Smb: how do you log access & disconnect users?

I've always relied on AFP for file sharing, but since it seems like that's kind of on the way out and SMB is the new way to do things, I've been trying that out instead. A few questions though...
Where are the access logs? I'm looking for the equivalent of the AppleFileServiceAccess.log that I see in the Console, that shows timestamps with IPs for opening & deleting files, etc. (Maybe logging has to be enabled with some seperate step that's not in the Server app GUI, or the log isn't called something obvious?)
How do you force a user to disconnect? (Remote users sometimes drop connections, so they're really not connected anymore but the server still shows the connection. For AFP users, I can use the Disconnect button to remove these ghosts, but when I try to use that button on an SMB connection I just get a message saying it only works for AFP. So... do the ghosts just pile up and you're supposed to ignore them, or do you have to restart the server, etc.?)

This is exactly what i was looking for, and Nelson is correct.  When you enter the DAP configuration for a profile click on "Advanced" and there is the option to create a logical expression.  The guide (ther is a button to access this) is really helpful, with a couple of examples.  This is what i used:
assert(function()
   if ( (type(aaa.ldap.distinguishedName) == "string") and
        (string.find(aaa.ldap.distinguishedName, "OU=Users") ~= nil) )
then
       return true
   end
   return false
end)()
from the debug dap you can see what Users relates to;
DAP_TRACE: Username: MyUsername, aaa.ldap.distinguishedName = CN=Mr B,OU=Users,OU=Site ******,DC=CH,DC=Mycompany,DC=com
My admin account fails to get me in to the same profile:
DAP_TRACE: dap_add_to_lua_tree:aaa["ldap"]["distinguishedName"]="CN=Admin Mr B,OU=Admin Users,OU=Site *****,DC=CH,DC=Mycompany,DC=com"
Thanks
Andrew

Similar Messages

  • ASA WebVPN. How do you restrict access to users in an AD group using LDAP?

    Hi All,
    I am trying to configure separate WebVPN connection profiles to give different portal bookmark contents to users based on their AD group membership.  This has been very difficult, even though I beleive it should be easy.
    The login page of teh ASA by default has a dropdown to allow default users to access the default portal and the SSL VPN client connection.
    There are two other portals that I would like to restrict access to based on AD group membership.  I have set these up to be selected by URL.
    The biggest problem is, I have no way of knowing how to go about this.  The AAA LDAP options show a group membership search, which I have configured, but I cannot say "Profile X is restricted to AD group CarpetBaggers", so that if soneone that is NOT a carpetbagger tries to log in, it fails.
    I can only do an all or nothing scenario.
    It would be nice to use Dynamic Access Policies to do this, and I have created a few, but they do NOT seem to work when the drop down aliases or URLs are in use.  So how do I go about using them in this scenario?  Turning off the aliases or URLs is not really an option right now.
    Scenario 1 would work the best for me.  Restrict access to profiles/groups based on AD group membership using LDAP.
    Scenario 2 would be an ideal longer term solution.
    Any thoughts, ideas or assitance would be greatly appreciated.
    Cheers

    This is exactly what i was looking for, and Nelson is correct.  When you enter the DAP configuration for a profile click on "Advanced" and there is the option to create a logical expression.  The guide (ther is a button to access this) is really helpful, with a couple of examples.  This is what i used:
    assert(function()
       if ( (type(aaa.ldap.distinguishedName) == "string") and
            (string.find(aaa.ldap.distinguishedName, "OU=Users") ~= nil) )
    then
           return true
       end
       return false
    end)()
    from the debug dap you can see what Users relates to;
    DAP_TRACE: Username: MyUsername, aaa.ldap.distinguishedName = CN=Mr B,OU=Users,OU=Site ******,DC=CH,DC=Mycompany,DC=com
    My admin account fails to get me in to the same profile:
    DAP_TRACE: dap_add_to_lua_tree:aaa["ldap"]["distinguishedName"]="CN=Admin Mr B,OU=Admin Users,OU=Site *****,DC=CH,DC=Mycompany,DC=com"
    Thanks
    Andrew

  • How do you gain access to all files on different users?

    How do you gain access to all files and folders for each user?

    http://forums.whirlpool.net.au/archive/718273

  • How do you log out of yahoo mail on ipad ?

    How do you log out from Yahoo Mail on a Ipad?

    Using the mail app? You don't. THe ipad was created to be a single user device so there's no support for locking down any single part of it.
    If you have your mail and want to keep it from other users, your best bet is to access yahoo via safari where you can log in and log out. You still get your mail access but it can be locked out as well.

  • How do you Enable/Disable a user's ScreenSaver and set it's time

    How do you Enable/Disable a user's ScreenSaver and set it's "Start Screen Saver" time.
    I am writting an application in java which uses JNI and a screen saver to lock users out of the computer unless they enter the correct username and password.
    If they enter the correct password I need to Enable the ScreenSaver at a specific about of time (time can be changed remotely) so I can "log out" the user.
    I need to disable the screen saver after the screen saver runs so that it doesn't run while the java login program is running.
    I have this working already on Windows XP but can't find any way to program this on Mac OS X.
    Thank you for any help!

    http://forums.macosxhints.com/showthread.php?t=61525
    Disable
    defaults -currentHost write com.apple.screensaver idleTime 0
    Enable for 180 seconds
    defaults -currentHost write com.apple.screensaver idleTime 180

  • How do you authorize access to itunes while blocking the access of the rest of the computer?

    How do you authorize access to itunes while blocking the access of the rest of the computer? I want to do a party and let people have access to the music but  I don't want them to look in my files. I have windows 7.
    I cannot log off and let the music play. Ideally I would want to have a password for access to the rest of the computer.
    Thank you!

    The following may help with the file sharing issues: OS X Mavericks: Share your files

  • When setting up a new ipad how do you know what your user name is?

    When setting up a new ipad how do you know what your user name is?

    How to set up Apple ID
    http://support.apple.com/kb/ht2731

  • How do you log values from RT target to the computer?

    Hi,
    I am using sbRIO 9633. How do you log values from RT target to the computer?
    I created a shared variable on the RT target and used them on the log VI created under "My Computer", but I get error.
    I get this error..
     \\192.168.1.140\temp deployment failed (error: -1967357949, IAK_SHARED:  (Hex 0x8ABC8003) Unable to query Measurement & Automation Explorer for the Shared Variable Engine. Make sure the Shared Variable Engine exists on the RT target and check that the network connection is valid.).
    kdm

    What are your data rates?  If you are producing data "continuously", you might find that Network Streams are easier and more reliable than Network Shared Variables.  In any case, you need an "engine" on one side (Host or Target) or the other.  I'm streaming 24 channels of 16-bit data from a PXI controller to a PC this way, with three other streams handling two-way messaging and transmission of "occasional" time-stamped data to the PC.
    Bob Schor

  • How do you log into Facetime after already logging in?

    How do you log into Facetime for 2nd time? I have 2 iPad 2's and trying to get them to connect to same Wi-Fi and at times different Wi-Fi. However on the 2nd iPad i logged into Facetime using same itune account info, i have since setup 2nd itune account & can not figure out how to log in using a different account info.

    You log into and out of accounts in Settings/FaceTime.
    You can contact devices logged into the same Apple ID as long as they are configured with different email addresses.

  • How do you log out of the twitter app?

    how do you log out of the twitter app on a apple imac

    I can't see an obvious log out function but Twitter menu > Preferences > Accounts and you can remove the account.  It's only entering the username and password to log back in. 
    mrtotes

  • How do you log out?

    How do you log out of a forum? Is it at all possible?
    Seems I am logged in to any forum I go to if I switch between different ones, even ones I never previously used to be a member of. So am I now a member of all existing forums just because I logged in?
    I've actually been a member of several Adobe forums since 2002, but today they all consider me a new member who only joined today and gave me a screenname I  haven't used for quite some time. Not funny.

    Curt Wrigley wrote:
    Kath-H wrote:
    Chronological discussions are not confusing in the slightest. It couldn't be simpler to clarify what you are replying to if necessary.
    Actually, it could be a lot simpler.  The system could add who you are replying to automatically.
    But; if it isnt obvious to you; Im not going to be able to convince you.
    Curt, please listen to me. First off, pointing out that some new features do not seem to be an improvement doesn't put me in dinosaur territory.
    Second, even if we added an extra 'feature' of telling me who is being replied to, that doesn't tell me what they said. To know that I'd have to start jumping back and forth. If I don't even realise that an apparent non sequitur is because a person is replying to something a couple of pages back - because they are using threaded view - that's a recipe for confusion.
    Before, if we needed to reply to a post some way back, we'd swipe through the relevant text - as more than one post was visible when replying, another new annoyance - add a greater than symbol, paste and carry on.
    How do you think people will react if they've never been here before, have no clue about what threaded/flat views even are?
    I don't particularly like threaded view, partly because of the ever-shrinking width, but I'd live with it if everyone used it.
    If I insisted on living in the past I'd still be using Pagemaker or Quark and Pagemill - but you don't have to lose your critical faculties every time someone waves something new and shiny in front of your eyes.

  • How do you handle change in user names if folks get married or divorced

    If an application is using the apex authentication scheme, how do you handle change in user names if folks get married or divorced. The reason I ask the question is that all of apex uses v('app_user'), which is the user_name. If I have transactions done by this user and then their name changes, which means so does their id, how do I get all of their transactions, before and after the name change. Traditionally I would expect to use user_id, not sure if this feature is still available. I can always create a custom auth scheme, but that is a lot of additional work. Any ideas?
    Thanks,

    Appreciate your help and time Jari, below is my game plan, unless someone has a better idea,
    I plan on doing the following to use user_id for auditing of transaction records:
    1. Get the user_id to use in the tables audit trail fields
    user_id := apex_util.get_user_id(v('app_user'));
    OR
    user_id := apex_util.get_current_user_id;
    2. If a user changes their name then use
    apex_util.set_last_name(p_user_id, p_new_lastname);
    apex_util.set_username(p_userid, p_new_username);
    Thanks,

  • How do you get access to window?

    When you do a typical System.out.print-whatever it prints a stream of text onto that default java window which popped up when you executed your program. My question is, how do you get access to this particular window, so you can resize it, clear it, or put text in specific locations instead of at the end of a buffer... any tips will be appreciated. thanks

    hmm so there is no way to do anything special to that dos-like window except append text to it? Is there a way at least to remove text from it? (sorta like printing dots and then removing them?)

  • How do you log out of the FB chat on the FB app on iPad 2?

    As the title says, how do you log out of the Facebook chat on the Facebook application on IPad 2 without having to shut down the entire application?

    Anybody?

  • How do you log out of email on ipod touch 4th generation

    how do you log out of email on ipod touch 4th generation?

    Email for what? You can log out of the your Apple ID by going to Settings>iTunes and App Store and tap the signed-in ID and then tap on log out.

Maybe you are looking for