ZabbixãåããŠèŠããšããæ å ±ã»ãã¥ãªãã£ã€ãã³ããç£èŠããããã®ãœãªã¥ãŒã·ã§ã³ãšããŠäœ¿çšããŠã¿ãŸãããã ãåãã®ããã«ãäŒæ¥ã®ITã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¯ãæ å ±ã»ãã¥ãªãã£ã€ãã³ãã®ã¹ããªãŒã ãçæããããŸããŸãªã·ã¹ãã ãããããããããã¹ãŠè¡šç€ºããããšã¯äžå¯èœã§ãã çŸåšãåœç€Ÿã®äŒæ¥ç£èŠã·ã¹ãã ã«ã¯ãæ°çŸã®ãµãŒãã¹ãéåžžã«è©³çŽ°ã«èŠ³å¯ãããŠããŸãã ãã®èšäºã§ã¯ãæ å ±ã»ãã¥ãªãã£ã€ãã³ããç£èŠããããã®ãœãªã¥ãŒã·ã§ã³ãšããŠZabbixã䜿çšããæ©èœãæ€èšããŸãã
Zabbixã§åé¡ã解決ã§ããã®ã¯ãªãã§ããïŒ ä»¥äžã«ã€ããŠïŒ
- ã€ã³ãã³ããªããã»ã¹ãè匱æ§ç®¡çãã»ãã¥ãªãã£ããªã·ãŒããã³å€æŽãžã®ã³ã³ãã©ã€ã¢ã³ã¹ã®èªååãæ倧åããŸãã
- æ å ±ã»ãã¥ãªãã£ã®èªåç£èŠã«ããäŒæ¥ãªãœãŒã¹ã®ãªã¢ã«ã¿ã€ã ä¿è·ã
- ãããã¯ãŒã¯ã»ãã¥ãªãã£ã®æãä¿¡é Œã§ããç»åãååŸããæ©èœã
- ã·ã¹ã³ããžã¥ãããŒãWindowsãLinuxãUnixãMSQLãOracleãMySQLãªã©ã®ãããã¯ãŒã¯æ©åšããããã¯ãŒã¯ã¢ããªã±ãŒã·ã§ã³ãWebãµãŒãã¹ãªã©ãå¹ åºãè€éãªã·ã¹ãã ã®åæã
- ç£æ»ã³ã¹ããšã»ãã¥ãªãã£ç®¡çã®æå°åã
ãã®èšäºã§ã¯ãäžèšã®ãã¹ãŠãæ€èšããããã§ã¯ãããŸããããæãäžè¬çã§ç°¡åãªè³ªåã«ã€ããŠã®ã¿è§ŠããŸãã
æºåãã
ããã§ãåå¿è åãã«ãZabbixç£èŠãµãŒããŒãã€ã³ã¹ããŒã«ããŸããã ãã©ãããã©ãŒã ãšããŠFreeBSD OSã䜿çšããŸãã ã€ã³ã¹ããŒã«ãšæ§æã®ããã»ã¹ã«ã€ããŠè©³ãã説æããå¿ èŠã¯ãªããšæããŸãããã·ã¢èªã®è©³çŽ°ãªããã¥ã¡ã³ãã¯ãã€ã³ã¹ããŒã«ããã»ã¹ãããã¹ãŠã®ã·ã¹ãã æ©èœã®èª¬æãŸã§ãéçºè ã®Webãµã€ãã«ãããŸãã
ãµãŒããŒãã€ã³ã¹ããŒã«ãããæ§æããããããšãšãã«åäœããããã«Webããã³ããšã³ããæ§æãããŠãããšæ³å®ããŸãã ãã®èšäºã®å·çæç¹ã§ã¯ãã·ã¹ãã ã¯OS FreeBSD 9.1ãZabbix 2.2.1ãå®è¡ããŠããŸãã
MS Windows Serverã»ãã¥ãªãã£ã€ãã³ãã®ç£èŠ
Zabbixç£èŠã·ã¹ãã ã䜿çšãããšãWindowsã·ã¹ãã ãã°ããå©çšå¯èœãªæ å ±ãä»»æã®è©³çŽ°åºŠã§åéã§ããŸãã ããã¯ãWindowsãã€ãã³ãããã°ã«æžã蟌ãå ŽåãZabbixãã€ãã³ãIDãããã¹ãããã€ããªãã¹ã¯ãªã©ã«ãã£ãŠããããèŠããããšãæå³ããŸãã ããã«ãZabbixã䜿çšãããšãã»ãã¥ãªãã£ãç£èŠããããã®èšå€§ãªæ°ã®èå³æ·±ãã€ãã³ãã確èªããã³åéã§ããŸããããšãã°ãå®è¡äžã®ããã»ã¹ãæ¥ç¶ã®ãªãŒãã³ãdllã䜿çšããã«ãŒãã«ã«ããŒãããããã©ã€ããŒãã³ã³ãœãŒã«ãŸãã¯ãªã¢ãŒããŠãŒã¶ãŒã¢ã¯ã»ã¹ãä»ãããã°ã€ã³ãªã©ã§ãã
æ®ã£ãŠããã®ã¯ãäºæ³ãããè åšã®å®çŸäžã«çºçããã€ãã³ããèå¥ããããšã§ãã
ITã€ã³ãã©ã¹ãã©ã¯ãã£ã§ISã€ãã³ããç£èŠããããã®ãœãªã¥ãŒã·ã§ã³ã確ç«ããå Žåããã¹ãŠãé£ç¶ããŠè¿œè·¡ããããšããèŠæãšãISã€ãã³ãã«é¢ãã倧éã®æ å ±ãåŠçããèœåãšã®ãã©ã³ã¹ãéžæããå¿ èŠæ§ãèæ ®ããå¿ èŠããããŸãã ããã§ãZabbixã¯éžæã®å€§ããªæ©äŒãæäŸããŸãã ZabbixããŒã¢ãžã¥ãŒã«ã¯C / C ++ã§æžãããŠããããããã¯ãŒã¯ããã®èšé²é床ãšç£èŠã€ãã³ãã®åŠçé床ã¯ãDBMSãæ£ããèšå®ãããéåžžã®ãµãŒããŒã§æ¯ç§1äžåã®æ°ããå€ã§ãã
ããã«ãããWindowsäžã®ç£èŠå¯Ÿè±¡ãã¹ãã§æãéèŠãªã»ãã¥ãªãã£ã€ãã³ãã远跡ã§ããŸãã
ãããã£ãŠããŸãæåã«ãã€ãã³ãIDãæã€ããŒãã«ãæ€èšããŠãã ãããããã¯ãæããã«ãæ å ±ã»ãã¥ãªãã£ã€ãã³ãã®ç£èŠã«äœ¿çšã§ããŸãã
IBã€ãã³ãWindows Serverã»ãã¥ãªãã£ãã°
EventIDã®èª¬æ | 2008ãµãŒã㌠| 2003ãµãŒã㌠|
ç£æ»ãã°ã®æ¶å» | 1102 | 517 |
ã¢ã«ãŠã³ãã®ãã°ã€ã³ã«æåããŸãã | 4624 | 528ã540 |
ã¢ã«ãŠã³ãããã°ã€ã³ã«å€±æããŸãã | 4625 | 529-535ã539 |
äœæããããŠãŒã¶ãŒã¢ã«ãŠã³ã | 4720 | 624 |
ã¢ã«ãŠã³ãã®ãã¹ã¯ãŒãããªã»ããããããšããŠããŸã | 4724 | 628 |
ç¡å¹ãªãŠãŒã¶ãŒã¢ã«ãŠã³ã | 4725 | 629 |
ãŠãŒã¶ãŒã¢ã«ãŠã³ããåé€ããŸãã | 4726 | 630 |
å®å šãªããŒã«ã«ã»ãã¥ãªãã£ã°ã«ãŒããäœæãããŸãã | 4731 | 635 |
ä¿è·ãããããŒã«ã«ã°ã«ãŒãã«è¿œå ãããã¡ã³ã㌠| 4732 | 636 |
ä¿è·ãããããŒã«ã«ã°ã«ãŒãããã¡ã³ããŒãåé€ããŸãã | 4733 | 637 |
åé€ãããã»ãã¥ã¢ããŒã«ã«ã»ãã¥ãªãã£ã°ã«ãŒã | 4734 | 638 |
ã»ãã¥ã¢ããŒã«ã«ã»ãã¥ãªãã£ã°ã«ãŒããå€æŽãããŸãã | 4735 | 639 |
ãŠãŒã¶ãŒã¢ã«ãŠã³ããå€æŽãããŸãã | 4738 | 642 |
ããã¯ããããŠãŒã¶ãŒã¢ã«ãŠã³ã | 4740 | 644 |
ã¢ã«ãŠã³ãåãå€æŽãããŸãã | 4781 | 685 |
ããŒã«ã«ã»ãã¥ãªãã£ã°ã«ãŒãã«æ³šæãæã£ãŠããŸãããããè€éãªADã¹ããŒã ã§ã¯ãåãäžè¬ã°ã«ãŒããšã°ããŒãã«ã°ã«ãŒããèæ ®ããå¿ èŠããããŸãã
æ å ±ãéè€ãããªãããã«ãèšäºã§éèŠãªã€ãã³ãã®è©³çŽ°ãèªãããšãã§ããŸãã
http://habrahabr.ru/company/netwrix/blog/148501/
æ å ±ã»ãã¥ãªãã£MS Windows Serverã®ã€ãã³ããç£èŠããæ¹æ³
ãã®ã¿ã¹ã¯ã®å®çšçãªã¢ããªã±ãŒã·ã§ã³ãæ€èšããŠãã ããã
ããŒã¿ãåéããã«ã¯ãæ°ããããŒã¿é ç®ãäœæããå¿ èŠããããŸãã
: eventlog[Security,,,,1102|4624|4625|4720|4724|4725|4726|4731|4732|4733|4734|4735|4738|4781] : Zabbix () : ()
å¿ èŠã«å¿ããŠãã€ãã³ãIDããšã«åå¥ã®ããŒã¿èŠçŽ ãäœæã§ããŸããã1ã€ã®ããŒã§è€æ°ã®ã€ãã³ãIDã䜿çšããŠãã¹ãŠã®ã¬ã³ãŒãã1ãæã«ä¿åãããããç°ãªãããŒã¿èŠçŽ ãåãæ¿ããããšãªãå¿ èŠãªæ å ±ããã°ããæ€çŽ¢ã§ããŸãã
ãã®ããŒã§ã¯ãã»ãã¥ãªãã£ã€ãã³ããã°ãååãšããŠäœ¿çšããŠããããšã«æ³šæããŠãã ããã
ããŒã¿é ç®ãåãåã£ãã®ã§ãããªã¬ãŒãæ§æããå¿ èŠããããŸãã ããªã¬ãŒã¯ãç£èŠå¯Ÿè±¡ã€ãã³ãã®ãããããçºçããããšãéç¥ã§ããZabbixã¡ã«ããºã ã§ãã ç§ãã¡ã®å Žåãããã¯ãµãŒããŒãã°ãŸãã¯MS Windowsã¯ãŒã¯ã¹ããŒã·ã§ã³ããã®ã€ãã³ãã§ãã
ããã§ãæå®ããã€ãã³ãIDã§ç£æ»ãã°ãèšé²ãããã¹ãŠã®ãã®ãç£èŠãµãŒããŒã«è»¢éãããŸãã ç¹å®ã®ã€ãã³ãIDãæå®ãããšãå¿ èŠãªæ å ±ã®ã¿ãååŸããããã以äžã®æ å ±ã¯åŸãããªããšããç¹ã§äŸ¿å©ã§ãã
ããªã¬ãŒåŒã®1ã€ã次ã«ç€ºããŸãã
{Template Windows - Eventlog 2008:eventlog[Security,,,,1102|4624|4625|4720|4724|4725|4726|4731|4732|4733|4734|4735|4738|4781].logeventid(4624)}=1&{Template Windows - Eventlog 2008:eventlog[Security,,,,1102|4624|4625|4720|4724|4725|4726|4731|4732|4733|4734|4735|4738|4781].nodata(5m)}=0
ãã®åŒã«ãããããã·ã¥ããŒãã«ãã¢ã«ãŠã³ãã§ã®ãã°ã€ã³ã«æåããŸããããšããæ å ±ã衚瀺ã§ããŸããããã¯ãMS Windows Server 2008ã®ã€ãã³ãID 4624ã«å¯Ÿå¿ããŸãããã®éã«åãã°ã€ã³ãè¡ãããªãã£ãå Žåãã€ãã³ãã¯5ååŸã«æ¶ããŸã
ã管çè ããªã©ã®ç¹å®ã®ãŠãŒã¶ãŒã远跡ããå¿ èŠãããå Žåã¯ãããªã¬ãŒåŒã«æ£èŠè¡šçŸæ€èšŒãè¿œå ã§ããŸãã
&{Template Windows - Eventlog 2008:eventlog[Security,,,,1102|4624|4625|4720|4724|4725|4726|4731|4732|4733|4734|4735|4738|4781,,skip].regexp()}=1
ããªã¬ãŒã¯ãã·ã¹ãã ãã管çè ããšããååã®ã¢ã«ãŠã³ãã§ãã°ã€ã³ããŠããå Žåã«ã®ã¿æ©èœããŸãã
PS
æãåçŽãªäŸãæ€èšããŸããããããè€éãªæ§é ã䜿çšã§ããŸãã ããšãã°ããã°ã€ã³ã¿ã€ãããšã©ãŒã³ãŒããæ£èŠè¡šçŸãããã³ãã®ä»ã®ãã©ã¡ãŒã¿ãŒã䜿çšããŸãã
ãããã£ãŠãWindowsã·ã¹ãã ã«ãã£ãŠçæããã倧éã®ã¡ãã»ãŒãžã¯ãç®ã§ã¯ãªãZabbixã«ãã£ãŠãã§ãã¯ãããŸãã Zabbixããã·ã¥ããŒãã®ã¿ãèŠãããšãã§ããŸãã
ããã«ãéç¥ãé»åã¡ãŒã«ã§éä¿¡ããããã«æ§æããŸããã ããã«ãããã€ãã³ãã«è¿ éã«å¯Ÿå¿ã§ããå¶æ¥æéå€ãªã©ã«çºçããã€ãã³ããèŠéãããšã¯ãããŸããã
Unixã·ã¹ãã ã®ã»ãã¥ãªãã£ã€ãã³ãç£èŠ
Zabbixç£èŠã·ã¹ãã ã§ã¯ãUnixãã¡ããªãŒOSã®ãã°ãã¡ã€ã«ããæ å ±ãåéããããšãã§ããŸãã
ãã¹ãŠã®äººã«é©ããUnixã·ã¹ãã äžã®IBã€ãã³ã
Unixãã¡ããªã·ã¹ãã ã®ãã®ãããªã»ãã¥ãªãã£ã®åé¡ã¯ãã¢ã«ãŠã³ãã®ãã¹ã¯ãŒããéžæããè©Šã¿ãšãSSHãFTPãªã©ã®èªèšŒããŒã«ã®è匱æ§ãæ€çŽ¢ããè©Šã¿ãšåãã§ãã
Unixã·ã¹ãã äžã®ããã€ãã®éèŠãªã€ãã³ã
äžèšã«åºã¥ããŠãã·ã¹ãã å ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã®è¿œå ãå€æŽãåé€ã«é¢é£ããã¢ã¯ã·ã§ã³ãç£èŠããå¿ èŠããããŸãã
ãŸããéèŠãªäºå®ã¯ãã·ã¹ãã ãžã®ãã°ã€ã³è©Šè¡ã远跡ããããšã§ãã sudoersãpasswdãªã©ã®äž»èŠãã¡ã€ã«ã®å€æŽ/ rc.confããã£ã¬ã¯ããªã®å 容/usr/local/etc/rc.då®è¡äžã®ããã»ã¹ã®ååšãªã©ã
Unixã·ã¹ãã ã§ã®ã»ãã¥ãªãã£ç£èŠæ¹æ³
次ã®äŸãèããŠã¿ãŸãããã SSHãããã³ã«ã䜿çšããŠãFreeBSDã·ã¹ãã ã§ãã°ã€ã³ã倱æãããã°ã€ã³è©Šè¡ããã¹ã¯ãŒãæšæž¬è©Šè¡ã远跡ããå¿ èŠããããŸãã
ããã«é¢ãããã¹ãŠã®æ å ±ã¯ããã°ãã¡ã€ã«/var/log/auth.logã«å«ãŸããŠããŸãã
ããã©ã«ãã§ã¯ããã®ãã¡ã€ã«ã«å¯Ÿããæš©éã¯600ã§ãããrootæš©éã§ã®ã¿è¡šç€ºã§ããŸãã ããŒã«ã«ã»ãã¥ãªãã£ããªã·ãŒãå°ãç ç²ã«ããŠããã®ã°ã«ãŒãã®zabbixãŠãŒã¶ãŒã«ãã®ãã¡ã€ã«ã®èªã¿åããèš±å¯ããå¿ èŠããããŸãã
ãã¡ã€ã«ã®ã¢ã¯ã»ã¹èš±å¯ãå€æŽããŸãã
chgrp zabbix /var/log/auth.log chmod 640 /var/log/auth.log
次ã®ããŒãæã€æ°ããããŒã¿é ç®ãå¿ èŠã§ãã
log[/var/log/auth.log,sshd,,,skip]
ãsshdããšããåèªãå«ã/var/log/auth.logãã¡ã€ã«ã®ãã¹ãŠã®è¡ã¯ããšãŒãžã§ã³ãã«ãã£ãŠç£èŠãµãŒããŒã«éä¿¡ãããŸãã
次ã«ã次ã®åŒã䜿çšããŠããªã¬ãŒãæ§æã§ããŸãã
{Template FreeBSD - SSH:log[/var/log/auth.log,sshd,,,skip].regexp(error:)}|{Template FreeBSD - SSH:log[/var/log/auth.log,sshd,,,skip].regexp(Wrong passwordr:)}&{Template FreeBSD - SSH:log[/var/log/auth.log,sshd,,,skip].nodata(3m)}=0
ãã®åŒã¯ãæ£èŠè¡šçŸãerrorïŒãã«ãã£ãŠéžæããããšã³ããªããã°ãã¡ã€ã«ã«è¡šç€ºããããšãã®åé¡ãšããŠå®çŸ©ãããŸãã åä¿¡ããããŒã¿ã®å±¥æŽãéããšãSSHãããã³ã«ã䜿çšããèªèšŒäžã«çºçãããšã©ãŒã衚瀺ãããŸãã
ãã®ããªã¬ãŒãããªã¬ãŒããããŒã¿èŠçŽ ã®æåŸã®å€ã®äŸã次ã«ç€ºããŸãã
FreeBSDã§ã®ã»ãã¥ãªãã£ç£èŠã®å¥ã®äŸãèããŠã¿ãŸãããã
ZabbixãšãŒãžã§ã³ãã䜿çšããŠã/ etc / passwdãã¡ã€ã«ã®ãã§ãã¯ãµã ã確èªã§ããŸãã
ãã®å Žåã®ããŒã¯æ¬¡ã®ãšããã§ãã
vfs.file.cksum[/etc/passwd]
ããã«ããããã¹ã¯ãŒãã®å€æŽããŠãŒã¶ãŒã®è¿œå ãŸãã¯åé€ãªã©ãã¢ã«ãŠã³ãã®å€æŽãå¶åŸ¡ã§ããŸãã ãã®å Žåãå®è¡ãããç¹å®ã®æäœã¯ããããŸããããããªã以å€ã«èª°ããµãŒããŒã«ã¢ã¯ã»ã¹ã§ããªãå Žåãããã¯è¿ éãªå¿çã®æ©äŒã§ãã ãã詳现ãªããªã·ãŒãå®è¡ããå¿ èŠãããå Žåã¯ãä»ã®ããŒïŒãŠãŒã¶ãŒãã©ã¡ãŒã¿ãŒãªã©ïŒã䜿çšã§ããŸãã
ããšãã°ãçŸåšã·ã¹ãã ã«ãã°ã€ã³ããŠãããŠãŒã¶ãŒã®ãªã¹ããååŸããå Žåã次ã®ãŠãŒã¶ãŒãã©ã¡ãŒã¿ãŒã䜿çšã§ããŸãã
UserParameter=system.users.list, /bin/cat /etc/passwd | grep -v "#" | awk -F\: '{print $$1}'
ãããŠãäŸãã°ãçµæãªã¹ãã§å€æŽããããªã¬ãŒãæ§æããŸãã
ãŸãã¯ã次ã®ãããªåçŽãªãã©ã¡ãŒã¿ãŒã䜿çšã§ããŸãã
UserParameter=system.users.online, /usr/bin/users
ãã®ãããçŸåšã·ã¹ãã ã«ãããŠãŒã¶ãŒãããã·ã¥ââããŒãã§ç¢ºèªã§ããŸãã
ãããã¯ãŒã¯ããã€ã¹äžã®ISã€ãã³ãã®ç£èŠ
Zabbixã䜿çšãããšãSNMPã䜿çšããŠCiscoããã³Juniperãããã¯ãŒã¯ããã€ã¹äžã®IBã€ãã³ããéåžžã«å¹ççã«ç£èŠããããšãã§ããŸãã ããã€ã¹ããã®ããŒã¿éä¿¡ã¯ããããããã©ããïŒSNMPãã©ããïŒã䜿çšããŠå®è¡ãããŸãã
æ å ±ã»ãã¥ãªãã£ã®èŠ³ç¹ãããç£èŠãå¿ èŠãªæ¬¡ã®ã€ãã³ããåºå¥ã§ããŸããæ©åšã®æ§æã®å€æŽãã¹ã€ãã/ã«ãŒã¿ãŒã§ã®ã³ãã³ãã®å®è¡ãèªèšŒã®æåããã°ã€ã³è©Šè¡ã®å€±æãªã©ã§ãã
ã¢ãã¿ãªã³ã°æ¹æ³
æ¿èªã®äŸãå床æ€èšããŠãã ããã
ã¹ã¿ã³ããšããŠãCisco 3745ã«ãŒã¿ãŒã§GNS3ãšãã¥ã¬ãŒã¿ã䜿çšããŸãããå€ãã®äººããã®ã¹ããŒã ã«ç²ŸéããŠãããšæããŸãã
æåã«ãSNMPãã©ãããã«ãŒã¿ãŒããç£èŠãµãŒããŒã«éä¿¡ããããã«èšå®ããå¿ èŠããããŸãã ç§ã®å Žåã次ã®ããã«ãªããŸãã
login block-for 30 attempts 3 within 60 login on-failure log login on-success log login delay 5 logging history 5 snmp-server enable traps syslog snmp-server enable traps snmp authentication snmp-server host 192.168.1.1 public
Syslogããã³èªèšŒã©ããŒããã€ãã³ããéä¿¡ããŸãã èªèšŒã®æåãšå€±æã¯ãSyslogã«æ£ç¢ºã«æžã蟌ãŸããŸãã
次ã«ãç£èŠãµãŒããŒã§å¿ èŠãªSNMPãã©ããã®åä¿¡ãæ§æããå¿ èŠããããŸãã
snmptt.confã«æ¬¡ã®è¡ãè¿œå ããŸãã
EVENT clogMessageGenerated .1.3.6.1.4.1.9.9.41.2.0.1 "Status Events" Normal FORMAT ZBXTRAP $ar $N $* SDESC EDESC
ãã®äŸã§ã¯ãSyslogã©ããŒããã£ããããŸãã
ããã§ã次ã®ããŒã䜿çšããŠçµ±èšãåéããããã«ããŒã¿é ç®ãæ§æããå¿ èŠããããŸãã
snmptrap[âStatusâ]
ã©ããŒãç£èŠãµãŒããŒã§æ§æãããŠããªãå ŽåããµãŒããŒãã°ã«æ¬¡ã®ãšã³ããªã衚瀺ãããŸãã
unmatched trap received from [192.168.1.14]:...
ãã®çµæã詳现ãªæ å ±ïŒãŠãŒã¶ãŒããœãŒã¹ãããŒã«ã«ããŒãã倱æããå Žåã®çç±ïŒãå«ããã°ã€ã³è©Šè¡ã«é¢ããæ å ±ããåä¿¡ãããã°ã«åæ ãããŸãã
ããŠãããã·ã¥ããŒãã«ã€ãã³ãã衚瀺ããããã«ããªã¬ãŒãæ§æã§ããŸãã
{192.168.1.14:snmptrap["Status"].regexp(LOGIN_FAILED)}&{192.168.1.14:snmptrap["Status"].nodata(3m)}=0
åã®æ®µèœãšçµã¿åãããŠãããã·ã¥ããŒãã«ãã®ãããªèšç»ã«é¢ããæ å ±ããããŸãã
äžèšã®äŸãšåæ§ã«ãCiscoã«ãŒã¿ãŒã§çºçããå€æ°ã®ã€ãã³ããç£èŠããããšãã§ããŸããã1ã€ã®èšäºã§ã¯æããã«äžååã§ãã
äžèšã®äŸã¯ãCisco ASAããã³PIX補åã§ã¯æ©èœããªãããšã«æ³šæããŠãã ãããèš±å¯ãã®ã³ã°ã®äœæ¥ã¯ãããã§ã¯å€å°ç°ãªãããã«ç·šæãããŠããããã§ãã
ãžã¥ãããŒãšSyslog
å¥ã®äŸãšããŠãJuniperããã€ã¹ã®JunOS 12.1ã§ã®æ¿èªç£èŠã調ã¹ãŸãã
ããã§ã¯ãSyslogã¡ãã»ãŒãžããã®ãã©ããéä¿¡ããµããŒãããŠããªããããSNMPãã©ããã䜿çšã§ããŸããã UnixããŒã¹ã®SyslogãµãŒããŒãå¿ èŠã§ãããã®å Žåãåãç£èŠãµãŒããŒã«ãªããŸãã
ã«ãŒã¿ã§ãã¹ãã¬ãŒãžãµãŒãã«éä¿¡ããSyslogãèšå®ããå¿ èŠããããŸãã
system syslog host 192.168.1.1 authorization info
ããã§ããã¹ãŠã®èªèšŒã¡ãã»ãŒãžãSyslogãµãŒããŒã«éä¿¡ãããŸãããã¡ããããã¹ãŠã®ã¡ãã»ãŒãžïŒä»»æïŒãéä¿¡ã§ããŸãããäœåãªæ å ±ã¯å¿ èŠãããŸãããå¿ èŠãªãã®ã ããéä¿¡ããŸãã
次ã«ãsyslogãµãŒããŒã«ç§»åããŸã
ã¡ãã»ãŒãžãæ¥ããã©ããã«ããããããtcpdumpã確èªããŸãã
tcpdump -n -i em0 host 192.168.1.112 and port 514 12:22:27.437735 IP 192.168.1.112.514 > 192.168.1.1.514: SYSLOG auth.info, length: 106
ããã©ã«ãã§ã¯ãsyslog.confèšå®ã§ãauth.infoã«ä»å±ãããã¹ãŠã®ãã®ã/var/log/auth.logã«æžã蟌ãŸããŸãã 次ã«ãUnixã§å ¥åãç£èŠããäŸãšåæ§ã«ãã¹ãŠãè¡ããŸãã
ãã°ããã®è¡ã®äŸã次ã«ç€ºããŸãã
ãã®ã€ãã³ãã®ããªã¬ãŒãèšå®ããã®ã¯ãUnixãµãŒããŒã§ã®èš±å¯ã®äŸã§èããããã®ãšåãæ¹æ³ã§ã®ã¿ã§ãã
PS
ãã®ããã«ããŠãããã€ã¹æ§æã®ä¿åïŒã³ãããïŒãæ§æç·šéã¢ãŒãã®éå§ãšçµäºïŒç·šéïŒãªã©ãå€ãã®ã€ãã³ãã远跡ã§ããŸãã
ãŸããCiscoããã€ã¹ã§åæ§ã®æ¹æ³ã§ç£èŠã§ããŸãããSNMPãã©ããã䜿çšããæ¹æ³ã¯ããé«éã§äŸ¿å©ãªããã«æãããäžéã®SyslogãµãŒããŒã¯äžèŠã«ãªããŸãã
ãããã«
çµè«ãšããŠããã®èšäºãžã®ã³ã¡ã³ããšè¿œå ãããã³Zabbixã䜿çšããæ å ±ã»ãã¥ãªãã£ã€ãã³ãã¢ãã¿ãªã³ã°ã®äœ¿çšã«é¢ããèå³æ·±ãææ¡ãåãã§åãå ¥ããŸãã
ãæž èŽããããšãããããŸããã :)