操作
Operationsは、StyleBookのオプションセクションです。このセクションでは、NetScaler Console Analyticsを設定して、すべてのトラフィックトランザクションまたは一部のトラフィックトランザクションでAppFlowレコードを収集できます。StyleBookを使用してNetScalerインスタンス上に作成された仮想サーバーが、トラフィックトランザクションを処理します。また、仮想サーバーで特定のトラフィック条件が満たされたときにアラームをトリガーするようにNetScaler Consoleを設定することもできます。
StyleBookを介してNetScaler Consoleを設定し、以下にリストされているさまざまなNetScaler Consoleインサイトからトラフィック統計を収集できます。
-
Bot インサイト
-
Web インサイト
-
Security インサイト
-
HDX™ インサイト
-
NetScaler Gateway インサイト
サポートされている仮想サーバーは、負荷分散、コンテンツスイッチング、およびVPN仮想サーバーです。
負荷分散またはコンテンツスイッチング仮想サーバーでの分析のために、Web インサイトとSecurity インサイトの両方、またはそのいずれかを有効にします。ただし、VPN仮想サーバーの場合は、HDX インサイトとNetScaler Gateway インサイトの両方、またはそのいずれかを有効にする必要があります。
StyleBookを介してNetScalerインスタンスで有効になっているNetScaler Consoleインサイトは、IPFIXプロトコル (AppFlow) を使用して、インスタンスからNetScalerにデータを送信します。
また、Web インサイトを有効にすると、負荷分散およびコンテンツスイッチング仮想サーバーで「クライアント側測定」が有効になります。この機能が有効になっていると、NetScaler ConsoleはHTMLインジェクションを介してHTMLページの読み込み時間とレンダリング時間のメトリックをキャプチャします。これらのメトリックを使用すると、管理者はL7遅延の問題を特定できます。
特定のNetScaler Consoleインサイトを有効にした後、アプリケーション概要ページを表示して、そのインサイトに関連する脅威の詳細を確認します。
例 1:
次の例は、StyleBookで操作セクションを記述して、VPN仮想サーバーでHDX インサイトとNetScaler Gateway インサイトの両方を有効にする方法を示しています。
name: simple-vpn-ops
namespace: com.example.stylebooks
schema-version: "1.0"
version: "0.1"
description: Test StyleBook to enable hdxinsight and gatewayinsight on a VPN vserver
import-stylebooks:
-
namespace: netscaler.nitro.config
version: "10.5"
prefix: ns
components:
-
name: vpnvserver-comp
type: ns::vpnvserver
properties:
name: str("vpn-") + str($current-target.ip)
servicetype: SSL
ipv46: 1.1.21.37
port: 443
operations:
analytics:
-
name: comp-ops
properties:
target: $components.vpnvserver-comp
filter: "true"
insights:
-
type: hdxinsight
-
type: gatewayinsight
outputs:
-
name: myvpns
value: $components.vpnvserver-comp
例2:
以下の例は、StyleBookでoperationsセクションを記述して、ロードバランシング仮想サーバー上でWeb Insight、Security Insight、およびBot Insightを有効にする方法を示しています。
---
name: enable-insights
namespace: com.acme.stylebooks
description: "This StyleBook enables Web,Security & Bot Insight on Load Balancing Vserver"
display-name: "SB Operations"
schema-version: "1.0"
version: "1.0"
import-stylebooks:
-
namespace: netscaler.nitro.config
prefix: ns
version: "10.5"
parameters:
-
name: lbname
type: string
required: true
-
name: vip
type: ipaddress
required: true
-
name: appflowfilter
type: string
required: true
components:
-
name: my-lbvserver-comp
type: ns::lbvserver
properties:
name: $parameters.lbname
servicetype: HTTP
ipv46: $parameters.vip
port: 80
outputs:
-
name: mylb
value: $components.my-lbvserver-comp
operations:
analytics:
-
name: lbvserver-op
properties:
target: $outputs.mylb
filter: $parameters.appflowfilter
insights:
-
type: webinsight
-
type: securityinsight
-
type: botinsight