J.3 Action log output format
Information related to audit events is output to the Performance Management action log. One action log information file is output for one host (physical host and logical host). The action log file is output to either of the following hosts:
-
When a service is executed: The file is output to the host on which the service runs.
-
When a command is executed: The file is output to the host on which the command was executed.
The following describes the format of the action log, the output destination, and the items that are output.
- Organization of this subsection
(1) Output format
CALFHM x.x,output-item-1=value-1,output-item-2=value-2,...,output-item-n=value-n
(2) Output destination
- On physical hosts
-
installation-folder\auditlog\
- On logical hosts
-
environment-folder\jp1pc\auditlog\
The action log output destination can be changed in the jpccomm.ini file. For details about how to specify the jpccomm.ini file, see J.4 Settings for outputting action logs.
(3) Output items
There are two types of output items:
-
Common output item
An item that is always output by all JP1 products that output action logs
-
Fixed output item
An item that is optionally output by a JP1 product that outputs action logs
(a) Common output items
The following table lists and describes the common output items and their values. This table also includes the items and information output by PFM - Manager.
No. |
Output item |
Value |
Explanation |
|
---|---|---|---|---|
Item name |
Output attribute name |
|||
1 |
Common specification identifier |
-- |
CALFHM |
Indicates the action log format. |
2 |
Common specification revision number |
-- |
x.x |
Revision number for managing action logs |
3 |
Serial number |
seqnum |
serial-number |
Serial number of the action log record |
4 |
Message ID |
msgid |
KAVExxxxx-x |
Message ID of the product |
5 |
Date and time |
date |
YYYY-MM-DDThh:mm:ss.sssTZD# |
Date, time, and time zone indication identifying when the action log was output |
6 |
Program name |
progid |
JP1PFM |
Name of the program for which the event occurred |
7 |
Component name |
compid |
service-ID |
Name of the component for which the event occurred |
8 |
Process ID |
pid |
process-ID |
Process ID of the process for which the event occurred |
9 |
Location |
ocp:host |
|
Location where the event occurred |
10 |
Event type |
ctgry |
|
Category name used to classify the event output to the action log |
11 |
Event result |
result |
|
Result of the event |
12 |
Subject identification information |
subj:pid |
process-ID |
One of the following:
|
subj:uid |
account-identifier (PFM user/JP1 user) |
|||
subj:euid |
effective-user-ID (OS user) |
(b) Fixed output items
The following table lists and describes the fixed output items and their values. This table also includes the items and information output by PFM - Manager.
No. |
Output item |
Value |
Explanation |
|
---|---|---|---|---|
Item name |
Output attribute name |
|||
1 |
Object information |
obj |
|
Intended object for the operation |
obj:table |
alarm-table-name |
|||
obj:alarm |
alarm-name |
|||
2 |
Action information |
op |
|
Information about the action that caused the event |
3 |
Permissions information |
auth |
|
Permissions information of the user who executed the command or service |
auth:mode |
|
Authentication mode of the user who executed the command or service |
||
4 |
Output source |
outp:host |
PFM - Manager-host-name |
Host that output the action log |
5 |
Instruction source |
subjp:host |
|
Host that issued the instruction for the operation |
6 |
Free description |
msg |
message |
Message that is output when an alarm occurs or when an automated action is executed |
Whether the fixed output items are output and what they contain differ depending on when the action log is output. The following describes the message ID and output information for each case.
■ A PFM service is started or stopped (StartStop)
-
Output host: The host on which the service is running
-
Output component: The service that was started or stopped
Item name
Attribute name
Value
Message ID
msgid
Started: KAVE03000-I
Stopped: KAVE03001-I
Action information
op
Started: Start
Stopped: Stop
■ Stand-alone mode is started or terminated (StartStop)
-
Output host: PFM - RM host
-
Output component: Remote Monitor Collector service and Remote Monitor Store service
Item name
Attribute name
Value
Message ID
msgid
Stand-alone mode has started: KAVE03002-I
Stand-alone mode has terminated: KAVE03003-I
■ The status of the connection with PFM - Manager changes (ExternalService)
-
Output host: PFM - RM host
-
Output component: Remote Monitor Collector service and Remote Monitor Store service
Item name
Attribute name
Value
Message ID
msgid
Sending of an event to PFM - Manager failed (queuing was started): KAVE03300-I
An event was resent to PFM - Manager: KAVE03301-I
■ An automated action is executed (ManagementAction)
-
Output host: The host on which the action was executed
-
Output component: Action Handler service
Item name
Attribute name
Value
Message ID
msgid
The command execution process was created successfully: KAVE03500-I.
An attempt to create a command execution process failed: KAVE03501-W.
E-mail was send successfully: KAVE03502-I.
Sending of e-mail failed: KAVE03503-W
Free description
msg
Command execution: cmd=executed-command-line.
E-mail sending: mailto=destination-email-address.
- Note:
-
KAVE03500-I is output when the command execution process is successfully created. After KAVE03500-I is output, whether the command is successfully executed or not and the execution result are not output to the action log.
(4) Output example
The following is an example of action log output.
CALFHM 1.0, seqnum=1, msgid=KAVE03000-I, date=2007-01-18T22:46:49.682+09:00, progid=JP1PFM, compid=OA1host01, pid=2076, ocp:host=host01, ctgry=StartStop, result=Occurrence, subj:pid=2076,op=Start,