ããã«ã¡ã¯ãSCSKã®äžç°ã§ãã ä»å㯠Zabbixã§è€éãªæ¡ä»¶ã®ãã°ç£èŠãè¡ãæ¹æ³ ãã玹ä»ããŸãã ãã°ç£èŠã¯ãäŸãã°ã”ERROR”ãšããæååãå«ãŸããããã€ãã³ãIDã”777″ããªã©ã·ã³ãã«ãªæ¡ä»¶ãªãç°¡åã«äœæã§ããã®ã§ããã “Error”ãšããæååãš”CPU”ãšããæååããšãã«ãå«ã æ·±å»åºŠã”èŠå”以äžãäœãã€ãã³ãIDã”777″ã®å Žåã¯é€å€ãã ãšãã£ã è€åæ¡ä»¶ ã é€å€æ¡ä»¶ ãå ãããšãäœæãé£ãããªããŸãã ããã§ä»åã¯ããã°ç£èŠã®äœææ¹æ³ãšãè€éãªæ¡ä»¶ã®ãã°ç£èŠãèšå®ããæ¹æ³ã«ã€ããŠç޹ä»ããŠãããŸãã Linuxã®ããã¹ããã°ç£èŠãšWindowsã®ã€ãã³ããã°ç£èŠã§ããæ¹ãç°ãªãã®ã§ãããããã«ã€ããŠæžããŠãããŸãã Linuxã®ãã°ç£èŠ ãŸãã¯ã Linuxã®ãã°ç£èŠ ã«ã€ããŠã§ãã ãã°ç£èŠã®ããæ¹ Linuxã®ãã°ã¯ã以äžã®ã¢ã€ãã ããŒã§ååŸã§ããŸãã ã¢ã€ãã ããŒïŒ log[ç£èŠãããã¡ã€ã«å] 以äžã¯ãå®éã«ååŸãããã¢ã€ãã ã®æ
å ±ã§ãã Linuxãã°ã®ã¢ã€ãã ååŸç»é¢ ãã®ããã«ãåºåããããã°ã ãã¬ãŒã³ããã¹ã ãšããŠååŸã§ããŸãã ãã®ãã°ããç¹å®ã®æååãæ€ç¥ããã«ã¯ã以äžã®ããªã¬ãŒé¢æ°ã䜿ããŸãã ããªã¬ãŒé¢æ°ïŒ find(/ãã¹ãå/log[ç£èŠãããã¡ã€ã«å],,,”æ€ç¥ãããæåå”) ãã®find颿°ã¯ã ã¢ã€ãã ã®ææ°ã®å€ã«æ€ç¥ãããæååã å«ãŸããŠããå Žå1 ãã å«ãŸããŠããªãå Žå0 ãè¿ããŸãã äŸãã°ã/var/log/messagesã§ “ERROR” ãå«ãŸãããã°ãæ€ç¥ãããå Žåãã¢ã€ãã ããŒã “log[/var/log/messages]” ã®ã¢ã€ãã ãäœæããããªã¬ãŒæ¡ä»¶åŒã “find(ãã¹ãå/log[/var/log/messages],,,”ERROR”)=1″ ãšãªãããªã¬ãŒãäœæããŸãã è€éãªãã°ç£èŠã®ããæ¹ Linuxã§ã¯ã è€åæ¡ä»¶ ã é€å€æ¡ä»¶ ãã ã°ããŒãã«æ£èŠè¡šçŸ ã䜿ãã®ãæå¹ã§ãã å¥ã®èšäº “æ£èŠè¡šçŸã®äœ¿ãæ¹” ã«ãŠæ£èŠè¡šçŸã®äœ¿ãæ¹ãšãã°ç£èŠãžã®å¿ç𿹿³ã玹ä»ããŠãããŸãã®ã§ããã¡ãããåç
§ãã ããã ãã°ç£èŠã«åœ¹ç«ã€Zabbixæ£èŠè¡šçŸã®äœ¿ãæ¹ Zabbixã«ãããæ£èŠè¡šçŸã®äœ¿ãæ¹ã説æããŸããæ£èŠè¡šçŸã䜿ãããšã§ãè€éãªæ¡ä»¶ã«ããããããã°ã®æ€ç¥ãè¡ãããšãã§ããŸãã blog.usize-tech.com 2024.07.24 Windowsã®ãã°ç£èŠ ç¶ããŠã Windowsã®ãã°ç£èŠ ã«ã€ããŠã§ãããã¡ãã¯Linuxãšæ¯ã¹ãŠå°ã
è€éã§ããïŒçç±ã¯åŸè¿°ïŒ ãã°ç£èŠã®ããæ¹ ãŸããã°ååŸã®ã¢ã€ãã ã§ããã ã¢ã€ãã ããŒïŒ eventlog[ã€ãã³ããã°å]ïŒãŸã㯠eventlog[ã€ãã³ããã°åç§°,,,,,,skip]ïŒ ã§ååŸããŸãããã©ã¡ãŒã¿ã«ã skip ããæå®ããªããšã ãã¹ãã«èç©ãããéå»ã®ãã°ãå
šãŠååŸãããŠããŸããŸã ã®ã§ãã¢ã€ãã ç»é²ããæç¹ããã®ãã°ã ãååŸãããå Žåã¯skipä»ãã®ã®ã¢ã€ãã ããŒã䜿ã£ãŠãã ãããïŒæ¬èšäºã§ã¯skipç¡ãã®ã¢ã€ãã ããŒã䜿çšããŠããŸããïŒ ä»¥äžã¯ãå®éã«ååŸãããã¢ã€ãã ã®æ
å ±ã§ãã Windowsã€ãã³ããã°ã®ã¢ã€ãã ååŸç»é¢ Linuxã®ãã°ãšã¯ç°ãªãã1ã€ã®ãã¬ãŒã³ããã¹ãã§ã¯ãªã ããœãŒã¹ã ã ãæ·±å»åºŠã ã ãã€ãã³ãIDã ã ãå€ïŒãã°ã®å
容ïŒã ãšåãããŠå€ãååŸãããèŠçŽ ããšã«ããªã¬ãŒé¢æ°ãåãããŠããŸãã ïŒãããWindowsã®ã€ãã³ããã°ç£èŠãè€éã«ãªãçç±ã§ãïŒ ãœãŒã¹ïŒ logsource (/ãã¹ãå/eventlog[ã€ãã³ããã°å],,”æ€ç¥ããããœãŒã¹”) æ·±å»åºŠïŒ logseverity(/ãã¹ãå/eventlog[ã€ãã³ããã°å]) ã€ãã³ãIDïŒ logeventid (/ãã¹ãå/eventlog[ã€ãã³ããã°å],,”æ€ç¥ãããã€ãã³ãID”) å€ïŒ find(ãã¹ãå/log[/var/log/messages],,,”æ€ç¥ãããæåå”) ãœãŒã¹ãã€ãã³ãIDãå€ã®é¢æ°ã¯ã ææ°ã®ã€ãã³ããã°ã«æ€ç¥ãããèŠçŽ ã å«ãŸããŠããå Žå1 ãã å«ãŸããŠããªãå Žå0 ãè¿ããŸãã æ·±å»åºŠã®é¢æ°ã¯ãæ·±å»åºŠã “æ
å ±”ãªã1ã”èŠå”ãªã2ã,”ãšã©ãŒ”ãªã4ã”ã¯ãªãã£ã«ã«”ãªã9 ãè¿ããŸãã äŸãã°ãã·ã¹ãã ãã°ã§ã€ãã³ãã® æ·±å»åºŠããšã©ãŒ ã®ãã°ãæ€ç¥ãããå Žåã” logseverity(/ãã¹ãå/eventlog[System]) =4″ã ã€ãã³ãIDã777 ã®ãã°ãæ€ç¥ããããšã㯔 logeventid (/ãã¹ãå/eventlog[System],,”777″)=1″ ãšãã颚ã«ãé©åãªé¢æ°ãéžãã§ããªã¬ãŒãèšå®ããŸãã è€éãªãã°ç£èŠã®ããæ¹ ããã§ã¯ãè€éãªæ¡ä»¶ã®ãã°ç£èŠãèšå®ããŠã¿ãŸãããã â è€åæ¡ä»¶ ãŸããããœãŒã¹ãââããã€ãæ·±å»åºŠãââããã€ãã»ã»ã»ããšãã è€åæ¡ä»¶ ãèããŠã¿ãŸãã ããªã¬ãŒæ¡ä»¶åŒã¯ã è«çæŒç®å”and” ã “or” ã䜿ããã®ã§ãããã䜿ã£ãŠæ¡ä»¶åŒãçµã¿ç«ãŠãŠã¿ãŸãã äŸãšããŠã以äžã®ãã¹ãŠã®æ¡ä»¶ãæºããæ¡ä»¶åŒãäœã£ãŠã¿ãŸãããã ãœãŒã¹ãtest æ·±å»åºŠãèŠåä»¥äž ã€ãã³ãIDã777 ãã®å Žåã以äžã®ãããªæ¡ä»¶åŒã«ãªããŸãã logsource(/ãã¹ãå/eventlog[System],,”test”)=1 and logseverity(/ãã¹ãå/eventlog[System])>=2 and logeventid(/ãã¹ãå/eventlog[System],,”777″)=1 ã€ãã³ããã°ç£èŠããªã¬ãŒâ ããã§å®éã«è©²åœã®ã€ãã³ããã°ãæ€ç¥ã§ããã詊ããŠã¿ãŸããããã€ãã³ããã°ãçæããã«ã¯ã “EVENTCREATE” ã³ãã³ãã䜿ããŸãã ç£èŠå¯Ÿè±¡æ©åšã®ã³ãã³ãããã³ããã§ã以äžã®ã³ãã³ããå®è¡ããŠã¿ãŸãããã EVENTCREATE /ID 777 /L system /SO test /T ERROR /D "ã€ãã³ããã¹ã" ãããšãæ³å®éãé害ãšããŠæ€ç¥ããŸããã é害æ€ç¥ â¡é€å€æ¡ä»¶ ç¶ããŠã é€å€æ¡ä»¶ ãèããŠã¿ãŸããããäŸãã°ããæ·±å»åºŠããšã©ãŒä»¥äžãäœããœãŒã¹ãââã®ã¢ãã¯é€ãããšãã£ãæ¡ä»¶ã§ãã ããªã¬ãŒæ¡ä»¶åŒã§ã¯ã åŠå®æŒç®å”not” ã䜿ããã®ã§ãããã䜿ã£ãŠæ¡ä»¶ãçµã¿ç«ãŠãŸãã 以äžã®æ¡ä»¶ãèããŠã¿ãŸãããã æ·±å»åºŠãèŠåä»¥äž äœããã€ãã³ãIDã”777″ã®ãã°ã¯é€ã ãã®å Žåã以äžã®ãããªæ¡ä»¶åŒã«ãªããŸãã logseverity(/ãã¹ãå/eventlog[System])>=2 and not logeventid(/ãã¹ãå/eventlog[System],,”777″)=1 ã€ãã³ããã°ç£èŠããªã¬ãŒâ¡ ãã®åŸãEVENTCREATEã§ä»¥äžã®ã€ãã³ããçæããŸãã EVENTCREATE /ID 888 /L system /SO test /T ERROR /D "ã€ãã³ããã¹ã" ããã¯ã æ·±å»åºŠãèŠåä»¥äž ã§ ã€ãã³ãID㯔777″ã§ã¯ãªã ã®ã§ãæ¡ä»¶ã«ãããããŠé害ãšããŠæ€ç¥ãããŸãã é害æ€ç¥â¡ ãã®åŸãä»åºŠã¯é€å€æ¡ä»¶ã«ããããã以äžã®ã€ãã³ããçæããŸãã EVENTCREATE /ID 777 /L system /SO test /T ERROR /D "ã€ãã³ããã¹ã" ãã¡ãã¯é€å€æ¡ä»¶ã«ãããããã®ã§ãæ³å®éã é害ãçºçããŸããã â¢è€åæ¡ä»¶ãšé€å€æ¡ä»¶ã®MIX æåŸã«ãããã«è€éãªã è€åæ¡ä»¶ ãš é€å€æ¡ä»¶ ã® åããæ ããã£ãŠã¿ãŸãã äŸãã°ã以äžã®ãããªæ¡ä»¶ãèããŸãã æ·±å»åºŠãèŠåä»¥äž äœãã以äžã®æ¡ä»¶ã®ãããããæºãããã®ã¯é€å€ããïŒ ã1:ããœãŒã¹ã”test”ããã€ãã€ãã³ãIDã”777″ã ã2:ããœãŒã¹ã”hoge”ããã€ãã€ãã³ãIDã”888″ããã€ãå
容㫔ãã¹ã”ãšããæååãå«ãŸããã è€éãªã®ã§ãäžã€äžã€çŽè§£ããŠãããŸãã ãŸãã”æ·±å»åºŠãèŠå以䞔ãšããæ¡ä»¶ã¯ãä»ãŸã§åºãŠããŠããéãã logseverity(/ãã¹ãå/eventlog[System])>=2 ãšãªããŸãã ç¶ããŠ1ãš2ã®æ¡ä»¶åŒã¯ãè€åæ¡ä»¶ãªã®ã§ä»¥äžã®ããã«æžããŸãã 1: logsource (/ãã¹ãå/eventlog[System],,”test”)=1 and logeventid(/ãã¹ãå/eventlog[System],,”777″)=1 2:logsource(/ãã¹ãå/eventlog[System],,”hoge”)=1 and logeventid(/ãã¹ãå/eventlog[System],,”888″)=1 and find(/ãã¹ãå/eventlog[System],,,”ãã¹ã”)=1 ãããã®æ¡ä»¶ãæºããå Žåã¯æ€ç¥ããªãã®ã§ããã®æ¡ä»¶ãnotã§åŠå®ããæåã®æ¡ä»¶ãšçµåããŸããè€æ°æ¡ä»¶ã«æŒç®åãé©çšããå Žåã¯ã()ã§æ¬ããŸãã logseverity(/ãã¹ãå/eventlog[System])>=2 and not (logsource(/ãã¹ãå/eventlog[System],,”test”)=1 and logeventid(/ãã¹ãå/eventlog[System],,”777″)=1) and not (logsource(/ãã¹ãå/eventlog[System],,”hoge”)=1 and logeventid(/ãã¹ãå/eventlog[System],,”888″)=1 and find(/ãã¹ãå/eventlog[System],,,”ãã¹ã”)=1) ã€ãã³ããã°ç£èŠããªã¬ãŒâ¢ ããã§ã¯ããããæ£ããåäœãããããã¹ãããŠã¿ãŸãããã ãŸãã¯é€å€æ¡ä»¶ã«åœãŠã¯ãŸããªããã°ãçæããé害æ€ç¥ããããã¹ãããŸãã EVENTCREATE /ID 888 /L system /SO test /T ERROR /D "ã€ãã³ããã¹ã" ããã¯é€å€æ¡ä»¶1,2ãšãã«ããæããŠããã®ã§ãé害ãšããŠæ€ç¥ãããŸãã é害æ€ç¥â¢ ç¶ããŠã以äžã®ãã°ãçæããŸãã EVENTCREATE /ID 777 /L system /SO test /T ERROR /D "ã€ãã³ããã¹ã" ããã¯é€å€æ¡ä»¶1ã«ãããããŠããã®ã§ãé害ãšããŠæ€ç¥ãããŸããã 以äžã®ãã°ã§ã詊ããŠã¿ãŸãããã EVENTCREATE /ID 888 /L system /SO hoge /T ERROR /D "ã€ãã³ããã¹ã" ããã¯é€å€æ¡ä»¶2ã«ãããããŠããã®ã§ããã¡ããé害ãšããŠã¯æ€ç¥ãããŸããã 以äžã®ãã¹ããããæ³å®éã é€å€æ¡ä»¶ã«ããããããã°ã¯æ€ç¥ããªã ããšãåãããŸãã ãŸãšã ä»åã¯ãLinuxãšWindowsã®ãã°ç£èŠã«ã€ããŠç޹ä»ããŸããã Linuxã¯æ£èŠè¡šçŸã䜿ãã°è€åæ¡ä»¶ãé€å€æ¡ä»¶ãç°¡åã«äœæã§ããŸãããWindowsã¯ã€ãã³ããã°ã®èŠçŽ ã«ãã£ãŠé¢æ°ãåãããŠãããããã©ãããŠãè€éãªããªã¬ãŒæ¡ä»¶åŒã«ãªã£ãŠããŸããŸããããããè«çæŒç®å “and” “or” “not” ãããŸãçµã¿åãããã°æè»ãªæ¡ä»¶åŒãäœæã§ããã®ã§ããã®èšäºãåèã«ãã²è©ŠããŠã¿ãŠãã ããã æåŸã«ãåŒç€Ÿãåå ããã€ãã³ãã«ã€ããŠå®£äŒãããŠãã ããã â Zabbixå
šåœ5éœåžãã£ã©ãã³2024 Zabbix瀟䞻å¬ã®ã å
šåœ5éœåžãåãã»ãããŒã€ãã³ã ã§ããæ±äº¬ã»åå€å±ã¯çµäºããŸããã 2024幎9æã«å€§éªã»ä¹å·ã»åæµ·éã§ãéå¬ ããŸãã®ã§ãæ¯éãè¿ãã®äŒå Žã«è¶³ãéãã§ã¿ãŠãã ããïŒ Zabbix5都市キャラバン2024 www.zabbix.com â¡ Zabbix7.0ã»ãã㌠ãã¡ã㯠2024幎10æ2æ¥(æ°Ž) ã«éå¬ãããã SCSKäž»å¬ã®WEBã»ãã㌠ã§ããZabbix7.0ã®æ°æ©èœãããŒãžã§ã³ã¢ããã®åæã«ã€ããŠã玹ä»ããŸãã æ¬èšäºã®çè
ãè¬åž«ãšããŠç»å£ããŸã ã®ã§ãæ¯éãèŠèŽãã ããïŒ Zabbix7.0ã»ãããŒïœæ°æ©èœãšããŒãžã§ã³ã¢ããã®èŠç¹ïœ æ¬ã»ãããŒã§ã¯ãZabbix 7.0ã®æ°æ©èœãšæ¹åç¹ã«ã€ããŠè©³ããã玹ä»ãããŠããã ããŸããå®éã®ã¢ããã°ã¬ãŒãæé ã«ã€ããŠãã説æããçæ§ã®Zabbix 7.0ãžã®ç§»è¡ãã¹ã ãŒãºã«é²ããããã®ãã³ãããäŒãããããŸãã www.scsk.jp æåŸãŸã§èªãã§ããã ããããããšãããããŸããã åŒç€Ÿã§ã¯Zabbixé¢é£ãµãŒãã¹ãå±éããŠããŸãã以äžããŒãžããåç
§ãã ããã â
SCSK Plus ãµããŒã for Zabbixâ
SCSK Plus サポート for Zabbix äžçã§æã人æ°ã®ãããªãŒãã³ãœãŒã¹çµ±åç£èŠããŒã«ãZabbixãã®å°å
¥æ§ç¯ããéçšä¿å®ãŸã§SCSKã匷åã«ãµããŒãããŸã www.scsk.jp â
YouTubeã«ãSCSK Zabbixãã£ã³ãã«ãéèšããŸããïŒâ
SCSK Zabbixãã£ã³ãã« æ¬ãã£ã³ãã«ã§ã¯ãSCSKæ ªåŒäŒç€Ÿã§ã®Zabbixã«é¢ãããã¬ã³ã/äºäŸç޹ä»ãªã©ãåç»ã«ãŸãšããŠåãäžããŠãããŸãã ææ°ã®ãããã¯ã«ã€ããŠã¯ã以äžã®åŒç€ŸHPãããã¯ãã€ãã¿ãŒã¢ã«ãŠã³ãããã²åç
§ãã ããã ãã€ãã¿ãŒã¢ã«ãŠã³ãïŒ www.youtube.com â
XïŒæ§TwitterïŒã«ãSCSK Zabbixã¢ã«ãŠã³ããéèšããŸããïŒâ
x.com x.com