操作
Operations 是 StyleBook 中的一个可选部分。在此部分中,您可以配置 NetScaler Console Analytics 以收集所有或部分流量事务的 AppFlow 记录。通过 StyleBook 在 NetScaler 实例上创建的虚拟服务器处理流量事务。您还可以配置 NetScaler Console 以在虚拟服务器上满足特定流量条件时触发警报。
您可以通过 StyleBook 配置 NetScaler Console,以从以下列出的各种 NetScaler Console Insight 中收集流量统计信息:
-
Bot 洞察
-
Web 洞察
-
安全洞察
-
HDX™ 洞察
-
NetScaler Gateway 洞察
支持的虚拟服务器包括负载平衡、内容交换和 VPN 虚拟服务器。
在负载平衡或内容交换虚拟服务器上,为分析启用 Web Insight 和 Security Insight 或其中之一。但是,对于 VPN 虚拟服务器,您必须同时启用 HDX Insight 和 NetScaler Gateway Insight 或其中之一。
通过 StyleBook 在 NetScaler 实例上启用的任何 NetScaler Console Insight 都使用 IPFIX 协议 (AppFlow) 将数据从实例发送到 NetScaler。
此外,当您启用 Web Insight 时,“客户端测量”会在负载平衡和内容交换虚拟服务器上启用。启用此功能后,NetScaler Console 会通过 HTML 注入捕获 HTML 页面的加载时间和渲染时间指标。使用这些指标,管理员可以识别 L7 延迟问题。
启用特定的 NetScaler Console Insight 后,查看“应用程序概览”页面以查看与该 Insight 相关的威胁详细信息。
示例 1:
以下示例说明了如何在 StyleBook 中编写操作部分,以在 VPN 虚拟服务器上同时启用 HDX Insight 和 NetScaler Gateway Insight:
name: simple-vpn-ops
namespace: com.example.stylebooks
schema-version: "1.0"
version: "0.1"
description: Test StyleBook to enable hdxinsight and gatewayinsight on a VPN vserver
import-stylebooks:
-
namespace: netscaler.nitro.config
version: "10.5"
prefix: ns
components:
-
name: vpnvserver-comp
type: ns::vpnvserver
properties:
name: str("vpn-") + str($current-target.ip)
servicetype: SSL
ipv46: 1.1.21.37
port: 443
operations:
analytics:
-
name: comp-ops
properties:
target: $components.vpnvserver-comp
filter: "true"
insights:
-
type: hdxinsight
-
type: gatewayinsight
outputs:
-
name: myvpns
value: $components.vpnvserver-comp
示例 2:
以下示例展示了如何在 StyleBook 中编写操作部分,以在负载均衡虚拟服务器上启用 Web Insight、Security Insight 和 Bot Insight:
---
name: enable-insights
namespace: com.acme.stylebooks
description: "This StyleBook enables Web,Security & Bot Insight on Load Balancing Vserver"
display-name: "SB Operations"
schema-version: "1.0"
version: "1.0"
import-stylebooks:
-
namespace: netscaler.nitro.config
prefix: ns
version: "10.5"
parameters:
-
name: lbname
type: string
required: true
-
name: vip
type: ipaddress
required: true
-
name: appflowfilter
type: string
required: true
components:
-
name: my-lbvserver-comp
type: ns::lbvserver
properties:
name: $parameters.lbname
servicetype: HTTP
ipv46: $parameters.vip
port: 80
outputs:
-
name: mylb
value: $components.my-lbvserver-comp
operations:
analytics:
-
name: lbvserver-op
properties:
target: $outputs.mylb
filter: $parameters.appflowfilter
insights:
-
type: webinsight
-
type: securityinsight
-
type: botinsight