Have a look at cifs auditing
If you want to know what is happening to data on the SAN but inside a Windows lun you need to turn on Windows auditing on the server. This is because NetApp only sees the LUN and not it's contents.
If you want to see who's trying to access a folder of sensitive files on your file server, you can enable the Audit Object Access audit policy under Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy in the appropriate GPO. Then use the ACL editor on the Security tab of the folder's properties sheet and specify which groups of users you want to audit accessing the folder.
If you want to detect unauthorized attempts at accessing the files, enable Failure auditing in the policy and audit Read permissions in the ACL.
If you want to see who is accessing the files and modifying them, enable Success auditing in the policy and audit Write and Append permissions in the ACL.
Hope this helps