ja:documentation:pandorafms:technical_annexes:rsyslog-audit-forwarding

差分

このページの2つのバージョン間の差分を表示します。

この比較画面へのリンク

両方とも前のリビジョン 前のリビジョン
ja:documentation:pandorafms:technical_annexes:rsyslog-audit-forwarding [2026/07/18 22:37] – [Re-anchoring the sender] junichija:documentation:pandorafms:technical_annexes:rsyslog-audit-forwarding [2026/07/18 22:39] (現在) – [Operational review list] junichi
行 388: 行 388:
 <wrap #ks7 /> <wrap #ks7 />
  
-===== Operational review list =====+===== 作業確認リスト =====
  
   * □ The receiver is online from the sender via ''TCP 10514''.   * □ The receiver is online from the sender via ''TCP 10514''.
行 396: 行 396:
   * □ The receiver's //log// file contains **only** lines with the ''pandora-audit'' //tag// (without ''CROND'' / ''rsyslogd'').   * □ The receiver's //log// file contains **only** lines with the ''pandora-audit'' //tag// (without ''CROND'' / ''rsyslogd'').
   * □ ''systemctl enable rsyslog'' applied on both //hosts// so that forwarding survives a restart.   * □ ''systemctl enable rsyslog'' applied on both //hosts// so that forwarding survives a restart.
 +
 +  * □ 送信元から受信側へ ''TCP 10514'' で接続可能である。
 +  * □ 両端で ''rsyslogd -N1'' を実行し、設定に問題がないことを確認済みである。
 +  * □ 受信側で ''ss -ltn | grep 10514'' を実行すると、''LISTEN'' 状態であることが確認できる。
 +  * □ ''audit.log'' に追加したテスト行が、ポーリング間隔以内に ''/var/log/received/pandora-audit.log'' へ反映される。
 +  * □ 受信側のログファイルには、''pandora-audit'' タグが付いた行**のみ**が含まれている(''CROND'' や ''rsyslogd'' などの行は含まれない)。
 +  * □ 再起動後も転送が継続されるよう、両ホストで ''systemctl enable rsyslog'' が実行されている。
  
 [[ja:documentation:pandorafms:start|Pandora FMS ドキュメント一覧に戻る]] [[ja:documentation:pandorafms:start|Pandora FMS ドキュメント一覧に戻る]]
  
  • ja/documentation/pandorafms/technical_annexes/rsyslog-audit-forwarding.1784414233.txt.gz
  • 最終更新: 2026/07/18 22:37
  • by junichi