CIS 에 대한 활동 추적 이벤트

IBM Cloud IBM Cloud Internet Services 와 같은 서비스는 활동 추적 이벤트를 생성합니다.

활동 추적 이벤트는 IBM Cloud에서 서비스의 상태를 변경하는 활동에 대해 보고합니다. 이 이벤트를 활용하여 비정상적인 활동과 중대한 조치를 조사하고, 규제 감사 요건을 준수할 수 있습니다.

플랫폼 서비스인 IBM Cloud Activity Tracker Event Routing을 사용하여 활동 추적 이벤트가 전송되는 위치를 정의하는 대상 및 라우트를 구성하여 계정의 감사 이벤트를 선택한 대상으로 라우팅할 수 있습니다. 자세한 정보는 IBM Cloud Activity Tracker Event Routing 정보를 참조하십시오.

IBM Cloud Logs 을 사용하여 계정에서 생성되고 IBM Cloud Activity Tracker Event Routing 에 의해 IBM Cloud Logs 인스턴스로 라우팅되는 이벤트를 시각화하고 경보할 수 있습니다.

CIS 달라스(DAL), 워싱턴 D.C.(WDC), 프랑크푸르트(FRA)에 위치한 글로벌 제어 플레인을 활용합니다. 이벤트는 리소스 자체의 위치에 관계없이 요청을 처리하는 컨트롤 플레인에서 생성됩니다.

활동 추적 이벤트가 생성되는 위치

기본적으로 CIS Activity Tracker 이벤트는 프랑크푸르트 (eu-de) 지역에 저장됩니다. 이러한 이벤트를 해당 지역에 저장하지 않으려면 Internet Services Activity Tracker 이벤트 라우팅을 구성하여 지원되는 모든 지역으로 이벤트를 전송할 수 있습니다.

CIS 에 대한 활동 추적 이벤트 보기

IBM Cloud Logs 을 사용하여 계정에서 생성되고 IBM Cloud Activity Tracker Event Routing 에 의해 IBM Cloud Logs 인스턴스로 라우팅되는 이벤트를 시각화하고 경보할 수 있습니다.

관찰 가능성 페이지에서 IBM Cloud Logs 실행

IBM Cloud Logs UI 실행에 대한 정보는 IBM Cloud Logs 문서에서 UI 실행 을 참조하십시오.

DNS 도메인에 대한 이벤트

DNS 도메인 이벤트를 발생시키는 작업
조치 설명
internet-svcs.zones.create DNS 도메인 생성.
internet-svcs.zones.update DNS 도메인 업데이트.
internet-svcs.zones.delete DNS 도메인 삭제.
internet-svcs.zones-activation-check.update DNS 도메인에 대한 활성화 검사를 실행합니다.
internet-svcs.dnssec.update DNS 도메인에 대해 DNSSEC를 활성화하거나 비활성화합니다.

DNS 레코드에 대한 이벤트

다음 표에서는 DNS 레코드와 관련된 조치를 나열하고 이벤트를 생성합니다.

DNS 레코드 이벤트를 발생시키는 작업
조치 설명
internet-svcs.dns-records.create DNS 레코드를 작성합니다.
internet-svcs.dns-records.update DNS 레코드를 업데이트합니다.
internet-svcs.dns-records.delete DNS 레코드를 삭제합니다.
internet-svcs.dns-records-bulk.create 존 파일에서 DNS 레코드 가져오기.
internet-svcs.dns-records-batch.create DNS 레코드를 일괄 생성합니다.
internet-svcs.dns-records-batch.update DNS 레코드를 일괄 업데이트합니다.
internet-svcs.dns-records-batch.delete DNS 레코드를 일괄 삭제합니다.

로드 밸런서에 대한 이벤트

다음 표에서는 로드 밸런서와 관련된 조치를 나열하고 이벤트를 생성합니다.

로드 밸런서 이벤트를 발생시키는 작업
조치 설명
internet-svcs.load-balancers.create 글로벌 로드 밸런서를 작성합니다.
internet-svcs.load-balancers.update 글로벌 로드 밸런서를 업데이트합니다.
internet-svcs.load-balancers.delete 글로벌 로드 밸런서를 삭제합니다.
internet-svcs.load-balancer-monitors.create 글로벌 로드 밸런서 상태 검사를 작성합니다.
internet-svcs.load-balancer-monitors.update 글로벌 로드 밸런서 상태 검사를 업데이트합니다.
internet-svcs.load-balancer-monitors.delete 글로벌 로드 밸런서 상태 검사를 삭제합니다.
internet-svcs.load-balancer-pools.create 글로벌 로드 밸런서 풀 생성.
internet-svcs.load-balancer-pools.update 전역 부하 분산 풀 업데이트
internet-svcs.load-balancer-pools.delete 글로벌 로드 밸런서 풀 삭제.

캐시를 제거하기 위한 이벤트

다음 표에서는 캐시 제거와 관련된 조치를 나열하고 이벤트를 생성합니다.

캐시 삭제 이벤트를 발생시키는 작업
조치 설명
internet-svcs.purge-cache-all.update 엣지 서버에서 특정 도메인의 모든 캐시된 자산을 삭제합니다.
internet-svcs.purge-cache-by-urls.update 엣지 서버에서 URL별로 캐시된 리소스를 삭제합니다.
internet-svcs.purge-cache-by-cache-tags.update 엣지 서버에서 캐시 태그별로 캐시된 자산을 삭제합니다.
internet-svcs.purge-cache-by-hosts.update 엣지 서버에서 호스트명별로 캐시된 자산을 삭제합니다.
internet-svcs.purge-cache-by-prefixes.update URL 접두사를 기준으로 캐시를 삭제합니다.

페이지 규칙에 대한 이벤트

다음 표에서는 페이지 규칙과 관련된 조치를 나열하고 이벤트를 생성합니다.

페이지 규칙 이벤트를 발생시키는 동작
조치 설명
internet-svcs.pagerules.create 페이지 규칙 만들기.
internet-svcs.pagerules.update 페이지 규칙 업데이트.
internet-svcs.pagerules.delete 페이지 규칙 삭제.

방화벽에 대한 이벤트

다음 표에서는 방화벽과 관련된 조치를 나열하고 이벤트를 생성합니다.

방화벽 이벤트를 발생시키는 작업
조치 설명
internet-svcs.waf-groups.update WAF 규칙 세트 그룹을 활성화하거나 비활성화합니다
internet-svcs.waf-rules.update WAF 규칙을 활성화하거나 비활성화합니다.
internet-svcs.ip-firewall-rules.create 도메인 레벨 또는 인스턴스 레벨에서 IP 방화벽 규칙을 작성합니다.
internet-svcs.ip-firewall-rules.update 도메인 레벨 또는 인스턴스 레벨에서 IP 방화벽 규칙을 업데이트합니다.
internet-svcs.ip-firewall-rules.delete 도메인 레벨 또는 인스턴스 레벨에서 IP 방화벽 규칙을 삭제합니다.
internet-svcs.filters.create 필터를 작성합니다.
internet-svcs.filters.update 필터를 업데이트합니다.
internet-svcs.filters.delete 필터를 삭제합니다.
internet-svcs.filters-validate-expr.create 필터 표현식을 유효성 검증합니다.
internet-svcs.firewall-rules.create 필터 기반 방화벽 규칙을 작성합니다.
internet-svcs.firewall-rules.update 필터 기반 방화벽 규칙을 업데이트합니다.
internet-svcs.firewall-rules.delete 필터 기반 방화벽 규칙을 삭제합니다.
internet-svcs.ua-rules.create 사용자 에이전트 차단 규칙을 작성합니다.
internet-svcs.ua-rules.update 사용자 에이전트 차단 규칙을 업데이트합니다.
internet-svcs.ua-rules.delete 사용자 에이전트 차단 규칙을 삭제합니다.
internet-svcs.domain-lockdown-rules.create 도메인 잠금 규칙 생성.
internet-svcs.domain-lockdown-rules.update 도메인 잠금 규칙 업데이트.
internet-svcs.domain-lockdown-rules.delete 도메인 잠금 규칙 삭제.

WAF 재정의 관련 이벤트

다음 표에는 WAF 재정의와 관련되어 이벤트를 발생시키는 작업들이 나열되어 있습니다:

WAF 재정의 이벤트를 발생시키는 동작
조치 설명
internet-svcs.waf-overrides.create WAF 패키지 재정의 생성.
internet-svcs.waf-overrides.update WAF 패키지 재정의 업데이트.
internet-svcs.waf-overrides.delete WAF 패키지 재정의 삭제.

WAF 규칙 세트에 대한 이벤트

다음 표에는 WAF 규칙 집합과 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:

WAF 규칙 세트 이벤트를 발생시키는 동작
조치 설명
internet-svcs.zone-rulesets.create 영역 수준의 WAF 규칙 집합을 생성합니다.
internet-svcs.zone-rulesets.update 영역 수준의 WAF 규칙 세트를 업데이트합니다.
internet-svcs.zone-rulesets.delete 영역 수준의 WAF 규칙 집합 삭제.
internet-svcs.zone-rulesets-rules.create 영역 규칙 집합에 규칙 생성.
internet-svcs.zone-rulesets-rules.update 존 규칙 집합의 규칙을 업데이트합니다.
internet-svcs.zone-rulesets-rules.delete 영역 규칙 집합에서 규칙 삭제.
internet-svcs.zone-rulesets-phases.create 구역 규칙 세트 단계 항목 생성.
internet-svcs.zone-rulesets-phases.update 구역 규칙 집합 단계 항목 업데이트.
internet-svcs.zone-rulesets-phases.delete 존 규칙 세트 단계 항목 삭제.
internet-svcs.zone-rulesets-phases-entrypoint.update 구역 규칙 세트 단계의 진입점을 업데이트합니다.

사용자 정의 목록에 대한 이벤트

다음 표에는 사용자 정의 목록과 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:

사용자 정의 목록 이벤트를 생성하는 작업
조치 설명
internet-svcs.custom-lists.create 사용자 지정 IP/ASN/호스트명 목록 생성.
internet-svcs.custom-lists.update 사용자 지정 목록 업데이트.
internet-svcs.custom-lists.delete 사용자 지정 목록 삭제.
internet-svcs.custom-lists-items.create 사용자 지정 목록에 항목을 추가합니다.
internet-svcs.custom-lists-items.update 사용자 지정 목록의 항목 업데이트.
internet-svcs.custom-lists-items.delete 사용자 지정 목록에서 항목 삭제.
internet-svcs.custom-lists-operations.create 사용자 정의 목록에 대해 일괄 작업을 수행합니다.

관리 대상 목록에 대한 이벤트

다음 표에는 관리 목록과 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:

관리형 목록 이벤트를 생성하는 작업
조치 설명
internet-svcs.managed-lists.create 관리 대상 IP 목록 생성.
internet-svcs.managed-lists.update 관리 목록 업데이트.
internet-svcs.managed-lists.delete 관리 목록 삭제.

비율 제한에 대한 이벤트

다음 표에서는 속도 제한과 관련된 조치를 나열하고 이벤트를 생성합니다.

속도 제한 이벤트를 발생시키는 동작
조치 설명
internet-svcs.rate-limits.create 속도 제한 규칙을 만듭니다
internet-svcs.rate-limits.update 속도 제한 규칙을 업데이트합니다.
internet-svcs.rate-limits.delete 속도 제한 규칙 삭제.

라우팅에 대한 이벤트

다음 표에서는 라우팅과 관련된 조치를 나열하고 이벤트를 생성합니다.

라우팅 이벤트를 발생시키는 동작
조치 설명
internet-svcs.smart-routing.update 스마트 라우팅을 사용 또는 사용 안함으로 설정합니다.
internet-svcs.tiered-caching.update 티어링된 캐싱을 사용 또는 사용 안함으로 설정합니다.

인증서 팩의 이벤트

다음 표에서는 인증서 팩과 관련된 조치를 나열하고 이벤트를 생성합니다.

인증서 팩 이벤트를 발생시키는 작업
조치 설명
internet-svcs.certificate-packs.create 전용 와일드카드 인증서 또는 맞춤형 인증서를 신청하세요.
internet-svcs.certificate-packs.delete 전용 와일드카드 인증서 또는 사용자 지정 인증서 삭제.

사용자 정의 인증서에 대한 이벤트

다음 표에서는 사용자 정의 인증서와 관련된 조치를 나열하고 이벤트를 생성합니다.

사용자 정의 인증서 이벤트를 생성하는 조치
조치 설명
internet-svcs.custom-certificates.create 사용자 정의 인증서를 업로드합니다.
internet-svcs.custom-certificates.update 사용자 정의 인증서를 업데이트합니다.
internet-svcs.custom-certificates.delete 사용자 정의 인증서를 삭제합니다.
internet-svcs.custom-certificates-prioritize.update SSL 인증서 우선순위 재설정.

오리진 인증서에 대한 이벤트

다음 표에서는 오리진 인증서와 관련된 조치를 나열하고 이벤트를 생성합니다.

오리진 인증서 이벤트를 생성하는 조치
조치 설명
internet-svcs.origin-certificates.create 오리진 인증서를 작성합니다.
internet-svcs.origin-certificates.delete 오리진 인증서를 취소합니다.

인증된 원본에 대한 풀 요청 이벤트

다음 표에는 인증된 오리진 풀과 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:

인증된 원본 풀 이벤트를 생성하는 작업
조치 설명
internet-svcs.origin-tls-client-auth.create 영역 수준 클라이언트 인증서를 업로드합니다.
internet-svcs.origin-tls-client-auth.delete 영역 수준 클라이언트 인증서 삭제.
internet-svcs.origin-tls-client-auth-settings.update 특정 영역에 대해 인증된 출처의 풀을 토글합니다.
internet-svcs.origin-tls-client-auth-hostnames.update 호스트명별 인증된 원본 가져오기 구성.
internet-svcs.origin-tls-client-auth-hostname-certificates.create 호스트명별 클라이언트 인증서를 업로드합니다.
internet-svcs.origin-tls-client-auth-hostname-certificates.delete 호스트명별 클라이언트 인증서 삭제.

에지 함수에 대한 이벤트

다음 표에서는 Edge Functions와 관련된 조치를 나열하고 이벤트를 생성합니다.

Edge Functions 이벤트를 생성하는 조치
조치 설명
internet-svcs.edge-functions-scripts.create 엣지 함수 스크립트 생성.
internet-svcs.edge-functions-scripts.update Edge Functions 스크립트의 새 버전을 업데이트합니다.
internet-svcs.edge-functions-scripts.delete 엣지 함수 스크립트 삭제.
internet-svcs.edge-functions-routes.create 엣지 함수 경로 생성.
internet-svcs.edge-functions-routes.update 엣지 기능 경로 업데이트.
internet-svcs.edge-functions-routes.delete 경로에서 에지 함수 삭제.

범위 애플리케이션에 대한 이벤트

다음 표에서는 Range 애플리케이션과 관련된 조치를 나열하고 이벤트를 생성합니다.

Range 이벤트를 생성하는 조치
조치 설명
internet-svcs.range-apps.create 범위 애플리케이션을 작성합니다.
internet-svcs.range-apps.update 범위 애플리케이션을 업데이트합니다.
internet-svcs.range-apps.delete 범위 애플리케이션을 삭제합니다.

logpush 관련 이벤트

다음 표에서는 Logpush와 관련된 조치를 나열하고 이벤트를 생성합니다.

Logpush 이벤트를 생성하는 조치
조치 설명
internet-svcs.logpush-ownership.create 로그푸시 소유권 이의 제기 시작.
internet-svcs.logpush-ownership-validate.create 로그푸시 소유권 챌린지 유효성 검사.
internet-svcs.logpush-jobs.create 로그푸시 작업 생성.
internet-svcs.logpush-jobs.update 로그푸시 작업 업데이트.
internet-svcs.logpush-jobs.delete 로그푸시 작업 삭제하기

즉시 로그용 이벤트

다음 표에는 인스턴트 로그와 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:

즉시 로그 이벤트를 생성하는 작업
조치 설명
internet-svcs.instant-logs-jobs.create 즉시 로그 작업 생성.
internet-svcs.instant-logs-jobs.update 즉시 로그 작업 업데이트.
internet-svcs.instant-logs-jobs.delete 인스턴트 로그 작업을 삭제합니다.

사용자 정의 오류 페이지에 대한 이벤트

다음 표에서는 사용자 정의 오류 페이지와 관련된 조치를 나열하고 이벤트를 생성합니다.

사용자 정의 오류 페이지 이벤트를 생성하는 조치
조치 설명
internet-svcs.custom-pages.create 사용자 정의 오류 페이지를 작성합니다.
internet-svcs.custom-pages.update 사용자 정의 오류 페이지를 업데이트합니다.

설정에 대한 이벤트

다음 표에서는 구성 설정과 관련된 조치를 나열하고 이벤트를 생성합니다.

설정 이벤트를 생성하는 조치
조치 설명
internet-svcs.cache-level-setting.update 캐싱 레벨을 변경합니다.
internet-svcs.browser-cache-ttl-setting.update 브라우저 캐시 TTL 변경.
internet-svcs.development-mode-setting.update 개발 모드 활성화 또는 비활성화.
internet-svcs.security-level-setting.update 보안 레벨을 변경합니다.
internet-svcs.ssl-setting.update SSL 설정을 변경하세요.
internet-svcs.tls-1-2-only-setting.update TLS 1.2 지원 기능을 활성화하거나 비활성화합니다.
internet-svcs.waf-setting.update 웹 애플리케이션 방화벽을 활성화하거나 비활성화합니다.
internet-svcs.cname-flattening-setting.update CNAME 평탄화 설정을 변경합니다.
internet-svcs.always-online-setting.update 해당 도메인에 대해 오래된 콘텐츠 제공 기능을 활성화하거나 비활성화합니다.
internet-svcs.sort-query-string-for-cache-setting.update 캐시에 저장된 콘텐츠를 조회할 때 쿼리 인수의 정렬 기능을 활성화하거나 비활성화합니다.
internet-svcs.tls-1-3-setting.update TLS 1.3 설정 변경.
internet-svcs.automatic-https-rewrites-setting.update HTTPS 의 자동 리라이팅 기능을 활성화하거나 비활성화합니다.
internet-svcs.opportunistic-encryption-setting.update 기회적 암호화 활성화 또는 비활성화.
internet-svcs.browser-check-setting.update 브라우저 무결성 검사 활성화 또는 비활성화.
internet-svcs.challenge-ttl-setting.update 인증 확인 TTL을 업데이트하십시오.
internet-svcs.always-use-https-setting.update Always Use HTTPS 를 활성화하거나 비활성화합니다.
internet-svcs.true-client-ip-header-setting.update True 클라이언트 IP 헤더를 사용 또는 사용 안함으로 설정합니다.
internet-svcs.image-size-optimization-setting.update 이미지 크기 최적화를 사용 또는 사용 안함으로 설정합니다.
internet-svcs.script-load-optimization-setting.update 스크립트 로드 최적화를 사용 또는 사용 안함으로 설정합니다.
internet-svcs.image-load-optimization-setting.update 이미지 로드 최적화를 사용 또는 사용 안함으로 설정합니다.
internet-svcs.minify-setting.update HTML, CSS 또는 JavaScript 파일의 압축 기능을 활성화하거나 비활성화합니다.
internet-svcs.min-tls-version-setting.update 최소 TLS 버전을 변경합니다.
internet-svcs.ip-geolocation-setting.update IP 지리적 위치 헤더를 사용 또는 사용 안함으로 설정합니다.
internet-svcs.http2-setting.update 도메인에 대해 HTTP2를 사용하거나 사용하지 않도록 설정합니다.
internet-svcs.max-upload-setting.update 방문자가 한 번의 요청으로 웹사이트에 업로드할 수 있는 데이터 양을 변경합니다.
internet-svcs.origin-error-page-pass-thru-setting.update 오리진 서버에서 리턴되는 502및 504오류 페이지의 프록시를 사용 또는 사용 안함으로 설정합니다.
internet-svcs.bot-management.update 봇 관리 설정을 변경합니다.
internet-svcs.universal-ssl-setting.update 범용 모드 전환 SSL.
internet-svcs.logs-retention.update 업데이트 로그 보관 기간 설정.

알림 대상 이벤트

다음 표에는 경고 알림과 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:

경보 이벤트를 발생시키는 동작
조치 설명
internet-svcs.alerting-policies.create 알림 정책 생성.
internet-svcs.alerting-policies.update 경고 알림 정책 업데이트.
internet-svcs.alerting-policies.delete 알림 정책 삭제.
internet-svcs.alerting-webhooks.create 알림 웹훅 수신처를 생성합니다.
internet-svcs.alerting-webhooks.update 알림 웹훅 수신처를 업데이트합니다.
internet-svcs.alerting-webhooks.delete 알림 웹훅 수신처를 삭제합니다.

추가 정보

IBM Cloud Activity Tracker에서 생성되는 IBM Cloud Internet Services 이벤트를 모니터하고 추가 정보가 필요한 API 요청을 식별하는 경우 이벤트에서 requestData 필드를 확인하십시오.

지원 요청을 등록하고, xml-ph-0000@deepl.internal에서 확인할 수 있는 해당 필드의 값을 requestIdrequestData 에서 확인할 수 있는 해당 필드의 값을 기재해 주십시오.

CIS 활동 추적 이벤트 분석

API를 사용하여 감사 이벤트를 호출하는 방법에 대한 자세한 정보는 CIS API 문서 에서 각 메소드의 감사 섹션을 참조하십시오.