For the complete documentation index, see llms.txt. This page is also available as Markdown.

Zeek 로그

Zeek 로그를 Panther Console에 연결

개요

Panther는 일반적인 방법을 통해 Zeek 로그 수집을 지원합니다 데이터 전송 옵션: Amazon Web Services(AWS) S3 및 SQS.

Zeek 로그를 Panther에 온보딩하는 방법

이 로그를 Panther로 가져오려면:

  1. Panther Console의 왼쪽 탐색 모음에서 로그 소스.

  2. 클릭합니다 새로 만들기.

  3. 온보딩하려는 로그 유형을 검색한 다음 해당 타일을 클릭합니다.

  4. 이 통합에 사용할 데이터 전송 방법을 선택한 다음, Panther의 해당 방법 구성 지침을 따르세요:

  5. Data Transport 소스로 로그를 푸시하도록 Zeek를 구성합니다.

    • 선택한 Data Transport 소스로 로그를 푸시하는 방법은 Zeek 문서를 참조하세요.

지원되는 로그 유형

Zeek.CaptureLoss

Zeek CaptureLoss 로그는 패킷 캡처 프로세스가 측정 손실을 겪는 정도에 관한 증거를 기록합니다.

참조: 캡처 손실

Zeek.Conn

참조: conn.log

Zeek.DHCP

참조: dhcp.log

Zeek.DNS

Zeek DNS 활동

참조: Zeek 문서 - DNS::info

Zeek.DPD

Zeek 동적 프로토콜 디택션.

참조: dpd.log

Zeek.Files

참조: files.log

Zeek.HTTP

참조: http.log

Zeek.KnownHosts

Zeek 알려진 호스트 - TCP 연결을 완료한 호스트를 추적합니다.

참조: known-hosts.log

Zeek.KnownServices

known-services 로그의 열 필드를 포함하는 레코드 유형입니다.

참조: known-services.log

Zeek.Notice

참조: notice.log

Zeek.NTP

참조: ntp.log

Zeek.OCSP

참조: ocsp.log

Zeek.Reporter

Zeek 내부 경고 및 오류.

참조: reporter.log

Zeek.SIP

이 스키마는 Zeek SIP 분석 로그를 나타냅니다.

참조: sip.log

Zeek.Software

참조: software.log

Zeek.SSH

참조: ssh.log

Zeek.SSL

참조: ssl.log

Zeek.Stats

참조: stats.log

Zeek.Telemetry

카운터 및 게이지 메트릭을 기록하는 데 사용되는 레코드 유형.

참조: telemetry.log

Zeek.Tunnel

Zeek의 tunnel.log의 목적은 캡슐화된 트래픽을 식별하는 것입니다.

참조: tunnel.log

Zeek.Weird

참조: weird.log

Zeek.X509

참조: x509.log

마지막 업데이트

도움이 되었나요?