VMware Airwatch ๋กœ๊ทธ ์ˆ˜์ง‘

๋‹ค์Œ์—์„œ ์ง€์›:

์ด ๋ฌธ์„œ์—์„œ๋Š” Bindplane์„ ์‚ฌ์šฉํ•˜์—ฌ VMware Airwatch (VMware Workspace ONE UEM) ๋กœ๊ทธ๋ฅผ Google Security Operations์— ์ˆ˜์ง‘ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. ํŒŒ์„œ๋Š” ๋‹ค์–‘ํ•œ ํ˜•์‹ (SYSLOG + KV, CEF)์˜ ๋กœ๊ทธ์—์„œ ๋ณด์•ˆ ์ด๋ฒคํŠธ ๋ฐ์ดํ„ฐ๋ฅผ ์ถ”์ถœํ•ฉ๋‹ˆ๋‹ค. ๋จผ์ € AirWatch ๋กœ๊ทธ ๊ตฌ์กฐ์— ํŠน์ •ํ•œ ์ผ๋ จ์˜ Grok ํŒจํ„ด์„ ์‚ฌ์šฉํ•˜์—ฌ ๋กœ๊ทธ ๋ฉ”์‹œ์ง€๋ฅผ ํŒŒ์‹ฑํ•œ ๋‹ค์Œ ์ด๋ฒคํŠธ ๋ฐ์ดํ„ฐ์—์„œ ํ‚ค-๊ฐ’ ์Œ์„ ์ถ”์ถœํ•˜์—ฌ ํ†ตํ•ฉ ๋ฐ์ดํ„ฐ ๋ชจ๋ธ (UDM) ํ•„๋“œ์— ๋งคํ•‘ํ•˜๊ณ , ์ด๋ฒคํŠธ๋ฅผ ๋ถ„๋ฅ˜ํ•˜๊ณ  ๋ณด์•ˆ ๋ถ„์„์„ ์œ„ํ•œ ์ปจํ…์ŠคํŠธ ์ •๋ณด๋กœ ๋ณด๊ฐ•ํ•ฉ๋‹ˆ๋‹ค.

์‹œ์ž‘ํ•˜๊ธฐ ์ „์—

๋‹ค์Œ ๊ธฐ๋ณธ ์š”๊ฑด์ด ์ถฉ์กฑ๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

  • Google SecOps ์ธ์Šคํ„ด์Šค
  • Windows 2016 ์ด์ƒ ๋˜๋Š” systemd๊ฐ€ ์„ค์น˜๋œ Linux ํ˜ธ์ŠคํŠธ
  • ํ”„๋ก์‹œ ๋’ค์—์„œ ์‹คํ–‰ํ•˜๋Š” ๊ฒฝ์šฐ ๋ฐฉํ™”๋ฒฝ ํฌํŠธ๊ฐ€ ์—ด๋ ค ์žˆ๋Š”์ง€ ํ™•์ธ
  • VMware Airwatch์— ๋Œ€ํ•œ ๊ถŒํ•œ ์•ก์„ธ์Šค

Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ์ˆ˜์ง‘ ์—์ด์ „ํŠธ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค. Bindplane์ด ์„ค์น˜๋  ์‹œ์Šคํ…œ์— ํŒŒ์ผ์„ ์•ˆ์ „ํ•˜๊ฒŒ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Google SecOps ๊ณ ๊ฐ ID ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ํ”„๋กœํ•„๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์กฐ์ง ์„ธ๋ถ€์ •๋ณด ์„น์…˜์—์„œ ๊ณ ๊ฐ ID๋ฅผ ๋ณต์‚ฌํ•˜์—ฌ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ ์„ค์น˜

๋‹ค์Œ ์•ˆ๋‚ด์— ๋”ฐ๋ผ Windows ๋˜๋Š” Linux ์šด์˜์ฒด์ œ์— Bindplane ์—์ด์ „ํŠธ๋ฅผ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

Windows ์„ค์น˜

  1. ๋ช…๋ น ํ”„๋กฌํ”„ํŠธ ๋˜๋Š” PowerShell์„ ๊ด€๋ฆฌ์ž๋กœ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet
    

Linux ์„ค์น˜

  1. ๋ฃจํŠธ ๋˜๋Š” sudo ๊ถŒํ•œ์œผ๋กœ ํ„ฐ๋ฏธ๋„์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh
    

์ถ”๊ฐ€ ์„ค์น˜ ๋ฆฌ์†Œ์Šค

์ถ”๊ฐ€ ์„ค์น˜ ์˜ต์…˜์€ ์„ค์น˜ ๊ฐ€์ด๋“œ๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.

Syslog๋ฅผ ์ˆ˜์ง‘ํ•˜์—ฌ Google SecOps๋กœ ์ „์†กํ•˜๋„๋ก Bindplane ์—์ด์ „ํŠธ ๊ตฌ์„ฑ

  1. ๊ตฌ์„ฑ ํŒŒ์ผ์— ์•ก์„ธ์Šคํ•ฉ๋‹ˆ๋‹ค.
    • config.yaml ํŒŒ์ผ์„ ์ฐพ์Šต๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ Linux์—์„œ๋Š” /etc/bindplane-agent/ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๊ณ  Windows์—์„œ๋Š” ์„ค์น˜ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ์Šต๋‹ˆ๋‹ค.
    • ํ…์ŠคํŠธ ํŽธ์ง‘๊ธฐ (์˜ˆ: nano, vi, ๋ฉ”๋ชจ์žฅ)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ๊ณผ ๊ฐ™์ด config.yaml ํŒŒ์ผ์„ ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

    receivers:
        udplog:
            # Replace the port and IP address as required
            listen_address: "0.0.0.0:514"
    
    exporters:
        chronicle/chronicle_w_labels:
            compression: gzip
            # Adjust the path to the credentials file you downloaded in Step 1
            creds_file_path: '/path/to/ingestion-authentication-file.json'
            # Replace with your actual customer ID from Step 2
            customer_id: <customer_id>
            endpoint: malachiteingestion-pa.googleapis.com
            # Add optional ingestion labels for better organization
            log_type: 'AIRWATCH'
            raw_log_field: body
            ingestion_labels:
    
    service:
        pipelines:
            logs/source0__chronicle_w_labels-0:
                receivers:
                    - udplog
                exporters:
                    - chronicle/chronicle_w_labels
    
    • ์ธํ”„๋ผ์— ํ•„์š”ํ•œ ๋Œ€๋กœ ํฌํŠธ์™€ IP ์ฃผ์†Œ๋ฅผ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
    • <customer_id>๋ฅผ ์‹ค์ œ ๊ณ ๊ฐ ID๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
    • Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ ์„น์…˜์—์„œ ์ธ์ฆ ํŒŒ์ผ์ด ์ €์žฅ๋œ ๊ฒฝ๋กœ๋กœ /path/to/ingestion-authentication-file.json๋ฅผ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜์—ฌ ๋ณ€๊ฒฝ์‚ฌํ•ญ ์ ์šฉ

  • Linux์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo systemctl restart bindplane-agent
    
  • Windows์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ์„œ๋น„์Šค ์ฝ˜์†”์„ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.

    net stop BindPlaneAgent && net start BindPlaneAgent
    

VMware Airwatch (VMware Workspace ONE UEM)์šฉ Syslog ๊ตฌ์„ฑ

  1. VMware AirWatch ์›น UI์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. ๋ชจ๋‹ˆํ„ฐ > ๋ณด๊ณ ์„œ ๋ฐ ๋ถ„์„ > ์ด๋ฒคํŠธ > Syslog๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ๋‹ค์Œ ๊ตฌ์„ฑ ์„ธ๋ถ€์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
    • Syslog Integration(Syslog ํ†ตํ•ฉ): Enabled(์‚ฌ์šฉ ์„ค์ •)๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • ํ˜ธ์ŠคํŠธ ์ด๋ฆ„: Bindplane ์—์ด์ „ํŠธ IP ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    • ํ”„๋กœํ† ์ฝœ: UDP๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • ํฌํŠธ: Bindplane ์—์ด์ „ํŠธ ํฌํŠธ ๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    • ๋ฉ”์‹œ์ง€ ํƒœ๊ทธ: Airwatch๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    • ๋ฉ”์‹œ์ง€ ์ฝ˜ํ…์ธ : ๊ธฐ๋ณธ๊ฐ’์œผ๋กœ ์œ ์ง€ํ•ฉ๋‹ˆ๋‹ค.
  4. ๊ณ ๊ธ‰ ํƒญ์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  5. ๋‹ค์Œ ๊ตฌ์„ฑ ์„ธ๋ถ€์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
    • ์ฝ˜์†” ์ด๋ฒคํŠธ: ์‚ฌ์šฉ ์„ค์ •์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • Select Console Events to Send to Syslog(Syslog๋กœ ์ „์†กํ•  ์ฝ˜์†” ์ด๋ฒคํŠธ ์„ ํƒ): Select All(๋ชจ๋‘ ์„ ํƒ)์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
    • ๊ธฐ๊ธฐ ์ด๋ฒคํŠธ: ์‚ฌ์šฉ ์„ค์ •์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • Syslog๋กœ ์ „์†กํ•  ๊ธฐ๊ธฐ ์ด๋ฒคํŠธ ์„ ํƒ: ๋ชจ๋‘ ์„ ํƒ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  6. ์ €์žฅ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  7. Test Connection(์—ฐ๊ฒฐ ํ…Œ์ŠคํŠธ)์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

UDM ๋งคํ•‘ ํ…Œ์ด๋ธ”

๋กœ๊ทธ ํ•„๋“œ UDM ๋งคํ•‘ ๋…ผ๋ฆฌ
AdminAccount principal.user.userid ์ด ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ AdminAccount ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
Application target.application ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
ApplicationUUID additional.fields[].value.string_value ์ด ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ApplicationUUID ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค. ํ‚ค๊ฐ€ 'ApplicationUUID'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
BytesReceived network.received_bytes ์ด ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ BytesReceived ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
Device target.hostname ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ๊ธฐ๊ธฐ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
DeviceEventLogDescription metadata.description ์ด ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ DeviceEventLogDescription ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
Enrollment User principal.user.userid event_name์ด AppCatalogLaunch, InstallApplicationConfirmed, InstallProfileConfirmed, BreakMDMConfirmed, DeviceOperatingSystemChanged, RemoveProfileConfirmed, CertificateIssued, CompromisedStatusChanged, AppListSampleRefused, CertificateListSampleRefused, DeviceInformationRefused, ProfileListRefused, SecurityInformation, SecureChannelCheckIn, SecurityInformationConfirmed, StartACMConfirmed, DeviceAttributeDeviceMCCModified, DeviceAttributePhoneNumberModified, AvailableOSUpdatesList, AvailableOsUpdatesConfirmed ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ๋“ฑ๋ก ์‚ฌ์šฉ์ž ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
Event Category additional.fields[].value.string_value ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์ด๋ฒคํŠธ ์นดํ…Œ๊ณ ๋ฆฌ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค. ํ‚ค๋Š” '์ด๋ฒคํŠธ ์นดํ…Œ๊ณ ๋ฆฌ'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
Event Module additional.fields[].value.string_value ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์ด๋ฒคํŠธ ๋ชจ๋“ˆ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค. ํ‚ค๋Š” 'Event Module'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
Event Source additional.fields[].value.string_value ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์ด๋ฒคํŠธ ์†Œ์Šค ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค. ํ‚ค๋Š” '์ด๋ฒคํŠธ ์†Œ์Šค'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
Event Timestamp metadata.event_timestamp.seconds ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์ด๋ฒคํŠธ ํƒ€์ž„์Šคํƒฌํ”„ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
FriendlyName target.hostname ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ FriendlyName ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
GroupManagementData security_result.description ์ด ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ GroupManagementData ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
Hmac additional.fields[].value.string_value ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ Hmac ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค. ํ‚ค๊ฐ€ 'Hmac'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
LoginSessionID network.session_id ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ LoginSessionID ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
MessageText metadata.description ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ MessageText ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
OriginatingOrganizationGroup principal.user.group_identifiers ์ด ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ OriginatingOrganizationGroup ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
OwnershipType additional.fields[].value.string_value ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ OwnershipType ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค. ํ‚ค๊ฐ€ 'OwnershipType'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
Profile target.resource.name ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ํ”„๋กœํ•„ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
ProfileName target.resource.name ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ProfileName ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
Request Url target.url ์ด ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์š”์ฒญ URL ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
SmartGroupName target.group.group_display_name ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ SmartGroupName ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
Tags additional.fields[].value.string_value ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ํƒœ๊ทธ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค. ํ‚ค๊ฐ€ 'ํƒœ๊ทธ'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
User target.user.userid event_name์ด SSPUserLoginAttemptFailed์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์‚ฌ์šฉ์ž ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
event_name metadata.product_event_type ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์ด๋ฒคํŠธ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
extensions.auth.type event_name์ด AdminUserLoggedIn, SSPUserLoginAttemptFailed, AdminUserLoggedOut, AuthTokenIssued, AuthTokenRevoked ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'SSO'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
is_alert event_name์ด ComplianceStatusChanged, DeviceProfileTypeBlocked, ComplianceActionTaken ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'true'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
is_significant event_name์ด ComplianceStatusChanged์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'true'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
is_significant event_name์ด DeviceProfileTypeBlocked์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'false'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด SecureChannelCheckIn์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'GENERIC_EVENT'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด ApplicationGroupCreated์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'GROUP_CREATION'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด SmartGroupsDeleted์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'GROUP_DELETION'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด SmartGroupsModified, ApplicationGroupAssignmentModified ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'GROUP_MODIFICATION'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_data ํ•„๋“œ์— 'session'์ด ํฌํ•จ๋˜๊ณ  hash_value ํ•„๋“œ๊ฐ€ 'org'๋กœ ๋๋‚˜๋ฉด ๊ฐ’์€ 'NETWORK_CONNECTION'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type principal_hostname ๋˜๋Š” src_ip ํ•„๋“œ๊ฐ€ ๋น„์–ด ์žˆ์ง€ ์•Š๊ณ  target_hostname ๋˜๋Š” target_ip ํ•„๋“œ๊ฐ€ ๋น„์–ด ์žˆ์ง€ ์•Š์œผ๋ฉด ๊ฐ’์ด 'NETWORK_CONNECTION'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด Revoked์ด๊ณ  event_data ํ•„๋“œ์— 'Certificate'๊ฐ€ ํฌํ•จ๋˜์ง€ ์•Š์€ ๊ฒฝ์šฐ ๊ฐ’์€ 'SETTING_DELETION'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด DeviceAttributeDeviceMCCModified, DeviceAttributePhoneNumberModified, ComplianceStatusChanged, DeviceProfileTypeBlocked, DeviceProfileTypeUnblocked ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'SETTING_MODIFICATION'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด AppListSampleRefused, CertificateListSampleRefused, DeviceInformationRefused, ProfileListRefused, SecurityInformation, StartACMRequested, AvailableOSUpdatesList, AvailableOsUpdatesConfirmed, AvailableOsUpdatesRequested ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'STATUS_UNCATEGORIZED'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด BreakMDMRequested, CertificateIssued, CompromisedStatusChanged, SecureChannelCheckIn, EditDevice ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'STATUS_UPDATE'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด AdminUserLoggedOut, AuthTokenIssued, AuthTokenRevoked ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'USER_LOGOUT'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด AdminUserLoggedIn, SSPUserLoginAttemptFailed ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'USER_LOGIN'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type request_url ํ•„๋“œ๊ฐ€ ๋น„์–ด ์žˆ์ง€ ์•Š์œผ๋ฉด ๊ฐ’์ด 'USER_RESOURCE_ACCESS'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด AppCatalogLaunch์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'USER_RESOURCE_ACCESS'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด ApplicationDownload, EnrollmentComplete, InstallApplicationConfirmed, InstallProfileConfirmed ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'USER_RESOURCE_CREATION'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด BreakMDMConfirmed, RemoveProfileConfirmed ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'USER_RESOURCE_DELETION'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด ProfileModified, ProfilePublished, ProfileSetToInactive, ProfileVersionAdded, RestrictionPayloadModified, DeviceOperatingSystemChanged ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'USER_RESOURCE_UPDATE_CONTENT'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด EULAAccepted์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'USER_RESOURCE_UPDATE_PERMISSIONS'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.event_type event_name์ด Revoked, ComplianceNotificationSent, DeleteDeviceRequested, DeviceClearPasscodeRequested, DeviceWipeRequested, InstallApplicationRequested, ApplicationInstallOnDeviceRequested, RemoveApplicationRequested, SendMessageRequested, AddMissingUserCompletedEvent, AddMissingUserFailureEvent, ApplicationAdded, ApplicationDeleted, ApplicationRemoveFromDeviceRequested, ApplicationModified, ApplicationPublished, ApplicationPublishFailed, ApplicationPublishStarted, ApplicationVersionAdded, SyncGroupCompletedEvent, SyncGroupFailureEvent, SearchMissingUserCompleteEvent, SyncAdminFailure, SyncUserCompletedEvent, SyncUserFailureEvent, UserDeleted, HealthAttestationCertificateRequestConfirmed, WindowsDeviceCheckInMode, SampleResponseListReceived, HealthAttestationCertificateRequested, WindowsInformationConfirmed, RemoteManagement, HealthAttestationServerToServerSyncReqConfirmed, ScepThumbprintSampleConfirmed, HealthAttestationSampleRequestConfirmed, HealthAttestationServerToServerSyncRequested, HealthAttestationServerToServerSyncRequestFailed, WipeRequest, InstallApplicationFailed, OwnershipChanged, WipeConfirmed, FreshDeviceCreatedInDeviceState, UserSetToInactive, ExistingDeviceUpdatedInDeviceState, HealthAttestationCertificateRequestFailed, AppleOsXmdmDeviceTokenUpdate, DeviceUnenrolled, ScheduleOsUpdateResults, UserRoleAssignmentModified, UserModified, AppleTokenUpdateComplete, UserEnrollmentTokenCreated, ScheduleOsUpdatesConfirmed, OsUpdateStatusRequested, InstallProfileConfirmed, TagAssignmentChanged ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'USER_UNCATEGORIZED'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.log_type ๊ฐ’์€ 'AIRWATCH'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.product_name ๊ฐ’์€ 'AirWatch'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
metadata.vendor_name ๊ฐ’์€ 'VMWare'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
network.application_protocol application_protocol ํ•„๋“œ์— 'HTTP'๊ฐ€ ํฌํ•จ๋œ ๊ฒฝ์šฐ ๊ฐ’์€ 'HTTP'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
network.http.method ์ด ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ method_url ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
network.http.referral_url ์ด ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ referral_url ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
network.http.response_code ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ http_status ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
network.http.user_agent ์ด ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ user_agent ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
network.ip_protocol ํ”„๋กœํ† ์ฝœ ํ•„๋“œ๊ฐ€ 'TCP'์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'TCP'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
network.ip_protocol ํ”„๋กœํ† ์ฝœ ํ•„๋“œ๊ฐ€ 'UDP'์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'UDP'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
principal.administrative_domain event_name์ด SmartGroupsDeleted, SmartGroupsModified, ProfileModified, ProfilePublished, ProfileSetToInactive, DeleteDeviceRequested, DeviceEnterpriseWipeRequested, InstallProfileRequested, RemoveProfileRequested, FindDeviceRequested, InstallApplicationRequested, ApplicationInstallOnDeviceRequested, RemoveApplicationRequested, SendMessageRequested, ApplicationAdded, ApplicationDeleted, ApplicationRemoveFromDeviceRequested, ApplicationModified, ApplicationPublished, ApplicationPublishFailed, ApplicationPublishStarted, ApplicationVersionAdded, UserDeleted ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ๋„๋ฉ”์ธ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
principal.hostname ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
principal.ip event_name์ด AuthTokenIssued, AuthTokenRevoked, BreakMDMRequested, ComplianceNotificationSent, DeleteDeviceRequested, Revoked, ComplianceStatusChanged, CompliancePolicyModified, ProfileModified, ProfilePublished, ProfileSetToInactive, SmartGroupsDeleted, ApplicationDownload, EnrollmentComplete, EULAAccepted, StartACMRequested, DeviceEnterpriseWipeRequested, InstallApplicationRequested, InstallProfileRequested, RemoveProfileRequested, ApplicationInstallOnDeviceRequested, FindDeviceRequested, RemoveApplicationRequested, SendMessageRequested, AvailableOsUpdatesRequested, DeviceProfileTypeBlocked, DeviceProfileTypeUnblocked, AddMissingUserCompletedEvent, AddMissingUserFailureEvent, ApplicationAdded, ApplicationDeleted, ApplicationGroupAssignmentModified, ApplicationGroupCreated, ApplicationRemoveFromDeviceRequested, ApplicationModified, ApplicationPublished, ApplicationPublishFailed, ApplicationPublishStarted, ApplicationVersionAdded, DeviceWipeRequested, ProfileVersionAdded, RestrictionPayloadModified, SmartGroupsModified, SyncGroupCompletedEvent, SyncGroupFailureEvent, SearchMissingUserCompleteEvent, SyncAdminFailure, SyncUserCompletedEvent, SyncUserFailureEvent, UserDeleted, HealthAttestationCertificateRequestConfirmed, WindowsDeviceCheckInMode, SampleResponseListReceived, HealthAttestationCertificateRequested, WindowsInformationConfirmed, RemoteManagement, HealthAttestationServerToServerSyncReqConfirmed, ScepThumbprintSampleConfirmed, HealthAttestationSampleRequestConfirmed, HealthAttestationServerToServerSyncRequested, HealthAttestationServerToServerSyncRequestFailed, WipeRequest, InstallApplicationFailed, OwnershipChanged, WipeConfirmed, FreshDeviceCreatedInDeviceState, UserSetToInactive, ExistingDeviceUpdatedInDeviceState, HealthAttestationCertificateRequestFailed, AppleOsXmdmDeviceTokenUpdate, DeviceUnenrolled, ScheduleOsUpdateResults, UserRoleAssignmentModified, UserModified, ComplianceActionTaken, AppleTokenUpdateComplete, UserEnrollmentTokenCreated, ScheduleOsUpdatesConfirmed, OsUpdateStatusRequested ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ์›์‹œ ๋กœ๊ทธ์˜ sys_ip ํ•„๋“œ์—์„œ ๊ฐ’์„ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
principal.process.pid ์ด ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ process_id ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
principal.user.group_identifiers event_name์ด AuthTokenIssued, AuthTokenRevoked ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ auth_group ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
principal.user.user_display_name ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ user_info ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
principal.user.userid ์ด ๊ฐ’์€ event_name์ด AuthTokenIssued, AuthTokenRevoked, BreakMDMRequested, ComplianceNotificationSent, DeleteDeviceRequested, Revoked, ComplianceStatusChanged, CompliancePolicyModified, ProfileModified, ProfilePublished, ProfileSetToInactive, SmartGroupsDeleted, ApplicationDownload, EnrollmentComplete, EULAAccepted, StartACMRequested, DeviceEnterpriseWipeRequested, InstallApplicationRequested, InstallProfileRequested, RemoveProfileRequested, ApplicationInstallOnDeviceRequested, FindDeviceRequested, RemoveApplicationRequested, SendMessageRequested, AvailableOsUpdatesRequested, DeviceProfileTypeBlocked, DeviceProfileTypeUnblocked, AddMissingUserCompletedEvent, AddMissingUserFailureEvent, ApplicationAdded, ApplicationDeleted, ApplicationGroupAssignmentModified, ApplicationGroupCreated, ApplicationRemoveFromDeviceRequested, ApplicationModified, ApplicationPublished, ApplicationPublishFailed, ApplicationPublishStarted, ApplicationVersionAdded, DeviceWipeRequested, ProfileVersionAdded, RestrictionPayloadModified, SmartGroupsModified, SyncGroupCompletedEvent, SyncGroupFailureEvent, SearchMissingUserCompleteEvent, SyncAdminFailure, SyncUserCompletedEvent, SyncUserFailureEvent, UserDeleted, HealthAttestationCertificateRequestConfirmed, WindowsDeviceCheckInMode, SampleResponseListReceived, HealthAttestationCertificateRequested, WindowsInformationConfirmed, RemoteManagement, HealthAttestationServerToServerSyncReqConfirmed, ScepThumbprintSampleConfirmed, HealthAttestationSampleRequestConfirmed, HealthAttestationServerToServerSyncRequested, HealthAttestationServerToServerSyncRequestFailed, WipeRequest, InstallApplicationFailed, OwnershipChanged, WipeConfirmed, FreshDeviceCreatedInDeviceState, UserSetToInactive, ExistingDeviceUpdatedInDeviceState, HealthAttestationCertificateRequestFailed, AppleOsXmdmDeviceTokenUpdate, DeviceUnenrolled, ScheduleOsUpdateResults, UserRoleAssignmentModified, UserModified, ComplianceActionTaken, AppleTokenUpdateComplete, UserEnrollmentTokenCreated, ScheduleOsUpdatesConfirmed, OsUpdateStatusRequested, EditDevice ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ์›์‹œ ๋กœ๊ทธ์˜ user_name ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
security_result.action event_name์ด DeviceProfileTypeUnblocked์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'ALLOW'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
security_result.action event_name์ด DeviceProfileTypeBlocked, SyncAdminFailure, SyncGroupFailureEvent, SyncUserFailureEvent ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'BLOCK'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
security_result.category event_name์ด SSPUserLoginAttemptFailed์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'AUTH_VIOLATION'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
security_result.category event_name์ด ComplianceStatusChanged, DeviceProfileTypeBlocked, DeviceProfileTypeUnblocked, ComplianceNotificationSent, CompromisedStatusChanged ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'POLICY_VIOLATION'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
security_result.category_details ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์ด๋ฒคํŠธ ์นดํ…Œ๊ณ ๋ฆฌ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
security_result.description ์„ค๋ช… ํ•„๋“œ์— IP ์ฃผ์†Œ๊ฐ€ ํฌํ•จ๋œ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ des ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
security_result.description ์„ค๋ช… ํ•„๋“œ์— IP ์ฃผ์†Œ๊ฐ€ ํฌํ•จ๋˜์ง€ ์•Š์€ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์„ค๋ช… ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
security_result.description event_name์ด SyncAdminFailure์ธ ๊ฒฝ์šฐ ๊ฐ’์€ '์˜ˆ๊ธฐ์น˜ ์•Š์€ ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ–ˆ์Šต๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ๋กœ๊ทธ๋ฅผ ํ™•์ธํ•˜์„ธ์š”'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
security_result.description event_name์ด MergeGroupCompletedEvent์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ GroupManagementData ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
security_result.summary ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์š”์•ฝ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.administrative_domain event_name์ด CompliancePolicyModified์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ๋„๋ฉ”์ธ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.application event_name์ด InstallApplicationRequested, ApplicationInstallOnDeviceRequested, RemoveApplicationRequested, ApplicationAdded, ApplicationDeleted, ApplicationRemoveFromDeviceRequested, ApplicationModified, ApplicationPublished, ApplicationPublishFailed, ApplicationPublishStarted, ApplicationVersionAdded, ApplicationDownload, InstallApplicationConfirmed ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ app_name ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.asset_id event_name์ด DeleteDeviceRequested์ด๊ณ  device_serial_number ๋ฐ device_udid ํ•„๋“œ๊ฐ€ ๋น„์–ด ์žˆ์ง€ ์•Š์œผ๋ฉด ๊ฐ’์€ 'device_serial_number:device_udid'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
target.group.group_display_name event_name์ด ApplicationGroupAssignmentModified, ApplicationGroupCreated ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ApplicationGroup ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.hostname event_name์ด DeviceLocationGroupChanged์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ๊ธฐ๊ธฐ ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.ip event_name์ด SSPUserLoginAttemptFailed์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ sys_ip ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.ip event_name์ด CompliancePolicyModified, CertificateIssued, CompromisedStatusChanged, AppListSampleRefused, CertificateListSampleRefused, DeviceInformationRefused, ProfileListRefused, SecurityInformation, SecureChannelCheckIn, SecurityInformationConfirmed, StartACMConfirmed, AdminUserLoggedIn, AdminUserLoggedOut, AvailableOSUpdatesList, AvailableOsUpdatesConfirmed ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ target_ip ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.port ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ target_port ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.resource.name event_name์ด Revoked, CompliancePolicyModified, ComplianceStatusChanged, DeviceProfileTypeBlocked, DeviceProfileTypeUnblocked ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'SETTING'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
target.resource.type event_name์ด ApplicationDownload์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'APP'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
target.resource.type event_name์ด EnrollmentComplete์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'DEVICE'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
target.resource.type event_name์ด EULAAccepted์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'EULA'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
target.resource.type event_name์ด DeviceOperatingSystemChanged์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'OS'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
target.resource.type event_name์ด InstallProfileConfirmed์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'PROFILE'๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
target.resource.type event_name์ด Revoked, CompliancePolicyModified, ComplianceStatusChanged, DeviceProfileTypeBlocked, DeviceProfileTypeUnblocked ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ 'SETTING'์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
target.url method_url ํ•„๋“œ๊ฐ€ ๋น„์–ด ์žˆ์ง€ ์•Š์œผ๋ฉด ๊ฐ’์ด ์›์‹œ ๋กœ๊ทธ์˜ target_url ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.user.group_identifiers event_name์ด AuthTokenIssued, AuthTokenRevoked ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ auth_group ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.user.userid event_name์ด AddMissingUserCompletedEvent, AddMissingUserFailureEvent ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ group_user ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.user.userid event_name์ด BreakMDMRequested, ComplianceNotificationSent, DeleteDeviceRequested, Revoked, ComplianceStatusChanged, ApplicationDownload, EnrollmentComplete, EULAAccepted, StartACMRequested, DeviceEnterpriseWipeRequested, InstallApplicationRequested, InstallProfileRequested, RemoveProfileRequested, ApplicationInstallOnDeviceRequested, FindDeviceRequested, RemoveApplicationRequested, SendMessageRequested, AuthTokenIssued, AuthTokenRevoked, InstallApplicationConfirmed, InstallProfileConfirmed, BreakMDMConfirmed, DeviceOperatingSystemChanged, RemoveProfileConfirmed, DeviceAttributeDeviceMCCModified, DeviceAttributePhoneNumberModified, AvailableOsUpdatesRequested, DeviceProfileTypeBlocked, DeviceProfileTypeUnblocked, ApplicationRemoveFromDeviceRequested, DeviceClearPasscodeRequested, DeviceWipeRequested ์ค‘ ํ•˜๋‚˜์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ enrollment_user ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
target.user.userid event_name์ด UserDeleted์ธ ๊ฒฝ์šฐ ๊ฐ’์€ ์›์‹œ ๋กœ๊ทธ์˜ ์‚ฌ์šฉ์ž ํ•„๋“œ์—์„œ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.

๋„์›€์ด ๋” ํ•„์š”ํ•˜์‹ ๊ฐ€์š”? ์ปค๋ฎค๋‹ˆํ‹ฐ ํšŒ์› ๋ฐ Google SecOps ์ „๋ฌธ๊ฐ€๋กœ๋ถ€ํ„ฐ ๋‹ต๋ณ€์„ ๋ฐ›์œผ์„ธ์š”.