> For the complete documentation index, see [llms.txt](https://docs.panther.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.panther.com/ko/data-onboarding/data-pipeline-tools/cribl.md).

# Cribl 온보딩 가이드

## 개요

이 가이드에 설명된 프로세스는 Cribl Cloud 또는 Cribl Self-Hosted를 사용하여 민감한 로그 데이터를 마스킹하는 방법을 설명하며, 특히 Amazon Web Services(AWS) S3 버킷과 Panther 내에서 작업합니다. 전반적으로 다음을 수행합니다:

* Cribl에서 S3 버킷을 인증하며, 수동 방식과 Event Breakers의 예시를 포함합니다.
* JSON 데이터 형식을 사용하여 AWS S3 소스와 대상을 구성합니다.
* 사전 및 사후 Cribl 마스크를 사용한 JSON 이벤트 예시를 제공합니다.

## Cribl로 민감한 필드를 마스킹하는 방법

### 1단계: Cribl에서 AWS S3 소스 구성

1. Cribl에 로그인합니다. 왼쪽 메뉴에서 **Groups**로 이동한 다음 페이지 상단에서 **Routing** 드롭다운을 클릭하고 **Quick Connect를 선택합니다.**\
   ![In Cribl, the groups icon on the left is highlighted. The Routing tab's dropdown menu is displayed, showing the options "Data Routes" and "QuickConnect."](/files/272bcfa39662559c74da53ff75b88f26b1d8d83b)
2. 다음을 클릭합니다 **Add Source**를 클릭한 다음 소스 목록에서 Amazon S3를 선택합니다.\
   ![The image shows a screen with the header "QuickConnect." The option "Unconnected" is selected. Beneath that, there is a button labeled "Add Source."](/files/08073dc23d2985a6d7a24aca4df67b5393eaab58)
3. 아래에서 **Configure > General Settings**에서 고유한 Input ID, SQS Queue의 ARN을 입력하고 필요에 따라 추가 필터를 지정합니다.\
   ![The image shows Cribl's Configure > General Settings page. It includes fields for Input ID, Queue, Filename Filter, Region, and Tags.](/files/45119c8d1e9d040f61e76baab0e225ccbef10dea)
4. 다음을 클릭합니다 **Authentication** 왼쪽에서 클릭하여 다음 인증 방법 중 하나를 선택합니다:
   * **Manual** - Access Key와 Secret Key가 필요합니다(AWS에서 Access Key와 Secret Key를 생성해야 합니다)
   * **시크릿** - Secret key pair(AWS에서 이 키 쌍을 생성해야 합니다)
   * **자동** - AWS Account ID와 Assume Role 섹션에서 구성할 ARN이 필요합니다. 이 역할은 S3 및/또는 SQS에 대한 접근 권한이 있어야 합니다.\
     ![The Configure section of Cribl is displayed. On the left sidebar, "Authentication" is highlighted. The Authentication Method is set to manual. There are fields for Access Key and Secret Key.](/files/bf491e0e809dab1c3af51be126231bfaa2c86c2a)\
     위의 예시 화면에서는 "Manual"이 선택되어 있습니다.
5. 다음을 클릭합니다 **Event Breakers** 왼쪽에서 Cribl 이벤트 브레이커를 선택합니다.
   * 참고: 이 단계는 Cribl이 들어오는 JSON 데이터를 파싱할 수 있게 합니다.

### 2단계: Cribl에서 AWS S3 대상 구성

1. QuickConnect 페이지로 다시 이동합니다.  **대상 추가** 를 클릭하고 Amazon S3를 선택합니다.\
   ![In QuickConnect under "Sources", Amazon S3 is chosen.](/files/8172dba7ec5150aa929de2a152cd0aefaa76b9bf)
2. General Settings 페이지에서 다음을 입력합니다:
   * **S3 버킷 이름.** AWS에서 이러한 S3 버킷은 동일할 수 있습니다. 필요한 경우 버킷 내 객체는 prefix 필터로 구분할 수 있습니다.
   * **버킷 리전**
   * **접두사** 출력되는 JSON 파일용
   * **파일 이름 접두사 표현식**\
     ![The General Settings page for the S3 source is displayed. It contains fields for Output ID, S3 Bucket Name, Region, Staging Location, Key Prefix, Partitioning Expression, Data Format, File Name Prefix Expression, File Name Suffix Expression, Compress, Backpressure behavior, and Tags.](/files/055612fb88273e36310068fb8f7a8977e6ceaf23)\\
3. 다음을 클릭합니다 **Authentication** 왼쪽에서 클릭하여 다음 인증 방법 중 하나를 선택합니다:
   * **Manual** - Access Key와 Secret Key가 필요합니다(AWS에서 Access Key와 Secret Key를 생성해야 합니다)
   * **시크릿** - Secret key pair(AWS에서 이 키 쌍을 생성해야 합니다)
   * **자동** - AWS Account ID와 Assume Role 섹션에서 구성할 ARN이 필요합니다. 이 역할은 S3 및/또는 SQS에 대한 접근 권한이 있어야 합니다.\
     ![The Configure section of Cribl is displayed. On the left sidebar, "Authentication" is highlighted. The Authentication Method is set to manual. There are fields for Access Key and Secret Key.](/files/3a5e0ebf194366de4f06bf195af739a7f5143c77)\
     위의 예시 화면에서는 "Manual"이 선택되어 있습니다.

### 3단계: Cribl에서 파이프라인 구성

1. 소스와 대상을 연결하는 점선 을 클릭합니다:\
   ![The sources page in Cribl is displayed. At the bottom of the screen, there is a popup dialog labeled "Connection Configuration." "Pipeline" is selected.](/files/9bbe5d769f5ecc0ebd0d5f304022d425cb0a8e9f)
   * Connection Configuration 대시보드로 리디렉션됩니다.
2. Connection Configuration 대시보드의 오른쪽 상단에서 **+ Pipeline.** 를 클릭합니다. 나타나는 드롭다운 메뉴에서 **Create Pipeline**.\
   ![In the Connection Configuration dashboard, in the upper right, the "Pipeline" dropdown menu is expanded.](/files/7738df6bde3739844b7fd333632d1006af083c66)
3. 나타나는 "Create New Pipeline" 팝업 대화상자에서 이름 `redacted` 를 **ID** 필드에 입력합니다. 필요에 따라 Async Function Timeout과 Description을 입력한 다음 **저장**.\
   ![The "Create New Pipeline" form is open. There are fields are ID, Async Function Timeout (ms), and Description.](/files/ad5f8b95c0a136a672874906e1df66698b822357)
4. Processing / Pipelines 페이지에서 파란색 기어 아이콘을 클릭합니다.\
   ![The "Processing / Pipelines" tab at the top is seleted. There is a red arrow pointing to a gear icon in the upper right.](/files/f6750248e4b54fe9289ec10b08055fd90d27eadb)
5. 오른쪽 상단 모서리에서 다음을 클릭하세요 **Edit as JSON**.\
   ![The "Processing / Pipelines" tab is selected at the top. In the upper right, there is an "Edit as JSON" link.](/files/68bf5af703fc7c78ac3193869e34fbe2a03027cc)
6. 아래의 JSON 블록을 붙여넣습니다. 아래 JSON 블록에는 두 개의 필터가 있습니다:

   * **Mask:** 의 모든 내용을 `이름` 필드에서 `REDACTED`
   * **로 대체합니다.** 다음 필드를 제거합니다 `_raw` `cribl_breaker` `crible_pipe` `_time`\\

   ```
   {
     "id": "redaction",
     "conf": {
       "asyncFuncTimeout": 1000,
       "functions": [
         {
           "filter": "true",
           "conf": {
             "rules": [
               {
                 "matchRegex": "/(.*)/i",
                 "replaceExpr": "`REDACTED`"
               }
             ],
             "fields": [
               "name"
             ],
             "depth": 5,
             "flags": []
           },
           "id": "mask",
           "description": "Masking Filter",
           "final": false
         },
         {
           "filter": "true",
           "conf": {
             "remove": [
               "_raw",
               "cribl_breaker",
               "cribl_pipe",
               "_time"
             ]
           },
           "id": "eval",
           "final": true
         }
       ],
       "description": "redaction-pipeline",
       "groups": {}
     }
   }
   ```
7. JSON을 저장합니다.

JSON이 저장되면 UI에 아래 스크린샷과 유사하게 마스킹 규칙이 반영됩니다:

<figure><img src="/files/9a0cb6ff0f6b2ff5b4d53a09b7dbeaa0f675749a" alt="The Processing / Pipelines page is open. Under &#x22;Masking Rules&#x22;, the Match Regex value is /(.*) and the Replace Expression value is &#x60;REDACTED&#x60;."><figcaption></figcaption></figure>

완성된 Data Route는 아래 스크린샷과 유사하게 표시됩니다:

<figure><img src="/files/baa72bcd935046c3dd0b5562d98f3a8036829278" alt="The image shows the QuickConnect screen. On the left under Sources, &#x22;S3, cribl-source-s3&#x22; is listed. There is a dotted line connecting it to &#x22;S3 cribl-destination&#x22; under the Destinations header."><figcaption></figcaption></figure>

## JSON 예시: Cribl 전후

다음 예시는 이 가이드의 이전 단계에서 언급한 `mask` 필터를 사용한 JSON 이벤트를 보여줍니다. mask 필터를 사용한 후 name 필드 `Bella` 는 `REDACTED.`

**Cribl 이전 마스크:**

```json
{ ... "name": "Bella", ...} 
```

**Cribl 이후 마스크:**

```json
{ ... "name":"REDACTED", ...}
```

구성 후 마스크 필터가 예상대로 작동하는지 반드시 확인하시기 바랍니다. 마스크 필터가 올바르게 작동하는 것이 확인되면, 마스킹된 로그를 Panther로 수집하세요 [S3 Data Transport를 사용하여](/ko/data-onboarding/data-transports/aws/s3.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.panther.com/ko/data-onboarding/data-pipeline-tools/cribl.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
