I
I
IDepresnakI2020-04-10 08:02:01
Samba
IDepresnakI, 2020-04-10 08:02:01

Samba logging problems write, pwrite, read, pread, rename what could be the problem?

Hello
samaba 4.9.5

encountered the following problem:
write, pwrite, read, pread events are not written to the log, while all the rest have

the following config

[обменник1]
comment = share directory
inherit acls = yes
inherit owner = yes
path = /storage/Обменник1
inherit permissions = yes
hide unreadable = yes
writeable = yes
read only = no
browseable = yes
# guest ok = yes
valid users = samara, buzuluk, volgograd, krym, tolyatti, ulyanovsk, otradnyj, kogalym, mirniy, krasnodar, samaratc, crimeatc, moskva, nnovgorod, sevastopol, chelyabinsk,
vfs objects = recycle crossrename full_audit
full_audit:prefix: = %u|%I|%L|%m|%s
full_audit:success = connect, disconnect, mkdir, rmdir, read, pread, sendfile, write, rename, pwrite, fchown, chmod, fchmod
full_audit:failure = open, connect, disconnect, mkdir, rmdir, read, pread, sendfile, write, rename, pwrite, fchown, chmod, fchmod
full_audit:failure = none
full_audit:facility = local5
full_audit:priority = notice
recycle:repository = /storage/recycle/.recycle
btrfs: manipulate snapshots = no
recycle:exclude = *.tmp,*.temp,*.o,*.obj,~$*,*.~??,*.trace,*.VOB,*.mp4,*.avi,*.crdownload,~*,*TMP,*.iso,*.flv,*.webm,*.MOV,*.mpg,*.wmv,*.exe
recycle:excludedir = /tmp,/temp,/cache
recycle:keeptree = yes
recycle:touch = yes
recycle:touch_mtime = yes
recycle:versions = yes
recycle:maxsize = 0
recycle:directory_mode = 0777


/etc/rsyslog.conf
local5.notice -/var/log/samba/audit.log
What could be the problem?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
K
Karpion, 2020-04-10
@Karpion

Why do you have twice full_audit:failure?

I
IDepresnakI, 2020-04-16
@IDepresnakI

If you use extd_audit, then all operations are visible, but there is no way to see on whose behalf these actions were performed, it turns out that the cant is only in full_audit, I looked at the changes in samba 4.9.5, they ruled vfs_full_audit from false positives, maybe this is the case?

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question