Skip to main content

Product Data - Eyeglass and ECA Log Content Definitions

Overview

This page defines the "System Data" and "Product Data" referenced throughout the Superna EULA and Support Services Agreements. It lists each Eyeglass and ECA log file, its location on the appliance, the product(s) it applies to, whether it is included in a support data collection bundle, and a description of its contents.

Eyeglass (SCA) Logs

Location: /opt/superna/sca/logs

Log NameProductIncluded in Support DataLog Contents
adprincipalcache.logAllNoCache of AD domain user names to accelerate GUI display and SID-to-user / AD group operations without needing AD domain availability. SIDs and AD groups, AD group SIDs for RBAC and SID-to-user-name display in the GUI. Not included in support backup files.
cacheinit.logAllYesAPI calls to cluster requests and the payload of the response from the cluster.
error.logAllYesInternal process errors from Eyeglass process operation functions, internal to Eyeglass code.
fingerprint.logAllYesInternal process errors from Eyeglass process operation functions, internal to Eyeglass code, for DR IP pool and restart process checkpoint on last status.
main.logAllYesInternal process errors from Eyeglass process operation functions, internal to Eyeglass code.
evtreporter.logPerformance AuditorYesWebsocket log of Performance Auditor GUI updates sent to the GUI.
apiaudit.logAllYesInternal API logging of modules that log each function used in the GUI to track administrator actions for security purposes of product usage. Documented in documentation.
eyeglass_installer_<version>-<date>.logAllYesUpgrade log tracking what happened during an upgrade to a specific release on a specific day and time. Support tool for upgrade issues.
phonehome.logAll (if enabled)YesIf enabled, tracks phone-home log requests and registration of the appliance, and communication issues to the phone-home portal.
audit.logAllYesDR configuration audit of the configuration data comparison between two clusters using in-memory inventory to compare shares, exports, and quota differences. Audit log generates errors in the GUI if needed to resolve differences.
backup_archive.logAllYesBackup configuration log; logs errors when the create-backup script fails to create the backup zip file.
alarms.logAllYesNot currently used; reserved for future use to log alarms created and sent to the GUI and through email.
anycopy.logAnyCopyYesAnyCopy log of user actions and API calls; only applies to the AnyCopy product license.
changemanagement.logAllYesCluster report feature comparison log, comparing two cluster reports to identify changes from one day to the next. Stores comparison data only if the feature is used; logs issues found during the comparison, which is performed in RAM.
cli.logAllYesMay contain CLI commands from igls command issues; currently not used.
csm.logAllYesCluster Storage Monitor product log of all quota assignments assessed and created during a CSM job, if scheduled. Internal to the product function.
database-state.logAllYesTracks database repair operations internal to the product.
debug.logAllYesInternal process errors from Eyeglass process operation functions, internal to Eyeglass code.
gui.logAllYesNot used.
hbase.logEasy AuditorYesHBase database health check of ECA Easy Auditor status, raising an alarm to the user if HBase validations fail. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code.
installlicenses*AllYesSummary of license key operations. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code.
jobchange.logAllYesDR job state changes (enable, disable, etc.) made in the GUI. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code.
learning_mode.logRansomware DefenderYesRansomware Defender learning mode of user behaviors and decisions made on user behaviors. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code.
License.logAllYesSummary of license key operations. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code.
lightsout.logAllYesReduced-data API log to clusters; removes IP addresses from the logs for security when an API call log cannot be shared with support.
locks.logCluster Storage MonitorYes"Unlock my files" log for the Cluster Storage Monitor product feature, when break-lock commands fail over SSH to clusters. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code.
memory.logAllYesTracks product memory usage over time.
pruning.logAllYesTracks database normal operations to reduce old records. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code.
query.logEasy AuditorYesSummary of Easy Auditor queries issued, with basic parameters entered into Easy Auditor, to track issues in queries for support purposes. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code.
ransomware_defender.logRansomware DefenderYesRansomware Defender log that tracks security event states over time and new signals of user behaviors sent from the ECA for processing. Used to support issues with event detection. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code.
readiness.logAllYesRansomware Defender log that tracks security event states over time and new signals of user behaviors sent from the ECA for processing. Used to support issues with event detection. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code.
remote.logAllYesAll REST API calls and SSH commands sent to clusters for product functionality. Internal process errors from Eyeglass process operation functions, internal to Eyeglass code.
roboaudit.logEasy AuditorYesEasy Auditor log tracking each execution of the Robo-Audit self-test feature, for support of this feature. Internal process errors from Eyeglass process operation functions.
securityguard.logRansomware DefenderYesRansomware Defender log tracking each execution of the security guard self-test feature, for support of this feature. Internal process errors from Eyeglass process operation functions.
syncmonitor.logAllYesNot used yet.
tl1.logAllYesLegacy; not used.
webhook.logAllYesNotification log of the alarm post to a webhook external system; only logs if configured in the notification center.
wiretap.logEasy AuditorYesEasy Auditor wiretap feature logs; websocket and event processing when sending output to the GUI from the Eyeglass VM. Internal process errors from Eyeglass process operation functions.

ECA Logs

Location: /opt/superna/eca/logs

Log NameProductIncluded in Support DataLog Contents
ecactl_conf_<date>.logRansomware Defender, Easy Auditor, Performance AuditorYesCluster CLI commands logged for issues during configuration of nodes.
ecactl_deploy_<date>.logRansomware Defender, Easy Auditor, Performance AuditorYesCluster-wide CLI command logging; internal logging of steps to bring up the software to a running state.
evtreporter.logPerformance AuditorYesPerformance Auditor product event processing; internal logging of events.
fluentd.logRansomware Defender, Easy Auditor, Performance AuditorYesSyslog forwarding log data to Eyeglass for centralized logging; syslog forwarding logging of processing log data, internal to the syslog function fluentd log forwarding process.
hbase-master.logEasy AuditorYesDatabase for Easy Auditor master; provides monitoring of all database instances across the cluster to roll up status information and health of the database.
iglssvc.logRansomware Defender, Easy Auditor, Performance AuditorYesCollects ECA cluster-wide status, CPU/memory health, and forwards to Eyeglass over REST API to update the GUI on health and validations.
kafkahq.logRansomware Defender, Easy Auditor, Performance AuditorYesGUI tool to monitor the event subsystem across the cluster; internal messaging bus within the ECA cluster only.
kafka.logRansomware Defender, Easy Auditor, Performance AuditorYesProcessing of internal messages between modules: health, status, errors, internal process status.
profiler.stats.logRansomware Defender, Easy Auditor, Performance AuditorYesCPU, memory, and disk usage summary on each node, for support purposes.
prometheus.logRansomware Defender, Easy Auditor, Performance AuditorYesFuture use.
spark-history.logEasy AuditorYesEasy Auditor historical search log issues, stored and indexed for all searches of the database. Internal code logging only.
spark-master.logEasy AuditorYesEasy Auditor overseeing all search processes executing searches, reporting on them: status, errors, and health across all search modules.
zk-cleanup.logRansomware Defender, Easy Auditor, Performance AuditorYesCleans up Zookeeper transactions that are not needed, to reduce disk space. Run by cron; internal maintenance task.
zookeeper.logRansomware Defender, Easy Auditor, Performance AuditorYesCluster quorum software debug and health of each cluster witness module on the ECA. Internal code logging only.
evtarchive.logEasy AuditorYesEasy Auditor module to save data to Isilon using the HBase database; processing rate, status, health, and errors during saving operations. Internal code logging only.
fastanalysis.logRansomware Defender, Easy Auditor, Performance AuditorYesRansomware Defender event analysis for user behavior, rates, health of processing. Internal code debugging only.
hbase-rs.logEasy AuditorYesEasy Auditor database engine instance processing: health, errors, processing rates, tasks. Internal code debugging only.
log.spark.err.logEasy AuditorYesEasy Auditor search failure log. Internal code logging only.
spark-worker.logEasy AuditorYesEasy Auditor distributed search worker: active tasks, progress, errors. Code level logging only.
turboaudit.logRansomware Defender, Easy Auditor, Performance AuditorYesAll products' audit data ingestion processing, cluster load balancing of audit data, HA heartbeats to Zookeeper, active file processing logic, rates of audit data processed per minute, NFS mount issues, filtering of audit data not required to reduce load, license key validation updates. Internal code level logging.

Other Product Data

ItemLocationProductIncluded in Support DataContents
Databases/opt/superna/dbAllYesDatabase with cluster inventory: shares, exports, aliases, SmartConnect names, quotas, and other cluster inventory.
Failover logsBackup zip fileDRYesDR failover logs.
Ransomware summary file listsBackup zip fileRansomware DefenderYesCSV from false positive or real Ransomware attacks; list of affected files.

See Also