Product Data - Eyeglass and ECA Log Content Definitions
Overview
This page defines the "System Data" and "Product Data" referenced throughout the Superna EULA and Support Services Agreements. It lists each Eyeglass and ECA log file, its location on the appliance, the product(s) it applies to, whether it is included in a support data collection bundle, and a description of its contents.
Eyeglass (SCA) Logs
Location: /opt/superna/sca/logs
| Log Name | Product | Included in Support Data | Log Contents |
|---|---|---|---|
adprincipalcache.log | All | No | Cache of AD domain user names to accelerate GUI display and SID-to-user / AD group operations without needing AD domain availability. SIDs and AD groups, AD group SIDs for RBAC and SID-to-user-name display in the GUI. Not included in support backup files. |
cacheinit.log | All | Yes | API calls to cluster requests and the payload of the response from the cluster. |
error.log | All | Yes | Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
fingerprint.log | All | Yes | Internal process errors from Eyeglass process operation functions, internal to Eyeglass code, for DR IP pool and restart process checkpoint on last status. |
main.log | All | Yes | Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
evtreporter.log | Performance Auditor | Yes | Websocket log of Performance Auditor GUI updates sent to the GUI. |
apiaudit.log | All | Yes | Internal API logging of modules that log each function used in the GUI to track administrator actions for security purposes of product usage. Documented in documentation. |
eyeglass_installer_<version>-<date>.log | All | Yes | Upgrade log tracking what happened during an upgrade to a specific release on a specific day and time. Support tool for upgrade issues. |
phonehome.log | All (if enabled) | Yes | If enabled, tracks phone-home log requests and registration of the appliance, and communication issues to the phone-home portal. |
audit.log | All | Yes | DR configuration audit of the configuration data comparison between two clusters using in-memory inventory to compare shares, exports, and quota differences. Audit log generates errors in the GUI if needed to resolve differences. |
backup_archive.log | All | Yes | Backup configuration log; logs errors when the create-backup script fails to create the backup zip file. |
alarms.log | All | Yes | Not currently used; reserved for future use to log alarms created and sent to the GUI and through email. |
anycopy.log | AnyCopy | Yes | AnyCopy log of user actions and API calls; only applies to the AnyCopy product license. |
changemanagement.log | All | Yes | Cluster report feature comparison log, comparing two cluster reports to identify changes from one day to the next. Stores comparison data only if the feature is used; logs issues found during the comparison, which is performed in RAM. |
cli.log | All | Yes | May contain CLI commands from igls command issues; currently not used. |
csm.log | All | Yes | Cluster Storage Monitor product log of all quota assignments assessed and created during a CSM job, if scheduled. Internal to the product function. |
database-state.log | All | Yes | Tracks database repair operations internal to the product. |
debug.log | All | Yes | Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
gui.log | All | Yes | Not used. |
hbase.log | Easy Auditor | Yes | HBase database health check of ECA Easy Auditor status, raising an alarm to the user if HBase validations fail. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
installlicenses* | All | Yes | Summary of license key operations. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
jobchange.log | All | Yes | DR job state changes (enable, disable, etc.) made in the GUI. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
learning_mode.log | Ransomware Defender | Yes | Ransomware Defender learning mode of user behaviors and decisions made on user behaviors. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
License.log | All | Yes | Summary of license key operations. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
lightsout.log | All | Yes | Reduced-data API log to clusters; removes IP addresses from the logs for security when an API call log cannot be shared with support. |
locks.log | Cluster Storage Monitor | Yes | "Unlock my files" log for the Cluster Storage Monitor product feature, when break-lock commands fail over SSH to clusters. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
memory.log | All | Yes | Tracks product memory usage over time. |
pruning.log | All | Yes | Tracks database normal operations to reduce old records. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
query.log | Easy Auditor | Yes | Summary of Easy Auditor queries issued, with basic parameters entered into Easy Auditor, to track issues in queries for support purposes. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
ransomware_defender.log | Ransomware Defender | Yes | Ransomware Defender log that tracks security event states over time and new signals of user behaviors sent from the ECA for processing. Used to support issues with event detection. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
readiness.log | All | Yes | Ransomware Defender log that tracks security event states over time and new signals of user behaviors sent from the ECA for processing. Used to support issues with event detection. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
remote.log | All | Yes | All REST API calls and SSH commands sent to clusters for product functionality. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code. |
roboaudit.log | Easy Auditor | Yes | Easy Auditor log tracking each execution of the Robo-Audit self-test feature, for support of this feature. Internal process errors from Eyeglass process operation functions. |
securityguard.log | Ransomware Defender | Yes | Ransomware Defender log tracking each execution of the security guard self-test feature, for support of this feature. Internal process errors from Eyeglass process operation functions. |
syncmonitor.log | All | Yes | Not used yet. |
tl1.log | All | Yes | Legacy; not used. |
webhook.log | All | Yes | Notification log of the alarm post to a webhook external system; only logs if configured in the notification center. |
wiretap.log | Easy Auditor | Yes | Easy Auditor wiretap feature logs; websocket and event processing when sending output to the GUI from the Eyeglass VM. Internal process errors from Eyeglass process operation functions. |
ECA Logs
Location: /opt/superna/eca/logs
| Log Name | Product | Included in Support Data | Log Contents |
|---|---|---|---|
ecactl_conf_<date>.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | Cluster CLI commands logged for issues during configuration of nodes. |
ecactl_deploy_<date>.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | Cluster-wide CLI command logging; internal logging of steps to bring up the software to a running state. |
evtreporter.log | Performance Auditor | Yes | Performance Auditor product event processing; internal logging of events. |
fluentd.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | Syslog forwarding log data to Eyeglass for centralized logging; syslog forwarding logging of processing log data, internal to the syslog function fluentd log forwarding process. |
hbase-master.log | Easy Auditor | Yes | Database for Easy Auditor master; provides monitoring of all database instances across the cluster to roll up status information and health of the database. |
iglssvc.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | Collects ECA cluster-wide status, CPU/memory health, and forwards to Eyeglass over REST API to update the GUI on health and validations. |
kafkahq.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | GUI tool to monitor the event subsystem across the cluster; internal messaging bus within the ECA cluster only. |
kafka.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | Processing of internal messages between modules: health, status, errors, internal process status. |
profiler.stats.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | CPU, memory, and disk usage summary on each node, for support purposes. |
prometheus.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | Future use. |
spark-history.log | Easy Auditor | Yes | Easy Auditor historical search log issues, stored and indexed for all searches of the database. Internal code logging only. |
spark-master.log | Easy Auditor | Yes | Easy Auditor overseeing all search processes executing searches, reporting on them: status, errors, and health across all search modules. |
zk-cleanup.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | Cleans up Zookeeper transactions that are not needed, to reduce disk space. Run by cron; internal maintenance task. |
zookeeper.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | Cluster quorum software debug and health of each cluster witness module on the ECA. Internal code logging only. |
evtarchive.log | Easy Auditor | Yes | Easy Auditor module to save data to Isilon using the HBase database; processing rate, status, health, and errors during saving operations. Internal code logging only. |
fastanalysis.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | Ransomware Defender event analysis for user behavior, rates, health of processing. Internal code debugging only. |
hbase-rs.log | Easy Auditor | Yes | Easy Auditor database engine instance processing: health, errors, processing rates, tasks. Internal code debugging only. |
log.spark.err.log | Easy Auditor | Yes | Easy Auditor search failure log. Internal code logging only. |
spark-worker.log | Easy Auditor | Yes | Easy Auditor distributed search worker: active tasks, progress, errors. Code level logging only. |
turboaudit.log | Ransomware Defender, Easy Auditor, Performance Auditor | Yes | All products' audit data ingestion processing, cluster load balancing of audit data, HA heartbeats to Zookeeper, active file processing logic, rates of audit data processed per minute, NFS mount issues, filtering of audit data not required to reduce load, license key validation updates. Internal code level logging. |
Other Product Data
| Item | Location | Product | Included in Support Data | Contents |
|---|---|---|---|---|
| Databases | /opt/superna/db | All | Yes | Database with cluster inventory: shares, exports, aliases, SmartConnect names, quotas, and other cluster inventory. |
| Failover logs | Backup zip file | DR | Yes | DR failover logs. |
| Ransomware summary file lists | Backup zip file | Ransomware Defender | Yes | CSV from false positive or real Ransomware attacks; list of affected files. |