ロックされたvsadminについてEMSログでイベントsecurity.invalid.loginが報告される
環境
- ONTAP 9
- ONTAPI
- SnapDrive
問題
- 外部システムからのログイン試行に関する通知の受信Alert
EMS.LOG.GZ
:security.invalid.login: Failed to authenticate login attempt to Vserver: svm_data, username: vsadmin, application: ontapi
CLIの場合:Cluster-01::> event log show -message-name security.invalid.login Time Node Severity Event ------------------- ---------------- ------------- --------------------------- 3/22/2021 08:00:07 Cluster-01 ALERT security.invalid.login: Failed to authenticate login attempt to Vserver: svm_data, username: vsadmin, application: ontapi.
- ログインに失敗したIPアドレスとユーザを特定します。
security audit log show
Cluter-01::> security audit log show -timestamp "3/22/2021 08:00:07" Time Node Audit Message ------------------------ ----------- ----------------------- Mon Mar 22 08:00:07 2021 Cluster-01 [kern_audit:info:2345] 8503e800002b7bbe :: Cluster-01:ontapi :: 10.10.10.1:10101 :: svm_data:vsadmin :: Login Attempt :: Error: Error: Account currently locked. Contact the storage administrator to unlock it. Mon Mar 22 08:00:07 2021 Cluster-01 [kern_audit:info:2345] 8503e800002b7bbe :: Cluster-01:ontapi :: 10.10.10.1:10101 :: svm_data:vsadmin :: Login Attempt :: Error: Authentication failed. Mon Mar 22 08:00:07 2021 Cluster-01 [kern_audit:info:8617] 8503e800002b7bbe :: Cluster-01:ontapi :: 10.10.10.1:10101 :: svm_data:vsadmin :: POST /servlets/netapp.servlets.admin.XMLrequest_filer HTTP/1.1 :: Error: 401 Unauthorized 3 entries were displayed.
- vsadminユーザを使用してSnapDriveとして識別されるIP