差分
このページの2つのバージョン間の差分を表示します。
| 両方とも前のリビジョン 前のリビジョン 次のリビジョン | 前のリビジョン | ||
| ja:documentation:pandorafms:management_and_operation:02_events [2026/04/24 22:42] – [イベント作成と承諾] junichi | ja:documentation:pandorafms:management_and_operation:02_events [2026/08/07 22:04] (現在) – [イベント] junichi | ||
|---|---|---|---|
| 行 1: | 行 1: | ||
| ====== イベント ====== | ====== イベント ====== | ||
| - | {{indexmenu_n> | + | {{indexmenu_n> |
| [[ja: | [[ja: | ||
| 行 52: | 行 52: | ||
| * **Add a comment**: Any text that provides information and can be used to filter searches. If needed, URLs may be added in MarkDown format: '' | * **Add a comment**: Any text that provides information and can be used to filter searches. If needed, URLs may be added in MarkDown format: '' | ||
| * **Make customizable responses**. | * **Make customizable responses**. | ||
| + | * Add or modify [[# | ||
| + | |||
| * **状態の変更** | * **状態の変更** | ||
| * **所有者の変更** | * **所有者の変更** | ||
| 行 57: | 行 59: | ||
| * **追加情報の表示** | * **追加情報の表示** | ||
| * **コメントの追加**: | * **コメントの追加**: | ||
| - | * **カスタム応答の実施**< | + | * **カスタム応答の実施** |
| + | * [[#ks6_4|カスタムイベントタグ]]の追加または変更 | ||
| + | <wrap #ks2 /> | ||
| ===== 一般情報 ===== | ===== 一般情報 ===== | ||
| 行 495: | 行 499: | ||
| ==== イベント表示カスタマイズ ==== | ==== イベント表示カスタマイズ ==== | ||
| - | It is possible to customize the fields displayed by default by the event viewer. To do so, choose the fields to be displayed from <wrap :en>**Events | + | <WRAP group> |
| + | <WRAP half column>< | ||
| + | <WRAP half column> | ||
| + | </ | ||
| - | イベントビューワにデフォルトで表示されるフィールドをカスタマイズすることができます。それには、<wrap :ja>**イベント(Events)** → **イベント参照(View events)** から、**イベント管理(Manage events)** → **カスタムフィールド(Custom columns)**</wrap> へ行き、表示するフィールドを選択します。 | + | <WRAP group> |
| + | <WRAP half column>< | ||
| + | <WRAP half column>イベントビューワにデフォルトで表示されるフィールドをカスタマイズできます:</WRAP> | ||
| + | </WRAP> | ||
| - | [[: | + | {{ : |
| - | The default fields | + | There are five fields displayed by default in the list of selected fields (the <wrap : |
| - | デフォルトのフィールドは 5 つですが、追加できるフィールドがさらにあります。 | + | 選択されたフィールドのリストには、デフォルトで 5つのフィールドが表示されています(例として **Event Tags** および **Tags** フィールドが追加されています)。{{: |
| + | |||
| + | There are more fields available to add: | ||
| + | |||
| + | 追加可能なフィールドは他にもあります: | ||
| <WRAP group> | <WRAP group> | ||
| 行 509: | 行 523: | ||
| <WRAP half column> | <WRAP half column> | ||
| - | * **Event ID**. | + | * <wrap :en>**Event ID**</ |
| - | * **Agent | + | * <wrap :en>**Agent |
| - | * **User**. | + | * <wrap : |
| - | * **Group**. | + | * <wrap :en>**User**</ |
| - | * **Event type**. | + | * <wrap :en>**Group**</ |
| - | * **Module name**. | + | * <wrap :en>**Event type**</ |
| - | * **Alert**. | + | * <wrap :en>**Module name**</ |
| - | * **Severity**. | + | * <wrap :en>**Alert**</ |
| - | * **Comment**. | + | * <wrap :en>**Severity**</ |
| - | * **Tags**. | + | * <wrap :en>**Comment**</ |
| + | * <wrap :en>**Source**</ | ||
| </ | </ | ||
| <WRAP half column> | <WRAP half column> | ||
| - | * **Source**. | + | * <wrap :en>**Extra ID**</ |
| - | * **Extra ID**. | + | * <wrap :en>**Owner**</ |
| - | * **Owner**. | + | * <wrap :en>**ACK Timestamp**</ |
| - | * **ACK Timestamp**. | + | * <wrap :en>**Instructions**</ |
| - | * **Instructions**. | + | * <wrap :en>**Server name**</ |
| - | * **Server name**. | + | * <wrap :en>**Data**</ |
| - | * **Data**. | + | * <wrap :en>**Module status**</ |
| - | * **Module status**. | + | * <wrap :en>**Module custom ID**</ |
| - | * **Module custom ID**. | + | * <wrap : |
| + | * <wrap : | ||
| + | * <wrap : | ||
| </ | </ | ||
| 行 563: | 行 582: | ||
| * **モジュールの状態(Module status)** | * **モジュールの状態(Module status)** | ||
| * **モジュールカスタム ID(Module custom ID)**: モジュールのモジュールカスタムIDフィールドの値。 | * **モジュールカスタム ID(Module custom ID)**: モジュールのモジュールカスタムIDフィールドの値。 | ||
| + | * <wrap : | ||
| + | * <wrap : | ||
| + | * <wrap : | ||
| </ | </ | ||
| </ | </ | ||
| - | < | + | <WRAP center round info 90%> |
| + | |||
| + | //At least one selected field must be added//; otherwise, the system will automatically add the field < | ||
| + | |||
| + | </ | ||
| + | |||
| + | <WRAP center round info 90%> | ||
| + | |||
| + | // | ||
| + | |||
| + | </WRAP> | ||
| + | <wrap #ks6_2 /> | ||
| ==== イベントフィルタの作成 ==== | ==== イベントフィルタの作成 ==== | ||
| 行 589: | 行 622: | ||
| === 概要 === | === 概要 === | ||
| - | An event response is a custom action that may be executed on an event, such as creating a ticket in [[: | + | <WRAP left round box 50%> |
| - | ここでは、イベント応答を作成、編集、削除できます。 イベント応答は、イベントに対して実行できるパーソナライズされたアクションです。たとえば、イベントの関連情報と統合した [[:en: | + | < |
| - | Enter a representative name, description, | + | </WRAP> |
| + | \\ \\ \\ \\ \\ | ||
| - | 代表名、説明、カンマで区切られたパラメータ、使用するコマンド (マクロの使用が可能)、タイプ、コマンドを実行するサーバを入力します。<wrap :ja>**パラメータ(Parameters)**</ | + | <WRAP left round box 50%> |
| - | < | + | < |
| - | === イベント応答マクロ === | + | </ |
| + | \\ \\ \\ \\ \\ | ||
| - | < | + | In Pandora FMS, the [[# |
| - | == _agent_address_ == | + | Pandora FMSでは、< |
| - | Agent address. | + | A macro is a text tag enclosed in backticks (such as '' |
| - | エージェントアドレス. | + | マクロとは、バッククォートで囲まれたテキストタグ(例:'' |
| - | < | + | They are used in various sections of PFMS, such as [[# |
| - | == _agent_alias_ == | + | これらは、[[# |
| - | Agent alias. | + | Example of how to use the '' |
| - | エージェントの別名。 | + | イベントに含まれる IP アドレスをコマンドに渡すために、'' |
| - | <wrap #ks6_3_2_3 /> | + | {{ : |
| - | == _agent_id_ == | + | <wrap #ks6_3_2 /> |
| - | Agent identifier. | + | === イベント応答マクロ === |
| - | エージェント ID。 | + | ^ Macro ^ Description ^ |
| + | | <wrap #ks6_3_2_1 />'' | ||
| + | | <wrap #ks6_3_2_2 />'' | ||
| + | | <wrap #ks6_3_2_3 />'' | ||
| + | | <wrap #ks6_3_2_4 />'' | ||
| + | | <wrap #ks6_3_2_5 />'' | ||
| + | | <wrap #ks6_3_2_6 />'' | ||
| + | | <wrap #ks6_3_2_7 />'' | ||
| + | | <wrap #ks6_3_2_8 />'' | ||
| + | | <wrap #ks6_3_2_9 />'' | ||
| + | | <wrap #ks6_3_2_10 />'' | ||
| + | | <wrap #ks6_3_2_11 />'' | ||
| + | | <wrap #ks6_3_2_12 />'' | ||
| + | | <wrap #ks6_3_2_13 />'' | ||
| + | | <wrap #ks6_3_2_14 />'' | ||
| + | | <wrap #ks6_3_2_15 />'' | ||
| + | | <wrap #ks6_3_2_16 />'' | ||
| + | | <wrap #ks6_3_2_17 />'' | ||
| + | | <wrap #ks6_3_2_18 />'' | ||
| + | | <wrap #ks6_3_2_19 />'' | ||
| + | | <wrap #ks6_3_2_20 />'' | ||
| + | | <wrap #ks6_3_2_21 />'' | ||
| + | | <wrap #ks6_3_2_22 />'' | ||
| + | | <wrap #ks6_3_2_23 />'' | ||
| + | | <wrap #ks6_3_2_24 />'' | ||
| + | | <wrap #ks6_3_2_25 />'' | ||
| + | | <wrap #ks6_3_2_26 />'' | ||
| + | | <wrap #ks6_3_2_27 />'' | ||
| + | | <wrap #ks6_3_2_28 />'' | ||
| + | | <wrap #ks6_3_2_29 />'' | ||
| + | | <wrap #ks6_3_2_3 />'' | ||
| + | | <wrap #ks6_3_2_31 />'' | ||
| + | | <wrap #ks6_3_2_32 />'' | ||
| + | | <wrap #ks6_3_2_33 />'' | ||
| + | | <wrap #ks6_3_2_34 />'' | ||
| - | <wrap #ks6_3_2_4 /> | + | ^ マクロ ^ 説明 ^ |
| + | | <wrap #ks6_3_2_1 />'' | ||
| + | | <wrap #ks6_3_2_2 />'' | ||
| + | | <wrap #ks6_3_2_3 />'' | ||
| + | | | ||
| + | | <wrap #ks6_3_2_5 />'' | ||
| + | | <wrap #ks6_3_2_6 />'' | ||
| + | | <wrap #ks6_3_2_7 />'' | ||
| + | | <wrap #ks6_3_2_8 />'' | ||
| + | | <wrap #ks6_3_2_9 />'' | ||
| + | | <wrap #ks6_3_2_10 />'' | ||
| + | | <wrap #ks6_3_2_11 />'' | ||
| + | | <wrap #ks6_3_2_12 />'' | ||
| + | | <wrap #ks6_3_2_13 />'' | ||
| + | | <wrap #ks6_3_2_14 />'' | ||
| + | | <wrap #ks6_3_2_15 />'' | ||
| + | | <wrap #ks6_3_2_16 />'' | ||
| + | | <wrap #ks6_3_2_17 />'' | ||
| + | | <wrap #ks6_3_2_18 />'' | ||
| + | | <wrap #ks6_3_2_19 />'' | ||
| + | | <wrap #ks6_3_2_20 />'' | ||
| + | | <wrap #ks6_3_2_21 />'' | ||
| + | | <wrap #ks6_3_2_22 />'' | ||
| + | | <wrap #ks6_3_2_23 />'' | ||
| + | | <wrap #ks6_3_2_24 />'' | ||
| + | | <wrap #ks6_3_2_25 />'' | ||
| + | | <wrap #ks6_3_2_26 />'' | ||
| + | | <wrap #ks6_3_2_27 />'' | ||
| + | | <wrap #ks6_3_2_28 />'' | ||
| + | | <wrap #ks6_3_2_29 />'' | ||
| + | | <wrap #ks6_3_2_3 />'' | ||
| + | | <wrap #ks6_3_2_31 />'' | ||
| + | | <wrap #ks6_3_2_32 />'' | ||
| + | | <wrap #ks6_3_2_33 />'' | ||
| + | | <wrap #ks6_3_2_34 />'' | ||
| + | <wrap #ks6_4 /> | ||
| - | == _agent_name_ | + | ==== カスタマイズ可能なイベントラベル ==== |
| - | Agent name. | + | <WRAP group> |
| + | <WRAP half column>< | ||
| + | <WRAP half column> | ||
| + | </ | ||
| - | エージェント名。 | + | <WRAP group> |
| - | + | <WRAP half column><WRAP center round box 90%>< | |
| - | <wrap #ks6_3_2_5 /> | + | <WRAP half column> |
| - | + | </WRAP> | |
| - | == _alert_id_ == | + | |
| - | + | ||
| - | Identifier of the alert associated with the event. | + | |
| - | + | ||
| - | イベントに関連するアラート ID | + | |
| - | + | ||
| - | <wrap #ks6_3_2_6 /> | + | |
| - | + | ||
| - | == _command_timeout_ == | + | |
| - | + | ||
| - | Command response time (seconds). | + | |
| - | + | ||
| - | コマンド応答時間(秒) | + | |
| - | + | ||
| - | <wrap #ks6_3_2_7 /> | + | |
| - | + | ||
| - | == _current_user_ == | + | |
| - | + | ||
| - | Identifier of the user running the response. | + | |
| - | + | ||
| - | 応答を実行したユーザの ID | + | |
| - | + | ||
| - | < | + | |
| - | + | ||
| - | + | ||
| - | == _current_username_ == | + | |
| - | + | ||
| - | Full name of the user executing the response. | + | |
| - | + | ||
| - | 応答を実行したユーザのフルネーム。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_9 /> | + | |
| - | + | ||
| - | == _customdata_json_ == | + | |
| - | + | ||
| - | It retrieves information from custom data in JSON format. | + | |
| - | + | ||
| - | カスタムデータから取り出した JSON フォーマットの情報。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_10 /> | + | |
| - | + | ||
| - | + | ||
| - | == _customdata_text_ == | + | |
| - | + | ||
| - | Output all custom data in text mode (with line breaks). | + | |
| - | + | ||
| - | テキストモードですべてのカスタムデータ情報を取得(改行含む)。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_11 /> | + | |
| - | + | ||
| - | + | ||
| - | == _customdata_X_ == | + | |
| - | + | ||
| - | It retrieves a particular field from custom data, replacing the X with the field name. | + | |
| - | + | ||
| - | カスタムデータから特定のフィールドを取得。X をフィールドの名前に置き換え。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_12 /> | + | |
| - | + | ||
| - | + | ||
| - | == _event_date_ == | + | |
| - | + | ||
| - | Date on which the event took place. | + | |
| - | + | ||
| - | イベントが発生した日付。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_13 /> | + | |
| - | + | ||
| - | == _event_extra_id_ == | + | |
| - | + | ||
| - | Extra identifier. | + | |
| - | + | ||
| - | 拡張イベント ID。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_14 /> | + | |
| - | + | ||
| - | + | ||
| - | == _event_id_ == | + | |
| - | + | ||
| - | Event identifier. | + | |
| - | + | ||
| - | イベント ID。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_15 /> | + | |
| - | + | ||
| - | + | ||
| - | == _event_instruction_ == | + | |
| - | + | ||
| - | Event instructions. | + | |
| - | + | ||
| - | イベント手順。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_16 /> | + | |
| - | + | ||
| - | == _event_severity_id_ == | + | |
| - | + | ||
| - | Event severity identifier. | + | |
| - | + | ||
| - | イベント重要度 ID。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_17 /> | + | |
| - | + | ||
| - | + | ||
| - | == _event_severity_text_ == | + | |
| - | + | ||
| - | Event severity | + | |
| - | + | ||
| - | イベント重要度 | + | |
| - | + | ||
| - | < | + | |
| - | + | ||
| - | == _event_source_ == | + | |
| - | + | ||
| - | Event source. | + | |
| - | + | ||
| - | イベントソース。 | + | |
| - | + | ||
| - | <wrap # | + | |
| - | + | ||
| - | == _event_status_ == | + | |
| - | + | ||
| - | Event status (new, validated or event in process). | + | |
| - | + | ||
| - | イベントの状態 (new, validated または event in process)。 | + | |
| - | + | ||
| - | <wrap # | + | |
| - | + | ||
| - | == _event_tags_ == | + | |
| - | + | ||
| - | Event tags separated by commas. | + | |
| - | + | ||
| - | カンマ区切りのイベントタグ。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_21 /> | + | |
| - | + | ||
| - | == _event_text_ == | + | |
| - | + | ||
| - | Full event text. | + | |
| - | + | ||
| - | イベントの全テキスト。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_22 /> | + | |
| - | + | ||
| - | + | ||
| - | == _event_type_ == | + | |
| - | + | ||
| - | Type of event: | + | |
| - | + | ||
| - | イベントのタイプ: | + | |
| - | + | ||
| - | * Monitor in critical status. | + | |
| - | * Monitor in warning status. | + | |
| - | * Monitor in normal status. | + | |
| - | * Unknown. | + | |
| - | * Unknown Monitor. | + | |
| - | * Alert triggered. | + | |
| - | * Alert recovered. | + | |
| - | * Alert stopped. | + | |
| - | * Manual alert validation. | + | |
| - | * Agent created. | + | |
| - | * Recon host detected. | + | |
| - | * System. | + | |
| - | * Error. | + | |
| - | * Configuration change. | + | |
| - | * Network configuration manager. | + | |
| - | + | ||
| - | <wrap #ks6_3_2_23 /> | + | |
| - | + | ||
| - | == _event_utimestamp_ == | + | |
| - | + | ||
| - | Date on which the event occurred in utimestamp format. | + | |
| - | + | ||
| - | utimestamp 形式でのイベントが発生した日時。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_24 /> | + | |
| - | + | ||
| - | == _group_id_ == | + | |
| - | + | ||
| - | Group identifier. | + | |
| - | + | ||
| - | グループ ID。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_25 /> | + | |
| - | + | ||
| - | + | ||
| - | == _group_name_ == | + | |
| - | + | ||
| - | Name of the group in the database. | + | |
| - | + | ||
| - | データベース内におけるグループ名。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_26 /> | + | |
| - | + | ||
| - | + | ||
| - | == _group_contact_ == | + | |
| - | + | ||
| - | [[:en: | + | |
| - | + | ||
| - | エージェントのグループの[[: | + | |
| - | + | ||
| - | <wrap #ks6_3_2_27 /> | + | |
| - | + | ||
| - | == _module_address_ == | + | |
| - | + | ||
| - | Address of the module associated with the event. | + | |
| - | + | ||
| - | イベントに関連付けられたモジュールアドレス。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_28 /> | + | |
| - | + | ||
| - | + | ||
| - | == _module_id_ == | + | |
| - | + | ||
| - | Identifier of the module associated to the event. | + | |
| - | + | ||
| - | イベントに関連付けられたモジュール | + | |
| - | + | ||
| - | <wrap #ks6_3_2_29 /> | + | |
| - | + | ||
| - | + | ||
| - | == _module_name_ == | + | |
| - | + | ||
| - | Name of the module associated with the event. | + | |
| - | + | ||
| - | イベントに関連付けられたモジュール名。 | + | |
| - | + | ||
| - | < | + | |
| - | + | ||
| - | + | ||
| - | == _node_id_ == | + | |
| - | + | ||
| - | //For Command Center (Metaconsole) and Node:// it returns the node identifier. | + | |
| - | + | ||
| - | // | + | |
| - | + | ||
| - | <wrap # | + | |
| - | + | ||
| - | + | ||
| - | == _node_name_ == | + | |
| - | + | ||
| - | //For Command Center (Metaconsole) and Node//: it returns the node name. | + | |
| - | + | ||
| - | // | + | |
| - | + | ||
| - | <wrap # | + | |
| - | + | ||
| - | == _owner_user_ == | + | |
| - | + | ||
| - | User who owns the event. | + | |
| - | + | ||
| - | イベント所有者ユーザ。 | + | |
| - | + | ||
| - | <wrap #ks6_3_2_33 /> | + | |
| - | + | ||
| - | + | ||
| - | == _owner_username_ == | + | |
| - | + | ||
| - | Full name of the user who owns the event. | + | |
| - | イベント所有者ユーザのフルネーム。 | + | {{ : |
| - | < | + | You can add as many tags as you need, and it is recommended that you add the < |
| - | == _user_id_ == | + | 必要なだけタグを追加できます。また、[[# |
| - | User identifier. | + | * If two or more custom tags are added to an event, only the first one will be displayed; to view the others, click on the help icon {{: |
| + | * The items in the previous point are listed in alphabetical order. If you wish to have them in a strict order, you can create them with a leading number, whereby the item with the lowest number will always be displayed first. | ||
| + | * In this events view, you can sort by all the other columns, //except for the custom tags column//. | ||
| - | ユーザ ID。 | + | * イベントに複数のカスタムタグが追加されている場合、最初に追加されたタグのみが表示されます。他のタグを表示するには、ヘルプアイコン {{: |
| + | * 前述の項目はアルファベット順に表示されます。厳密な順序で表示したい場合は、先頭に番号を付けて作成してください。番号が小さい項目が常に最初に表示されます。 | ||
| + | * このイベント表示では、カスタムタグ列を除くすべての列を並べ替えることができます。 | ||
| [[: | [[: | ||