CIS 에 대한 활동 추적 이벤트
IBM Cloud IBM Cloud Internet Services 와 같은 서비스는 활동 추적 이벤트를 생성합니다.
활동 추적 이벤트는 IBM Cloud에서 서비스의 상태를 변경하는 활동에 대해 보고합니다. 이 이벤트를 활용하여 비정상적인 활동과 중대한 조치를 조사하고, 규제 감사 요건을 준수할 수 있습니다.
플랫폼 서비스인 IBM Cloud Activity Tracker Event Routing을 사용하여 활동 추적 이벤트가 전송되는 위치를 정의하는 대상 및 라우트를 구성하여 계정의 감사 이벤트를 선택한 대상으로 라우팅할 수 있습니다. 자세한 정보는 IBM Cloud Activity Tracker Event Routing 정보를 참조하십시오.
IBM Cloud Logs 을 사용하여 계정에서 생성되고 IBM Cloud Activity Tracker Event Routing 에 의해 IBM Cloud Logs 인스턴스로 라우팅되는 이벤트를 시각화하고 경보할 수 있습니다.
CIS 달라스(DAL), 워싱턴 D.C.(WDC), 프랑크푸르트(FRA)에 위치한 글로벌 제어 플레인을 활용합니다. 이벤트는 리소스 자체의 위치에 관계없이 요청을 처리하는 컨트롤 플레인에서 생성됩니다.
활동 추적 이벤트가 생성되는 위치
기본적으로 CIS Activity Tracker 이벤트는 프랑크푸르트 (eu-de) 지역에 저장됩니다. 이러한 이벤트를 해당 지역에 저장하지 않으려면 Internet Services Activity Tracker 이벤트 라우팅을 구성하여 지원되는 모든 지역으로 이벤트를 전송할 수 있습니다.
CIS 에 대한 활동 추적 이벤트 보기
IBM Cloud Logs 을 사용하여 계정에서 생성되고 IBM Cloud Activity Tracker Event Routing 에 의해 IBM Cloud Logs 인스턴스로 라우팅되는 이벤트를 시각화하고 경보할 수 있습니다.
관찰 가능성 페이지에서 IBM Cloud Logs 실행
IBM Cloud Logs UI 실행에 대한 정보는 IBM Cloud Logs 문서에서 UI 실행 을 참조하십시오.
DNS 도메인에 대한 이벤트
| 조치 | 설명 |
|---|---|
internet-svcs.zones.create |
DNS 도메인 생성. |
internet-svcs.zones.update |
DNS 도메인 업데이트. |
internet-svcs.zones.delete |
DNS 도메인 삭제. |
internet-svcs.zones-activation-check.update |
DNS 도메인에 대한 활성화 검사를 실행합니다. |
internet-svcs.dnssec.update |
DNS 도메인에 대해 DNSSEC를 활성화하거나 비활성화합니다. |
DNS 레코드에 대한 이벤트
다음 표에서는 DNS 레코드와 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.dns-records.create |
DNS 레코드를 작성합니다. |
internet-svcs.dns-records.update |
DNS 레코드를 업데이트합니다. |
internet-svcs.dns-records.delete |
DNS 레코드를 삭제합니다. |
internet-svcs.dns-records-bulk.create |
존 파일에서 DNS 레코드 가져오기. |
internet-svcs.dns-records-batch.create |
DNS 레코드를 일괄 생성합니다. |
internet-svcs.dns-records-batch.update |
DNS 레코드를 일괄 업데이트합니다. |
internet-svcs.dns-records-batch.delete |
DNS 레코드를 일괄 삭제합니다. |
로드 밸런서에 대한 이벤트
다음 표에서는 로드 밸런서와 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.load-balancers.create |
글로벌 로드 밸런서를 작성합니다. |
internet-svcs.load-balancers.update |
글로벌 로드 밸런서를 업데이트합니다. |
internet-svcs.load-balancers.delete |
글로벌 로드 밸런서를 삭제합니다. |
internet-svcs.load-balancer-monitors.create |
글로벌 로드 밸런서 상태 검사를 작성합니다. |
internet-svcs.load-balancer-monitors.update |
글로벌 로드 밸런서 상태 검사를 업데이트합니다. |
internet-svcs.load-balancer-monitors.delete |
글로벌 로드 밸런서 상태 검사를 삭제합니다. |
internet-svcs.load-balancer-pools.create |
글로벌 로드 밸런서 풀 생성. |
internet-svcs.load-balancer-pools.update |
전역 부하 분산 풀 업데이트 |
internet-svcs.load-balancer-pools.delete |
글로벌 로드 밸런서 풀 삭제. |
캐시를 제거하기 위한 이벤트
다음 표에서는 캐시 제거와 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.purge-cache-all.update |
엣지 서버에서 특정 도메인의 모든 캐시된 자산을 삭제합니다. |
internet-svcs.purge-cache-by-urls.update |
엣지 서버에서 URL별로 캐시된 리소스를 삭제합니다. |
internet-svcs.purge-cache-by-cache-tags.update |
엣지 서버에서 캐시 태그별로 캐시된 자산을 삭제합니다. |
internet-svcs.purge-cache-by-hosts.update |
엣지 서버에서 호스트명별로 캐시된 자산을 삭제합니다. |
internet-svcs.purge-cache-by-prefixes.update |
URL 접두사를 기준으로 캐시를 삭제합니다. |
페이지 규칙에 대한 이벤트
다음 표에서는 페이지 규칙과 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.pagerules.create |
페이지 규칙 만들기. |
internet-svcs.pagerules.update |
페이지 규칙 업데이트. |
internet-svcs.pagerules.delete |
페이지 규칙 삭제. |
방화벽에 대한 이벤트
다음 표에서는 방화벽과 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.waf-groups.update |
WAF 규칙 세트 그룹을 활성화하거나 비활성화합니다 |
internet-svcs.waf-rules.update |
WAF 규칙을 활성화하거나 비활성화합니다. |
internet-svcs.ip-firewall-rules.create |
도메인 레벨 또는 인스턴스 레벨에서 IP 방화벽 규칙을 작성합니다. |
internet-svcs.ip-firewall-rules.update |
도메인 레벨 또는 인스턴스 레벨에서 IP 방화벽 규칙을 업데이트합니다. |
internet-svcs.ip-firewall-rules.delete |
도메인 레벨 또는 인스턴스 레벨에서 IP 방화벽 규칙을 삭제합니다. |
internet-svcs.filters.create |
필터를 작성합니다. |
internet-svcs.filters.update |
필터를 업데이트합니다. |
internet-svcs.filters.delete |
필터를 삭제합니다. |
internet-svcs.filters-validate-expr.create |
필터 표현식을 유효성 검증합니다. |
internet-svcs.firewall-rules.create |
필터 기반 방화벽 규칙을 작성합니다. |
internet-svcs.firewall-rules.update |
필터 기반 방화벽 규칙을 업데이트합니다. |
internet-svcs.firewall-rules.delete |
필터 기반 방화벽 규칙을 삭제합니다. |
internet-svcs.ua-rules.create |
사용자 에이전트 차단 규칙을 작성합니다. |
internet-svcs.ua-rules.update |
사용자 에이전트 차단 규칙을 업데이트합니다. |
internet-svcs.ua-rules.delete |
사용자 에이전트 차단 규칙을 삭제합니다. |
internet-svcs.domain-lockdown-rules.create |
도메인 잠금 규칙 생성. |
internet-svcs.domain-lockdown-rules.update |
도메인 잠금 규칙 업데이트. |
internet-svcs.domain-lockdown-rules.delete |
도메인 잠금 규칙 삭제. |
WAF 재정의 관련 이벤트
다음 표에는 WAF 재정의와 관련되어 이벤트를 발생시키는 작업들이 나열되어 있습니다:
| 조치 | 설명 |
|---|---|
internet-svcs.waf-overrides.create |
WAF 패키지 재정의 생성. |
internet-svcs.waf-overrides.update |
WAF 패키지 재정의 업데이트. |
internet-svcs.waf-overrides.delete |
WAF 패키지 재정의 삭제. |
WAF 규칙 세트에 대한 이벤트
다음 표에는 WAF 규칙 집합과 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:
| 조치 | 설명 |
|---|---|
internet-svcs.zone-rulesets.create |
영역 수준의 WAF 규칙 집합을 생성합니다. |
internet-svcs.zone-rulesets.update |
영역 수준의 WAF 규칙 세트를 업데이트합니다. |
internet-svcs.zone-rulesets.delete |
영역 수준의 WAF 규칙 집합 삭제. |
internet-svcs.zone-rulesets-rules.create |
영역 규칙 집합에 규칙 생성. |
internet-svcs.zone-rulesets-rules.update |
존 규칙 집합의 규칙을 업데이트합니다. |
internet-svcs.zone-rulesets-rules.delete |
영역 규칙 집합에서 규칙 삭제. |
internet-svcs.zone-rulesets-phases.create |
구역 규칙 세트 단계 항목 생성. |
internet-svcs.zone-rulesets-phases.update |
구역 규칙 집합 단계 항목 업데이트. |
internet-svcs.zone-rulesets-phases.delete |
존 규칙 세트 단계 항목 삭제. |
internet-svcs.zone-rulesets-phases-entrypoint.update |
구역 규칙 세트 단계의 진입점을 업데이트합니다. |
사용자 정의 목록에 대한 이벤트
다음 표에는 사용자 정의 목록과 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:
| 조치 | 설명 |
|---|---|
internet-svcs.custom-lists.create |
사용자 지정 IP/ASN/호스트명 목록 생성. |
internet-svcs.custom-lists.update |
사용자 지정 목록 업데이트. |
internet-svcs.custom-lists.delete |
사용자 지정 목록 삭제. |
internet-svcs.custom-lists-items.create |
사용자 지정 목록에 항목을 추가합니다. |
internet-svcs.custom-lists-items.update |
사용자 지정 목록의 항목 업데이트. |
internet-svcs.custom-lists-items.delete |
사용자 지정 목록에서 항목 삭제. |
internet-svcs.custom-lists-operations.create |
사용자 정의 목록에 대해 일괄 작업을 수행합니다. |
관리 대상 목록에 대한 이벤트
다음 표에는 관리 목록과 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:
| 조치 | 설명 |
|---|---|
internet-svcs.managed-lists.create |
관리 대상 IP 목록 생성. |
internet-svcs.managed-lists.update |
관리 목록 업데이트. |
internet-svcs.managed-lists.delete |
관리 목록 삭제. |
비율 제한에 대한 이벤트
다음 표에서는 속도 제한과 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.rate-limits.create |
속도 제한 규칙을 만듭니다 |
internet-svcs.rate-limits.update |
속도 제한 규칙을 업데이트합니다. |
internet-svcs.rate-limits.delete |
속도 제한 규칙 삭제. |
라우팅에 대한 이벤트
다음 표에서는 라우팅과 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.smart-routing.update |
스마트 라우팅을 사용 또는 사용 안함으로 설정합니다. |
internet-svcs.tiered-caching.update |
티어링된 캐싱을 사용 또는 사용 안함으로 설정합니다. |
인증서 팩의 이벤트
다음 표에서는 인증서 팩과 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.certificate-packs.create |
전용 와일드카드 인증서 또는 맞춤형 인증서를 신청하세요. |
internet-svcs.certificate-packs.delete |
전용 와일드카드 인증서 또는 사용자 지정 인증서 삭제. |
사용자 정의 인증서에 대한 이벤트
다음 표에서는 사용자 정의 인증서와 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.custom-certificates.create |
사용자 정의 인증서를 업로드합니다. |
internet-svcs.custom-certificates.update |
사용자 정의 인증서를 업데이트합니다. |
internet-svcs.custom-certificates.delete |
사용자 정의 인증서를 삭제합니다. |
internet-svcs.custom-certificates-prioritize.update |
SSL 인증서 우선순위 재설정. |
오리진 인증서에 대한 이벤트
다음 표에서는 오리진 인증서와 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.origin-certificates.create |
오리진 인증서를 작성합니다. |
internet-svcs.origin-certificates.delete |
오리진 인증서를 취소합니다. |
인증된 원본에 대한 풀 요청 이벤트
다음 표에는 인증된 오리진 풀과 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:
| 조치 | 설명 |
|---|---|
internet-svcs.origin-tls-client-auth.create |
영역 수준 클라이언트 인증서를 업로드합니다. |
internet-svcs.origin-tls-client-auth.delete |
영역 수준 클라이언트 인증서 삭제. |
internet-svcs.origin-tls-client-auth-settings.update |
특정 영역에 대해 인증된 출처의 풀을 토글합니다. |
internet-svcs.origin-tls-client-auth-hostnames.update |
호스트명별 인증된 원본 가져오기 구성. |
internet-svcs.origin-tls-client-auth-hostname-certificates.create |
호스트명별 클라이언트 인증서를 업로드합니다. |
internet-svcs.origin-tls-client-auth-hostname-certificates.delete |
호스트명별 클라이언트 인증서 삭제. |
에지 함수에 대한 이벤트
다음 표에서는 Edge Functions와 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.edge-functions-scripts.create |
엣지 함수 스크립트 생성. |
internet-svcs.edge-functions-scripts.update |
Edge Functions 스크립트의 새 버전을 업데이트합니다. |
internet-svcs.edge-functions-scripts.delete |
엣지 함수 스크립트 삭제. |
internet-svcs.edge-functions-routes.create |
엣지 함수 경로 생성. |
internet-svcs.edge-functions-routes.update |
엣지 기능 경로 업데이트. |
internet-svcs.edge-functions-routes.delete |
경로에서 에지 함수 삭제. |
범위 애플리케이션에 대한 이벤트
다음 표에서는 Range 애플리케이션과 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.range-apps.create |
범위 애플리케이션을 작성합니다. |
internet-svcs.range-apps.update |
범위 애플리케이션을 업데이트합니다. |
internet-svcs.range-apps.delete |
범위 애플리케이션을 삭제합니다. |
logpush 관련 이벤트
다음 표에서는 Logpush와 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.logpush-ownership.create |
로그푸시 소유권 이의 제기 시작. |
internet-svcs.logpush-ownership-validate.create |
로그푸시 소유권 챌린지 유효성 검사. |
internet-svcs.logpush-jobs.create |
로그푸시 작업 생성. |
internet-svcs.logpush-jobs.update |
로그푸시 작업 업데이트. |
internet-svcs.logpush-jobs.delete |
로그푸시 작업 삭제하기 |
즉시 로그용 이벤트
다음 표에는 인스턴트 로그와 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:
| 조치 | 설명 |
|---|---|
internet-svcs.instant-logs-jobs.create |
즉시 로그 작업 생성. |
internet-svcs.instant-logs-jobs.update |
즉시 로그 작업 업데이트. |
internet-svcs.instant-logs-jobs.delete |
인스턴트 로그 작업을 삭제합니다. |
사용자 정의 오류 페이지에 대한 이벤트
다음 표에서는 사용자 정의 오류 페이지와 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.custom-pages.create |
사용자 정의 오류 페이지를 작성합니다. |
internet-svcs.custom-pages.update |
사용자 정의 오류 페이지를 업데이트합니다. |
설정에 대한 이벤트
다음 표에서는 구성 설정과 관련된 조치를 나열하고 이벤트를 생성합니다.
| 조치 | 설명 |
|---|---|
internet-svcs.cache-level-setting.update |
캐싱 레벨을 변경합니다. |
internet-svcs.browser-cache-ttl-setting.update |
브라우저 캐시 TTL 변경. |
internet-svcs.development-mode-setting.update |
개발 모드 활성화 또는 비활성화. |
internet-svcs.security-level-setting.update |
보안 레벨을 변경합니다. |
internet-svcs.ssl-setting.update |
SSL 설정을 변경하세요. |
internet-svcs.tls-1-2-only-setting.update |
TLS 1.2 지원 기능을 활성화하거나 비활성화합니다. |
internet-svcs.waf-setting.update |
웹 애플리케이션 방화벽을 활성화하거나 비활성화합니다. |
internet-svcs.cname-flattening-setting.update |
CNAME 평탄화 설정을 변경합니다. |
internet-svcs.always-online-setting.update |
해당 도메인에 대해 오래된 콘텐츠 제공 기능을 활성화하거나 비활성화합니다. |
internet-svcs.sort-query-string-for-cache-setting.update |
캐시에 저장된 콘텐츠를 조회할 때 쿼리 인수의 정렬 기능을 활성화하거나 비활성화합니다. |
internet-svcs.tls-1-3-setting.update |
TLS 1.3 설정 변경. |
internet-svcs.automatic-https-rewrites-setting.update |
HTTPS 의 자동 리라이팅 기능을 활성화하거나 비활성화합니다. |
internet-svcs.opportunistic-encryption-setting.update |
기회적 암호화 활성화 또는 비활성화. |
internet-svcs.browser-check-setting.update |
브라우저 무결성 검사 활성화 또는 비활성화. |
internet-svcs.challenge-ttl-setting.update |
인증 확인 TTL을 업데이트하십시오. |
internet-svcs.always-use-https-setting.update |
Always Use HTTPS 를 활성화하거나 비활성화합니다. |
internet-svcs.true-client-ip-header-setting.update |
True 클라이언트 IP 헤더를 사용 또는 사용 안함으로 설정합니다. |
internet-svcs.image-size-optimization-setting.update |
이미지 크기 최적화를 사용 또는 사용 안함으로 설정합니다. |
internet-svcs.script-load-optimization-setting.update |
스크립트 로드 최적화를 사용 또는 사용 안함으로 설정합니다. |
internet-svcs.image-load-optimization-setting.update |
이미지 로드 최적화를 사용 또는 사용 안함으로 설정합니다. |
internet-svcs.minify-setting.update |
HTML, CSS 또는 JavaScript 파일의 압축 기능을 활성화하거나 비활성화합니다. |
internet-svcs.min-tls-version-setting.update |
최소 TLS 버전을 변경합니다. |
internet-svcs.ip-geolocation-setting.update |
IP 지리적 위치 헤더를 사용 또는 사용 안함으로 설정합니다. |
internet-svcs.http2-setting.update |
도메인에 대해 HTTP2를 사용하거나 사용하지 않도록 설정합니다. |
internet-svcs.max-upload-setting.update |
방문자가 한 번의 요청으로 웹사이트에 업로드할 수 있는 데이터 양을 변경합니다. |
internet-svcs.origin-error-page-pass-thru-setting.update |
오리진 서버에서 리턴되는 502및 504오류 페이지의 프록시를 사용 또는 사용 안함으로 설정합니다. |
internet-svcs.bot-management.update |
봇 관리 설정을 변경합니다. |
internet-svcs.universal-ssl-setting.update |
범용 모드 전환 SSL. |
internet-svcs.logs-retention.update |
업데이트 로그 보관 기간 설정. |
알림 대상 이벤트
다음 표에는 경고 알림과 관련되어 이벤트를 생성하는 작업들이 나열되어 있습니다:
| 조치 | 설명 |
|---|---|
internet-svcs.alerting-policies.create |
알림 정책 생성. |
internet-svcs.alerting-policies.update |
경고 알림 정책 업데이트. |
internet-svcs.alerting-policies.delete |
알림 정책 삭제. |
internet-svcs.alerting-webhooks.create |
알림 웹훅 수신처를 생성합니다. |
internet-svcs.alerting-webhooks.update |
알림 웹훅 수신처를 업데이트합니다. |
internet-svcs.alerting-webhooks.delete |
알림 웹훅 수신처를 삭제합니다. |
추가 정보
IBM Cloud Activity Tracker에서 생성되는 IBM Cloud Internet Services 이벤트를 모니터하고 추가 정보가 필요한 API 요청을 식별하는 경우 이벤트에서 requestData 필드를 확인하십시오.
지원 요청을 등록하고, xml-ph-0000@deepl.internal에서 확인할 수 있는 해당 필드의 값을 requestIdrequestData 에서 확인할 수 있는 해당 필드의 값을 기재해 주십시오.
CIS 활동 추적 이벤트 분석
API를 사용하여 감사 이벤트를 호출하는 방법에 대한 자세한 정보는 CIS API 문서 에서 각 메소드의 감사 섹션을 참조하십시오.