ログ管理

ログソースの状態と直近のログエントリを確認できます

ログソース状態

🔥Firewall
128,402 eventsHealthy
🛡IDS / IPS
22,918 eventsHealthy
📋Access Log
301,554 eventsHealthy
💻Endpoint
89,120 eventsDelayed
⚙️Operation Log
14,091 eventsHealthy
🔄Process Log
210,885 eventsHealthy
合計取込イベント (24h)766,970

直近のログエントリ

🔍
時刻ソースレベルホストメッセージ
11:54:12FirewallBLOCKfw-01Outbound connection blocked: 185.220.101.42:443 → fileserver-01
11:54:01Access LogINFOfileserver-01GET /admin/files/confidential/ HTTP/1.1 200 admin.tanaka
11:53:48Process LogWARNwin-client-23powershell.exe spawned by cmd.exe: -EncodedCommand SGVsbG8=
11:53:30IDS / IPSALERTids-01Signature match: ET POLICY PE EXE or DLL Windows file download
11:53:12EndpointINFOwin-client-23File created: C:\Users\sato.yuki\AppData\Local\Temp\tmp_8f3a.exe
11:52:55FirewallBLOCKfw-01Inbound connection blocked: 203.0.113.91:41822 → cloud-auth:443
11:52:40Access LogERRORcloud-authAuthentication failed: user@acme.corp (attempt 12/15) from 203.0.113.91
11:52:18VPNINFOvpn-gwVPN session established: admin.tanaka / 185.220.101.42 (Amsterdam, NL)
11:51:44FirewallINFOfw-01Outbound HTTPS allowed: linux-app-04 → 198.51.100.24:443
11:51:20IDS / IPSALERTids-01C2 beacon pattern detected: linux-app-04 → 198.51.100.24 (interval: 60s)
11:50:55Operation LogWARNlinux-app-04Privileged command executed: sudo chmod 777 /etc/shadow by sato.yuki
11:50:30Process LogINFOwin-client-23Process started: wscript.exe /e:vbscript C:\Temp\update.vbs
表示: 12 件 / 総ログ 766,970 件(過去24時間)