> For the complete documentation index, see [llms.txt](https://docs.panther.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.panther.com/ko/data-onboarding/supported-logs/atlassian.md).

# Atlassian 로그

## 개요

Panther는 다음을 쿼리하여 Atlassian 이벤트 로그를 가져올 수 있습니다. [Atlassian Organizations REST API](https://developer.atlassian.com/cloud/admin/organization/rest/intro/). Panther는 특히 다음 Atlassian 이벤트를 모니터링합니다:

* 설정 또는 기타 조직 페이지와 관련된 관리 작업
* 조직 관리자가 조직의 보안 정책과 관련하여 수행하는 작업

## Atlassian 로그를 Panther에 온보드하는 방법

Panther에서 Atlassian을 로그 소스로 설정하려면, Atlassian 계정에서 스코프가 없는 API 키를 생성하여 Atlassian에서 Panther를 승인한 다음 Panther에서 Atlassian을 로그 소스로 설정해야 합니다.

### 사전 요구 사항

* 귀하의 조직에는 Atlassian Guard Standard, Cloud Enterprise 또는 Atlassian Guard Premium 요금제가 있습니다.
  * Atlassian [감사 로그에는 어떤 활동이 포함되나요?](https://support.atlassian.com/security-and-access-policies/docs/accessing-audit-log-activities/) 문서에는 "Atlassian Guard Premium은 모든 앱의 로그에 대한 전체 액세스를 제공합니다. Cloud Enterprise 및 Atlassian Cloud Premium 요금제는 해당 요금제가 적용된 앱에 대해 특정한 로그 액세스를 부여합니다."라고 명시되어 있습니다.
  * [여기에서 Atlassian Guard에 대해 자세히 알아보세요](https://support.atlassian.com/security-and-access-policies/docs/understand-atlassian-guard/).
* 귀하의 Atlassian 사용자에게는 [조직 관리자 역할](https://support.atlassian.com/user-management/docs/give-users-admin-permissions/#Make-someone-an-organization-admin).

### 1단계: Atlassian에서 API 키 생성

{% hint style="info" %}
API 키를 반드시 생성하세요 [스코프 없이](https://support.atlassian.com/organization-administration/docs/manage-an-organization-with-the-admin-apis/) (스코프가 있는 키가 아니라). [감사 로그 이벤트 폴링 API 엔드포인트](https://developer.atlassian.com/cloud/admin/organization/rest/api-group-events/#api-v1-orgs-orgid-events-stream-get) Panther가 사용하는 이 엔드포인트는 스코프가 있는 API 키를 지원하지 않습니다.
{% endhint %}

1. 다음의 조직에서 [admin.atlassian.com](http://admin.atlassian.com/), 선택 **설정** > **API 키**.
2. 클릭합니다 **API 키 만들기**.
3. 설명적인 API 키 이름을 입력하세요.
   * 기본적으로 키는 생성 후 1주일 뒤에 만료됩니다. 만료일을 변경하려면 다음 아래에서 새 날짜를 선택하세요. **만료일**. 만료일을 연장할 수 있는 최대 기간은 생성일로부터 최대 1년입니다.
4. 클릭합니다 **생성** 를 눌러 API 키를 저장하세요.
5. 다음 값들을 복사하세요: **조직 ID** 및 **API 키**.
   * 2단계에서 조직에 액세스하려면 이 값들이 필요합니다.
   * Atlassian에서 다시 표시하지 않으므로 이 값들은 안전한 곳에 보관하세요.
6. 클릭합니다 **성공적으로 추론됨**. 새 키가 API 키 목록에 표시됩니다.

### 2단계: Panther에서 새 Atlassian 로그 소스 생성

1. Panther Console의 왼쪽 탐색 표시줄에서 다음을 클릭합니다: **로그 소스**.
2. 클릭합니다 **새로 만들기.**
3. 선택 **Atlassian** 사용 가능한 로그 소스 목록에서. 다음을 클릭합니다: **소스 설정 시작**.
4. 다음 화면에서 소스에 대한 설명적인 이름을 입력하세요. 예: `내 Atlassian 이벤트 로그.`
5. 클릭합니다 **설정.**
6. 다음 페이지에서 **자격 증명 설정** 페이지에서 양식을 작성하세요:
   * **조직**: 문서의 이전 단계에서 생성한 Atlassian 조직 ID를 입력하세요.
   * **API 키**: 문서의 이전 단계에서 생성한 Atlassian API 키를 입력하세요.
7. 클릭합니다 **설정**. 성공 화면으로 이동됩니다:\\

   <figure><img src="/files/e0820e5acb9452e294cfe3ba72060f0fbbfd3b32" alt="The success screen reads, &#x22;Everything looks good! Panther will now automatically pull &#x26; process logs from your account&#x22;" width="281"><figcaption></figcaption></figure>

   * 선택적으로 하나 이상의 [디택션 팩](https://docs.panther.com/detections/panther-managed/packs).
   * 다음 **이벤트가 처리되지 않으면 알러트를 발생시키기** 설정의 기본값은 **예**. 일정 시간이 지난 후 로그 소스에서 데이터 흐름이 멈추면 알러트를 받게 되므로 이 설정을 활성화한 상태로 두는 것을 권장합니다. 이 시간 범위는 구성 가능하며 기본값은 24시간입니다.\\

     <figure><img src="/files/7db146cd7acee3d0704a4a8b2157f230cfa22168" alt="The &#x22;Trigger an alert when no events are processed&#x22; toggle is set to YES. The &#x22;How long should Panther wait before it sends you an alert that no events have been processed&#x22; setting is set to 1 Day" width="320"><figcaption></figcaption></figure>

## 지원되는 로그 유형

### Atlassian.Audit

조직의 이벤트 감사 로그.

참조: [감사 로그 및 이벤트에 대한 Atlassian 문서.](https://developer.atlassian.com/cloud/admin/organization/rest/api-group-orgs/#api-orgs-orgid-events-get)

```yaml
schema: Atlassian.Audit
파서:
    네이티브:
        name: Atlassian.Audit
description: 조직의 이벤트 감사 로그.
referenceURL: https://developer.atlassian.com/cloud/admin/organization/rest/api-group-orgs/#api-orgs-orgid-events-get
필드:
    - 이름: type
      필수: true
      description: 이벤트 객체의 유형 이름
      유형: string
    - 이름: id
      필수: true
      description: 이벤트 객체의 고유 식별자
      유형: string
    - 이름: attributes
      필수: true
      description: 이벤트 객체의 속성
      유형: object
      필드:
        - name: time
          description: 이벤트의 날짜와 시간
          유형: string
          시간 형식: rfc3339
          이벤트 시간 여부: true
        - 이름: action
          description: 이벤트와 연결된 작업 유형입니다. 전체 목록은 event-actions API로 확인할 수 있습니다.
          유형: string
        - name: actor
          description: 이벤트와 연결된 행위자
          유형: object
          필드:
            - 이름: id
              description: 이벤트 행위자의 고유 식별자
              유형: string
            - 이름: name
              description: 이벤트를 수행한 행위자의 이름
              유형: string
              지표:
                - username
            - 이름: email
              description: 이벤트를 수행한 행위자의 이메일
              유형: string
              지표:
                - email
            - 이름: links
              description: 이벤트를 수행한 행위자의 프로필
              유형: object
              필드:
                - name: self
                  description: 이벤트의 self 링크
                  유형: string
                - name: alt
                  description: 이벤트의 alt 링크
                  유형: string
        - 이름: context
          description: 작업이 수행된 하나 이상의 엔터티
          유형: array
          요소:
            유형: object
            필드:
                - 이름: id
                  description: 이벤트 컨텍스트의 고유 식별자
                  유형: string
                - 이름: type
                  description: 이벤트 컨텍스트 유형
                  유형: string
                - 이름: attributes
                  description: 이벤트 컨텍스트 속성
                  유형: json
                - 이름: links
                  description: 이벤트 컨텍스트의 self 또는 alt 링크
                  유형: object
                  필드:
                    - name: self
                      description: 이벤트의 self 링크
                      유형: string
                    - name: alt
                      description: 이벤트의 alt 링크
                      유형: string
                  지표:
                    - url
        - name: container
          description: 이벤트와 연결된 컨테이너 목록
          유형: array
          요소:
            유형: object
            필드:
                - 이름: id
                  description: 이벤트 컨테이너의 고유 식별자
                  유형: string
                - 이름: type
                  description: 이벤트 컨테이너 객체의 유형 이름
                  유형: string
                - 이름: attributes
                  description: 이벤트 컨테이너 객체의 속성
                  유형: json
                - 이름: links
                  description: 이벤트 컨테이너 객체의 링크
                  유형: object
                  필드:
                    - name: self
                      description: 이벤트의 self 링크
                      유형: string
                    - name: alt
                      description: 이벤트의 alt 링크
                      유형: string
        - 이름: location
          description: 작업이 수행된 위치
          유형: object
          필드:
            - 이름: ip
              description: 행위자 위치의 IP 주소
              유형: string
              지표:
                - ip
            - 이름: geo
              description: IP 주소의 지리적 위치
              유형: string
            - name: countryName
              description: IP 주소에 따른 국가 위치
              유형: string
            - name: regionName
              description: IP 주소에 따른 지역 위치
              유형: string
            - 이름: city
              description: IP 주소에 따른 도시 위치
              유형: string
    - 이름: message
      description: 이벤트 객체와 연결된 메시지
      유형: object
      필드:
        - 이름: content
          description: 이벤트와 연결된 메시지 내용
          유형: string
        - 이름: format
          description: 이벤트의 메시지 형식
          유형: string
    - name: relations
      description: 이벤트 객체와 연결된 관계
      유형: json
    - 이름: links
      필수: true
      description: 이 리소스를 가져오는 URL
      유형: object
      필드:
        - name: self
          description: 이벤트의 self 링크
          유형: string
        - name: alt
          description: 이벤트의 alt 링크
          유형: string
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.panther.com/ko/data-onboarding/supported-logs/atlassian.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
