CONTAP-203409:ARW clear - suspect recordに、正確なcleared countではなく0 clearedと表示される
問題
- ARW activity alert is reported for a volume when new file extensions are detected:
Cluster::*> security anti-ransomware volume workload-behavior show -vserver vs0 -volume testvol_mrt_1 Vserver: vs0 Volume: testvol_mrt_1 File Extensions Observed: mp3_html, doc_html Number of File Extensions Observed: 2 Historical Statistics High Entropy Data Write Percentage: - High Entropy Data Write Peak Rate (KB/Minute): - File Create Peak Rate (per Minute): 20 File Delete Peak Rate (per Minute): - File Rename Peak Rate (per Minute): - Surge Observed Surge Timeline: - High Entropy Data Write Percentage: - High Entropy Data Write Peak Rate (KB/Minute): - File Create Peak Rate (per Minute): - File Delete Peak Rate (per Minute): - File Rename Peak Rate (per Minute): - Newly Observed File Extensions: doc_html, mp3_html Number of Newly Observed File Extensions: 101, 102
- While running the clear-suspect command to either mark the extension as false positive, the clear-suspect record displays '0' instead of the actual count:
Cluster::*> security anti-ransomware volume attack clear-suspect -vserver vs0 -volume testvol_mrt_1 -extensions doc_html -false-positive true Suspect records cleared: 0. Cluster::*> security anti-ransomware volume attack clear-suspect -vserver vs0 -volume testvol_mrt_1 -extensions mp3_html -false-positive false Suspect records cleared: 0.