差分
このページの2つのバージョン間の差分を表示します。
| 両方とも前のリビジョン 前のリビジョン 次のリビジョン | 前のリビジョン | ||
| ja:documentation:pandorafms:cybersecurity:50_fim [2025/11/28 23:30] – [Configuration on an agent] junichi | ja:documentation:pandorafms:cybersecurity:50_fim [2025/11/28 23:41] (現在) – [FIM (File Integrity Monitoring)] junichi | ||
|---|---|---|---|
| 行 1: | 行 1: | ||
| - | ====== FIM (File Integrity Monitoring) ====== | + | ====== FIM (ファイル整合性監視) ====== |
| {{indexmenu_n> | {{indexmenu_n> | ||
| 行 66: | 行 66: | ||
| <wrap #ks2_1 /> | <wrap #ks2_1 /> | ||
| - | ==== Files to include in the FIM search | + | ==== FIM 検索に含めるファイル |
| Here you may specify a list of files or directories that will be monitored in detail to detect new files in that directory, files that disappear, or modified files. The maximum depth parameter and the maximum number of files to be processed in a directory parameter are designed so that if a very generic directory is entered, e.g., '' | Here you may specify a list of files or directories that will be monitored in detail to detect new files in that directory, files that disappear, or modified files. The maximum depth parameter and the maximum number of files to be processed in a directory parameter are designed so that if a very generic directory is entered, e.g., '' | ||
| + | |||
| + | ここでは、詳細に監視するファイルまたはディレクトリのリストを指定できます。これにより、ディレクトリ内の新規ファイル、消失ファイル、変更されたファイルを検出できます。最大深度パラメータとディレクトリパラメータで処理するファイルの最大数は、非常に一般的なディレクトリ(例:c: | ||
| There is also a way to exclude certain directories and/or files from the search, for example: | There is also a way to exclude certain directories and/or files from the search, for example: | ||
| + | |||
| + | 特定のディレクトリやファイルを検索から除外する方法もあります。次に例を示します。 | ||
| < | < | ||
| 行 78: | 行 82: | ||
| Or just leave comments by adding a number at the beginning of each line. That way, they will not be taken into account and may be activated if necessary: | Or just leave comments by adding a number at the beginning of each line. That way, they will not be taken into account and may be activated if necessary: | ||
| + | |||
| + | または、各行の先頭に数字を追加してコメントを残すこともできます。そうすれば、コメントは考慮されず、必要に応じて有効にできます。 | ||
| < | < | ||
| 行 85: | 行 91: | ||
| Dynamic directories (with asterisk wildcards) may be included in the search as follows: | Dynamic directories (with asterisk wildcards) may be included in the search as follows: | ||
| + | |||
| + | 動的ディレクトリ (アスタリスク ワイルドカードを使用) は次のように検索に含めることができます。 | ||
| < | < | ||
| 行 92: | 行 100: | ||
| <wrap #ks3 /> | <wrap #ks3 /> | ||
| - | ===== Monitoring policy settings | + | |
| + | ===== 監視ポリシー設定 | ||
| The same configuration that may be made on an [[# | The same configuration that may be made on an [[# | ||
| + | |||
| + | [[# | ||
| <WRAP center round important 90%> | <WRAP center round important 90%> | ||
| When **FIM** monitoring is applied from a policy, it will not be possible to modify this configuration directly in agents. | When **FIM** monitoring is applied from a policy, it will not be possible to modify this configuration directly in agents. | ||
| + | |||
| + | </ | ||
| + | |||
| + | <WRAP center round important 90%> | ||
| + | |||
| + | **FIM** 監視がポリシーから適用される場合、エージェントでこの設定を直接変更することはできません。 | ||
| </ | </ | ||
| When editing a policy, there will be a tab to enable this option: | When editing a policy, there will be a tab to enable this option: | ||
| + | |||
| + | ポリシーを編集するときに、このオプションを有効にするタブが表示されます。 | ||
| <wrap : | <wrap : | ||
| + | |||
| + | <wrap : | ||
| <WRAP center round info 90%> | <WRAP center round info 90%> | ||
| In addition to this option, you will also need to continue to indicate whether FIM is enabled or disabled for policy agents (option <wrap : | In addition to this option, you will also need to continue to indicate whether FIM is enabled or disabled for policy agents (option <wrap : | ||
| + | |||
| + | </ | ||
| + | |||
| + | <WRAP center round info 90%> | ||
| + | |||
| + | このオプションに加えて、ポリシーエージェントに対して FIM を有効にするか無効にするかを指定する必要があります(オプション< | ||
| </ | </ | ||
| These last two options work together to enable disabling FIM monitoring on a set of agents from the policy itself. In such a case, <wrap : | These last two options work together to enable disabling FIM monitoring on a set of agents from the policy itself. In such a case, <wrap : | ||
| + | |||
| + | これら最後の 2つのオプションを組み合わせることで、ポリシー自体からエージェントセットの FIM 監視を無効にすることができます。この場合、< | ||
| <WRAP center round tip 90%> | <WRAP center round tip 90%> | ||
| For EndPoints installed on MS Windows® operating systems, they must be replaced with the following files in the <wrap : | For EndPoints installed on MS Windows® operating systems, they must be replaced with the following files in the <wrap : | ||
| + | |||
| + | </ | ||
| + | |||
| + | <WRAP center round tip 90%> | ||
| + | |||
| + | MS Windows® オペレーティングシステムにインストールされたエンドポイントの場合は、< | ||
| </ | </ | ||
| 行 158: | 行 193: | ||
| Otherwise, the configuration is exactly the same as that [[# | Otherwise, the configuration is exactly the same as that [[# | ||
| + | |||
| + | それ以外の場合、設定は [[# | ||
| <wrap #ks4 /> | <wrap #ks4 /> | ||
| - | ===== FIM monitoring results | + | |
| + | ===== FIM 監視結果 | ||
| **FIM** monitoring generates the following modules in each agent that has it enabled: | **FIM** monitoring generates the following modules in each agent that has it enabled: | ||
| + | |||
| + | **FIM** 監視は、有効になっている各エージェントに次のモジュールを生成します。 | ||
| * '' | * '' | ||
| 行 169: | 行 209: | ||
| * '' | * '' | ||
| * '' | * '' | ||
| + | |||
| + | * '' | ||
| + | * '' | ||
| + | * '' | ||
| + | * '' | ||
| + | * '' | ||
| + | |||
| In addition, for each new, changed, or deleted file, log entries will be generated that may be viewed if [[: | In addition, for each new, changed, or deleted file, log entries will be generated that may be viewed if [[: | ||
| + | |||
| + | さらに、新規作成、変更、または削除されたファイルごとにログエントリが生成され、[[: | ||
| <wrap #ks5 /> | <wrap #ks5 /> | ||
| - | ===== Integration with SIEM ===== | + | |
| + | ===== SIEM との統合 | ||
| **FIM** monitoring is also integrated with [[: | **FIM** monitoring is also integrated with [[: | ||
| + | |||
| + | **FIM** 監視は [[: | ||
| [[ja: | [[ja: | ||