ja:documentation:pandorafms:management_and_operation:02_events

差分

このページの2つのバージョン間の差分を表示します。

この比較画面へのリンク

両方とも前のリビジョン 前のリビジョン
次のリビジョン
前のリビジョン
ja:documentation:pandorafms:management_and_operation:02_events [2026/04/24 23:03] – [イベント応答マクロ] junichija:documentation:pandorafms:management_and_operation:02_events [2026/08/07 22:04] (現在) – [イベント] junichi
行 1: 行 1:
 ====== イベント ======  ====== イベント ====== 
  
-{{indexmenu_n>2}}+{{indexmenu_n>20}}
  
 [[ja:documentation:start|Pandora FMS ドキュメント一覧に戻る]] [[ja:documentation:start|Pandora FMS ドキュメント一覧に戻る]]
行 52: 行 52:
   * **Add a comment**: Any text that provides information and can be used to filter searches. If needed, URLs may be added in MarkDown format: ''[](URL)'', even for the <wrap :en>**Event Custom ID**</wrap> field.   * **Add a comment**: Any text that provides information and can be used to filter searches. If needed, URLs may be added in MarkDown format: ''[](URL)'', even for the <wrap :en>**Event Custom ID**</wrap> field.
   * **Make customizable responses**.   * **Make customizable responses**.
 +  * Add or modify [[#ks6_4|custom event tags]].
 +
   * **状態の変更**  (承諾または処理中)   * **状態の変更**  (承諾または処理中)
   * **所有者の変更**   * **所有者の変更**
行 57: 行 59:
   * **追加情報の表示**   * **追加情報の表示**
   * **コメントの追加**: 情報を提供し、検索をフィルタリングするために使用できる任意のテキスト。必要に応じて、<wrap :ja>**イベントカスタム ID(Event Custom ID)**</wrap> フィールドに対しても、MarkDown 形式 (''[](URL)'') で URL を追加できます。   * **コメントの追加**: 情報を提供し、検索をフィルタリングするために使用できる任意のテキスト。必要に応じて、<wrap :ja>**イベントカスタム ID(Event Custom ID)**</wrap> フィールドに対しても、MarkDown 形式 (''[](URL)'') で URL を追加できます。
-  * **カスタム応答の実施**<wrap #ks2 />+  * **カスタム応答の実施** 
 +  * [[#ks6_4|カスタムイベントタグ]]の追加または変更
  
 +<wrap #ks2 />
  
 ===== 一般情報 ===== ===== 一般情報 =====
行 495: 行 499:
 ==== イベント表示カスタマイズ ==== ==== イベント表示カスタマイズ ====
  
-It is possible to customize the fields displayed by default by the event viewer. To do so, choose the fields to be displayed from <wrap :en>**Events → View events → Manage events → Custom columns**</wrap>.+<WRAP group> 
 +<WRAP half column><WRAP center round box 90%><wrap :en>**Management → {{:wiki:pfms-configuration_icon.svg?nolink&21x21}} Configuration → Events → Custom columns**</wrap> menu.</WRAP></WRAP> 
 +<WRAP half column>You can customise the fields that are displayed by default in the event viewer:</WRAP> 
 +</WRAP>
  
-イベントビューワにデフォルトで表示されるフィールドをカスタマイズすることができます。それには、<wrap :ja>**イベント(Events)** → **イベント参照(View events)** から、**イベント管理(Manage events)** → **カスタムフィールド(Custom columns)**</wrapへ行き、表示するフィールドを選択します。+<WRAP group> 
 +<WRAP half column><WRAP center round box 90%>**管理(Management) → {{:wiki:pfms-configuration_icon.svg?nolink&21x21}} 設定(Configuration) → イベント(Events) → カスタムカラム(Custom columns)**</wrap> メニュー。</WRAP></WRAP> 
 +<WRAP half column>イベントビューワにデフォルトで表示されるフィールドをカスタマイズできます</WRAP> 
 +</WRAP>
  
-[[:wiki:pfms-management-configuration-events-custom_columns.png?id=ja%3Adocumentation%3Apandorafms%3Amanagement_and_operation%3A02_events&media=wiki:pfms-management-configuration-events-custom_columns.png|{{  :wiki:pfms-management-configuration-events-custom_columns.png  }}]]+{{  :wiki:pfms-management-configuration-events-custom_columns-803_version.png  }}
  
-The default fields are five, however there are more fields to add:+There are five fields displayed by default in the list of selected fields (the <wrap :en>**Event TagsTags**</wrap> fields have been added as an example) and you can reset them to **the last saved state** by clicking the {{:wiki:icon_clean.png?nolink&21x21|Load the fields from previous events}} button.
  
-デフォルトのフィールドは 5 つですが追加できフィールドがさらにあります+選択されたフィールドのリストには、デフォルトで 5つのフィールドが表示されていま(例として **Event Tags** および **Tags** フィールドが追加されています)。{{:wiki:icon_clean.png?nolink&21x21|以前のイベントからフィールドを読み込む(Load the fields from previous events)}} ボタンをクリックすると、これらを**最後に保存された状態**にリセットできます。 
 + 
 +There are more fields available to add: 
 + 
 +追加可能なフィールドは他あります
  
 <WRAP group> <WRAP group>
行 509: 行 523:
 <WRAP half column> <WRAP half column>
  
-  * **Event ID**. +  * <wrap :en>**Event ID**</wrap>
-  * **Agent name**. +  * <wrap :en>**Agent ID**</wrap>
-  * **User**. +  * <wrap :en>**Agent IP**</wrap>
-  * **Group**. +  * <wrap :en>**User**</wrap>
-  * **Event type**. +  * <wrap :en>**Group**</wrap>
-  * **Module name**. +  * <wrap :en>**Event type**</wrap>
-  * **Alert**. +  * <wrap :en>**Module name**</wrap>
-  * **Severity**. +  * <wrap :en>**Alert**</wrap>
-  * **Comment**. +  * <wrap :en>**Severity**</wrap>
-  * **Tags**.+  * <wrap :en>**Comment**</wrap>
 +  * <wrap :en>**Source**</wrap>. 
 </WRAP> </WRAP>
  
 <WRAP half column> <WRAP half column>
  
-  * **Source**. +  * <wrap :en>**Extra ID**</wrap>
-  * **Extra ID**. +  * <wrap :en>**Owner**</wrap>
-  * **Owner**. +  * <wrap :en>**ACK Timestamp**</wrap>
-  * **ACK Timestamp**. +  * <wrap :en>**Instructions**</wrap>
-  * **Instructions**. +  * <wrap :en>**Server name**</wrap>
-  * **Server name**. +  * <wrap :en>**Data**</wrap>
-  * **Data**. +  * <wrap :en>**Module status**</wrap>
-  * **Module status**. +  * <wrap :en>**Module custom ID**</wrap>. 
-  * **Module custom ID**.+  * <wrap :en>**Custom data**</wrap>
 +  * <wrap :en>**Event Custom ID**</wrap>
 +  * <wrap :en>**Module custom ID**</wrap>
 </WRAP> </WRAP>
  
行 563: 行 582:
   * **モジュールの状態(Module status)**  : モジュールの現在の状態   * **モジュールの状態(Module status)**  : モジュールの現在の状態
   * **モジュールカスタム ID(Module custom ID)**: モジュールのモジュールカスタムIDフィールドの値。   * **モジュールカスタム ID(Module custom ID)**: モジュールのモジュールカスタムIDフィールドの値。
 +  * <wrap :ja>**カスタムデータ(Custom data)**</wrap>
 +  * <wrap :ja>**イベントカスタムID(Event Custom ID)**</wrap>
 +  * <wrap :ja>**モジュールカスタムID(Module custom ID)**</wrap>
 </WRAP> </WRAP>
  
 </WRAP> </WRAP>
  
-<wrap #ks6_2 />+<WRAP center round info 90%>
  
 +//At least one selected field must be added//; otherwise, the system will automatically add the field <wrap :en>**Timestamp**</wrap>.
 +
 +</WRAP>
 +
 +<WRAP center round info 90%>
 +
 +//少なくとも 1つのフィールドを選択して追加する必要があります//。そうしないと、システムは自動的に **Timestamp** フィールドを追加します。
 +
 +</WRAP>
 +
 +<wrap #ks6_2 />
  
 ==== イベントフィルタの作成 ==== ==== イベントフィルタの作成 ====
行 645: 行 678:
 |  <wrap #ks6_3_2_18 />''_event_source_''  |Event source.  | |  <wrap #ks6_3_2_18 />''_event_source_''  |Event source.  |
 |  <wrap #ks6_3_2_19 />''_event_status_''  |Event status (new, validated or event in process).  | |  <wrap #ks6_3_2_19 />''_event_status_''  |Event status (new, validated or event in process).  |
-|  <wrap #ks6_3_2_20 />''_event_tags_''  |Event tags separated by commas.  |+|  <wrap #ks6_3_2_20 />''_event_tags_''  |Event tags separated by commas. This macro refers to **general event tags**, as distinct from [[#ks6_4|custom event tags]].  |
 |  <wrap #ks6_3_2_21 />''_event_text_''  |Full event text.  | |  <wrap #ks6_3_2_21 />''_event_text_''  |Full event text.  |
 |  <wrap #ks6_3_2_22 />''_event_type_''  |Type of event: \\ * Monitor in critical status. \\ * Monitor in warning status. \\ * Monitor in normal status. \\ * Unknown. \\ * Unknown Monitor. \\ * Alert triggered. \\ * Alert recovered. \\ * Alert stopped. \\ * Manual alert validation. \\ * Agent created. \\ * Recon host detected. \\ * System. \\ * Error. \\ * Configuration change. \\ * Network configuration manager.  | |  <wrap #ks6_3_2_22 />''_event_type_''  |Type of event: \\ * Monitor in critical status. \\ * Monitor in warning status. \\ * Monitor in normal status. \\ * Unknown. \\ * Unknown Monitor. \\ * Alert triggered. \\ * Alert recovered. \\ * Alert stopped. \\ * Manual alert validation. \\ * Agent created. \\ * Recon host detected. \\ * System. \\ * Error. \\ * Configuration change. \\ * Network configuration manager.  |
行 681: 行 714:
 |  <wrap #ks6_3_2_18 />''_event_source_''  |イベントソース  | |  <wrap #ks6_3_2_18 />''_event_source_''  |イベントソース  |
 |  <wrap #ks6_3_2_19 />''_event_status_''  |イベント状態 (new, validated または event in process).  | |  <wrap #ks6_3_2_19 />''_event_status_''  |イベント状態 (new, validated または event in process).  |
-|  <wrap #ks6_3_2_20 />''_event_tags_''  |カンマ区切りのイベントタグ  |+|  <wrap #ks6_3_2_20 />''_event_tags_''  |カンマ区切りのイベントタグ。このマクロは、[[#ks6_4|カスタムイベントタグ]]とは別の **汎用イベントタグ **を指します。  |
 |  <wrap #ks6_3_2_21 />''_event_text_''  |イベントテキスト  | |  <wrap #ks6_3_2_21 />''_event_text_''  |イベントテキスト  |
 |  <wrap #ks6_3_2_22 />''_event_type_''  |イベントのタイプ: \\ * Monitor in critical status. \\ * Monitor in warning status. \\ * Monitor in normal status. \\ * Unknown. \\ * Unknown Monitor. \\ * Alert triggered. \\ * Alert recovered. \\ * Alert stopped. \\ * Manual alert validation. \\ * Agent created. \\ * Recon host detected. \\ * System. \\ * Error. \\ * Configuration change. \\ * Network configuration manager.  | |  <wrap #ks6_3_2_22 />''_event_type_''  |イベントのタイプ: \\ * Monitor in critical status. \\ * Monitor in warning status. \\ * Monitor in normal status. \\ * Unknown. \\ * Unknown Monitor. \\ * Alert triggered. \\ * Alert recovered. \\ * Alert stopped. \\ * Manual alert validation. \\ * Agent created. \\ * Recon host detected. \\ * System. \\ * Error. \\ * Configuration change. \\ * Network configuration manager.  |
行 697: 行 730:
 |  <wrap #ks6_3_2_34 />''_user_id_''  |ユーザ ID  | |  <wrap #ks6_3_2_34 />''_user_id_''  |ユーザ ID  |
  
 +<wrap #ks6_4 />
  
-== _agent_address_ ==+==== カスタマイズ可能なイベントラベル ====
  
-Agent address.+<WRAP group> 
 +<WRAP half column><WRAP center round box 90%><wrap :en>**Management → {{:wiki:pfms-configuration_icon.svg?nolink&21x21}} Configuration → Events → Event tags**</wrap> menu.</WRAP></WRAP> 
 +<WRAP half column>Unlike system tags, which can be added via the [[:en:documentation:pandorafms:technical_reference:03_anexo_cli#create_event|creating an event]], custom tags managed by [[:en:documentation:pandorafms:introduction:03_glossary#superadmin|superadmin]] users are added to or removed from events [[#ks2|visually via the Web Console]].</WRAP> 
 +</WRAP>
  
-エージェントアドレス. +<WRAP group
- +<WRAP half column><WRAP center round box 90%><wrap :ja>**管理(Management→ {{:wiki:pfms-configuration_icon.svg?nolink&21x21}} 設定(Configuration→ イベント(Events→ イベントタグ(Event tags)**</wrap> メニュー。</WRAP></WRAP
-<wrap #ks6_3_2_2 /> +<WRAP half column>イベント作成時に追加できシステムタとは異なり、[[:ja:documentation:pandorafms:introduction:03_glossary#superadmin|管理者]]ザが管理するカタムタグは、ウェブコール上で視覚的にイベントへの追加や削除が行わます [[#ks2|(ウェブコンソールでの操作)]]。</WRAP
- +</WRAP>
-== _agent_alias_ == +
- +
-Agent alias. +
- +
-エージェントの別名。 +
- +
-<wrap #ks6_3_2_3 /> +
- +
-== _agent_id_ == +
- +
-Agent identifier. +
- +
-エージェント ID。 +
- +
-<wrap #ks6_3_2_4 /> +
- +
- +
-== _agent_name_ == +
- +
-Agent name. +
- +
-エージェント名。 +
- +
-<wrap #ks6_3_2_5 /> +
- +
-== _alert_id_ == +
- +
-Identifier of the alert associated with the event. +
- +
-イベントに関連するアラート ID +
- +
-<wrap #ks6_3_2_6 /> +
- +
-== _command_timeout_ == +
- +
-Command response time (seconds). +
- +
-コマンド応答時間() +
- +
-<wrap #ks6_3_2_7 /> +
- +
-== _current_user_ == +
- +
-Identifier of the user running the response. +
- +
-応答を実行したユーザの ID +
- +
-<wrap #ks6_3_2_8 /> +
- +
- +
-== _current_username_ == +
- +
-Full name of the user executing the response. +
- +
-応答を実行したユーザのフルネーム。 +
- +
-<wrap #ks6_3_2_9 /> +
- +
-== _customdata_json_ == +
- +
-It retrieves information from custom data in JSON format. +
- +
-カスタムデータから取り出した JSON フォーマットの情報。 +
- +
-<wrap #ks6_3_2_10 /> +
- +
- +
-== _customdata_text_ == +
- +
-Output all custom data in text mode (with line breaks). +
- +
-テキストモードですべてのカスタムデータ情報を取得(改行含む)。 +
- +
-<wrap #ks6_3_2_11 /> +
- +
- +
-== _customdata_X_ == +
- +
-It retrieves a particular field from custom data, replacing the X with the field name. +
- +
-カスタムデータから特定のフィールドを取得。X をフィールドの名前に置き換え。 +
- +
-<wrap #ks6_3_2_12 /> +
- +
- +
-== _event_date_ == +
- +
-Date on which the event took place. +
- +
-イベントが発生した日付。 +
- +
-<wrap #ks6_3_2_13 /> +
- +
-== _event_extra_id_ == +
- +
-Extra identifier. +
- +
-拡張イベント ID。 +
- +
-<wrap #ks6_3_2_14 /> +
- +
- +
-== _event_id_ == +
- +
-Event identifier. +
- +
-イベント ID。 +
- +
-<wrap #ks6_3_2_15 /> +
- +
- +
-== _event_instruction_ == +
- +
-Event instructions. +
- +
-イベント手順。 +
- +
-<wrap #ks6_3_2_16 /> +
- +
-== _event_severity_id_ == +
- +
-Event severity identifier. +
- +
-イベント重要度 ID。 +
- +
-<wrap #ks6_3_2_17 /> +
- +
- +
-== _event_severity_text_ == +
- +
-Event severity (translated by Pandora FMS console)+
- +
-イベント重要度 (文字列表示)。 +
- +
-<wrap #ks6_3_2_18 /> +
- +
-== _event_source_ == +
- +
-Event source. +
- +
-イベントソ +
- +
-<wrap #ks6_3_2_19 /> +
- +
-== _event_status_ == +
- +
-Event status (new, validated or event in process). +
- +
-イベントの状態 (new, validated または event in process)。 +
- +
-<wrap #ks6_3_2_20 /> +
- +
-== _event_tags_ == +
- +
-Event tags separated by commas. +
- +
-カンマ区切りのイベントタグ。 +
- +
-<wrap #ks6_3_2_21 /> +
- +
-== _event_text_ == +
- +
-Full event text. +
- +
-イベントの全テキスト。 +
- +
-<wrap #ks6_3_2_22 /> +
- +
- +
-== _event_type_ == +
- +
-Type of event: +
- +
-イベントのタイプ: +
- +
-  * Monitor in critical status. +
-  * Monitor in warning status. +
-  * Monitor in normal status. +
-  * Unknown. +
-  * Unknown Monitor. +
-  * Alert triggered. +
-  * Alert recovered. +
-  * Alert stopped. +
-  * Manual alert validation. +
-  * Agent created. +
-  * Recon host detected. +
-  * System. +
-  * Error. +
-  * Configuration change. +
-  * Network configuration manager. +
- +
-<wrap #ks6_3_2_23 /> +
- +
-== _event_utimestamp_ == +
- +
-Date on which the event occurred in utimestamp format. +
- +
-utimestamp 形式でのイベントが発生した日。 +
- +
-<wrap #ks6_3_2_24 /> +
- +
-== _group_id_ == +
- +
-Group identifier. +
- +
-グループ ID。 +
- +
-<wrap #ks6_3_2_25 /> +
- +
- +
-== _group_name_ == +
- +
-Name of the group in the database. +
- +
-データベース内おけるグループ名。 +
- +
-<wrap #ks6_3_2_26 /> +
- +
- +
-== _group_contact_ == +
- +
-[[:en:documentation:pandorafms:management_and_operation:11_managing_and_administration#ks1_2_3|Contact information]] of a group of agents. +
- +
-ジェントのグルプの[[:ja:documentation:pandorafms:management_and_operation:11_managing_and_administration#グループ作成|連絡先情報]]。 +
- +
-<wrap #ks6_3_2_27 /> +
- +
-== _module_address_ == +
- +
-Address of the module associated with the event. +
- +
-イベントに関連付けられたモジュルアドレ。 +
- +
-<wrap #ks6_3_2_28 /> +
- +
- +
-== _module_id_ == +
- +
-Identifier of the module associated to the event. +
- +
-イベトに関連付けられたモジュール ID。 +
- +
-<wrap #ks6_3_2_29 /> +
- +
- +
-== _module_name_ == +
- +
-Name of the module associated with the event. +
- +
-イベントに関連付けらたモジュール名。 +
- +
-<wrap #ks6_3_2_30 /> +
- +
- +
-== _node_id_ == +
- +
-//For Command Center (Metaconsole) and Node:// it returns the node identifier. +
- +
-//コマンドセンター(メタコンソール)とノードにおける// ノード ID +
- +
-<wrap #ks6_3_2_31 /> +
- +
- +
-== _node_name_ == +
- +
-//For Command Center (Metaconsole) and Node//: it returns the node name. +
- +
-//コマンドセンター(メタコンソール)とノードにおける//ノード名。 +
- +
-<wrap #ks6_3_2_32 /> +
- +
-== _owner_user_ == +
- +
-User who owns the event. +
- +
-イベント所有者ユーザ。 +
- +
-<wrap #ks6_3_2_33 /> +
- +
- +
-== _owner_username_ == +
- +
-Full name of the user who owns the event.+
  
-イベント所有者ユーザのフルネーム。+{{  :wiki:pfms-manage-configuration-events-events_tags-803_version.png  }}
  
-<wrap #ks6_3_2_34 />+You can add as many tags as you need, and it is recommended that you add the <wrap :en>Event tags</wrapfield to the [[#ks6_1|events view]]. If all of the above applies:
  
-== _user_id_ ==+必要なだけタグを追加できます。また、[[#ks6_1|イベント表示]]に「イベントタグ」フィールドを追加することをお勧めします。上記の条件をすべて満たす場合:
  
-User identifier.+  * If two or more custom tags are added to an event, only the first one will be displayed; to view the others, click on the help icon {{:wiki:pfms_icon_general-info_or_help_2.svg?nolink&21x21|Other tags}}. 
 +  * The items in the previous point are listed in alphabetical order. If you wish to have them in a strict order, you can create them with a leading number, whereby the item with the lowest number will always be displayed first. 
 +  * In this events view, you can sort by all the other columns, //except for the custom tags column//.
  
-ユーザ ID+  * イベントに複数のカスタムタグが追加されている場合、最初に追加されたタグのみが表示されます。他のタグを表示するには、ヘルプアイコン {{:wiki:pfms_icon_general-info_or_help_2.svg?nolink&21x21|その他のタグ}} をクリックしてください。 
 +  * 前述の項目はアルファベット順に表示されます。厳密な順序で表示したい場合は、先頭に番号を付けて作成してください。番号が小さい項目が常に最初に表示されます。 
 +  * このイベント表示では、カスタムタグ列を除くすべての列を並べ替えることができます
  
 [[:ja:documentation:start|Pandora FMS ドキュメント一覧に戻る]] [[:ja:documentation:start|Pandora FMS ドキュメント一覧に戻る]]
  • ja/documentation/pandorafms/management_and_operation/02_events.1777071801.txt.gz
  • 最終更新: 2026/04/24 23:03
  • by junichi