Skip to main content

Monitoring Scope

Review a full list of object types and activities monitored on Pure Storage FlashArray with the add-on.

ObjectActionProperty
File, FolderAddedWho, What (path), Where (server), When, Workstation (client IP), Protocol (SMB/NFS)
File, FolderRemovedWho, What, Where, When, Workstation, Protocol
File, FolderModifiedWho, What, Where, When, Workstation, Protocol
File, FolderModified (owner/attribute change)Who, What, Where, When, Workstation, Protocol, Owner (SMB only; not available for NFS or if ACL enrichment is disabled)
File, FolderModified (permissions/DACL change)Who, What, Where, When, Workstation, Protocol, Permissions (SMB only; not available for NFS or if ACL enrichment is disabled)
File, FolderRenamedWho, What, Where, When, Workstation, Protocol, Name (before/after)
File, FolderMovedWho, What, Where, When, Workstation, Protocol, Path (before/after)
File, FolderAdd (Failed Attempt), Remove (Failed Attempt), Modify (Failed Attempt), Rename (Failed Attempt), Move (Failed Attempt)Same properties as the corresponding successful action, for access-denied attempts

Notes:

  • The add-on reports What as a \\server\share\... UNC-style path for SMB events. For NFS events, it reports the path exactly as FlashArray provides it — a native Unix path — since there is no Windows-style UNC equivalent to convert it to.
  • Owner and Permissions "after" values require SMB and ACL enrichment enabled in the add-on configuration; they are never available for NFS events.
  • If you configure a Monitoring Plan in the wizard, every activity record also includes its name as a detail.