J.3 Output format of action logs
Information about audit events is output to the Performance Management action logs. A separate action log file is output for each host. An action log's output destination host is as follows:
-
When a service is executed
Action logs are output to the host where the service is running.
-
When a command is executed
Action logs are output to the host that executed the command.
The following describes the output format, output destination, and output items for action logs.
- Organization of this subsection
(1) Output format
CALFHM x.x,output-item-1=value-1,output-item-2=value-2,...,output-item-n=value-n
(2) Output destination
installation-folder\auditlog\
You can use the jpccomm.ini file to change the output destination of action logs. For details about how to set the jpccomm.ini file, see J.4 Action log output settings.
(3) Output items
There are two types of output items:
- Common output items
-
Output items common to all JP1 products that output action logs
- Fixed output items
-
Optional items that are output by JP1 products that output action logs
(a) Common output items
The table below lists and describes the common output items and their values, including the items that are output by PFM - Manager.
Output item |
Value |
Description |
|
---|---|---|---|
Item name |
Output attribute |
||
Common specification identifier |
-- |
CALFHM |
Identifier indicating that this is the action log format |
Common specification revision number |
-- |
x.x |
Revision number used for managing action logs |
Sequence number |
seqnum |
sequence-number |
Sequence number of action log records |
Message ID |
msgid |
KAVExxxxx-x |
Message ID |
Date and time |
date |
YYYY-MM-DDThh:mm:ss.sssTZD# |
Output date, time, and time zone of an action log |
Generated program name |
progid |
JP1PFM |
Name of the program where the event occurred |
Generated component name |
compid |
service-ID |
Name of the component where the event occurred |
Generated process ID |
pid |
process-ID |
Process ID of the process where the event occurred |
Generated location |
ocp:host |
|
Location where the event occurred |
Event type |
ctgry |
|
Category names used to classify the events that are output to action logs |
Event result |
result |
|
Result of the event |
Subject identification information |
subj:pid |
process-ID |
One of the following:
|
subj:uid |
account-identifier (PFM user/JP1 user) |
||
subj:euid |
effective-user-ID (OS user) |
(b) Fixed output items
The table below lists and describes the fixed output items and their values, including the items that are output by PFM - Manager.
Output item |
Value |
Description |
|
---|---|---|---|
Item name |
Output attribute |
||
Object information |
obj |
|
Operation target |
obj:table |
alarm-table-name |
||
obj:table |
alarm-name |
||
Action information |
op |
|
Action that caused the event |
Permissions information |
auth |
|
Permissions of the user who performed the operation |
auth:mode |
|
Authentication mode of the user who performed the operation |
|
Output source |
outp:host |
name-of-PFM-Manager-host |
Host that output the action log |
Instruction source |
subjp:host |
|
Host that issued the operation instruction |
Free description |
msg |
message |
Message that is output in the event of an alarm and execution of automatic action |
Whether each fixed output item exists depends on the output timing. The following subsections describe the message ID and fixed output items for each output timing.
■ Startup and termination of PFM services (StartStop)
-
Output host
Host on which the corresponding service is running
-
Output component
Each service that starts and stops
A message ID and operation information are output when the PFM service starts and stops (StartStop). The following table lists and describes the message IDs and operation information that are output.
Item name |
Attribute name |
Value |
---|---|---|
Message ID |
msgid |
|
Operation information |
op |
|
■ Startup and termination of the stand-alone mode (StartStop)
-
Output host
PFM - RM host
-
Output component
Remote Monitor Collector and Remote Monitor Store services
A message ID is output when the stand-alone mode starts and ends (StartStop). The following table lists and describes the message IDs that are output.
Item name |
Attribute name |
Value |
---|---|---|
Message ID |
msgid |
|
■ Change to the status of the connection to PFM - Manager (ExternalService)
-
Output host
PFM - RM host
-
Output component
Remote Monitor Collector and Remote Monitor Store services
A message ID is output when the status of the connection to PFM - Manager changes (ExternalService). The following table lists and describes the message IDs that are output.
Item name |
Attribute name |
Value |
---|---|---|
Message ID |
msgid |
|
■ Execution of automatic action (ManagementAction)
-
Output host
Host that executed the action
-
Output component
Action Handler service
When an automatic action is executed (ManagementAction), a message ID and free description item are output. The following table lists and describes the message IDs and free description items that are output.
Item name |
Attribute name |
Value |
---|---|---|
Message ID |
msgid |
|
Free description |
msg |
|
(4) Output example
The following shows an output example of action logs:
CALFHM 1.0, seqnum=1, msgid=KAVE03000-I, date=2007-01-18T22:46:49.682+09:00, progid=JP1PFM, compid=7A1host01, pid=2076, ocp:host=host01, ctgry=StartStop, result=Occurrence, subj:pid=2076,op=Start