In ONTAP 9.6, command-line activity is recorded in audit.log. The audit log captures administrative activity such as commands issued through the CLI and other management interfaces, which is essential for security review, accountability, and troubleshooting administrative changes. messages.log and ems.log are used for system and event messages, not specifically for recording administrator command history. command-history.log may sound plausible, but ONTAP 9.6 centralizes management audit activity in audit.log. mgwd.log records management gateway daemon behavior and can be useful for deeper support investigation, but it is not the primary file used to review CLI activity. A support engineer investigating who changed a configuration should know the difference between event logs, daemon logs, and audit logs. This distinction prevents wasted time during escalations because the correct log source depends on whether the issue is an administrator action, an EMS event, or daemon behavior. References/topics: ONTAP log architecture, audit.log, CLI activity auditing, administrative traceability, and management-plane troubleshooting.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit