumes.
You must be aware of and have a plan for ensuring that there is sufficient space in the volumes used to store event logs. You can specify the number of event logs to retain in the auditing directory by using the -rotate-limit parameter when creating an auditing configuration, which can help to ensure that there is enough available space for the event logs in the volume.
Dynamic Access Control is not enabled by default.