On 22/09/2016 13:56, Eugene M. Zheganin wrote: > Is there any way to figure out what these writes are ? Because I cannot > propose any simple enough method.
Given you're using volumes for datasets where ZFS knows nothing about the contained filesystem structure, about the only way to proceed is via the windows site of things. You'ld need to somehow trap where windows issues a write and proceed from there. Ideally you could do something like snapshot NTFS, wait until windows has written something and then compare the snapshot with the live filesystem. Very cursory Googling suggests that Microsoft calls this sort of thing a 'shadow copy' Cheers, Matthew
Description: OpenPGP digital signature