Which Computer/IP deleted 25% of Data on closed network

Status
Not open for further replies.

Niktronics

Cadet
Joined
Sep 25, 2017
Messages
4
Build FreeNAS-11.0-U3 (c5dcf4416), Dataset is wide open allowing computers in closed network, to erase/delete/move file/folders inside the dataset.

Lost 25% of data in a dataset at a know time. Yes running snap shots and recover. Would like to find the Computer/IP address that connect to the Nas and deleted the files. Think there might be a LOG of this event, where do I look??

Please Help, Which IP deleted the data?
 

bigphil

Patron
Joined
Jan 30, 2014
Messages
486
With default settings, I don't think there is a log of file operations. For an SMB share, you'd first need to enable one or all of the vfs "audit" objects. See the documentation on the available vfs objects for details.
 

Ericloewe

Server Wrangler
Moderator
Joined
Feb 15, 2014
Messages
20,194
Yeah, this is the sort of thing you have to preemptively log.
 

JoshDW19

Community Hall of Fame
Joined
May 16, 2016
Messages
1,077
Bump! Op asked me to see if there are any more answers out there.
 

JoshDW19

Community Hall of Fame
Joined
May 16, 2016
Messages
1,077
One of the devs had this to say:

"We need more details... Was it done locally? via smb? nfs? etc. Locally? check auth log for ssh connections, zpool history, etc. Oh btw, it's probably a good idea to not keep things wide open like that ;-)"
 
Status
Not open for further replies.
Top