Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 2.15.0

CLI Guide

Introduction

This page consolidates the igls CLI commands referenced across the Data Security documentation into a single reference, organized by task. Each command links back to the full procedure on its source page for complete context and prerequisites. For ECA node-level (ecactl/kubectl) commands, see the dedicated cards below.

Ransomware Defender CLI Commands

General Ransomware Settings

View the current general Ransomware Defender settings (some settings are managed only in the GUI):

igls rsw generalsettings

Sample output:

{
"snapshot_expiry_hours": 48,
"escalate": false,
"critical_on": true,
"monitor_only": false,
"snapshotOn": "WARNING",
"lock_root": false,
"root_sids": [
"S-1-1-1-0",
"S-1-22-1-0"
]
}

Default Snapshot Expiry

The Snapshot Quota default snapshot expiry (48 hours — see Snapshots — PowerScale-specific) can be changed with this command:

igls rsw generalsettings set --snapshot_expiry_hours 72

Security Guard Delay Detection

Use this command to change the Security Guard timer that delays the failure message when audit events are behind on the cluster:

igls rsw securityguardsettings help

This shows the available options:

  • sg_waitforevent_timer_seconds — the security guard wait-for-event timer, in seconds.
  • sg_restore_timer_seconds — the security guard restore (permissions) timer, in seconds.
igls rsw securityguardsettings set --sg_waitforevent_timer_seconds=600
igls rsw securityguardsettings set --sg_restore_timer_seconds=60

See Health Check — Advanced Timer Configuration for the feature these commands tune.

NFS Event Processing and Lockout

Enable or disable ransomware detection and lockout for NFS activity:

igls rsw nfsevents set --enabled=monitor

Sets NFS events to Monitor mode (default recommended) — detects and logs NFS activity without triggering a lockout.

igls rsw nfsevents set --enabled=true
igls rsw nfsevents set --enabled=false

Enables or disables NFS lockout outright, once the operational impact has been reviewed. See Threat Response, Lockout and Snapshots.

Generic (Broader-Scope) Learned Thresholds

igls rsw genericthresholds set --enabled=true

Enables applying a Learned Threshold beyond the current user only — to a user group, globally across all users, or to a specific path — when flagging an event as a false positive. See Detection Controls and False Positive Management.

Appliance ID

The appliance ID is also displayed directly in the 2.15.0 GUI, in Inventory → License Management, with a Copy Appliance ID button next to it. To retrieve it over SSH instead:

igls admin appid

Displays the appliance ID — used, for example, when gathering configuration details for a Threat Hunting ML VM deployment. See ML VM (Threat Hunting) Deployment.

Suspicious Extensions List

igls rsw filefiltersettings

Views the current update mode and available extension-list versions.

igls rsw filefiltersettings --diff=<version1>,<version2>

Compares what changed between two versions before updating — recommended, since adding extensions can trigger new alerts and lockouts.

igls rsw filefiltersettings set --mode=Fixed --version=<version>

Pins the list to a specific version.

igls rsw filefiltersettings set --mode=Latest

Switches to automatic updates.

igls rsw filefiltersettings --version=<version>

Rolls back to a specific version.

See Suspicious Extensions List Maintenance for how the list itself is maintained.

Data Auditing

igls config settings set --tag=bulkingestpath --value=<PATH>

Configures a non-default path for .gz audit log files used by Bulk Ingest. See Data Auditing.

SQL Database Retention Management

igls adv sqldbarchive

Archives records from the userEvents table older than the configured threshold (sendRecordsToColdStoreDays, default 90 days) to the configured cold-store path.

igls adv sqldbrestore set --startDate=2024_06_04 --endDate=2024_07_06

Restores archived records for a specific date range.

igls adv sqldb add …

Adds the PostgreSQL database to Eyeglass — a prerequisite for using archival/restoration. See SQL DB Retention Management for full parameters, scheduling, and how the archival process works.

See Also