差分
このページの2つのバージョン間の差分を表示します。
| 次のリビジョン | 前のリビジョン | ||
| ja:documentation:pandorafms:cybersecurity:50_fim [2025/11/28 23:24] – 作成 junichi | ja:documentation:pandorafms:cybersecurity:50_fim [2025/11/28 23:41] (現在) – [FIM (File Integrity Monitoring)] junichi | ||
|---|---|---|---|
| 行 1: | 行 1: | ||
| - | ====== FIM (File Integrity Monitoring) ====== | + | ====== FIM (ファイル整合性監視) ====== |
| {{indexmenu_n> | {{indexmenu_n> | ||
| + | |||
| + | [[ja: | ||
| <wrap #ks1 /> | <wrap #ks1 /> | ||
| - | ===== Introduction | + | ===== 概要 |
| File integrity monitoring (**FIM**) allows you to find out whether critical and important files, such as configuration files, have been modified at any time in a system. | File integrity monitoring (**FIM**) allows you to find out whether critical and important files, such as configuration files, have been modified at any time in a system. | ||
| + | |||
| + | ファイル整合性監視 (**FIM**) を使用すると、設定ファイルなどの重要なファイルがシステム内でいつでも変更されたかどうかを確認できます。 | ||
| Pandora FMS incorporates these monitoring features in [[: | Pandora FMS incorporates these monitoring features in [[: | ||
| + | |||
| + | Pandora FMS では、バージョン 784 以降、Linux® と MS Windows® システムの両方で、これらの監視機能を [[: | ||
| <wrap #ks2 /> | <wrap #ks2 /> | ||
| - | ===== Configuration on an agent ===== | + | |
| + | ===== エージェントでの設定 | ||
| In the security settings tab of an agent, you may enable or disable **FIM** monitoring: | In the security settings tab of an agent, you may enable or disable **FIM** monitoring: | ||
| + | |||
| + | エージェントのセキュリティ設定タブでは、**FIM** 監視を有効または無効にすることができます。 | ||
| <wrap : | <wrap : | ||
| + | |||
| + | <wrap : | ||
| Enabling this monitoring allows you to specify [[# | Enabling this monitoring allows you to specify [[# | ||
| + | |||
| + | この監視を有効にすると、**エンドポイント** 間隔ごとにチェックされる [[# | ||
| Within the configuration box (<wrap : | Within the configuration box (<wrap : | ||
| + | |||
| + | 設定ボックス(< | ||
| {{ : | {{ : | ||
| For all the paths indicated, a cache time in seconds will be stored, <wrap : | For all the paths indicated, a cache time in seconds will be stored, <wrap : | ||
| + | |||
| + | 指定されたすべてのパスについて、キャッシュ時間(秒単位)が保存されます(< | ||
| In the case of paths to directories, | In the case of paths to directories, | ||
| + | |||
| + | ディレクトリへのパスの場合、そこに含まれるファイルの変更を検出するための特定のパラメータを指定することもできます。 | ||
| * You may specify the maximum depth (number of subdirectories) within the directory to search for files. | * You may specify the maximum depth (number of subdirectories) within the directory to search for files. | ||
| * You may also specify the maximum number of files to monitor in each directory, the maximum size of the files within it, and the file extensions you wish to ignore. | * You may also specify the maximum number of files to monitor in each directory, the maximum size of the files within it, and the file extensions you wish to ignore. | ||
| + | |||
| + | * ファイルを検索するディレクトリ内の最大深度(サブディレクトリの数)を指定できます。 | ||
| + | * 各ディレクトリで監視するファイルの最大数、ディレクトリ内のファイルの最大サイズ、および無視するファイル拡張子も指定できます。 | ||
| <WRAP center round tip 90%> | <WRAP center round tip 90%> | ||
| To indicate the maximum file size (<wrap : | To indicate the maximum file size (<wrap : | ||
| + | |||
| + | </ | ||
| + | |||
| + | <WRAP center round tip 90%> | ||
| + | |||
| + | 最大ファイルサイズ(< | ||
| </ | </ | ||
| <wrap #ks2_1 /> | <wrap #ks2_1 /> | ||
| - | ==== Files to include in the FIM search | + | |
| + | ==== FIM 検索に含めるファイル | ||
| Here you may specify a list of files or directories that will be monitored in detail to detect new files in that directory, files that disappear, or modified files. The maximum depth parameter and the maximum number of files to be processed in a directory parameter are designed so that if a very generic directory is entered, e.g., '' | Here you may specify a list of files or directories that will be monitored in detail to detect new files in that directory, files that disappear, or modified files. The maximum depth parameter and the maximum number of files to be processed in a directory parameter are designed so that if a very generic directory is entered, e.g., '' | ||
| + | |||
| + | ここでは、詳細に監視するファイルまたはディレクトリのリストを指定できます。これにより、ディレクトリ内の新規ファイル、消失ファイル、変更されたファイルを検出できます。最大深度パラメータとディレクトリパラメータで処理するファイルの最大数は、非常に一般的なディレクトリ(例:c: | ||
| There is also a way to exclude certain directories and/or files from the search, for example: | There is also a way to exclude certain directories and/or files from the search, for example: | ||
| + | |||
| + | 特定のディレクトリやファイルを検索から除外する方法もあります。次に例を示します。 | ||
| < | < | ||
| 行 49: | 行 82: | ||
| Or just leave comments by adding a number at the beginning of each line. That way, they will not be taken into account and may be activated if necessary: | Or just leave comments by adding a number at the beginning of each line. That way, they will not be taken into account and may be activated if necessary: | ||
| + | |||
| + | または、各行の先頭に数字を追加してコメントを残すこともできます。そうすれば、コメントは考慮されず、必要に応じて有効にできます。 | ||
| < | < | ||
| 行 56: | 行 91: | ||
| Dynamic directories (with asterisk wildcards) may be included in the search as follows: | Dynamic directories (with asterisk wildcards) may be included in the search as follows: | ||
| + | |||
| + | 動的ディレクトリ (アスタリスク ワイルドカードを使用) は次のように検索に含めることができます。 | ||
| < | < | ||
| 行 63: | 行 100: | ||
| <wrap #ks3 /> | <wrap #ks3 /> | ||
| - | ===== Monitoring policy settings | + | |
| + | ===== 監視ポリシー設定 | ||
| The same configuration that may be made on an [[# | The same configuration that may be made on an [[# | ||
| + | |||
| + | [[# | ||
| <WRAP center round important 90%> | <WRAP center round important 90%> | ||
| When **FIM** monitoring is applied from a policy, it will not be possible to modify this configuration directly in agents. | When **FIM** monitoring is applied from a policy, it will not be possible to modify this configuration directly in agents. | ||
| + | |||
| + | </ | ||
| + | |||
| + | <WRAP center round important 90%> | ||
| + | |||
| + | **FIM** 監視がポリシーから適用される場合、エージェントでこの設定を直接変更することはできません。 | ||
| </ | </ | ||
| When editing a policy, there will be a tab to enable this option: | When editing a policy, there will be a tab to enable this option: | ||
| + | |||
| + | ポリシーを編集するときに、このオプションを有効にするタブが表示されます。 | ||
| <wrap : | <wrap : | ||
| + | |||
| + | <wrap : | ||
| <WRAP center round info 90%> | <WRAP center round info 90%> | ||
| In addition to this option, you will also need to continue to indicate whether FIM is enabled or disabled for policy agents (option <wrap : | In addition to this option, you will also need to continue to indicate whether FIM is enabled or disabled for policy agents (option <wrap : | ||
| + | |||
| + | </ | ||
| + | |||
| + | <WRAP center round info 90%> | ||
| + | |||
| + | このオプションに加えて、ポリシーエージェントに対して FIM を有効にするか無効にするかを指定する必要があります(オプション< | ||
| </ | </ | ||
| These last two options work together to enable disabling FIM monitoring on a set of agents from the policy itself. In such a case, <wrap : | These last two options work together to enable disabling FIM monitoring on a set of agents from the policy itself. In such a case, <wrap : | ||
| + | |||
| + | これら最後の 2つのオプションを組み合わせることで、ポリシー自体からエージェントセットの FIM 監視を無効にすることができます。この場合、< | ||
| <WRAP center round tip 90%> | <WRAP center round tip 90%> | ||
| For EndPoints installed on MS Windows® operating systems, they must be replaced with the following files in the <wrap : | For EndPoints installed on MS Windows® operating systems, they must be replaced with the following files in the <wrap : | ||
| + | |||
| + | </ | ||
| + | |||
| + | <WRAP center round tip 90%> | ||
| + | |||
| + | MS Windows® オペレーティングシステムにインストールされたエンドポイントの場合は、< | ||
| </ | </ | ||
| 行 129: | 行 193: | ||
| Otherwise, the configuration is exactly the same as that [[# | Otherwise, the configuration is exactly the same as that [[# | ||
| + | |||
| + | それ以外の場合、設定は [[# | ||
| <wrap #ks4 /> | <wrap #ks4 /> | ||
| - | ===== FIM monitoring results | + | |
| + | ===== FIM 監視結果 | ||
| **FIM** monitoring generates the following modules in each agent that has it enabled: | **FIM** monitoring generates the following modules in each agent that has it enabled: | ||
| + | |||
| + | **FIM** 監視は、有効になっている各エージェントに次のモジュールを生成します。 | ||
| * '' | * '' | ||
| 行 140: | 行 209: | ||
| * '' | * '' | ||
| * '' | * '' | ||
| + | |||
| + | * '' | ||
| + | * '' | ||
| + | * '' | ||
| + | * '' | ||
| + | * '' | ||
| + | |||
| In addition, for each new, changed, or deleted file, log entries will be generated that may be viewed if [[: | In addition, for each new, changed, or deleted file, log entries will be generated that may be viewed if [[: | ||
| + | |||
| + | さらに、新規作成、変更、または削除されたファイルごとにログエントリが生成され、[[: | ||
| <wrap #ks5 /> | <wrap #ks5 /> | ||
| - | ===== Integration with SIEM ===== | + | |
| + | ===== SIEM との統合 | ||
| **FIM** monitoring is also integrated with [[: | **FIM** monitoring is also integrated with [[: | ||
| - | [[:en: | + | **FIM** 監視は |
| + | |||
| + | [[ja:documentation: | ||