Unsolved
1 Rookie
•
6 Posts
0
69
February 26th, 2025 19:39
Powerscale isi_audit_cee service doesn't seem to be working
The issue is the isi_audit_cee service doesn’t appear to be working, nothing in the log files, no error message stating it can’t reach the configured CEE server.
Tried restarting the cluster, advancing the cursor for the CEE logs, deleting the log files and restarting the service, but it never appear to be running. At least I only see the isi_audit_d running when using “isi_for_array -s pgrep audit”
Using isi services -a it is supposedly enabled, but there’s nothing in the log file besides that the log file was created.
No Events found!
DELL-Sam L
Moderator
•
7.5K Posts
0
February 27th, 2025 08:33
Hello DAS-Engineering
Which Powerscale system do you have, and which version of CEE server are you using? Have you tried the steps listed in the kb’s below to see if they have any assistance?
https://dell.to/439Z6bx
https://dell.to/41abXb2
DAS-Engineering
1 Rookie
•
6 Posts
0
February 27th, 2025 14:44
@DELL-Sam L
That first link goes to "
Page Not Found
"
for the second,
I don't have that error in the logs.
CEE version 9 on a windows server 2022 host, it is receiving Events from a Unity server I have setup, and the powerscale systems is able to route to the CEE server
DELL-Sam L
Moderator
•
7.5K Posts
0
February 27th, 2025 15:39
Isilon: isi_audit_syslog is not starting Audience Level: Customer
Summary: Customer has configured the cluster for AUDIT. This KB describes one situation why isi_audit_syslog is not running.
Symptoms
isi_audit_syslog is not starting. No error messages are found in logs.
Cause
Resolution
It is recommended that an SR be opened with DELL EMC Isilon Support, quoting this KB so that support personnel can analyse the DEBUG logs for a cause why isi_audit_syslog has failed to start.
Additional Information
As long as events are being forwarded from the nodes via CEE, isi_audit_syslog is not needed. To check if events are being forwarded, execute the following command on a node where isi_audit_syslog is not running:
isi_audit_progress -t protocol CEE_FWD
Output indicating CEE events are being forwarded will look like the following:
mycluster-2: Last consumed event time: '2018-02-15 16:24:44'
mycluster-2: Last logged event time: '2018-02-15 16:24:45'
If the cluster was configured to forward to a syslog server, then isi_audit_syslog should be running. But it is not necessarily the case, that CEE is failing if that daemon is not started. These points should be reviewed before opening a support case. If remote syslog has not been configured as stated in the KB above, there is no need to have that enabled to support the functionality of CEE protocol auditing.
isi audit settings global modify --config-auditing-enabled yes --config-syslog-enabled yes
cluster-1# isi audit settings global view
Protocol Auditing Enabled: Yes
Audited Zones: System
CEE Server URIs: https://dell.to/4ifuZ6M
Hostname: https://dell.to/41Adk4n
Config Auditing Enabled: Yes
Config Syslog Enabled: Yes
isi audit settings global modify --config-auditing-enabled yes --config-syslog-enabled yes
cluster-1# isi audit settings global view
Protocol Auditing Enabled: Yes
Audited Zones: System
CEE Server URIs: https://dell.to/4ifuZ6M
Hostname: https://dell.to/41Adk4n
Config Auditing Enabled: Yes
Config Syslog Enabled: Yes
Those settings are not needed unless a remote syslog server is actually configured. CEE forwarding of audit events works without enabling this. If there is no remote syslog server configured, these yellow high-lighted options should be configured as "no".
The following command is also helpful to determine the number of events being sent per second:
mycluster-1# isi statistics query current --nodes=all --stats=node.audit.cee.export.rate
Node node.audit.cee.export.rate
-----------------------------------
1 893.000000
2 21.200000
3 37.400000
4 8.400000
5 59.400000
6 66.800000
7 75.800000
8 349.800000
9 831.000000
10 28.800000
average 237.160000
-----------------------------------
Total: 11
In the example above, Node 1 is sending 893 events per second to the CEE servers configured. The events are sent one after the other, in a round robin fashion to ALL CEE servers that have been configured (as long as the CEE servers are reachable). Node 2 is sending 21.2 events per second, and so on.
NOTE that in OneFS v8.0.1.x+, events are sent in parallel, resulting in quite a performance improvement for the CEE auditing feature.
Partner Notes
1. Enable DEBUG logging for the AUDIT subsystem as follows. This will generate a LOT of logs if the cluster is busy sending events via CEE to a server. This will enable DEBUG logging for the /var/log/isi_audit_cee.log file.
Do this on one node where isi_audit_syslog is not starting.
pkill -SIGUSR1 isi_audit_cee
2. Try to manually start the isi_audit_syslog process as follows.
/usr/libexec/isilon/isi_audit_syslog /usr/bin/isi_audit_syslog
3. Stop DEBUG logging as follows. DO NOT FORGET THIS STEP.
pkill -SIGUSR1 isi_audit_cee
4. Review the isi_audit_cee.log files in /var/log. Depending on the activity level, there could be several wrapped logs to review before you find the point where the attempt to start isi_audit_syslog occurred.
The causative log entry will look something like this:
2018-02-15 18:04:33 mycluster-5 isi_audit_syslog[8536][0x817f4fc00]: Opening audit/logs/node005/protocol/00000000: No such file or directory
You will have to hunt for this in the DEBUG logs - there are a lot of logs!
5. Touch that file and restart isi_audit_syslog manually.
touch /ifs/.ifsvar/audit/logs/node005/protocol/00000000
/usr/libexec/isilon/isi_audit_syslog /usr/bin/isi_audit_syslog
6. Control that isi_audit_syslog has started on the node
ps -auwx | grep audit | grep -v grep
7. Repeat for other nodes as needed
DAS-Engineering
1 Rookie
•
6 Posts
0
February 28th, 2025 15:03
cluster1-1# touch /ifs/.ifsvar/audit/logs/node001/protocol/00000000
cluster1-1# /usr/libexec/isilon/isi_audit_syslog /usr/bin/isi_audit_syslog
cluster1-1# ps -auwx | grep audit | grep -v grep
root 10 0.0 0.0 0 40 - DL Fri15 0:00.00 [audit]
root 2524 0.0 0.2 54360 13624 - Ss Fri15 0:26.54 /usr/sbin/isi_audit_d -d
cluster1-1# cat /var/log/isi_audit_cee.log
Oct 11 14:38:01 newsyslog[737]: logfile first created
cluster1-1#
don't seem to be getting anything in the logs
and the cee service never seems to start
cluster1-1# pgrep -l audit
2524 isi_audit_d
DELL-Sam L
Moderator
•
7.5K Posts
0
February 28th, 2025 18:12
Hello DAS-Engineering,
Have you used the document listed below?
https://dell.to/4inoBul
What is your current Onefs version on your Powerscale system?
DAS-Engineering
1 Rookie
•
6 Posts
0
March 3rd, 2025 17:33
Yes I have used that document. I have a Unity instance that is able to communicate to my configured CEE correctly.
It's currently on 9.7.0.0
DELL-Sam L
Moderator
•
7.5K Posts
0
March 3rd, 2025 18:27
Hello DAS-Engineering,
If your CEE server is able to communicate with your unity then you see the aduit. Since you are not able to see the audit’s then it is best to open a support case for this issue.
DAS-Engineering
1 Rookie
•
6 Posts
0
March 3rd, 2025 20:27
Also got this
cluster1-1# isi_audit_progress -t protocol CEE_FWD
Consumer 'CEE_FWD' does not exist for topic 'protocol'
DELL-Sam L
Moderator
•
7.5K Posts
0
March 4th, 2025 17:25
Hello DAS-Engineering,
I am not sure why you are getting that message as that would state that the service is not present or active.