Configuring the Change Auditor template for auditing changes to multiple CIFS servers is not straightforward. Complexity can be increased if VDMs are used exclusively as well.
We cannot upload the cepp.conf file to VDMs. The cepp.conf is a global file found on the physical data mover for which the virtual data mover(s) reside.
To audit multiple CIFS servers residing on the same data mover, follow the steps below:
1. A CIFS server must exist (or be created) on the physical data mover to upload/update the cepp.conf file via Change Auditor.
2. Configure the Change Auditor template for any 1 CIFS server on the physical data mover.
3. Once a Change Auditor auditing template is added for the 1st CIFS server on the physical data mover, additional templates can be assigned to any additional CIFS server(s), whether or on the physical or virtual data movers. When adding these additional templates, skip the final step, which allows for re-configuration of the cepp.conf as it has already been updated in step 2 above.
Note: All CIFS server auditing templates applied to the filer must be applied to the same "pool" of Change Auditor Agent(s) for processing, as the EMC device will only be forwarding events to Change Auditor Agents included in the "pool name" field controlled by the cepp.conf file.
4. - The event(s) defined in the cepp.conf file that is pushed out when editing the first CIFS server template must encompass the events for all CIFS server templates on that data mover.
e.g., if one template needs the read event and another needs the write event, the cepp.conf pushed MUST include both events
5. "cifsserver" field must not be populated in cepp.conf, or EMC will only produce events for the specified CIFS Server.