Hello is anyone else using Dynatrace to make API calls to Active IQ? We are wondering if there any resources to help us log relevant events to Dynatrace to setup both metrics, monitoring and alerts. Is this possible? Support states that only snmp traps are available but we see API support for Active IQ. Any help would be appreciated. Thanks everyone!
#╰・software
1 messages · Page 1 of 1 (latest)
We found this https://docs.netapp.com/us-en/active-iq-unified-manager-910/api-automation/concept_api_url_and_categories.html#categories so there is some API support... but maybe not for the customers? Do we have to become a partner to use this?
We are looking for the elusive.. "Unified Manager API Developer’s Guide " which is specified on these pages but there is no link to it. Very helpful. 😉
oh bless you oyoy! Thank you thank you!
Actually Google sometimes give better results than searching on NOW. I just googled what you wrote, "Unified Manager API Developer’s Guide ".
You probably want a newer version, which you can find on docs.
It's a great start that will help us experiment with our monitoring architects today in doing some test runs. I've requested an updated copy from our account manager along with a meeting with their API support team if possible. Thank you again. Yes Netapp's internal search is pretty worthless. Seems like it's siloed from the "good stuff"
this is the updated link from the 9.11 doc. this link is the equivalent of the pdf oyou linked, it's just no longer called that, and no longer provided as a pdf.
https://docs.netapp.com/us-en/active-iq-unified-manager/api-automation/concept_um_apis_list_intro.html
but if you compare the sections, you'll see most of the topics are the same.
and, i see where the confusion may be coming from. it's talking about the developer's guide when that section of the doc is not called that anymore.
i'll see if we can get that updated.
hi all! looking for some advice on this pls.. we recently had one of our controllers fail a failover after one of our SFP + Disks (root aggregate) failed at the same time, not entirely convinced this was the cause but that's all we can see. we engaged our vendor and they said there was no controller failover, but there was an EMS event on the dashboard stating a controller failover attempt failed so clearly something happened. it took all data LIFs down on the controller, so naturally our VMware environment saw APD and HA fail overed the VMs.
any advice on how to troubleshoot this please as we are a bit stumped? we went engaged our reseller support and they are stating there was no failover attempt but there clearly was based on the EMS event
Are the controllers sending ASUP?
Yeah that’s what I’m thinking, if we are getting the data then opening a case for this will be the quickest way to understand
we had to go through Lenovo (dm7100f) 😦
but Lenovo are saying there was no failover
if it said controller takeover failed, that means that the node failed but failover didn't work
"system node show" will show the controller uptime
ask them to explain why one of them is only a day or so, then ask to speak to level 2 support would be my suggestion
If you can get them to open a ticket, give me a ticket ID and dm me your contact details and I'll reach out to our contact there
Is there any GUI issue with ONTAP 9.11.1 ?
I just upgrade FAS8200's firmware ONTAP 9.9.1P4 to 9.11.1.
GUI is doesnt work!
Jul 29 13:35:56 snfilerN2 [filer-02:sp.firmware.incompatible:ALERT]: The SP firmware version 5.7 is not compatible with this version of Data ONTAP.
And after upgrade firmware SP error was shown
Hi @sturdy orbit When you say 9.9.4, do you actually mean 9.9.1 or 9.4? As there is no 9.9.4
9.11.1 does not include an SP firmware update for the FAS8200 system, so I would suggest manually updating the SP firmware to 5.11 Version.
SP 5.11 is compatible with FAS8200 and ONTAP 9.11.1.
Regarding your GUI issue, that def is not an expected result post an upgrade, so would suggest raising a support case.
oops i mean 9.9.1 P4
When you upgraded to 9.9.1P4 it should have also upgraded your SP firmware to 5.10, but for some reason that did not happen.
As 5.10 SP FW is bundled with 9.9.1P4.
https://activeiq.netapp.com/system-firmware/patch/9.9.1P4 for reference of where I went to check out what fw is bundled with a particular ONTAP release.
You may want to also check the BIOS version is correct too.
BIOS 11.11 is bundled with 9.9.1.P4.
11.15 is bundled with 9.11.1, so curious if that is updated.
Sometimes have to restart the SP first to get it to update.
system service-processor something something
regards
Good point @maiden depot. @sturdy orbit to your question on how to upgrade via ONTAP CLI, the steps are documented on the Downloads area for the particular SP firmware you wish to use, in t his case its 5.11 for the FAS8200 - https://mysupport.netapp.com/site/downloads/firmware/system-firmware-diagnostics/instruction-viewer/SYSTEM/30804094_SP/system-installation-instruction?fileName=index.shtml
thanks Mr. Ross.
Always-ALWAYS reboot all service processors before attempting any update. Does not matter if that is ontap or just a plain sp/bmc update. REBOOT the sp/bmc. I’ve actually seen systems get bricked during the update and if the sp were just rebooted before it would not happen. I think it’s even in the upgrade notes to do this now. Save the hassle and reboot the sp/bmc. This ends my public service announcement
How can I take over the qtree and quota information when I use CIFS service in 7mode ontap? Because CIFS service is on, takeover is not running normally.
And have one more question!
Does the lack of GUI access after the upgrade of ONTAP 9.11.1 relate to SP firmware?
Suggest contacting support. As already stated previously, the GUI not working is not expected behavior after an upgrade.
This KB article may be relevant to you - https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/After_upgrading_ONTAP%2C_System_Manager_and_API_are_failing
good day everyone!
i am new to this and i hope i am on the right channel for this topic:
does anyone have a list, what is taken with a migration from old netapp to new netapp system? which configuration is inherited or transferred?
I do not know all migration variants (there are such as well-known as e.g. via SnapMirror. I have known Cluster Join, vol move and then unjoin). is there an article where you can read (indepth also fine), the variants, differences, advantages, disadvantages and which configurations/IPs/settings are taken over?
My question originates from following: at the moment at the customers netapp the configuration backup is being tried to set up but network does not work and wont allow the configuration backup to be uploaded outside their network. This old netapp is replaced in about 1 year and therefore we think to to consider, whether the Troubleshooting is worthwhile now or we simply wait until the new netapp comes and is migrated there (via cluster join, vol move, cluster join). instead going through the trouble to set it up twice.
Last time i did a hardware replacement by headswap / aggregate relocation it took 12h and NetApp support locking out one of the techs they keep in the celler...
I learned some new cli spells I hope I never need again.
-the services was online the whole time, though! 👍
(going from 80x0 to 400. The cluster ports changed)
thank you for your answers and the doc to it, too!
it is used as a CIFS Filer commonly, so it should be NAS.
we went from old FAS8020 to FAS8300. It was i guess Ontap 9.3 or 9.5 (old filer) up to 9.8 (new filer) if i recall correctly.
I'd go the vol move method. That's pretty straight forward and no downtime.
Agree. But you'll need cluster switches and be able to add new controllers to cluster.
Yeah. a lot of partners will have temp ones. (we did when i was at a partner)
worth asking about.
Or you can buy CN1610s for very very little money on eBay - like $200 each
Can somebody explain what is the purpose of volume path ? It's different than junction_path.
If I have a volume called vol1 , the volume path is /vol/vol1 whether a junction path exists or not, and independently of the junction path value.
I've only seen it used in two places, with volume efficiency (sis) and when building a LUN path /vol/vol1/lun1 or /vol/vol1/qtree/lun1.
Also, is it always /vol or can this be configured?
I think it is when the old 7-mode underpinnings come through the cluster shell.
Another command that uses it is reallocate. I don't think it is configured.
Junction paths are for mounting volumes under other volumes. That's why you have a SVM root volume in NAS SVMs, then each volume under it is a junction path.
Yeah it’s the old 7-mode path structure, there’s some KBs about it
Yeah it's 7mode carry over. There's an option in the 7mtt to remove /vol/ it while transitioning.
don't think anyone has ever used it though 🙂
we used it with 7mtt to transition over to clustered. made it simple to keep the same structure for those super ancient apps that the sme's never quite want to decom, so we always have to support it
for all other migrations though, we removed it with 7mtt
any have the 9.11 changelog? im specifically looking for snapvault/mirror defaults and UI changes.
<paging @whole nova>
hey chris, just looking to see if 9.11 is worth getting out of bed for.
What would you be moving up from?
varies from 9.7. 9.8 & 9.10
some are hard stopped at 9.7 until ontap is fixed so just been waiting unit ontap is closer to the way it was before upgrading the rest of the stuff
9.8+ was such a kick in the face future generations will know how much i hate it.
there were a few big things i was waiting on... like manual aggregate creation in the ui, snapvault default relationship stuff, more reasonable UI with more logical flow etc
and everytime i search for ontap 9.11 release notes i get a bunch of cloud volumes related crap that i dont care about
Chris is out for the night and said he would stop by in the morning to rap with ya. He’s one of our ONTAP PMs that can help you break that down. Or some of the other field guys here. For me, seeing the auto update and other stuff in SysMgr are long overdue.
Release notes are here, you’ll need to login to get them, this covers a lot of stuff but you’ll want Gebs or one of the others to go into detail on UI/UX improvements. They are there, we do hear you and it’s being worked on (I just don’t remember which changes are in which versions so I’m not gonna comment too much). https://mysupport.netapp.com/documentation/productlibrary/index.html?productID=62286
❤️
on a side note anyone know when netapp support site will allow SMS or external MFA authenticator apps?
i think i asked that before, i believe yall said it could be integrated with adfs?
i should probably dot hat if thats teh case
@brazen jetty would likely know one way or the other
Check out the Federation section of this article:
https://kb.netapp.com/Advice_and_Troubleshooting/Miscellaneous/FAQs_for_NetApp_adoption_of_MS_Azure_AD_B2C_for_login#What_is_Identity_Federation.3F
Anything "external" will probably not happen unless MS implements it
perfect thanks the netapp federation request form is simple enough 😄
We're already at 9.9.1 and going to 9.10.1. 9.9.1 wasn't too bad - some nasty bugs fixed in the latest P releases. 9.11 is too bleeding edge for me. My workload is almost 100% NFS and a LOT of it (EDA).
our workload is 99% NFS 😄 a ton of snapvault stuff going on and very few production CIFS shares my only real compliants with 9.8+ is the UI we have 9 clusters many of which are silo'd so we don't really externally manage them
so system manager and cli for them
but a lot of that has already been discussed here at length and im ready for healing to begin
so looking towards the future to see if netapp actually is listening.
The same - bunch of snapvaults plus very few CIFS shares. We use almost 100% cli for management plus ocum for reporting.
that reminds me my ocum is super old. need to update lol
@meager vector since 9.8, I have been working to get early versions of ONTAP and specifically System Manager into the hands of users for their feedback. With 9.10.1, we opened up a virtual EAP (Early Access Program) to all partners and customers. You login to https://handsonlabs.netapp.com and spin up the Early Access ONTAP and ONTAP System Manager 9.11.1 v1.1. Much of what you are looking for is going to be in 9.11.1. Look for the next version of ONTAP to be in handsonlabs in about a month or so. Its not guaranteed but that's the goal. For the future versions @brazen jetty can add you to the EAP Community for each release and you can then provide direct feedback to product management through that community. Of course you sign a virtual NDA when you join the EAP program so we ask that you don't share publicly the contents of a particular EAP. Hope this helps. If you want specifics, we can chat.
Yeah you can. I would if I were you.
Hey guys...
can someone answer me of ONTAP S3 provides the atomic rename functionality Apache Iceberg needs? (https://iceberg.apache.org/spec/#file-system-operations)
Best Flo
Hi , I have an ontap 8.2 system which is all CLI, I am not very confident if i can manage it via CLI, is there any way to activate the Web management , i did try the httpd.enable on , but then it started giving error for indexing not enabled
Its an Old system which was configured to give our NFS3 share , i did map the share to a windows server to try to delete a few files to clean up but it says i do not have the permission to do it.
Hi @blissful musk, This is neto from Brazil. How are you? If I remember of the top of my head, you need to install OnCommand System Manager (Windows or Linux) to manage it.
Nice, i will try this link .
please let me know how it goes.
everytime i searched for it the result came back negative
wont allow me to download without login
"Starting with Data ONTAP 8.3, OnCommand System Manager is a bundled component of Data ONTAP,"
as you are in 8.2, please try to install it and let us know.
Thanks for asking and joining NetApp Discord 🙂
Hit a Support wall... wont let me download unless i login, 😢
registered as a Guest... but something tells me that wont be enough to download that software as the account is still pending
Support entitlements are required to download software, yes.
So basically Pay for support to be able to Download the software which is necessary for management of a legacy system.
what is the CLI command you are looking for?
In other words, what would you like to do using GUI?
he mentioned it here
check your current exports with the cmd: exportfs
To map to Windows, you need to use CIFS not NFS. Windows has a terrible NFS stack.
Does the exporttfs also give out the permissions of the NFS?
its mapped to a Veeam backup
Windows unfortunately
if this is UNIX, you are ok to delete the files (based on your export policy)
is this a 7-mode? qtree status
Thanks @plush storm for the message. I missed it 🙂
qtree status
Honetly not sure... The only exposure i ever had to the Ontap system is from the ontap 9.7 web ui
thats to just expand the volume etc
do you want to delete files (created via unix) in a cifs share (mapped to a VEAM windows server). is that correct?
Veeam wont work unless i delete some stuff from the 8.2 and the 8.2 wont let me delete some of the older files when i map it from a windows client
If there were ever a place to learn your way around the CLI, this group of rockstars here will help!
yes
ok
the veeam is hosted on a windows server
ok
please type qtree status on CLI
tell me if the qtree or volume that is "shared" is UNIX or NTFS
superman::> qtree status
Vserver Volume Tree Style Oplocks Status
db cl_repo_rman_repo_20190613112131 "" unix enable normal
db db_root "" unix enable normal
db foo "" unix enable normal
db goofy_orabin_40 "" unix enable normal
db goofy_oragrid_53 "" unix enable normal
db mickey_orabin_10 "" unix enable normal
db minnie_orabin_20 "" unix enable normal
db netofrombrazil "" unix enable normal
something like this
unix enalbeld normal
ok
if this is UNIX, probably you need name mapping to delete the files .... like root == administrator.
do you want to access this using UNIX as well or ONLY windows?
vol_veeam_01 unix enabled normal <<< its this volume that i wanna go into and delete some older files
got it
only have windows with me
ok
but i do have linux
Is CIFS set up?
if you go to windows box (cifs share) and try to create a folder, does it work or not?
I think the command is cifs status
yes it can be mapped using the mount x.x.x.x:/vol/vol_veeam_01 z:\
can you create a new folder called paul?
so cifs server is up
easiest would be to try it via NFS on your linux machine
but I let neto handle this 😛
- change the security to NTFS which will probably give everyone full control
or
- do what @OG1 said very well... Map using NFS (linux) and delete.
linux is good too i have a mint linux VM for just testing etc
cool let me try that
no
ok
just the veeam backup is going to do all the writing
go to #2 from OG1 suggestion.
i just need to make 1TB space for the backups to kick start and clean themselves up
Thanks for the help, let me try it
Many thanks, I need to re-setup the VM
HI a bit of update I managed to mount the volume in Linux "sudo mount 192.168.72.136:/mnt/sharedfolder /mnt/client_sharedfolder"
But it still doesnt have write permission, unable to delete anything
Error you require Permission from S-1-1-0 <<< error on windows,,,, on linux the Delete command is basically blanked out
Hi, I managed to mount the volume in Linux "sudo mount 192.168.72.136:/mnt/sharedfolder /mnt/client_sharedfolder"
But it still doesnt have write permission, unable to delete anything
Error you require Permission from S-1-1-0 <<< error on windows,,,, on linux the Delete command is basically blanked out
Is there any command for me to be able to check the vol_veeam Voume permissions?
once in a while i'd see the error HTTP XML Authentication failed from 192.168.72.136
Are you root on your VM?
Check the export policy on NetApp to see if there is root permission to delete the files
Yes i am su root
Check the export policy on NetApp
Maybe the root access is not writable (e.g., mnt)
Sorry would be easier to see it 🙂
Can you give me a CLI command please i could paste the data here
not sure how i can get vol vol_xyz infor from the cli
vserver export-policy check-access < gave an error vserver not found
tab complete is your friend with the (cdot) CLI - example -
`WOPR::> vserver export-policy check-access -vserver NFS -volume NFSData02 -client-ip 192.168.1.44 -authentication-method none -protocol nfs3 -access-type read-write
Policy Policy Rule
Path Policy Owner Owner Type Index Access
/ default NFS_root volume 1 read
/NFSData02 default NFSData02 volume 1 read-write
2 entries were displayed.
WOPR::>`
For this command though you will need to know the vserver name, volume name and IP
It is 7 mode I guess
ah oh. yeah missed that. vserver not found, vs vserver is a required field.
Already provided some examples 🙂
all thanks to @inner oar Finally managed to get it to work and yes he did a lot of hand holding
Again many thanks
NetApp - we love this company.
@brazen jetty @true finch - we used shared screen - amazing - did everything using my phone. It was great
Glad to help my friend, @blissful musk
Stay safe
Love you guys
Nice, it’s great that you’ve got all the options you need to get things solved
It’s great to see this kind of interaction 🙂
Honestly i was going nuts for past 2 days because of it...
Fantastic! The Meeting Rooms down below are there for anyone to use anytime! You can do voice, turn on cameras and share screens!
Hi everyone, hope you are doing well. Our company has storagegrid 11.6 and we - as developers - have started using it recently, together with k8s and trident (both are great btw:).
Looking at https://docs.netapp.com/us-en/storagegrid-116/ and not being able to find an answer to my question, I would like to ask here: AWS has a concept/feature (instance profile?) where I can create a IAM role, assigned it for example to the EC2 instance, and then when my java application that runs on that EC2 instance tries to get data from S3, it first fetches S3 secrets at runtime and uses them to execute those GET/PUT/DELETE requests it wants. This has a big advantange of not needing to store any S3 secrets beforehand somewhere in the EC2 or e.g. kubernetes configmaps/secrets.
As I am not perfectly familiar with AWS (rather onprem environment), I was able to find this https://docs.databricks.com/administration-guide/cloud-configurations/aws/instance-profiles.html (step 1-3) which describes how to go about it. So my question is simple: Does storagegrid support that kind of feature, where I could avoid storing S3 secrets in some file?
Learn how to set up instance profiles and use them in Databricks to access S3 buckets securely from your Databricks clusters.
Is there a way to show data reduction on individual volumes representing in a X:1 fashion?
@gusty ocean SG provides only S3 service. While it behaves very much like AWS S3, it's IAM setup cannot be compared to how AWS does it. It supports Bucket Policies and Group Policies though. Both behave similar to how AWS implements them and together, you can have pretty granular control over authorization.
Hi. Does anyone have SnapCenter experience? I’m trying to figure out how to create a publicly viewable report that mirrors the Resources/MSSQL databases listing tab in SC and sorted by last backup time. It seems possible with the powershell commandlets, but looks like it will take a lot of commands and massaging of output to achieve anything reasonably similar.
@ripe igloo I have talked to our support team that has some knowledge about SnapCenter reports. Though helping create reports is out of scope for support they do say that you would need to run a series of SC cmdlets to collect data and then build out a hierarchically organized custom PowerShell object to contain your DBs. Something like SQL instance/AG > Node > DB > last backup, or whatever data you want. So it appears your expectations are correct.
im having a brain fart, i want to inilizize some snapvault relationships but do so on the protection policy schedule (11pm) was there a way to do that.
i almost always just initialize immediately but i cant in this case
nevermind i got it lol
is there a TR for setting up NVME over TCP for VMware.. we have A400's running ONTAP 9.10.1P6 and ESXi 7.0 Update 3f
Hello guys how are you? quick question, someone knows how to get an IP from an eseries? i have access to the console, but there is no command to get that information
What model of E-Series do you have?

Message #╰・software
E2724
Try DHCP (connect with mgmt port 1, not 2), else use the provided IP mentioned in the guide
yes we tried that, but it seems the customer already put an IP and now he dont remember
though console is possible to know that IP?
If I remember correctly the console connection is really only for NetApp service
you should be able to change the IP there but you need to find the login credentials... Google should help
But I'm not entirely sure what the supported way would be to factory reset this system (or only rest the IP back to DHCP again)
At least without a support case...
ok thanks i understand
Is this system sending ASUPs back to NetApp? If so you might be able to view that info from ActiveIQ Digital Advisor or at least customer can. If you're viewing the specific ESeries system in AIQ Digital Advisor you can click on the Auto Support menu option, then loo kat the "STORAGE-ARRAY-PROFILE" section, which has ip address information for the ports. System would need to have active entitlement though access this info on AIQ Digital Advisor (aiq.netapp.com).
Otherwise support can look at the same ASUP info and share the details (if the system has entitlement).
The SANtricity Storage Manager Client actually will scan networks you tell it to in order to discover e-series... might be the easiest method
is it possible to update BIOS firmware if I only have access to the service processor?
you'll need to be able to get to a LOADER prompt in order to run the update_flash command
so, yes and no?
you don't need to be in ONTAP, but you can't do that from the SP that I'm aware of
If I'm wrong there, I hope someone can teach us both a new trick!
To update the BIOS, ONTAP can't run (just like you can't update the BIOS of your laptop if your Windows is still booted).
Since ONTAP is not running any management LIFs from ONTAP are not available.
So to access the LOADER prompt you can either connect via console or you access the SP/BMC of the relevant node via SSH (this IP stays online since it's OOB management) and type "system console". This will basically "jump to console" and you will see the same as with your connected console cable (which is the LOADER if ONTAP is not running).
console! I forgot about that!
There ya go @faint viper!
SSH to SP
system console
LOADER-A> update_flash
already tried that earlier. It shows updating from 13.12 to 13.12, but I am trying to update to 13.13
can I transfer files over the SP?
like I said... I have no connectivity to any other ports
what model system ?
AFF A800 - Ontap 9.10.1
so no mgmt access what so ever? just SP login?
I can 'system console' from the SP
so you can get here:
` ssh admin@192.168.1.223
admin@192.168.1.223's password:
SP WOPR-01> system console
Type Ctrl-D to exit.
SP-login: admin
Password:
- This is an SP console session. Output from the *
- serial console is also mirrored on this session. *
WOPR::>`
yes
is the A800 connected to a network that has a http or ftp server?
from there you can run system firmware download -package URL
but will that communicate through the SP?
is that the only port that is physically connected?
yes
ah ok
Support will need to assit with that KB, There is also a version via USB, support case is also needed.
yeah, I was looking into that by running 'system firmware download -package '
That would work, if you could plug something in to e0m
URL schemes include FTP, FTPS, TFTP, HTTP, HTTPS, GOPHER, SMTP, SMTPS, MAILTO, NEWS, NNTP, TELNET, WAIS, FILE, PROSPERO.
I'll contact tech support. Thank you
Here's the USB via cluster shell info - https://docs.netapp.com/us-en/ontap-cli-9101//system-node-firmware-download.html
I have that bookmarked already... was hoping to do this before next week. I won't have anyone to assist me on site until then.
alright, scratch the KB I sent ya. I went looking at the details and it's saying to point scp to the node mgmt ip, not the BMC.
sorry about that.
Though you could open a case saying I need to do this but via the BMC.
ah ok
wonder if SP only supports ssh
I was wondering if there is a way to pull the firmware from the other node
node A has what I want
There is a way to cross mount the mroot, but also requires support.
I checked the loader method doc btw. it also uses e0m
darn... seems I am stuck waiting for someone to assist on site. I appreciate all the info though, thank you!
no prob!
oh, now I'm getting it... the A800 has that dedicated BMC port
Error: command failed: Modification not permitted. Changing the volume language is not supported for a SnapMirror source volume.
I need to change a volume from C.UTF8 to utf8mb4.
We just setup SVMDR so its still not in a properly initialized state
I'm not sure. I checked the docs and it doesn't show language in the SVMDR matrix of what's what.
could be worth a support case at this point. the notes on that KB say contact Support.
activeiq mailed me about a pending ontap update, but now that i login i see nothing. currently running 9.11.1. is something coming?
ONTAP 9.9.1P11 released yesterday, so that shouldn't be it. I don't see any "new" 9.11.1 flavors on NSS either.
right. thanks!
@whole nova might know what's up
I have a general question regarding configuring audit logs on SVMs. One of the requirements is that the audit logs have a destination folder to write the logs to, how do I go about creating an audit log folder? I have tried to create a folder off of the root called audit_logs and then when I issue the vserver audit create command i pipe that to the -destination option but i keep getting the same response back when I issue the command
Error: command failed: The specified path "/audit_logs/" does not exist in the namespace belonging to Vserver
not sure if there is a better channel to post that on, if so let me know
can you share the mail you got in a private message please? might be able to help if I see what it says
nvm i figured it out via the following NetApp community post
Just saw this come through
ONTAP 9.10.1P7 has been published on the NetApp Support Site
Hi all, short question about AIQUM. Are there any plans to change the upgrade process? I'm thinking like you can upgrade a cluster over the UI. Since we have an environment with around 12 instances the way over the vCenter is a bit slow.
what version of ONTAP are you on currently?
i got a problem i cant seem to track down, i have a volume with the same snapshot policies as the rest on this particular cluster but its only doing a single daily the rest of them are fine. using a custom snapshot policy anything to look at offhand?
nevermind, i manually resassigned the policy from the cli and it started working who knows what that was about
¯_(ツ)_/¯
Yes this would be good.. A lot of times you dont have vCenter access and its a pain working with other teams to get it done. i get the issue is mounting the ISO
The text is incorrect in the blue field which points to the image with NVE... both blue fields indicate "without NVE" . I threw a case @sharp scroll
Thanks. This is fixed now
Hey peep, was wondering if anybody here had a deck on the new ontap ransomware feature. I would like to prepare a presentation on the same.
Hey @thorny musk we have a bunch of blog content out atm about that topic and a Technical Report - https://www.netapp.com/media/7334-tr4572.pdf . Not sure if we have a customer facing deck. If you're a partner you may have access to our Field Portal where there might be some content accessible for partners on the topic.
Thanks
quick question. Is anyone in here favoring "system node image update" over "cluster image update" to upgrade on ONTAP 9.7 or later releases and if you use "system node image update" why do you do so and what would convince you to use "cluster image update"?
I had a customer that was using node image until a about two years ago. Finally convinced them to use cluster image after they did a manual reboot of the wrong node at the wrong time for the umpteenth time and caused another outage.
why is the option there to begin with for node?
seems like any potential use case for node could instead be bundled into a switch for the cluster image command so it forces the user to think about if they need to use node v0v
use cases are going to be edge cases i think. i have to use node image in my lab vsims, because there is no storage ha.
allowing non HA upgrades (diag option maybe) would work for me.
dawnr-cl::> cluster image update -version 9.11.1 -pause-after none -ignore-validation-warning true -nodes dawnr-cl-01,dawnr-cl-02
Error: command failed: The list of nodes should contain HA pairs only
i've seen some customers using vsims as well, i'm not sure how many are single node clusters, or 2 non-ha nodes like mine
if there's a way to do this with cluster image, i'm all ears. i just fell back on what i knew worked from long ago.
Same. Heck I still do "sis status -l" on CDOT.
and early on (pre 8.3 or 9.0 at least) i don't think the cluster image update was a thing.
I switched to cluster image update about 9.3 or 5? I think. before that was manual.
manual updates of multi node 8.1 to 8.2 to 8.3 cdot was fun.
cluster image update with Single-Node Cluster should work... it will just be disruptive and reboot the node
I think it also works with 2-Node MCC-FC
we have switched to using cluster image update since some years ago and in I would say 99% it works perfectly
the only thing I'm still hesitant to use are these multi-hop updates where you give it both images, validate the lower version and let it update to the higher one
Anyone has experience with modifying NFS -tcp-max-xfer-size ? I'm following Oracle databases on ONTAP document and it recommends increasing it to 262144 which makes sense. I was thinking that increasing the value shouldn't impact or make any difference for existing connections but when I try to do it I get the following warning Warning: Setting "-tcp-max-xfer-size" to a value greater than the configured TCP transfer size could affect the performance for existing connections. Contact technical support for guidance. Does anyone know if this could really impact existing connections ( or the ones that will still have the mount options set to lower than limit ) ? The contact technical support part makes it seems like it is not something I want to change.
@humble stratus is who you’re looking for 🙂
I had a customer set it to 1G! I convinced them to make a new svm and deploy it there in case anything wonky happens. Certain applications love the larger xfer-size
A400 was slower than a vm serving nfs using 1g xfersize until they flipped the option
And if you read the message it could affect existing connections. So the way I read that is set the option and be sure to unmount/Mount or reboot every connected client
probably best to take a look at nfsstat and see if the connections are actually pushing big writes before one goes crazy on max-xfer-size
are there any known problems with config advisor and Metrocluster-IP configurations? I'm able to run the job and i get results for all nodes and switches, Visualization also works however in the Results page I only get "Data is not available" and in the Rules section "Rules are not available for this job"
there should not. at least nothing I heard of.
It's a max value, so if the current clients aren't requesting the max then nothing will change. The value is generally only read at mount time, so existing clients won't be affected until they are remounted. The concern revolves around impacting the network by increasing the amount of data requested. This could cause bottlenecks where none existed before. You are looking to increase the value to 256k. We haven't seen any problems at that point that I'm aware of.
As always, (If you can.) be smart and only make one change at a time so you know which change has been the impactful one.
Thanks Scott!
📢 ONTAP 9.11.1P1 has been published to the NetApp Support Site
Strange question.. does anyone know if you can find out the hostname or ip of your AIQUM server from the ONTAP cluster ?
ahh thats it application-record show
Yup you got it. 👌
every time a customer says "nah, we don't use any other NetApp software, there is nothing to check for interoperability" I do "application-record show" and tadaaa there is stuff connected...
"oh I didnt know this VM is still running" 🙃
so looks like im still having some odd behavior for a local snapshot policy on a single volume.
i have a snapshot policy assigned to an SVM. there are 4 volumes 3 of them are working with the custom snapshot policy just fine
one of them seems to be kinda using..both the custom policy and the default policy
(custom policy has every 2 hour)
looking at the volume details it shows the correct policy is assigned
i had re-assigned it manually last week and thought it fixed it because the 2hour started to appear
but its still running 2 daily snapshots from the default policy instead of 14 from the custom policy
Verify: snapshot show -fields create
They may be leftover snapshots from the original policy. You may need to delete them manually
it continues to create dailies (only 2 of them from the default policy) it does not create any more than the 2 and deletes any older than the latest two (new policy has 14 dailies)
Might need a support case to get to the underlying cause on that one. Might be something simple or not.
I'm assuming the CIFS Audit logging that ONTAP does is not accessible via API or Powershell?
yah i guess ill submit a ticket :/ nope this particular system is silo'd from everything else and we have some regulatory stuff dictating access.
Hello, I have a problem with my FAS2520, on the ontap 8.3, I deleted all the aggr (not the root ones), but I can't delete the Storage Pool, it always says one or more aggr are using it. Can someone assist me on this?
what's the output of the following - set d; debug vreport show
and "node run -node * aggr status" as well.
I migrated AIQUM from one host to another, using backup/restore. The restore configured SSL/HTTPS on the new system. Now I need to remove the certificates. My problem is that the GUI will not let me re-generate the certificates. My guess is because the hostname is not the same as what is configured. My question is: How do I regenerate the certificates for my new host?
your call is important to us on hold for 43 minutes and counting
lol of course they answer as soon as i say that
I like to think someone in support saw your message and rushed to start their shift early for you 🙃
Probably Paul. /s 😄
lol
so there seems to be a number of weird issues im having with this particular system. (2750 running 9.9) the alreayd mentiond snapshot policy issue ona single volume, now im noticing disappearing efficiency policies. (they become unassigned) the SIS changelog filling up and other weirdness.
Is there some documentation how much throughput is needed for the MCC-IP peering?
so for the CRS stuff
probably in the Arch TR
I'm sizing a ASA A400 MCC-IP with only 32Gb FC frontend
customer only really needs FC and no ETH, but I need some ETH for peering
You're a partner correct?
checked the TR-4689, but doesn't really say anything how throughtput, latency, etc, needs for CRS
yup
in that TR. page 15. there is a link to the ISL sizing calculator
will check the SE pres now 😛
but the ISL is only for mirroring the data via iWarp and SyncMirror
peering goes to the customer ETH network
unless youre snapmirroring from one side to the other, I don't think it would matter, but let me dig
I know it's not too bad if the cluster peering is down since the replication will catch up, but still I can't find any documented requirements of the MCC peering
nah, for peering to other clusters (to snapmirror volumes for exmaple) we always use other intercluster-LIFs in separate IPspaces
it will only be CRS replication on these intercluster-LIFs... I'm really just trying to find out if maybe 1GbE would be enough... we could host all management LIFs there plus the intercluster-LIFs
I only find this page: https://docs.netapp.com/us-en/ontap-metrocluster/install-ip/concept_considerations_peering.html but there are no clear requirements mentioned
no problem, we have time 🙂
it's my first ASA MCC-IP with FC-only
ASA MCC-IP is probably one of the longest acronyms when spelled out in the netapp eco system.
That also sounds fun.
All Storage Area Network All Flash Fabric Attached Storage Metro Cluster Cluster - Internet Protocol
I migrated AIQUM from one host to
does anyone have a high level list of tasks that wipeconfig does ? I need to send an email to a client about what it does..
You mean outside of a factory reset of the root vols/system of the cluster, wipe any existing config and zero all the drives?
Note: It won't touch the SP/BMC
yeah i think thats high level enough..
Anyone here work with the Powershell tools at all I'm trying to reclaim space on a LUN and having a bear of a time.
Is this a bug in the software? No matter how I try to present the Cluster Shared Volume (CSV) to the powershell command, it kicks back this error. The command works fine if given a physical drive letter, but all our LUNS are mounted as CSVs
That may be a limitation of the Powershell toolkit, so you may have to try to manually write zeros.
how's that done?
Happy Friday. Does anyone have any experience sending Active IQ Unified Manager (AIQUM) alerts to xMatters using a script?
Question regarding the ONTAP Mediator for MCC-IP: What's the stance regarding VMware Tools? Should we install it or not? The Mediator is currently running on CentOS.
The idea is to either exclude it and not use VMware Tools or install these Open VM Tools: https://docs.vmware.com/en/VMware-Tools/12.0.0/com.vmware.vsphere.vmwaretools.doc/GUID-C48E1F14-240D-4DD1-8D4C-25B6EBE4BB0F.html
The OS is on the individual admin to configure, it is not an appliance. Follow your org best practices.
From our point of view we will support either
ok, thanks alot!
https://www.netapp.tv/details/29476
Hey @true finch, nice introduction about the improvements and advantages of vVols and also the VMware commitment.
But everything still depends on the VASA provider where I'm really missing some announcements regarding a more resilient and scaled-out solution by NetApp... Unfortunately total silence since the last year sneak peak. The VASA provider is still the single point of failure. All these possible advantages of vVols I can't really realize when I can't convince customers to switch from the easy clean NFS world they know and love, to a possibly "easier" vVol world when there is this is one single component which sits in the middle and which customers learn to fear. 😕
Make-VASA-Great-Again ✊
Or...FreeTheScaleOutVASAProvider
i have a new customer request, they want a volume to have daily snapshots for the duration of a project (wihthout any idea on the time limit) and they want to keep every snapshot. im making some assumptions that it will be less than a year, but i guess i havent thought about it before, is there a better way than just making a snapshot policy for the volume with like a billion daily snapshots?
Eww.
yes
IIRC there's still the 255 per vol limit.
Can they roll up snapshots, or do they want each day for say a year (or whatever)?
the request is specifically dailies, im trying to push them towards a better way but its a bank lots of fed reqs and stuff
Oh bank? Forget it.
lol
I don't remember if you can clone a volume with multiple snapshots.
That's the only way I see getting around the 255 limit.
The other way is maybe have a SnapMirror destination (even on the same cluster or data center) then if they hit 255 just create a new SM dest vol.
yah I was thinking as its a VM just moving the VM to a new volume but i like the destination volume idea better
And maybe to make it more flexible, the VM itself (c drive or / VMDK) maybe can be separate from the data?
hmm, a little late to this, but the current snapshot limit is 1023 snapshots. it was upped in 9.4. unless they're running something super old, that should give a bit more room.
Oh that's right. Thanks. Still same problem, just it will take longer to hit.
Question regarding Broadcom Cluster-Switches and MCC-IP: With an AFF A250 MCC-IP the Broadcom switch also carries the local intra-cluster traffic.
In the Broadcom config docs it says to enable the "cluster switch log collection feature" (https://docs.netapp.com/us-en/ontap-systems-switches/switch-bes-53248/configure-log-collection.html), whereas in the MCC-IP docs it doesn't mention this (https://docs.netapp.com/us-en/ontap-metrocluster/install-ip/task_switch_config_broadcom.htm). You should only use the RCF file and that's basically it.
So my question is: Is it necessary to enable the "cluster switch log collection feature" for Broadcom switches in MCC-IP configs?
Any MCC TMEs around? 👀
AK may be on vacation still.
yep, you can take a flexclone of a snapshot to get around this limit
Brain works 🙂
memory is a wonderful thing!
I am taking it as "here's how you set up a broadcom switch".
and here's what needs to be done specifically for MCC".
Hey, can anyone provide me with some support, regarding the AIQ api?
how difficult is it to update the OnTap Version of a fileserver from 9.3P to the latest? is it recommended to do it by a pricey Netapp technician?
Depends on the rig in question and it’s level of ONTAP support… what platform? Sometimes you have to multi-hop but I think as long as you’re on ONTAP 9 or above you can make the jump
Honestly most platforms you just generate the upgrade advisor, plop the ONTAP image on, and run through it.
You just have to go to 9.5Platest, then 9.7Platest, etc.
The biggest consideration is IMT.
(Generally if you don't do SAN IMT checks are much easier, but it's good to double check)
9.5 -> 9.7 -> 9.9.1 -> 9.10.1 or 9.11.1.
but yeah. all depends. If it's just NAS, it's usually a pretty straight forward upgrade. if there's SAN, there's some interoperability to check.
but the upgrade itself is automated. pre and post checks have some manual parts, but spelled out in the upgrade advistor
Yup, Upgrade Advisor is your friend. Generate your plan at https://activeiq.netapp.com
is there any information why ONTAP wants me to rekey all its drives ?
ive never seen this before..its just a AFF250 with 24x8TB NVME drives
are they SEDs?
Not just a NAS its the Backbone Fileserver of our IT structure. FAS2650 24bay
Hi Xeur, as you are using your NetApp storage as a NAS solution, then you are likely using CIFS or NFS as the protocol that connects your hosts with the the storage. Given this fact, you likely can execute a non-disruptive upgrade. If your system is reporting ASUP (AutoSupport) back to NetApp, then you can login to https://activeiq.netapp.com and generate an Upgrade Advisor Plan which will walk you through the pre-checks, upgrade steps and post-checks.
If you want support to explain the upgrade process, then of course you are more than welcome to contact our support team (assuming you have active entitlement, which you would need to upgrade).
tyvm... btw its awesome you guys answere that random questions..
If you just want to learn a bit mor about the ONTAP upgrade process then head over to our docs area - https://docs.netapp.com/us-en/ontap/upgrade/
i did not think they were.. let me check
Is anyone else having issues with the upgrade from SnapCenter 4.6 to SnapCenter 4.7? Upgrading the SnapCenter server worked. When I try to upgrade hosts/clients, I get the ". Plugins are not available on the host to upgrade" error.
hello everyone. We are using an old FAS2220 Server with Netapp release 8.1.4 7-Mode. A coworker tried to create a junction with mklink but I learned that this does not work on a CIFS share. In this documentation I could find some information about symbolic links: https://library.netapp.com/ecmdocs/ECMP1401220/html/index.html. I found information about managing symlinks but no actual commands to create a symlink. I'd be thankful for any hints in the right direction 🙂
I'm trying to setup my vLab using simulator 9.11.1 on VMWk Pro 16x; simulator crashes on startup the first time and reboots; It does the same thing if it isn't shut down cleanly prior to a start, but it has a habit of crashing and burning on its own, so that can't be helped. I've got the 2+1 setup with 32GB RAM and 4vCPU's on each instance. Has anyone experienced this?
I don't see anywhere that we have run into that error yet. If you would create a case we'll be happy to look into it with you.
hello everyone, is this the right place for discussing about netapp trident ?
Hi all, I am having an issue where I cannot access my SMB/CIF share, I can access the top folder (FlexVol) but not the folder after that. I get the message: "Windows cannot access \servername\path". Any help is appreciated 🙂
If you're looking for urgent help, def recommend getting a support case open. We have a Resolution Guide, which is KB Article that references the most common known issues when troubleshooting CIFS - https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/CIFS_access_troubleshooting_-_Resolution_Guide
Based on your brief summary it's hard to know for sure where to start looking but double checking permissions might be a good place and checking your cluster (via System Manager) for any EMS events/errors to se if anything is standing out.
Also.. TIME. So often customers hit CIFS issues because the Active Directory time has skewed beyond 5 mins of the ONTAP cluster.
Ok so clearly the time is incorrect, Ive added the NTP same as my AD, how can I sync it now?
https://docs.netapp.com/us-en/ontap/system-admin/commands-manage-system-time-reference.html - bottom of page there is commands to manually correct the time. From there, it should keep in sync with the NTP server you've configured.
Any idea how to type this ?| [ -dateandtime <[[[[[cc]yy]mm]dd]hhmm[.ss]]> ]
cluster date modify -timezone GMT -dateandtime [2022]09]20]0307]]
?
its fine I figured it out
No worries - glad to hear it.
althought it hasnt fixed my issue 😦 I dont understand it was working this afternoon, but now I cant access the folder
Sorry to hear that. Any changes to your Active Directory? like it was upgraded (aka windows updates)?
Any change in results if you access share using IP address instead of FDQN?
Ive just tried event log show -messagename secd.*
I get the error: secd.kerberos.tktexpired: Kerberos client ticket has expired for vserver (Data)
This is related to time skew I believe. https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/EMS_reports_"secd.kerberos.tktexpired"_but_no_any_client_access_failures
yes I was just reading that, does things take time in order to resolve themselves after the time update?
You correcting the time manually to align with the DC should have sorted it AFAIK.
Just to confirm, timezones match between the Cluster and DC? https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_check_the_time_on_Cluster_and_Domain_Controllers_in_UTC
Otherwise yeah might need a support case to figure it out. Might be the time skew is just 1 piece of the puzzle here.
does it have to be identical to the seconds?
Shouldn't do from my understanding.
I will just try a reboot of my DC as Ive noticed it had done some updates
What version of ONTAP are you running?
9.8 I believe
five minutes is the requirement
Is there a quick way to show you how much of a volume has been tiered off on a single volume to a object store from command line ? i see the command (volume object-store tiering show) but it does not show how much has been pushed off per volume
https://docs.netapp.com/us-en/ontap/fabricpool/monitor-space-utilization-task.html "volume show-footprint" would give you that breakdown.
Awesome thats its.. i was looking at aggr object store.. I think NetApp need to rethink the System Manager GUI on how its displayed as well. When you have a new customer its not a simple task.. Maybe something like an additional bar under the volume capacity graph to show Fabric Pool footprint eg..
actually another bar that needs to added also is Storage Efficiencies.. Show me how much is de-duped,compressed etc..
Hey Greg, both observations are good feedback and there are product mgmt folks on this Discord whom will see that feedback.
On your last point, we do show efficiencies at aggregate level as the dedup/compression activities operate at that level.
That being said, I do know our ActiveIQ Unified Manager tool does have some additional capabilities that help monitor the capacity consumption for FabricPools. But agree, something more visible in System Manager would be worth while. Similar, with our new Cloud Manager portal there is some capability built into that for managing ONTAP based systems, setting up tiering and monitoring the usage.
going back to my issue, If I use \Volume\c$\Volume I can access the share, but no other way.
Hey @tame marten it does sound potentially like something wonky with permissions but really I would suggest opening a support case so our specialists can put their expertise to use and get this answered for you quickly.
Thanks Ross, I opened a case for this. it maybe permissions / authentication related. I tried doing a manual restart of both of DC and the netapp still to no avail
Hey guys, we gonna move from 9.7 and 9.8 to 9.10.1 - what are your observations on changes? Regarding gui we stopped at 9.7 because lots of admins was dissapointed by it after upgrade to 9.8. I see that many functionalities are back in 9.10.1 but what are your opinion? Ive generated upgrade advisor plans and they are ok - but are there any major considerations when upgrading from 9.7 and 9.8 to 9.10.1? Upgrade advisor just popped out that upgrade to 9.11 is not recommended and thats it
9.11 will be back in the running soon, but the aggr creation disk screen is enough IMO to wait for 9.11 to be stable.
You think that it will be before 8th October? Because at this date we have window from bussines and you dont see that very often from them haha 😀
But 9.10.1 seems very stable and good
well this is not metrocluster
what burt are you referring too that's patched in P8?
too many... I can get you the list tomorrow
Check the fixes in 9.11.1P2 which just got released
https://mysupport.netapp.com/site/bugs-online/product/ONTAP/BURT/1489494
https://mysupport.netapp.com/site/bugs-online/product/ONTAP/BURT/1459514
https://mysupport.netapp.com/site/bugs-online/product/ONTAP/BURT/1481369
https://mysupport.netapp.com/site/bugs-online/product/ONTAP/BURT/1400364
https://mysupport.netapp.com/site/bugs-online/product/ONTAP/BURT/1463874
has anyone setup ONTAP to be monitored by ManageEngine OPmanager ?
it looks like i can use API access so i can probably create a new user, give them admin access and ONTAPI and then just configure this module
there is not a lot of documents, process around
Might be safer to give read only access.
im trying to update my FAS2650 9.9.1P11 to 9.11.1P2... everytime i try to upload the new image i get >
any ideas?
tbh. i made a ugrade from 9.3p2 > 9.3p21 > 9.5.p19 > 9.7p20 and now stock on 9.9.1P11
Not supported. Check hwu. That platform, like the a200 only go to 9.10.1
Good hint.. but the same error with 9.10.1
I got it with the support. We had to remove the broken file in /mroot/etc/www/upload
For ontap, is there a way to keep the earlier snapshots when restoring to an old snapshot? Ex, I have snapshots A, B, and C (taken in that order). Is there a way to keep snapshot C when restoring to snapshot B?
I can tell you to stay away from SnapRestore. There is a KB that covers this question....https://kb.netapp.com/Advice_and_Troubleshooting/Data_Protection_and_Security/SnapRestore/How_to_restore_data_in_ONTAP
Hey guys!
I'm having some issues transferring an Ontap OS to my AFF A400 which is not in production yet. So it has no network connected to it.
I tried using e0M port to transfer it from boot_ontap menu option 7.
I added an IP address which was same range as I had on my local computer and had a local webserver running on it.
I can ping the netapp from my computer, but the netapp can't transfer the file.
Anyone experianced the same issue? Any one has a work around?
so you're just direct connect from e0m -> Laptop port.
and e0m has something like 192.168.1.100 and the laptop has 192.168.1.101?
Yes
that's typically pretty straight forward.
http is accessible outside of localhost on the laptop?
i.e. no firewall enabled or blocking etc on the laptop?
I disabled the firewall. Did not try it from another computer
if you boot normally, you could also configure e0m and ping from the netapp back to the laptop as well.
Yeah I booted normally as well. By default I had a mgmt_auto lif on default vserver.
configed my laptop after the IP and tried to ping it without success
got ya..
other thing that could happen is X over cable. I've always had laptops that auto detect.
i'd also verity that the http server is available outside of the laptop itself.
What do you mean by X over cable?
Any suggestions on http server? Sadly I can't download hfs coz its marked as virus...
tried something called Rebex today.
There was no issue downloading the file from another computer. Using the webserver. Just tested it 🙂
crossover cable.
scp at systemshell level?
This isn't something we normally tell customers because systemshell is very dangerous. Please do not do these commands without ONTAP supervision, but if you have access to the file system on the root volume:
pstejska_vsim::> set d
Warning: These diagnostic commands are for use by NetApp personnel only.
Do you want to continue? {y|n}: y
pstejska_vsim::*> systemshell local sudo bash
(system node systemshell)
bash-5.0# cd /mroot/etc/
bash-5.0# cd software
bash-5.0# ls
9101P1_q_image.tgz 98P1_q_image.tgz pstejska_vsim_1
bash-5.0#
Then you can scp from a *nix server the ONTAP image.
Yeah, we got access.
Thanks for the workaround!
I keep it in the back of my mind as last resort 🙂
But when it comes to e0M, it should be able to receive data. Correct?
Has the Netapp any recommended port when it comes to the web server?
I had some thought if I should try to find an SFP with RJ45 connection to insert it in slot e0e. But not sure if the system support it or which sfp it supports. But I guess I maybe find that in HWU.
And thanks for the support @quaint ether and @dim roost
Yw. Yes HWU.
this is a bit of a long shot, but does anyone know how to access the counter that shows if a cluster is serving VMware workloads?
I thought it was displayed in statit but that doesn't seem to be the case
any network adapter made in the last 10 (if not 20!) years should not require a crossover cable.
e0M should be able to receive data. I always used port 8080 with the simple Python webserver that comes with most versions of Python (e.g. the one on my MacBook)
There might be a counter in the volume object.
Totally unrelated, but does anyone have any Idea if there is a QNAP discord server? I am trying to see if a Azure SAML sso authenticated Folder share is possible on the local network
Not sure, might ask on the /r/qnap they would know for sure
Thanks
the StorageGrid docs say nothing about node names for the target node for cloning... just that they target node will take over the IP addresses of the source node... so... should/can they have the same name?
ok... second, unrelated question... even if I'm not sure if this is a software/data-mgmt/documentation question...
In the AIQUM docs about installing an "HTTPS certificate generated useing external tools", what does "1. Private Key of the server that belongs to the Active IQ UM host" actually mean? I've tried to load one such certificate with the private key concatenated at the start of the "bundle" but it kicks an error "Input certificate's public key differs from the existing certificate's public key. The keys must match" . which is bonkers since I know of no way of getting access to the "existing certificate's public key" since it was auto-generated locally
not to mention that this does really nothing for security... replacing the certificate generated with a new private key is not unusual
I don't think the Private key is ever known to the user replacing the certificate, I didn't use it.
What I found AIQUM does expect is a full chain (Root+Issuing+Server) in .pem format
bascially, one has to use the GUI to generate the CSR... at least on a vmware "appliance" node
which isn't documented
but there is an entire documentation section on doing the csr "externally" ... with no caveats about perhaps only being able to do this on systems that are not vmware "appliances"
and the locally generated CSR is broken too... nice... it doesn't even include the hostname or domain name
Oh, then I don't know how I managed to do it. 😕
Also running the OVA.
it worked for me last time... after I found out that one has to generate the CSR in the GUI...
but I reset the cert yesterday and now something is broken...
been in the diag mode and hacked a bit in UM now... everything else is ok... /etc/hosts and such... hostname is ok... just have to see if I can get a good CSR before I send it... the PKI guys are probably getting annoyed with me already
nada... still broken even after reboot... csr is still just IP and localhost
Why is that so? Most IT professionals know how to use Linux or BSD based systems
sorry to say but in the last 15 years the percentage of IT professionals knowing Linux or BSD has steeply declined. Also there are a lot of dependencies in certain areas of ONTAP, so modifying files or doing commands on a BSD level can have very unintended side effects.
The bsd underground is assumed to be and tested only in a fixed state - messing with the wrong parts will have unintended consequences
(The wrong parts are - all of it except under supervision)
Can anyone tell me how much impact the "statistics" command has on an OnTap cluster?
I have 12 LIFs that I don't think are being used at all. So, I kicked off a stat for each of them:
statistics start -object lif -sample-id sample_name -instance LIF_Name -counter total_data
After running for a day, each of them is showing 0B for the total_data, but we just started noticing that the vol0 snapshots are filling up. How much data is this command collecting, and where is it storing it?
Or, is there a better way to tell if a LIF is in use over time?
not much fun in that, hehe. I've spent weeks in the diag shell, if not months
<1%
Anybody know if it's possible to have NetApp Simulator with ALL Licenses ? Snapmirror Sync also, to test SM-BC ... Thanks
I just downloaded the 9.11.1 sim lic txt file and see -
SnapMirror XXXXXXXXXAAAAAAAAAAA SnapMirror, including synchronous SnapMirror
There might also be a way to req a temp key for the sim via your account team. i've not done it though.
I think that but in my sim the snapmirror licenses was split, I ve check on a A250 it's the same:
what ontap version was that ordered with? and did you have the DP or Premium bundle?
I think account teams can generate demo keys for the sim for everything except crypto stuff, since the sim is noDAR
We had a particularly unfruitful conversation trying to get NVMeoTCP included by default..
^ that makes sense. and TPM can't have a temp key
😑
i've done temp NVSE keys for POCs
For steel?
oki, in this case it's only simulator, without bundle, I will try to ask TPM ... Thanks
just to clarify - TPM In my comment is the Trusted Platform Module. Not Technical Partner Manager.
oki 🙂
Is there a way to dump OnTap cli commands to a text file? I'd like to dump a list of cifs shares to a local csv.
Set up PuTTY to log to a text file?
For commands you can audit the CLI https://docs.netapp.com/us-en/ontap-cli-98/security-audit-modify.html
but you want a report.
you can also mod the separator to a , so you can easily create a csv file. https://docs.netapp.com/us-en/ontap/system-admin/set-display-preferences-task.html
TIL
It’s a great feature
Goin to upgrade 9 aff200+fas2650 ha pairs from 9.7 to 9.10.1P7 this saturday. UA picked up no critical warnings or risks, its san fc setup with one cifs and 2 snapmirror. We are not using snapdiff. Any final thoughts? Gonna do andu through cli as always.
You're aware that's a double hop correct?
Ah yeah got 9.8 with latest P ready
Cool. Since there's san, did you verify IMT across 9.8 and 9.10?
there is centos 7.6 over there and I generated IMT for ontap 9.7, 9.8 and 9.10.1 for centos 7.6 and it threw me exactly same results (24 configurations)
compared all 3 xlsx files from these versions and they are identical
How can we confirm our NodeJS libraries with AWS SDK is compliant to NetApp S3 Restful APIs, we wanted to confirm if we are using the right the libraries. Reviewing the documentation we are using supported functions from NetApp, the “Put-Object”. We are having issues within application making the correct calls to NetApp ONTAP storage to S3. We have stood up a container pod with tools like AWS CLI, and able to move files in NetApp Storage, but still unsuccessful from our application to upload documents. We receive following error, “The s3 command not implemented”. From our application, we can connect, as we can list all the documents in S3, but not able upload/delete documents.
Anyone else solve this issue?
9.10.1P8 just got released
its not too new? how do you think
P7 was here for a while
It's a P-patch, likely some security/bug fixes
I was planning to upgrade 9 systems (18 controllers) to 9.10.1P7 at Saturday. That patch was here for a while and I didn't read about any disruptions. It's not too reckless to switch now for P8? It is critical environment
if you want to be 100% sure check this guide: https://kb.netapp.com/Support_Bulletins/Customer_Bulletins/SU2
but I think P7 is stable enough
from my experience it's enough to maybe wait one week after a P-release
Here's another listing of all the bugs fixed and things addressed in P8
If I will switch few days before planned update to new build and something will go wrong they gonna well... it will be painful for me
too bad that I can't wait more because this maintenance window was planned like for 6 months with business etc.
there's a new update every 4-6 weeks so it's usually never a good time to update 😉
P7 is fine (as long it's not a MCC-IP), we have it with quite some customer systems
yeah none of these systems are on MCC
28char temp keys are generic. Any temp key will work in the sim. NLF keys are a different story. NVE keys aren’t easy to deal with because of export controls, and the sim builds on the support site are NODAR builds for the same reason.
IIRC this has a massive fpolicy fix. @cosmic prairie I agree if you have fpolicy please do P8.
@quaint ether we dont have fpolicy. But today in morning we got executive meeting and one guy popped out upgrade advisor on activeiq then switched ver to 9.10.1P8 and it threw out "this version is not recommended" or smthn like that 😆 so they forbid me to deploy that version 😆
That's hilarous.
Could also be that it just dropped the other day so it's not listed as an official recommended version yet.
yep
it just dropped night before
@dim roost @quaint ether no fpolicy in environment, I think we will be fine
ehh 😄
@plush storm @quaint ether thanks for feedback and good words guys! everything patched to 9.10.1P7 🙂 no major issues but I've hit few bugs and unfortunately on most critical arrays xD but managed to sort this out. "backup image store not available", system manager corrupted image (needed to cancel and upload image again), and vldb was starting for too long and we hit timeout on giveback so we need to wait more and resume paused update. also some strange errors with "scriptexecution and error initialization failed" during prechecks
aah and also just after upgrade wafl started to do some crazy things and cpu on both nodes went crazy like from 80-99%
it was scanning volumes or smthn
dudes that were monitoring it through nagios got scared af
😄
aah and one SP got crazy reported 173 degrees celsius or 343 degrees fahrenheit and precheck told us that all sensors are not working good
but it was related to service processor bug
if you have the time always do the firmware and SP updates before the big ONTAP updates, helps alot
Also did you update to 9.7 P-latest before the big jump?
This also helps to fix possible update issues which have already been fixed
unfortunately not we've got like very strict window one per year and it was 9 arrays so 18 nodes. started with less important arrays
and man 7 of them was smooth
Yeah you can get tons of scary events during the update 😂
so we started 8th that was most important
and it threw all of the bugs we've hit
if we would hit that bugs on 1st array we would jump to platest 9.7 with firmwares
but since it went smooth on 7 systems we thought you know
lets do this
haha
yeah
because its aff200 and fas 2650
so just latest pupdates
hahaha
no 9.11 for us
we've did this since 9.3 - got this shipped with array
I'm still not brave enough to activate those automatic firmware updates which came with 9.10 I believe
Yeah unfortunately these are the latest for that generation
same for us
but updated dqp with this new firmware update feature
kinda nice
oh did you get a notification for that?
I think we activated it for one cluster but never got any notifications
nope, just from active iq
that dqp is outdated
and dqp its not part of ontap update
Yeah I still don't understand why... it's a tiny 40kb file
Same here. It’s never been included in ONTAP cluster mode. I’ve checked. I actually pulled down some old releases and extracted. Not there. I don’t recall it being in 7-mode but I might be wrong on that
I believe that ONTAP is “built” with the current version so that ONTAP will recognize the disks. The file just adds anything released after ONTAP versions are published
The file doesn’t need to be specifically there because it’s absorbed into the code so to speak
DQP is not included as all of the disks and adjustment up to the time of release are directly in ONTAP. File just adds "after release"
@covert stirrup Current version of NAbox keeps losing my largest cluster in the dashboards; I also have a playlist and it loses it there. The only way to bring it back is to reboot the appliance; Have you heard of that one?
@lone crane drop that into #┊・harvest-nabox🔒 channel, might get a quicker response!
Thanks Nick. Didn't see that; my wife tells me that all of the time...
This man husbands!
I can't believe I'm asking after all these years, but is there an equivalent of grep in the ONTAP CLI? I know how you can use -fields to limit the number of columns displayed, but that doesn't help when you're looking at tons of rows trying to find a needle in the proverbial haystack
few things ->
you can do a not. so find things that are not online
-state !online
you can also sort - https://tmacsrack.wordpress.com/2019/08/13/ever-wish-you-could-sort-on-the-ontap-cli/
helpful guide there by TMAC.
You can also mod the separator to create things like CSV docs.
I also do a "row 0" to help keep the formating cleaner.
What I used to do as an admin is put ssh keys on a linux host and then you can just pass grep on to the output
so ssh cluster command | grep foo
I was aware of the ! and row 0, thanks Mike, but I didn't know sort existed! Good to know about the SSH keys; I'll try that. It brings back memories of the days when you could just use rsh.. 🙂
Windows 10 even has ssh.exe built in. If you set up keys you can even use command prompt to SSH in and run commands. I use WSL2 for that, but basically it is the same thing.
I'm on a Mac but I have to say, WSL2 is excellent
Not sure I'm answering the correct thing here but to expand on the -fields to limit rows is using those Column names as a filter with for example -name svm1*
that would probably work for a lot of cases. yesterday I was doing some work in security login and the output of one command was about 500 rows, and I was looking for one row in particular 😦
There must be some information you are looking for in particular, like any username containing something or access to a specific application etc.
If you don't know what you are looking for then nothing can help 😆
For ONTAP, is it possible to snapshot a part of a volume (instead of the whole volume)?
I can't think of a way to do it, but.. why would you want to? snapshots are instantaneous and take up no space. what is the use-case of snapshotting only part of the volume?
In the case of multiple users using the same volume. For example, user A and user B use the same volume. User A wants to snapshot their files but not include user B's files.
A snapshot is a feature of a volume. A snapshot keeps the status of the volume when the snapshot is created. It needs to include every file inside the volume to keep the volume consistency
is it a privacy thing? if so, they shouldn't be able to see each others' files anyway. is it a space thing? if so, it doesn't matter (unless one user changes a ton of stuff after the snapshot is taken)
It's more a privacy thing
Are qtree snaps still a thing?
Nope
Or am I just showing my age? 😂
🙂
Security wise, Snapshots honor your NTFS ACLs
so as long as those are correct. There isn't a concern.
Okay. Thank you!
Hi, all:
Where should I ask StorageGrid questions?
Going to replace a virtual admin node with a SG1000. Need to upgrade the installer and SW, as it was shiped with 11.5
On https://mysupport.netapp.com/site/products/all/details/storagegrid-appliance/downloads-tab/download/64317/2022.08/downloads I find specific images for each model of compute nodes, but they seem to all be the same? Same checksum as far as I can see. What am I missing? Why publish archives with several copies of the same files? I'm confused. Again! 😄
Here or #┊・hardware is fine for now. I can also ping @peak thorn for ya to come and chat about it.
Can anyone explain Personas' for ConfigAdvisor and OneCollect? I'd like to collect on a weekly bases, but I'm not sure the proper Persona to use; I am in a dark site and connect send any asups or log collections to Support
Past the 12-hour mark since we completed our final cutover from Isilon to Netapp. knock on wood no major issues.
I don’t think that was the original plan, but it wasn’t blocked in code and people had already started rolling it out, so they went back and did the full qualification.
looks like it. I was lobbying internally for it, since the C190 has it and it's effectively the same platform
just spoke to ONTAP PM - confirmed it is supported now
win!
now thats a good win.. please go and tell them to enable snapdiff v1,v2 in ONTAP 9.10 and 9.11... seems the big backup software vendors ( TSM, Commvault and Veeam) dont want to support V3
At least Commvault supports snappdiff v3. But yes it's a problem for the others
same underlying hardware... it's just a specific debian image. Probably just thought to be easier for end-users this way
I know, but from what I could see the images are identical. So why ship 5 or 6 copies of identical files?
well, each user only downloads the one, hehe
perhaps they're preparing for diversifying later, hehe
No, there are archives with several copies in each on my link abowe
yeah, but disk is cheap... this is just for humans... if the images diversify later, then no one has to change their behavior
Yeah. And also there is a single file first, and then two archives for different platforms. But it seems its just copies of the same file
going with cloning for the transition?
My plan is to turn off the virtual admin, then install new physical and restore recovery package
i guess i'm not 100% sure about the cloning of VM to hardware anyway...
one could just add an admin node and decommission the old one i think too
but i haven't looked at it at all
There is a documentet way to transition from virtual to physical HW. Basically you do a recovery, but you have to provide your own disaster first... (Turn off the VM) 🙂
ahh... would be nice if there were fewer special solutions...
This is spesifically for the primary admin. Other node-types are able to pull their config from the admin (don't quote me on this)
yeah, not something i need to know so much about until i need to do it, hehe
-or you can just install them as new nodes. But you can only have one pri admin
which frankly could just be a configurable option to make things like migration easier
📢 ONTAP 9.11.1P3 has been published to the NetApp Support Site
https://mysupport.netapp.com/site/products/all/details/ontap9/downloads-tab/download/62286/9.11.1P3/downloads
is the SSET tool still supported? I need to scan a large volume to see what kind of efficiencies I can expect. I can find a link to Communities, but I get "permission denied" when trying to download it: https://communities.netapp.com/docs/DOC-18699
It’s not. Those are old links. Let me know where you found it so I can get that updated.
XCP is the preferred replacement. If you’ll DM me your email address, I’ll send you a set of instructions when I’m back in front of a computer.
For ONTAP, I was wondering if all snapshots are still full snapshots? There was an old post about this and I was wondering if this is still true (https://community.netapp.com/t5/ONTAP-Discussions/Snapshots-does-it-ever-do-a-full-snapshot/m-p/75964)
Snaps haven't changed no.
So not possible to do delta snapshots?
Oh sorry I meant yes they are the same, no they haven't changed in process in the last several years in WAFL.
The only thing added was features like cloud snapshot moving, etc.
I'd be careful calling it a full backup. It's a copy of the blocks at that point in time locked against the AFS.
That makes sense. Ty!
Yw
Hey all,
Anyone sitting on a powershell script for checking the systems Storage shelfs FW?
I dont believe this is true.. This is a statement i got from CV.
Product manager and development team confirmed NetApp has changed the rules around the use of SnapDiff, if customers want to do backup copies (IntelliSnap) or any kind of streaming backup, then snapdiff can no longer be used. This took effect for any new installs after Nov 30th/2021 or the use of ONTAP 9.10.x (currently not fully supported) no matter when the commcell was installed. We will no longer use the SnapDiff engine to determine changed files and will use our own scan processes. So we can still use the Network File Share backup option, just we will not use SnapDiff. This will result in the scan phase taking a bit longer, but the backup phase remains the same.
VSA backups and NDMP backups will not be affected by SnapDiff v3 since SnapDiff is ONLY used for Network File Share backup, ie Windows/Linus FS agents.
Hello guys, I don't know if this is the right place to ask. I'm wondering which is the best method to delete xcp indexes. Do I have to simply clean up indexes dir, or what else?
Thanks
Question when accessing a NTFS volume from a linux box using NFS. I know you cannot modify permissions but can a user set/create/update timestamps?
That's true that 9.10 uses SnapDiff v3 only.
Is there a way with volume quota report show to see only users at 100% or higher
Hey @pulsar yacht take a look at https://docs.netapp.com/us-en/ontap-cli-9101//volume-quota-report.html#description - I believe there is a few parameter's you can use to filter the report output. I think "[-disk-used-pct-disk-limit <percent_no_limit>" is what you're looking for.
Problem is that does not seem to accept a higher value or value range
I was going to look power shell tomorrow
We do also have our ActiveIQ Unified Manager tool that includes a bunch of reporting capabilities which may be more flexible to what you're trying to achieve (but yes would be another piece of software to deploy), so powershell may get you what you need.
Actually working on getting a new VM deployed to upgrade our AIQ Unified Manager to 9.11P1, we are still back at 9.6.
PS /Users/q1431233> Connect-NaController us-phl-equ-nta-prd-01 -Cred '****' -https
PowerShell credential request
Enter your credentials.
Password for user ****: ********************
Connect-NaController: API invoke failed.
getting that when trying to use powershell
user is auth is using our domain so "domain\userid"
which is a tunneled auth to our SVM
And with Connect-NcController ?
onnect-NcController: The remote server returned an error: (401) Unauthorized.
we have ONTAPI access configured
but for the admin/vsadmin is works?
Curl test works
✘ q1431233@WCHMLQVC00665 ~ curl -X GET -u userid -k "https://us-phl-equ-nta-prd-01.qvcdev.qvc.net/api/cluster?fields=version"
Enter host password for user 'USERID':
{
"version": {
"full": "NetApp Release 9.9.1P7: Sat Jan 29 01:25:00 UTC 2022",
"generation": 9,
"major": 9,
"minor": 1
},
"_links": {
"self": {
"href": "/api/cluster"
}
}
}%
have not testing admin because it is stored in our Cyberark and triggers questions why I am using it when I pull it from cyberark
try with the -ontapi switch for Connect-NcController
that worked
Name Address Vserver Version
us-phl-equ-nta-prd-… 10.176.7.25 NetApp Release 9.9.1P7: Sat Jan 29 01:25:00 UTC 2022
Odd issue I added an ja pair to an existing cluster and the shelf isn’t showing up but the disks are lol
Lol unsupported shelf wtf
It's because you added a "ja" pair instead of "HA" pair.
😄
What is the exact error?
Ses.shelf.unsupportallowerr:unsupported disk shelf found on channel 0a
It’s an old 8020 I’m repurposing
What kind of shelves?
Ds 2246
Hmm. Well that should work. Any other shelves?
I got a spare chassis I can move the iom6 s to i was gonna try
Just one shelf on this thing so far
This is weird
Showing up as different shelf
Unless someone swapped the chassis and I didn’t realize it
This one nah no support on this one just a backup target cluster not configured to send em
Don't matter. I can still see the ASUPs.
I double checked it’s a 2246
And I replaced the iom6 with different once’s and rebooted the whole shebang
721618000165
And “66
Oh it's been sending ASUPs.
Lol whoops
[?] Mon Feb 08 18:23:40 -0500 [localhost: config_check: config.sameHA:error]: Disk 0b.31.1P1 and other disks attached to the same port are dual-attached to the same adapter. For improved availability you should dual-attach them to separate adapters.
[?] Mon Feb 08 18:23:40 -0500 [localhost: config_check: config.sameHA:error]: Disk 0a.31.8P1 and other disks attached to the same port are dual-attached to the same adapter. For improved availability you should dual-attach them to separate adapters.
How do you have this thing cabled? 😮
Just however until new cables that can reach come in
I can cable it right after I replace the chassis just gonna move the whole thing so i can use the cables I have probably
Disk Qualification Package Details:
Package Date: Unable to load any package (Unknown error or Package may not be present)
Header Information
FileName = N/A
FileVersion = N/A
DriveRecordCount = N/A
AliasRecordCount = N/A
DeviceRecordCount = N/A
SystemRecordCount = N/A
You know what? Try shutting down both nodes and all the shelves and power on properly.
See if that does anything.
I did and it’s the same
What kind of cables do you have?
Uh...
X6594-r6
Lol
Crap
Never occurred to me
To check the cable
Just got a box of Netapp sas cables
I suppose I can see if new cables help
I'm stumped.
I think it might be cabled wrong.
I’ll double check but I’m pretty sure it’s in a supported cable config
Just like this but with a single shelf
Also without acp lol
That sas “error” is cause this filer has a sas expansion and I’m not using it
The little plastic cover that says ds2246 the 224c cover can fit in that same spot right. Maybe the covers just got swapped?
That looks like a 224c part
Wtf
Well it has the wrong covers in it
Once again I’ve outdone myself in seeing how dumb I can be
That gives me a 404
Reloaded and it just says cluster viewer with no content
Yeah was gonna say.
I’m pretty sure it’s just cause the other expansion is empty I could cable to the other side for extra resiliency I guess but I don’t want to lol
Also I need to get a real 2246
Not an imposter
Lol yep thanks for your help. I guess one of my guys in the inventory mistook the shelf and “built” one out of spares we had
Lol
😄
DS224C will take IOM6s? That’s.. not something I knew
Hammer required
Field portal docs say don’t do it. Not supported
Doesn't mean it won't boot! 😄
2 weeks ago we were upgrading our storage and today we've received mail like this: NetApp Automated Autosupport Acknowledgement from <name> You have indicated that this system is under maintenance for the next 10 hour(s).
I've checked active iq and our mail and last one was sent yesterday MANAGEMENT_LOG
it is possible that we've received that info delayed for two weeks?
last mails sent with MAINT=10h two weeks ago
it sounds like it
only other option might be that the autosupports did not get transmitted and are now retried
We've seen oddness like this from our maintenance requests as well. But, we have the opposite problem... we put them into maintenance for 6 hours, get an acknowledgement back right away, then an hour later we get another email from NetApp indicating that we submitted a request to disable maintenance mode (we did not).
I was thinking that maybe it was because we were putting comments after the MAINT=6h in the command? We used to be able to do that, but maybe it's confusing it now? i.e. we usually do something like:
system node autosupport invoke -node * -type all -message "MAINT=6h Starting NDU"
Should we just do?
system node autosupport invoke -node * -type all -message MAINT=6h
We tried testing the latter, and I don't think we ever got an end message.
The Upgrade advisor reports generated by Active IQ are saying: "MAINT=4h Starting_NDU"
So perhaps it's just a missing underscore. I haven't had a problem with that format anyway.
We have a customer asking for an attestation that a bucket was emptied and removed from storage grid. What are storagegrid admins using for something like this?
Hey Casey, I don't have a specific answer for you but the StorageGrid software does include certain audit logging capabilities - https://docs.netapp.com/us-en/storagegrid-116/audit/index.html
Ross, thank you, I hadn't really thought about that but we do log to splunk so I could possibly use that. Thanks for the reminder
Have you verified ntp on your cluster? Just making sure that a faulty time is not to blame…
Morning, I am wondering, is anyone running NVMe/TCP, VMware with ONTAP?
We are about to deploy it for our customers.. What questions do you have ?
Does ONTAP Support SR-IOV ?
like ONTAP nodes using SR-IOV on their internal network interfaces? no
No the question comes more from an IBM/Power world where some of their arrays can do SR-IOV when they are connected to IBM Power hosts... i would possibly think the "new" way getting maxium speed with a pretty lite protocol stack would be using NVME direct to hosts...
at this time it seems NVMe/FC for AIX is not supported by ONTAP, and NVMe/TCP is not supported by AIX.
How are you deploying the networking, single VLAN/Network or two VLANs/networks - more SAN-esque
Hey guys, question about Fabric Pool:
Can you throttle the tiering of cold data to the capacity tier and/or decide at what time during the day the tiering starts? Or maybe restrict to some hours?
That got asked and there is an ethernet rate limiter. I gotta find the KB.
Upgrade to ONTAP 9.8 to get fix for bug 1283802
This bug adds the capability to modify the throughput
Once the upgrade is complete then contact NetApp Support and reference this KB to get the command workaround
On version 9.10.1 or higher, the storage aggregate object-store put-rate-limit modify command can was introduced to throttle FabricPool tiering with a command
Example:
Cluster::> set advanced
Cluster::> storage aggregate object-store put-rate-limit modify -node node1 -default false -put-rate-bytes-limit 50MB
Do you need the 9.8 and 9.9 command? I can send it directly to you.
thanks a lot!.... I was searching and searching....
yes pls
guess my XP was too low today 👀 😉
There's no way to restrict the tiering to a certain time during the day, right?
(only perf tier to capa tier of course; capa tier to perf tier should always be possible because of needed availability for the cold blocks)
There is no scheduling in fabicpool
ok got you, thx
Hi,
I have a FAS8200 running 9.11.1 where the login to systemmanager is taking long time. It is only the time from pushing the "login" button and until we see the dashboard there take long time. I have checked CPU and disk load and that is only a few percent. I have looked in sysmgr.log and apache_error.log and the only error I can find is: The DOT-CSRF cookie is invalid. - but I have seen this error message on many systems.
Unfortunately this system is on a dark site, so providing logs to support is almost impossible.
Does it make a difference for performance or cluster traffic if I put volumes from 2 different node aggregates in a single SVM? I was pondering because SVM root volume is the base junction-path for everything.
hi @cobalt portal - can you try with Chrome? Developer Tools on and "Network" profiling?
that will show you if it's client side or ontap side. If it's client side you might be able to see a request taking forever that your client could blackhole for a fast drop
Short answer is yes. But how much is an architectural question - depends on cluster interconnect speed (10/40/100Gbit), volume of traffic on back end, volume of traversal traffic, amount of indirect traffic from LIFs on nodes non-local to storage
Load Sharing mirrors (LS) can help if traversal traffic is high, but there's pluses and minuses to it. Here's something I wrote on the topic of them https://community.netapp.com/t5/ONTAP-Discussions/Does-anyone-use-load-sharing-mirrors-any-more-ONTAP-9-1-for-SVM-root-vols/m-p/430729/highlight/true#M39777
The aim for SVM rootvol LS mirrors is to enable a cluster to continue serving data if a HA pair goes offline when that pair is not holding epsilon but IS holding an/several SVM root vols, but not all of the data for that SMV, and also to enable path traversal operations in volumes that exist across ...
Hi, question about Storage Grid. Not sure if I can/should post the link here but a lot of the NetApp documentation talks about automating setup of StorageGrid using a python script called "configure-sga.py"
Not a single web page of the documentation indicates where this script lives or can be downloaded from. Maybe I'm missing it but could someone point me to this file?
FYI I am a NetApp employee and can tell you how to reach me on team if you DM me
https://docs.netapp.com/us-en/storagegrid-116/sg100-1000/automating-installation-configuration-appliance-nodes-configure-sga-py-script.html - "You have downloaded the configure-sga.py file. The file is included in the installation archive, or you can access it by clicking Help > Appliance Installation Script in the StorageGRID Appliance Installer." .. any luck with this guidance? I'm not a StorageGRID specialist
"You have downloaded the configure-sga.py file." <--- thats the part I am missing. I am on that page as well
it doesnt indicate where to download
gotcha
" Appliance Installation Script in the StorageGRID Appliance Installer." < -- dont know how I glossed over that but I am downloading that right now
i chalk it up to its early
It is a 2 node A900 and will be used for VMware datastores via NFSv3. I have planned local LIFs on the nodes to avoid much indirect traffic. So does it make sense to also have a SVM with local root volume per node or should I just keep it simple with a single SVM?
Hi Alex, I will try that the next time i'm onsite 🙂
Hmm! I'd say it'd be negligible impact in that scenario. Fast Cluster interconnect, low number of files, while separate SVMs mean two places for export/snapmirror policies.
but each LIF means a new datastore, so from that POV.. two SVMs is no different
I believe this is an outdated recommendation, see first bullet here:
https://docs.netapp.com/us-en/netapp-solutions/virtualization/vsphere_ontap_best_practices.html#nfs
if you find out it is trying to access a URL and timing out, log a support case would be my suggestion, so we can get it captures
ah yes, that bit is indeed no longer best practice - but since in this case they are mounting from different IPs anyway, they will be different data stores
(unless I've missed that vmware can accept the same volume mounted from two different IPs as the same datastore - a quick check says not with NFSv3)
but I see how my comment could be interpretted that way. Here's a blog post I wrote in 2016 on the topic of why it was and was not a good idea - https://alexdawson.net/2016/08/ontap-why-and-why-not-to-have-one-lif-per-nfs-volume/
(I don't stand by it entirely - one LIF per SVM per node for simple NFSv3 datastores is fine in most cases imo now)
Thanks for your input. I have not planned 1:1 LIF to datastore relationship, but will use more than one because the ESX servers use LACP. To get some load spread on the network I still think it is favorable to have more LIFs per Node.
with TSSE dedupe, you can get dedupe over multiple volumes, so multiple datastores is less of an issue from that point of view - and more datastores means more parallelism inside ONTAP, my only concern would be needing to manage more datastores rather than less. But you're the admin 🙂
bed time for me here in Perth Australia! Enjoy EMEA Insight for anyone going! My colleagues around the world will continue to provide input on topics 🙂
Try upgrading to 9.11.1P3.
Thank you very much for your thoughts, much appreciated!
Been having a terrible time with ONTAP Simulator and VirtualBox. Has anyone else had any luck with the setup? If I do get through the setup without a core dump or root volume being full then the cluster nodes don't see each other.... Wants me to re-iniitialize the cluster nodes over and over.
Oof. Have you tried adding disks to it?
I have installed two instances of the ESX version of the 8.3 Simulator and within a few days I run into space problems on the root volume. See the messages below from the console. I have also runto into this same problem with instances installed in ESX in a Partner's lab. It appears that there ar...
I have a small query - Trying to change local ip subnet address of a ipsec security policy, if I try to modify to any of the host ip of local ip subnets, its not modifying.
current is 192.168.12.2/24 but not accepting any of 192.168.12.1-254
ontap910::> security ipsec policy modify -vserver ansibleSVM -name policy3 -local-ip-subnets 192.168.12.3/24
ontap910::> security ipsec policy show -vserver ansibleSVM -name policy3 -instance
Vserver: ansibleSVM
Policy Name: policy3
Local IP Subnets: 192.168.12.2/24
@humble spruce you around? This is right up your alley.
yeah, it works and resolves the root volume space issues, but then the root volume is dirty and\or some other nonsense. I think I was able stand up a single node cluster tho.
I have a storage grid appliance question? Basically, I need to know why some Applicance I can access the API on that node while others only respond to SSH and not API
Im not an Storage Grid person so forgive me if that's a simple question
if it's just a matter of turning on API support on those nodes could someone point me to the documentation on doing that. Thanks in advance
hi @spice pulsar hopefully someone from SG will answer your question, in the meantime, not sure if you've seen the docs or if your question is answered there? https://docs.netapp.com/us-en/storagegrid-116/ or https://docs.netapp.com/us-en/storagegrid-116/earlier-versions.html for earlier versions
@peak thorn is a lurker in here and should be able to help
@spice pulsar I need a bit more information. what API's are you trying to use?
i think I got my answer. I was trying to connect to the SG appliances to back up thier configs but it seems that that API/HTTP wont respond unless they are at install mode or maintenance mode
the other question was around the Admin node and approving a node to join
via api
accessing PGE API's will only work in PGE mode, yes.
but there is an /install endpoint on the admin node
until just this morning I didnt know that. Not being an SG guy
management API's are only available on the Admin nodes
But I appreciate your help. Literally just got an answer moments ago from an NG
I saw your email in the SES ng, and asked one of our perf lab TME's to respond with how we do it
though rather than back up the config each time we just deploy with a predefined config
well I wasnt backing up the config each time. I didnt have a backup and needed one to use for the automation
ahh
I just needed backups of our known good environment and struggled on how to 🙂
i do not like how sgareinstall prompts for "are you sure?" i wish you could pass -f or -y or something
i use ansible to modify that file and remove the prompts 😉
this is 100% for testing purposes: is it possible to erase the contents of the audit log?
I'm trying to do some back-to-back testing of RBAC and my life would be much easier if I could somehow erase the audit log between attempts
this is 100 for testing purposes is it
does anyone know how to clear nfs connected-client cache?
flc1-sys-phx2-cloudsys::> nfs connected-clients show -vserver t500_0_fls3
Node: flc1-02-sys-phx2-cloudsys
Vserver: t500_0_fls3
Data-Ip: 10.73.33.5
Client-Ip Volume-Name Protocol Idle-Time Local-Reqs Remote-Reqs
10.73.32.68 t500_0_fls3_phx2_data1 nfs3 23h 59m 17s 5505495 0
10.73.32.68 t500_0_fls3_pool54_root nfs3 1d 1h 26m 29s 25415634 0
10.73.32.69 t500_0_fls3_phx2_data1 nfs3 1d 0h 0m 34s 5505533 0
10.73.32.69 t500_0_fls3_pool54_root nfs3 1d 1h 26m 30s 187897825 0
10.73.32.94 t500_0_fls3_phx2_data1 nfs3 23h 59m 17s 5461236 0
or what the default time out is it just rolled past 24 hours
Hi NetApp team, when I list snapshot policies from rest api(/api/storage/snapshot_policies)) via cluster management port, only part of policies or no policies are retuned. but actually I do have some more policies on my cluster and if I list them by SDK I can get them all. do you have any insight?
@uneven violet you might get a better answer over at our #┊・ontap-api channel. So suggest posting your query there. You may want to also consider sharing what ONTAP version your cluster is running.
Thank you Ross, let me do that now
I don't know. I'd assume it would be live and updated. If it isn't then there might be something else needing done.
I think I read somewhere the NFS clients from the last 15min would be cached in that list
but not sure where I heard that
@humble spruce ?
ONTAP 9.12.1RC1 is out! 🎉
nicee
Nfs connected clients show probably what you’re referring to
Nfs connected clients show. the default cache is 48 hours, and I still can't find a way to force a clear sooner nor cam netapp support tell me how
Netapp came back with. no way for force cache clear for nfs-connected clients
Reboot.
Is there still a size limit to ONTAP (s3 in a SVM) with ONTAP 9.11.1P3 ?
S3 objects are limited in size to 16TB in ONTAP 9.11.1P3, transactions are limited to 5TB - meaning uploading a 16TB object is 4 PUT operations
(this limit also applies to 9.12.1, which includes support for files larger than 16TB, which is the base limitation in previous versions - larger objects aren't supported yet in 9.12 - if larger objects are a requirement for you, please let your account team know)
Ahh I think I might of confused you.. what is the max size of a “S3” svm.. I thought around 9.9.1 it was around 500TB and then it went to 800TB in 9.10.1.. are these limits still there or have they now been removed? Can I have PB of S3 now in ONTAP?
It's in HWU for the platform, under S3 Cluster Limits. Here is an example for the A800 on 9.11.1
Only 20Pb? Weak 😉
the whole point of wanting to clear cache is to identify what is still in use before taking svm down...
If you still have your case open, ask Support to open a bug as a RFE. Once the bug is opened your account team can help push it with PM/Eng and get it prioritized.
Yeah I know... You could maybe try the "network connections" cmds to check if something is still active