| 両方とも前のリビジョン 前のリビジョン 次のリビジョン | 前のリビジョン |
| ja:documentation:pandorafms:management_and_operation:02_events [2026/07/03 22:03] – [概要] junichi | ja:documentation:pandorafms:management_and_operation:02_events [2026/08/07 22:04] (現在) – [イベント] junichi |
|---|
| ====== イベント ====== | ====== イベント ====== |
| |
| {{indexmenu_n>2}} | {{indexmenu_n>20}} |
| |
| [[ja:documentation:start|Pandora FMS ドキュメント一覧に戻る]] | [[ja:documentation:start|Pandora FMS ドキュメント一覧に戻る]] |
| * **追加情報の表示** | * **追加情報の表示** |
| * **コメントの追加**: 情報を提供し、検索をフィルタリングするために使用できる任意のテキスト。必要に応じて、<wrap :ja>**イベントカスタム ID(Event Custom ID)**</wrap> フィールドに対しても、MarkDown 形式 (''[](URL)'') で URL を追加できます。 | * **コメントの追加**: 情報を提供し、検索をフィルタリングするために使用できる任意のテキスト。必要に応じて、<wrap :ja>**イベントカスタム ID(Event Custom ID)**</wrap> フィールドに対しても、MarkDown 形式 (''[](URL)'') で URL を追加できます。 |
| * **カスタム応答の実施**<wrap #ks2 /> | * **カスタム応答の実施** |
| * [[#ks6_4|カスタムイベントタグ]]の追加または変更 | * [[#ks6_4|カスタムイベントタグ]]の追加または変更 |
| |
| ==== イベント表示カスタマイズ ==== | ==== イベント表示カスタマイズ ==== |
| |
| It is possible to customize the fields displayed by default by the event viewer. To do so, choose the fields to be displayed from <wrap :en>**Events → View events → Manage events → Custom columns**</wrap>. | <WRAP group> |
| | <WRAP half column><WRAP center round box 90%><wrap :en>**Management → {{:wiki:pfms-configuration_icon.svg?nolink&21x21}} Configuration → Events → Custom columns**</wrap> menu.</WRAP></WRAP> |
| | <WRAP half column>You can customise the fields that are displayed by default in the event viewer:</WRAP> |
| | </WRAP> |
| |
| イベントビューワにデフォルトで表示されるフィールドをカスタマイズすることができます。それには、<wrap :ja>**イベント(Events)** → **イベント参照(View events)** から、**イベント管理(Manage events)** → **カスタムフィールド(Custom columns)**</wrap> へ行き、表示するフィールドを選択します。 | <WRAP group> |
| | <WRAP half column><WRAP center round box 90%>**管理(Management) → {{:wiki:pfms-configuration_icon.svg?nolink&21x21}} 設定(Configuration) → イベント(Events) → カスタムカラム(Custom columns)**</wrap> メニュー。</WRAP></WRAP> |
| | <WRAP half column>イベントビューワにデフォルトで表示されるフィールドをカスタマイズできます:</WRAP> |
| | </WRAP> |
| |
| [[:wiki:pfms-management-configuration-events-custom_columns.png?id=ja%3Adocumentation%3Apandorafms%3Amanagement_and_operation%3A02_events&media=wiki:pfms-management-configuration-events-custom_columns.png|{{ :wiki:pfms-management-configuration-events-custom_columns.png }}]] | {{ :wiki:pfms-management-configuration-events-custom_columns-803_version.png }} |
| |
| The default fields are five, however there are more fields to add: | There are five fields displayed by default in the list of selected fields (the <wrap :en>**Event Tags, Tags**</wrap> fields have been added as an example) and you can reset them to **the last saved state** by clicking the {{:wiki:icon_clean.png?nolink&21x21|Load the fields from previous events}} button. |
| |
| デフォルトのフィールドは 5 つですが、追加できるフィールドがさらにあります。 | 選択されたフィールドのリストには、デフォルトで 5つのフィールドが表示されています(例として **Event Tags** および **Tags** フィールドが追加されています)。{{:wiki:icon_clean.png?nolink&21x21|以前のイベントからフィールドを読み込む(Load the fields from previous events)}} ボタンをクリックすると、これらを**最後に保存された状態**にリセットできます。 |
| | |
| | There are more fields available to add: |
| | |
| | 追加可能なフィールドは他にもあります: |
| |
| <WRAP group> | <WRAP group> |
| <WRAP half column> | <WRAP half column> |
| |
| * **Event ID**. | * <wrap :en>**Event ID**</wrap>. |
| * **Agent name**. | * <wrap :en>**Agent ID**</wrap>. |
| * **User**. | * <wrap :en>**Agent IP**</wrap>. |
| * **Group**. | * <wrap :en>**User**</wrap>. |
| * **Event type**. | * <wrap :en>**Group**</wrap>. |
| * **Module name**. | * <wrap :en>**Event type**</wrap>. |
| * **Alert**. | * <wrap :en>**Module name**</wrap>. |
| * **Severity**. | * <wrap :en>**Alert**</wrap>. |
| * **Comment**. | * <wrap :en>**Severity**</wrap>. |
| * **Tags**. | * <wrap :en>**Comment**</wrap>. |
| | * <wrap :en>**Source**</wrap>. |
| </WRAP> | </WRAP> |
| |
| <WRAP half column> | <WRAP half column> |
| |
| * **Source**. | * <wrap :en>**Extra ID**</wrap>. |
| * **Extra ID**. | * <wrap :en>**Owner**</wrap>. |
| * **Owner**. | * <wrap :en>**ACK Timestamp**</wrap>. |
| * **ACK Timestamp**. | * <wrap :en>**Instructions**</wrap>. |
| * **Instructions**. | * <wrap :en>**Server name**</wrap>. |
| * **Server name**. | * <wrap :en>**Data**</wrap>. |
| * **Data**. | * <wrap :en>**Module status**</wrap>. |
| * **Module status**. | * <wrap :en>**Module custom ID**</wrap>. |
| * **Module custom ID**. | * <wrap :en>**Custom data**</wrap>. |
| | * <wrap :en>**Event Custom ID**</wrap>. |
| | * <wrap :en>**Module custom ID**</wrap>. |
| </WRAP> | </WRAP> |
| |
| * **モジュールの状態(Module status)** : モジュールの現在の状態 | * **モジュールの状態(Module status)** : モジュールの現在の状態 |
| * **モジュールカスタム ID(Module custom ID)**: モジュールのモジュールカスタムIDフィールドの値。 | * **モジュールカスタム ID(Module custom ID)**: モジュールのモジュールカスタムIDフィールドの値。 |
| | * <wrap :ja>**カスタムデータ(Custom data)**</wrap> |
| | * <wrap :ja>**イベントカスタムID(Event Custom ID)**</wrap> |
| | * <wrap :ja>**モジュールカスタムID(Module custom ID)**</wrap> |
| </WRAP> | </WRAP> |
| |
| </WRAP> | </WRAP> |
| |
| <wrap #ks6_2 /> | <WRAP center round info 90%> |
| |
| | //At least one selected field must be added//; otherwise, the system will automatically add the field <wrap :en>**Timestamp**</wrap>. |
| | |
| | </WRAP> |
| | |
| | <WRAP center round info 90%> |
| | |
| | //少なくとも 1つのフィールドを選択して追加する必要があります//。そうしないと、システムは自動的に **Timestamp** フィールドを追加します。 |
| | |
| | </WRAP> |
| | |
| | <wrap #ks6_2 /> |
| |
| ==== イベントフィルタの作成 ==== | ==== イベントフィルタの作成 ==== |
| | <wrap #ks6_3_2_18 />''_event_source_'' |Event source. | | | <wrap #ks6_3_2_18 />''_event_source_'' |Event source. | |
| | <wrap #ks6_3_2_19 />''_event_status_'' |Event status (new, validated or event in process). | | | <wrap #ks6_3_2_19 />''_event_status_'' |Event status (new, validated or event in process). | |
| | <wrap #ks6_3_2_20 />''_event_tags_'' |Event tags separated by commas. | | | <wrap #ks6_3_2_20 />''_event_tags_'' |Event tags separated by commas. This macro refers to **general event tags**, as distinct from [[#ks6_4|custom event tags]]. | |
| | <wrap #ks6_3_2_21 />''_event_text_'' |Full event text. | | | <wrap #ks6_3_2_21 />''_event_text_'' |Full event text. | |
| | <wrap #ks6_3_2_22 />''_event_type_'' |Type of event: \\ * Monitor in critical status. \\ * Monitor in warning status. \\ * Monitor in normal status. \\ * Unknown. \\ * Unknown Monitor. \\ * Alert triggered. \\ * Alert recovered. \\ * Alert stopped. \\ * Manual alert validation. \\ * Agent created. \\ * Recon host detected. \\ * System. \\ * Error. \\ * Configuration change. \\ * Network configuration manager. | | | <wrap #ks6_3_2_22 />''_event_type_'' |Type of event: \\ * Monitor in critical status. \\ * Monitor in warning status. \\ * Monitor in normal status. \\ * Unknown. \\ * Unknown Monitor. \\ * Alert triggered. \\ * Alert recovered. \\ * Alert stopped. \\ * Manual alert validation. \\ * Agent created. \\ * Recon host detected. \\ * System. \\ * Error. \\ * Configuration change. \\ * Network configuration manager. | |
| | <wrap #ks6_3_2_18 />''_event_source_'' |イベントソース | | | <wrap #ks6_3_2_18 />''_event_source_'' |イベントソース | |
| | <wrap #ks6_3_2_19 />''_event_status_'' |イベント状態 (new, validated または event in process). | | | <wrap #ks6_3_2_19 />''_event_status_'' |イベント状態 (new, validated または event in process). | |
| | <wrap #ks6_3_2_20 />''_event_tags_'' |カンマ区切りのイベントタグ | | | <wrap #ks6_3_2_20 />''_event_tags_'' |カンマ区切りのイベントタグ。このマクロは、[[#ks6_4|カスタムイベントタグ]]とは別の **汎用イベントタグ **を指します。 | |
| | <wrap #ks6_3_2_21 />''_event_text_'' |イベントテキスト | | | <wrap #ks6_3_2_21 />''_event_text_'' |イベントテキスト | |
| | <wrap #ks6_3_2_22 />''_event_type_'' |イベントのタイプ: \\ * Monitor in critical status. \\ * Monitor in warning status. \\ * Monitor in normal status. \\ * Unknown. \\ * Unknown Monitor. \\ * Alert triggered. \\ * Alert recovered. \\ * Alert stopped. \\ * Manual alert validation. \\ * Agent created. \\ * Recon host detected. \\ * System. \\ * Error. \\ * Configuration change. \\ * Network configuration manager. | | | <wrap #ks6_3_2_22 />''_event_type_'' |イベントのタイプ: \\ * Monitor in critical status. \\ * Monitor in warning status. \\ * Monitor in normal status. \\ * Unknown. \\ * Unknown Monitor. \\ * Alert triggered. \\ * Alert recovered. \\ * Alert stopped. \\ * Manual alert validation. \\ * Agent created. \\ * Recon host detected. \\ * System. \\ * Error. \\ * Configuration change. \\ * Network configuration manager. | |
| | <wrap #ks6_3_2_33 />''_owner_username_'' |イベントの所有者であるユーザのフルネーム | | | <wrap #ks6_3_2_33 />''_owner_username_'' |イベントの所有者であるユーザのフルネーム | |
| | <wrap #ks6_3_2_34 />''_user_id_'' |ユーザ ID | | | <wrap #ks6_3_2_34 />''_user_id_'' |ユーザ ID | |
| | |
| | <wrap #ks6_4 /> |
| | |
| | ==== カスタマイズ可能なイベントラベル ==== |
| | |
| | <WRAP group> |
| | <WRAP half column><WRAP center round box 90%><wrap :en>**Management → {{:wiki:pfms-configuration_icon.svg?nolink&21x21}} Configuration → Events → Event tags**</wrap> menu.</WRAP></WRAP> |
| | <WRAP half column>Unlike system tags, which can be added via the [[:en:documentation:pandorafms:technical_reference:03_anexo_cli#create_event|creating an event]], custom tags managed by [[:en:documentation:pandorafms:introduction:03_glossary#superadmin|superadmin]] users are added to or removed from events [[#ks2|visually via the Web Console]].</WRAP> |
| | </WRAP> |
| | |
| | <WRAP group> |
| | <WRAP half column><WRAP center round box 90%><wrap :ja>**管理(Management) → {{:wiki:pfms-configuration_icon.svg?nolink&21x21}} 設定(Configuration) → イベント(Events) → イベントタグ(Event tags)**</wrap> メニュー。</WRAP></WRAP> |
| | <WRAP half column>イベント作成時に追加できるシステムタグとは異なり、[[:ja:documentation:pandorafms:introduction:03_glossary#superadmin|スーパー管理者]]ユーザが管理するカスタムタグは、ウェブコンソール上で視覚的にイベントへの追加や削除が行われます [[#ks2|(ウェブコンソールでの操作)]]。</WRAP> |
| | </WRAP> |
| | |
| | {{ :wiki:pfms-manage-configuration-events-events_tags-803_version.png }} |
| | |
| | You can add as many tags as you need, and it is recommended that you add the <wrap :en>Event tags</wrap> field to the [[#ks6_1|events view]]. If all of the above applies: |
| | |
| | 必要なだけタグを追加できます。また、[[#ks6_1|イベント表示]]に「イベントタグ」フィールドを追加することをお勧めします。上記の条件をすべて満たす場合: |
| | |
| | * If two or more custom tags are added to an event, only the first one will be displayed; to view the others, click on the help icon {{:wiki:pfms_icon_general-info_or_help_2.svg?nolink&21x21|Other tags}}. |
| | * The items in the previous point are listed in alphabetical order. If you wish to have them in a strict order, you can create them with a leading number, whereby the item with the lowest number will always be displayed first. |
| | * In this events view, you can sort by all the other columns, //except for the custom tags column//. |
| | |
| | * イベントに複数のカスタムタグが追加されている場合、最初に追加されたタグのみが表示されます。他のタグを表示するには、ヘルプアイコン {{:wiki:pfms_icon_general-info_or_help_2.svg?nolink&21x21|その他のタグ}} をクリックしてください。 |
| | * 前述の項目はアルファベット順に表示されます。厳密な順序で表示したい場合は、先頭に番号を付けて作成してください。番号が小さい項目が常に最初に表示されます。 |
| | * このイベント表示では、カスタムタグ列を除くすべての列を並べ替えることができます。 |
| |
| [[:ja:documentation:start|Pandora FMS ドキュメント一覧に戻る]] | [[:ja:documentation:start|Pandora FMS ドキュメント一覧に戻る]] |