CommVault ๋ฐฑ์—… ๋ฐ ๋ณต๊ตฌ ๋กœ๊ทธ ์ˆ˜์ง‘

๋‹ค์Œ์—์„œ ์ง€์›:

์ด ๋ฌธ์„œ์—์„œ๋Š” Bindplane์„ ์‚ฌ์šฉํ•˜์—ฌ CommVault Backup and Recovery ๋กœ๊ทธ๋ฅผ Google Security Operations๋กœ ์ˆ˜์ง‘ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. ํŒŒ์„œ๋Š” Commvault ๋กœ๊ทธ ๋‚ด์˜ ์„ธ ๊ฐ€์ง€ ๋‹ค๋ฅธ ๋กœ๊ทธ ์œ ํ˜• (Alerts, Events, AuditTrail)์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ์ถ”์ถœํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ ๋‹ค์Œ ์ถ”์ถœ๋œ ํ•„๋“œ๋ฅผ Google SecOps UDM ์Šคํ‚ค๋งˆ์— ๋งคํ•‘ํ•˜์—ฌ ์ผ๊ด€๋œ ํ‘œํ˜„์„ ๋ณด์žฅํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์–‘ํ•œ ๋ฐ์ดํ„ฐ ์ •๋ฆฌ ๋ฐ ๋ณ€ํ™˜ ์ž‘์—…์„ ์ฒ˜๋ฆฌํ•ฉ๋‹ˆ๋‹ค.

์‹œ์ž‘ํ•˜๊ธฐ ์ „์—

  • Google Security Operations ์ธ์Šคํ„ด์Šค๊ฐ€ ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • Windows 2016 ์ด์ƒ ๋˜๋Š” systemd๊ฐ€ ์„ค์น˜๋œ Linux ํ˜ธ์ŠคํŠธ๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • ํ”„๋ก์‹œ ๋’ค์—์„œ ์‹คํ–‰ํ•˜๋Š” ๊ฒฝ์šฐ ๋ฐฉํ™”๋ฒฝ ํฌํŠธ๊ฐ€ ์—ด๋ ค ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • Commvault CommCell์— ๋Œ€ํ•œ ๊ถŒํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ์ˆ˜์ง‘ ์—์ด์ „ํŠธ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค. Bindplane์ด ์„ค์น˜๋  ์‹œ์Šคํ…œ์— ํŒŒ์ผ์„ ์•ˆ์ „ํ•˜๊ฒŒ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Google SecOps ๊ณ ๊ฐ ID ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ํ”„๋กœํ•„๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์กฐ์ง ์„ธ๋ถ€์ •๋ณด ์„น์…˜์—์„œ ๊ณ ๊ฐ ID๋ฅผ ๋ณต์‚ฌํ•˜์—ฌ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ ์„ค์น˜

Windows ์„ค์น˜

  1. ๋ช…๋ น ํ”„๋กฌํ”„ํŠธ ๋˜๋Š” PowerShell์„ ๊ด€๋ฆฌ์ž๋กœ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet
    

Linux ์„ค์น˜

  1. ๋ฃจํŠธ ๋˜๋Š” sudo ๊ถŒํ•œ์œผ๋กœ ํ„ฐ๋ฏธ๋„์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh
    

์ถ”๊ฐ€ ์„ค์น˜ ๋ฆฌ์†Œ์Šค

Syslog๋ฅผ ์ˆ˜์ง‘ํ•˜์—ฌ Google SecOps๋กœ ์ „์†กํ•˜๋„๋ก Bindplane ์—์ด์ „ํŠธ ๊ตฌ์„ฑ

  1. ๊ตฌ์„ฑ ํŒŒ์ผ์— ์•ก์„ธ์Šคํ•ฉ๋‹ˆ๋‹ค.

    1. config.yaml ํŒŒ์ผ์„ ์ฐพ์Šต๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ Linux์—์„œ๋Š” /etc/bindplane-agent/ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๊ณ  Windows์—์„œ๋Š” ์„ค์น˜ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ์Šต๋‹ˆ๋‹ค.
    2. ํ…์ŠคํŠธ ํŽธ์ง‘๊ธฐ (์˜ˆ: nano, vi, ๋ฉ”๋ชจ์žฅ)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ๊ณผ ๊ฐ™์ด config.yaml ํŒŒ์ผ์„ ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

    receivers:
        udplog:
            # Replace the port and IP address as required
            listen_address: "0.0.0.0:514"
    
    exporters:
        chronicle/chronicle_w_labels:
            compression: gzip
            # Adjust the path to the credentials file you downloaded in Step 1
            creds: '/path/to/ingestion-authentication-file.json'
            # Replace with your actual customer ID from Step 2
            customer_id: <customer_id>
            endpoint: malachiteingestion-pa.googleapis.com
            # Add optional ingestion labels for better organization
            ingestion_labels:
                log_type: COMMVAULT_COMMCELL
                raw_log_field: body
    
    service:
        pipelines:
            logs/source0__chronicle_w_labels-0:
                receivers:
                    - udplog
                exporters:
                    - chronicle/chronicle_w_labels
    
  3. ์ธํ”„๋ผ์— ํ•„์š”ํ•œ ๋Œ€๋กœ ํฌํŠธ์™€ IP ์ฃผ์†Œ๋ฅผ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

  4. <customer_id>๋ฅผ ์‹ค์ œ ๊ณ ๊ฐ ID๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

  5. Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ ์„น์…˜์—์„œ ์ธ์ฆ ํŒŒ์ผ์ด ์ €์žฅ๋œ ๊ฒฝ๋กœ๋กœ /path/to/ingestion-authentication-file.json๋ฅผ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜์—ฌ ๋ณ€๊ฒฝ์‚ฌํ•ญ ์ ์šฉ

  • Linux์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo systemctl restart bindplane-agent
    
  • Windows์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ์„œ๋น„์Šค ์ฝ˜์†”์„ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.

    net stop BindPlaneAgent && net start BindPlaneAgent
    

Commvault Syslog Server ๊ตฌ์„ฑ

  1. Commvault CommCell ์›น UI์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. ๊ด€๋ฆฌ > ์‹œ์Šคํ…œ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  3. ์‹œ์Šคํ…œ ๋กœ๊ทธ ์„œ๋ฒ„๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  4. ์‹œ์Šคํ…œ ๋กœ๊ทธ ์„œ๋ฒ„์˜ ๋‹ค์Œ ์„ธ๋ถ€์ •๋ณด๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.
    • ํ˜ธ์ŠคํŠธ ์ด๋ฆ„: Bindplane ์—์ด์ „ํŠธ์˜ IP ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    • ํฌํŠธ: Bindplane ํฌํŠธ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค(์˜ˆ: 514).
    • ์‚ฌ์šฉ ์„ค์ • ์ „ํ™˜ ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ syslog ์„œ๋ฒ„ ์„ค์ •์„ ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.
    • syslog๋กœ ์ „๋‹ฌ ํ•„๋“œ์—์„œ ์•Œ๋ฆผ, ๊ฐ์‚ฌ ์ถ”์ , ์ด๋ฒคํŠธ๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  5. ์ œ์ถœ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

UDM ๋งคํ•‘ ํ…Œ์ด๋ธ”

๋กœ๊ทธ ํ•„๋“œ UDM ๋งคํ•‘ ๋…ผ๋ฆฌ
AgentType observer.application ์ด๋ฒคํŠธ ๋กœ๊ทธ์˜ AgentType ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
Alertid security_result.detection_fields.Alertid.value ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertid ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
Alertname security_result.detection_fields.Alertname.value ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertname ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
Alertseverity security_result.severity ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertseverity ํ•„๋“œ์—์„œ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. UDM ์‹ฌ๊ฐ๋„ ์ˆ˜์ค€ (INFORMATIONAL, HIGH, LOW, CRITICAL)์œผ๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
Alerttime metadata.event_timestamp ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alerttime ํ•„๋“œ์—์„œ ํŒŒ์‹ฑ๋˜์–ด ํƒ€์ž„์Šคํƒฌํ”„๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
Audittime metadata.event_timestamp ๊ฐ์‚ฌ ๋กœ๊ทธ์˜ Audittime ํ•„๋“œ์—์„œ ํŒŒ์‹ฑ๋˜์–ด ํƒ€์ž„์Šคํƒฌํ”„๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
ํด๋ผ์ด์–ธํŠธ principal.hostname, principal.asset.hostname ์ด๋ฒคํŠธ, ์•Œ๋ฆผ ๋˜๋Š” ๊ฐ์‚ฌ ๋กœ๊ทธ์˜ Client ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
CommCell ์ด UDM ํ•„๋“œ๋Š” ์›์‹œ ๋กœ๊ทธ์—์„œ ๊ฐ€์ ธ์˜ค์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์•Œ๋ฆผ ์„ค๋ช…์—์„œ ์ถ”์ถœ๋œ ๊ฒฝ์šฐ backupcv๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
์ปดํ“จํ„ฐ ์ด UDM ํ•„๋“œ๋Š” ์›์‹œ ๋กœ๊ทธ์—์„œ ๊ฐ€์ ธ์˜ค์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ด ๊ฐ’์€ ์ด๋ฒคํŠธ ๋กœ๊ทธ์—์„œ ์ถ”์ถœ๋œ ๊ฒฝ์šฐ backupcv๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
์„ค๋ช… security_result.description ์ด๋ฒคํŠธ ๋กœ๊ทธ์˜ Description ํ•„๋“œ ๋˜๋Š” ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertdescription ํ•„๋“œ์—์„œ ํŒŒ์‹ฑ๋œ event_description ํ•„๋“œ์—์„œ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. Description ํ•„๋“œ์— A suspicious file์ด ํฌํ•จ๋œ ๊ฒฝ์šฐ A suspicious file is Detected๋กœ ๋ฎ์–ด์”๋‹ˆ๋‹ค.
์„ธ๋ถ€์ •๋ณด grok์„ ์‚ฌ์šฉํ•˜์—ฌ Client ํ•„๋“œ๋ฅผ ์ถ”์ถœํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
๊ธฐ๊ฐ„ ์ด UDM ํ•„๋“œ๋Š” ์›์‹œ ๋กœ๊ทธ์—์„œ ๊ฐ€์ ธ์˜ค์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ด ๊ฐ’์€ ์ด๋ฒคํŠธ ์„ค๋ช…์—์„œ ์ถ”์ถœํ•œ ๊ธฐ๊ฐ„์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
Eventid metadata.product_log_id ์ด๋ฒคํŠธ ๋กœ๊ทธ์˜ Eventid ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
Eventseverity security_result.severity ์ด๋ฒคํŠธ ๋กœ๊ทธ์˜ Eventseverity ํ•„๋“œ์—์„œ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. UDM ์‹ฌ๊ฐ๋„ ์ˆ˜์ค€ (INFORMATIONAL, HIGH, LOW, CRITICAL)์œผ๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
file_name security_result.detection_fields.SuspiciousFileName.value grok์„ ์‚ฌ์šฉํ•˜์—ฌ ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertdescription ํ•„๋“œ์—์„œ ์ถ”์ถœ๋ฉ๋‹ˆ๋‹ค.
Jobid principal.process.pid ์ด๋ฒคํŠธ ๋˜๋Š” ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Jobid ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
media_agent security_result.detection_fields.MediaAgent.value grok์„ ์‚ฌ์šฉํ•˜์—ฌ ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertdescription ํ•„๋“œ์—์„œ ์ถ”์ถœ๋ฉ๋‹ˆ๋‹ค.
no_of_files_created security_result.detection_fields.no_of_files_created.value grok์„ ์‚ฌ์šฉํ•˜์—ฌ ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertdescription ํ•„๋“œ์—์„œ ์ถ”์ถœ๋ฉ๋‹ˆ๋‹ค.
no_of_files_deleted security_result.detection_fields.no_of_files_deleted.value grok์„ ์‚ฌ์šฉํ•˜์—ฌ ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertdescription ํ•„๋“œ์—์„œ ์ถ”์ถœ๋ฉ๋‹ˆ๋‹ค.
no_of_files_modified security_result.detection_fields.no_of_files_modified.value grok์„ ์‚ฌ์šฉํ•˜์—ฌ ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertdescription ํ•„๋“œ์—์„œ ์ถ”์ถœ๋ฉ๋‹ˆ๋‹ค.
no_of_files_renamed security_result.detection_fields.no_of_files_renamed.value grok์„ ์‚ฌ์šฉํ•˜์—ฌ ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertdescription ํ•„๋“œ์—์„œ ์ถ”์ถœ๋ฉ๋‹ˆ๋‹ค.
๋ฐœ์ƒ ์‹œ๊ฐ„ metadata.event_timestamp ์ด๋ฒคํŠธ ๋กœ๊ทธ์˜ Occurrencetime ํ•„๋“œ์—์„œ ํŒŒ์‹ฑ๋˜์–ด ํƒ€์ž„์Šคํƒฌํ”„๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
์ž‘์—… security_result.detection_fields.Operation.value ๊ฐ์‚ฌ ๋กœ๊ทธ์˜ Operation ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
Opid security_result.detection_fields.Opid.value ๊ฐ์‚ฌ ๋กœ๊ทธ์˜ Opid ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
ํ”„๋กœ๊ทธ๋žจ principal.application ์ด๋ฒคํŠธ ๋กœ๊ทธ์˜ Program ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
Severitylevel security_result.severity ๊ฐ์‚ฌ ๋กœ๊ทธ์˜ Severitylevel ํ•„๋“œ์—์„œ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. UDM ์‹ฌ๊ฐ๋„ ์ˆ˜์ค€ (INFORMATIONAL, HIGH, LOW, CRITICAL)์œผ๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค.
์œ ํ˜• security_result.detection_fields.Type.value ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertdescription ํ•„๋“œ์—์„œ ์ถ”์ถœ๋œ Type ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
url network.http.referral_url ์•Œ๋ฆผ ๋กœ๊ทธ์˜ Alertdescription ํ•„๋“œ์—์„œ ์ถ”์ถœ๋œ url ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
์‚ฌ์šฉ์ž ์ด๋ฆ„ principal.user.userid ๊ฐ์‚ฌ ๋กœ๊ทธ์˜ Username ํ•„๋“œ์—์„œ ์ง์ ‘ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž ์ด๋ฆ„์ด Administrator์ด๋ฉด principal.user.user_role ํ•„๋“œ๊ฐ€ ๋Œ€์‹  ADMINISTRATOR๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
- metadata.vendor_name ์ด UDM ํ•„๋“œ๋Š” ์›์‹œ ๋กœ๊ทธ์—์„œ ๊ฐ€์ ธ์˜ค์ง€ ์•Š์Šต๋‹ˆ๋‹ค. COMMVAULT๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
- metadata.product_name ์ด UDM ํ•„๋“œ๋Š” ์›์‹œ ๋กœ๊ทธ์—์„œ ๊ฐ€์ ธ์˜ค์ง€ ์•Š์Šต๋‹ˆ๋‹ค. COMMVAULT_COMMCELL๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
- metadata.log_type ์ด UDM ํ•„๋“œ๋Š” ์›์‹œ ๋กœ๊ทธ์—์„œ ๊ฐ€์ ธ์˜ค์ง€ ์•Š์Šต๋‹ˆ๋‹ค. COMMVAULT_COMMCELL๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
- metadata.event_type ์ด UDM ํ•„๋“œ๋Š” ์›์‹œ ๋กœ๊ทธ์—์„œ ๊ฐ€์ ธ์˜ค์ง€ ์•Š์Šต๋‹ˆ๋‹ค. Client ํ•„๋“œ๊ฐ€ ์žˆ์œผ๋ฉด STATUS_UPDATE๋กœ ์„ค์ •๋˜๊ณ , ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด GENERIC_EVENT๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.

๋„์›€์ด ๋” ํ•„์š”ํ•˜์‹ ๊ฐ€์š”? ์ปค๋ฎค๋‹ˆํ‹ฐ ํšŒ์› ๋ฐ Google SecOps ์ „๋ฌธ๊ฐ€๋กœ๋ถ€ํ„ฐ ๋‹ต๋ณ€์„ ๋ฐ›์œผ์„ธ์š”.