> For the complete documentation index, see [llms.txt](https://docs.panther.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.panther.com/ko/data-onboarding/supported-logs/zscaler/zpa.md).

# Zscaler ZPA

## 개요

Panther는 수집을 지원합니다 [Zscaler](https://www.zscaler.com/) HTTP 또는 AWS S3 Data Transport 소스를 사용하여 Private Access (ZPA) 로그를 수집합니다. 다음 ZPA 로그 유형을 지원합니다:

* [감사 로그](https://help.zscaler.com/zpa/about-audit-log-fields)
* [사용자 활동](https://help.zscaler.com/zpa/about-user-activity-log-fields)
* [사용자 상태](https://help.zscaler.com/zpa/about-user-status-log-fields)
* [App Connector 상태](https://help.zscaler.com/zpa/about-connector-status-log-fields)
* [App Connector 메트릭](https://help.zscaler.com/zpa/about-app-connector-metrics-log-fields)

{% hint style="warning" %}
Panther에서 Zscaler ZPA 로그를 온보딩하려면 Zscaler ZPA 구독이 있어야 합니다.
{% endhint %}

## Zscaler ZPA 로그를 Panther에 온보딩하는 방법

Panther에서 ZPA 로그를 수집하려면 Panther에 로그 소스를 만든 다음 App Connector와 Log Receiver를 구성합니다.

### 사전 요구 사항

* Zscaler ZPA 콘솔에 액세스할 권한이 있어야 합니다.

### 1단계: Panther에서 Zscaler ZPA 소스 설정

1. Panther Console의 왼쪽 탐색 모음에서 **로그 소스**.
2. 오른쪽 상단에서 클릭합니다 **새로 만들기.**
3. "Zscaler ZPA"를 검색한 다음 해당 타일을 클릭합니다.
4. 다음 **전송 메커니즘** 슬라이드아웃 패널의 드롭다운에서 다음을 선택합니다 [데이터 전송](/ko/data-onboarding/data-transports.md) 이 통합에 사용할 방법: **AWS S3 버킷** 또는 **HTTP**.
   * 이 선택은 로그를 전달하도록 Log Receiver를 구성하는 방식에 따라 달라집니다( [3단계](#step-3-configure-one-or-more-log-receivers))—Panther HTTP 엔드포인트로 전달하거나, Panther가 나중에 가져오는 환경의 S3 버킷으로 전달할 수 있습니다.

     <figure><img src="/files/184a3206be5e2d3e31f306b9eb91d58fe1260483" alt="An arrow is drawn from a tile labeled &#x22;Zscaler ZPA&#x22; to a dropdown field called &#x22;Transport Mechanism&#x22; with an &#x22;AWS S3 Bucket&#x22; value populated. In the right-hand corner is a Start Setup button." width="375"><figcaption></figcaption></figure>
5. 클릭합니다 **설정 시작**.
6. 선택한 Data Transport 방법을 구성하려면 Panther의 지침을 따르세요:
   * **HTTP**: Panther의 [HTTP 소스 구성 지침을 따르세요](https://docs.panther.com/data-onboarding/data-transports/http#how-to-set-up-an-http-log-source-in-panther), 5단계부터 시작합니다.
     * 설정 중 보안 구성 페이지에서, [공유 비밀](/ko/data-onboarding/data-transports/http.md#shared-secret) 단순성 때문에 권장됩니다.
     * 이 소스로 전송되는 페이로드는 [모든 HTTP 소스의 페이로드 요구사항](https://docs.panther.com/data-onboarding/data-transports/http#payload-requirements).
     * HTTP 엔드포인트 생성이 완료될 때까지 다음 단계로 진행하지 마세요.
   * **S3**: 다음을 따르세요 [Panther에서 S3 Source를 구성하는 지침](/ko/data-onboarding/data-transports/aws/s3.md).
     * 다음을 따르세요. [Panther에서 S3 소스를 설정하는 지침](https://docs.panther.com/data-onboarding/data-transports/aws/s3#how-set-up-an-aws-s3-bucket-log-source-in-panther), 1.5단계부터 시작합니다.

### 2단계: ZPA에서 App Connector를 생성하고 배포

{% hint style="info" %}
이미 기존 Zscaler 인프라의 일부로 App Connector를 배포했다면 이를 사용하여 Panther로 로그를 전달할 수도 있습니다. 이 경우 이 단계는 건너뛸 수 있습니다.
{% endhint %}

생성 및 배포하려면 [App Connector](https://help.zscaler.com/zpa/about-connectors):

1. Zscaler [App Connector 구성](https://help.zscaler.com/zpa/configuring-connectors) 문서.
2. 다음에 App Connector를 배포하세요 [지원되는 플랫폼](https://help.zscaler.com/zpa/about-connectors#platforms) 다음의 관련 가이드를 따라 원하는 플랫폼에 [지원되는 플랫폼용 App Connector 배포 가이드](https://help.zscaler.com/zpa/app-connector-management/app-connector-deployment-guides-supported-platforms).
   * 배포에 대해 자세히 알아보려면 [App Connector 배포 정보](https://help.zscaler.com/zpa/about-deploying-connectors).

ZPA 콘솔에서 다음으로 이동하여 App Connector 인스턴스의 상태를 모니터링할 수 있습니다 **Configuration & Control** > **Private Infrastructure** > **App Connectors**.

<div align="center"><figure><img src="/files/3df278ca75ed7617e80707a00120a55880d69d46" alt="An &#x22;App Connectors&#x22; tab is shown. A table with various columns is visible, e.g., Name, Manager Version, Current Software Version." width="375"><figcaption></figcaption></figure></div>

### 3단계: 하나 이상의 Log Receiver 구성

Log Receiver는 App Connector에서 ZPA 로그가 포함된 TCP 트래픽을 수신한 다음 Panther의 HTTP 또는 S3 로그 소스로 전달할 수 있는 모든 저장 위치입니다.

Log Receiver로 Fluent Bit를 사용하는 것이 권장되지만, 필요에 따라 다른 Log Receiver를 사용할 수 있습니다. 아래 지침은 Fluent Bit를 사용한다고 가정합니다.

#### 3.1단계: Fluent Bit 서비스 배포

{% tabs %}
{% tab title="HTTP 소스" %}
Data Transport로 HTTP를 사용하는 경우:

* 다음을 따르세요. [Fluent Bit 온보딩 가이드](/ko/data-onboarding/data-pipeline-tools/fluent-bit-onboarding-guide.md) Panther 문서에서 1단계와 2단계를 건너뜁니다. (이미 생성한 ZPA HTTP 소스를 사용합니다.)
  * 다음 `[INPUT]` 변수:

    * **이름:** 이를 다음으로 설정하세요 `tcp`
    * **Listen:** 다음으로 설정 `0.0.0.0`
    * **Tag:** 다음으로 설정 `tcp_log`
    * **Port:** 원하는 포트로 설정하세요
    * **Format**: 다음으로 설정 `none`

    다음 항목을 추가하여 TCP 입력에 대해 TLS를 선택적으로 활성화할 수 있습니다 `[INPUT]` 변수:

    * **tls:** `에서`
    * **tls.verify:** `에서`
    * **tls.key\_file:** `{tls_key_path}`
    * **tls.cert\_file:** `{certificate_path}`

완성된 구성 파일은 다음과 비슷해야 합니다 [Fluent Bit Configuration Examples의 Panther HTTP 소스 예제](/ko/data-onboarding/data-pipeline-tools/fluent-bit-onboarding-guide/fluent-bit-configuration-examples.md#dummy-to-a-panther-http-source).
{% endtab %}

{% tab title="S3 소스" %}
Data Transport로 S3를 사용하는 경우:

* 다음을 따르세요. [Fluent Bit 온보딩 가이드](/ko/data-onboarding/data-pipeline-tools/fluent-bit-onboarding-guide.md) Panther 문서에서.
  * 다음을 사용하세요 [Fluent Bit Configuration Examples의 TCP to Amazon S3 예제](/ko/data-onboarding/data-pipeline-tools/fluent-bit-onboarding-guide/fluent-bit-configuration-examples.md#tcp-to-amazon-s3) 를 참고하세요.
  * 다음 항목을 추가하여 TCP 입력 간에 TLS를 선택적으로 활성화할 수 있습니다 `[INPUT]` 변수:
    * **tls:** `에서`
    * **tls.verify:** `에서`
    * **tls.key\_file:** `{tls_key_path}`
    * **tls.cert\_file:** `{certificate_path}`
      {% endtab %}
      {% endtabs %}

#### 3.2단계: ZPA에서 하나 이상의 Log Receiver 구성

{% hint style="info" %}
Panther로 전달하려는 각 로그 유형마다 별도의 Log Receiver를 만들어야 합니다. (이 모든 로그 유형에 대해 Panther에서 동일한 Fluent Bit 인스턴스와 로그 소스 \[HTTP 엔드포인트 또는 S3 버킷]를 사용할 수 있습니다.)
{% endhint %}

* Panther에서 수집하려는 각 로그 유형에 대해 Zscaler의 지침을 따라 Log Receiver를 추가하세요 [Log Receiver 구성](https://help.zscaler.com/zpa/configuring-log-receiver) 문서를 참고하세요. 다음 입력 지침에 유의하세요:

  * 다음 페이지에서 **Log Receiver** 탭:
    * **도메인 또는 IP 주소**: Fluent Bit 서비스의 도메인 또는 IP를 입력하세요.
    * **TCP 포트**: Fluent Bit 서비스가 실행 중인 포트를 입력하세요.
    * **TLS 암호화:** 선택 **활성화됨** Fluent Bit 입력으로 전송되는 데이터에 TLS 암호화가 필요하고, 이전 단계의 Fluent Bit 구성 파일에서 이를 활성화한 경우.

  <figure><img src="/files/b1d7a56c5f7081c1f874867e1d5bc242f697854e" alt="An &#x22;Add Log Receiver&#x22; pop-up modal is shown. It contains various form fields, such as &#x22;Name,&#x22; &#x22;Description,&#x22; and &#x22;Domain or IP Address.&#x22;" width="375"><figcaption></figcaption></figure>

  * 다음 페이지에서 **로그 스트림** 탭:
    * **로그 유형**: 다음 중 하나를 선택하세요 [Panther가 지원하는 로그 유형](#supported-log-types).
    * **로그 템플릿**: 선택 **JSON**.

## 지원되는 로그 유형

### Zscaler.ZPA.AuditLog

Audit log는 로그인, 로그아웃, 리소스 작업(생성 및 업데이트 등)과 같은 ZPA 콘솔의 주요 이벤트를 기록합니다. Audit log는 주로 잠재적으로 의심스러운 활동을 조사하거나 오류를 진단 및 문제 해결하는 데 사용됩니다.

참고:

* [Audit Logs에 대한 일반 정보](https://help.zscaler.com/zpa/about-audit-logs)
* [Admin Audit logs 형식](https://help.zscaler.com/zpa/about-audit-log-fields)

```yaml
schema: Zscaler.ZPA.AuditLog
description: Zscaler ZPA Audit Log
referenceURL: https://help.zscaler.com/zpa/about-audit-log-fields
필드:
  - name: ModifiedTime
    description: 객체가 마지막으로 수정된 시간.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: CreationTime
    필수: true
    description: 로그가 생성된 시간.
    유형: timestamp
    시간 형식:
      - rfc3339
    이벤트 시간 여부: true
  - name: ModifiedBy
    필수: true
    description: 객체를 수정한 사용자의 ID.
    유형: string
  - name: RequestID
    description: 요청과 연결된 고유 ID.
    유형: string
  - name: SessionID
    description: 사용자 세션의 ID.
    유형: string
  - name: AuditOldValue
    description: 변경 전의 이전 값.
    유형: json
  - name: AuditNewValue
    description: 변경 후의 새 값.
    유형: json
  - name: AuditOperationType
    필수: true
    설명: 수행된 작업.
    유형: string
  - name: ObjectType
    description: 작업이 수행된 ZPA Admin Portal 내 위치.
    유형: string
  - name: ObjectName
    description: 영향을 받는 객체의 이름.
    유형: string
  - name: ObjectID
    description: 영향을 받은 객체의 ID.
    유형: string
  - name: CustomerID
    description: 고객의 ZPA tenant ID.
    유형: string
  - 이름: User
    description: 감사 작업과 연결된 관리자 이름.
    유형: string
    지표:
      - email
      - username
      - actor_id
  - name: ClientAuditUpdate
    description: 클라이언트 감사가 업데이트되었는지 나타냅니다. 값은 0 또는 1입니다.
    유형: bigint
    
```

### Zscaler.ZPA.UserActivity

User Activity log는 사용자가 ZPA 서비스를 통해 내부 애플리케이션에 액세스할 때 수행한 다양한 활동을 캡처하고 기록합니다. User Activity log는 무단 액세스 시도를 조사하고, 규정 준수 모니터링을 수행하며, 비정상적인 애플리케이션 액세스 패턴을 식별하는 데 사용할 수 있습니다.

참조: [User Activity 로그 형식](https://help.zscaler.com/zpa/about-user-activity-log-fields)

```yaml
schema: Zscaler.ZPA.UserActivity
description: Zscaler ZPA User Activity log
referenceURL: https://help.zscaler.com/zpa/about-user-activity-log-fields
필드:
  - name: LogTimestamp
    필수: true
    description: 로그가 생성된 타임스탬프.
    유형: timestamp
    시간 형식:
      - '%a %b %e %H:%M:%S %Y'
    이벤트 시간 여부: true
  - name: Customer
    필수: true
    description: 고객 이름.
    유형: string
  - name: SessionID
    description: TLS 세션 ID.
    유형: string
  - name: ConnectionID
    description: 애플리케이션 연결 ID.
    유형: string
  - name: InternalReason
    필수: true
    description: 트랜잭션 상태의 내부 사유.
    유형: string
  - name: ConnectionStatus
    description: '연결 상태입니다. 이 필드의 예상 값은 Open, Close, Active입니다.'
    유형: string
  - name: IPProtocol
    description: IP 프로토콜 번호.
    유형: bigint
  - name: DoubleEncryption
    description: 이중 암호화 상태.
    유형: bigint
  - name: Username
    필수: true
    description: Zscaler Client Connector에 입력된 사용자 이름.
    유형: string
    지표:
      - username
  - name: ServicePort
    description: 애플리케이션 요청과 연결된 서비스 포트.
    유형: bigint
  - name: ClientPublicIP
    description: Zscaler Client Connector의 공용 IP 주소.
    유형: string
    지표:
      - ip
  - name: ClientPrivateIP
    description: Zscaler Client Connector의 개인 IP 주소.
    유형: string
    지표:
      - ip
  - name: ClientLatitude
    description: Zscaler Client Connector 위치의 위도 좌표.
    유형: float
  - name: ClientLongitude
    description: Zscaler Client Connector 위치의 경도 좌표.
    유형: float
  - name: ClientCountryCode
    description: Zscaler Client Connector 위치의 국가 코드.
    유형: string
  - name: ClientZEN
    description: Zscaler Client Connector에서 요청을 수신한 ZPA Public Service Edge.
    유형: string
  - name: Policy
    description: 액세스 정책 룰 이름.
    유형: string
  - name: Connector
    description: App Connector 이름.
    유형: string
  - name: ConnectorZEN
    description: App Connector에서 요청을 보낸 ZPA Public Service Edge.
    유형: string
  - name: ConnectorIP
    description: App Connector의 소스 IP 주소.
    유형: string
    지표:
      - ip
  - name: ConnectorPort
    description: 커넥터에서 사용한 포트 번호.
    유형: bigint
  - name: Host
    description: 호스트 도메인 또는 IP 주소.
    유형: string
    지표:
      - 호스트 이름
  - 이름: Application
    description: 애플리케이션 이름.
    유형: string
  - name: AppGroup
    description: 애플리케이션 그룹 이름.
    유형: string
  - name: Server
    description: 서버 ID 이름. 동적 서버 검색이 활성화된 경우 서버 ID는 0으로 설정됩니다.
    유형: string
  - name: ServerIP
    description: 서버의 대상 IP 주소.
    유형: string
    지표:
      - ip
  - name: ServerPort
    description: 서버의 대상 포트.
    유형: bigint
  - name: PolicyProcessingTime
    description: 애플리케이션과 연결된 액세스 정책을 처리하는 데 걸린 시간(마이크로초).
    유형: bigint
  - name: ServerSetupTime
    description: 서버에서 연결을 설정하는 데 걸린 시간(마이크로초).
    유형: bigint
  - name: TimestampConnectionStart
    description: ZPA Public Service Edge 또는 ZPA Private Service Edge가 Zscaler Client Connector로부터 연결 시작을 위한 초기 요청을 수신한 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampConnectionEnd
    description: ZPA Public Service Edge 또는 ZPA Private Service Edge가 연결을 종료한 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampCATx
    description: 중앙 기관이 ZPA Public Service Edge 또는 ZPA Private Service Edge로 요청을 보낸 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampCARx
    description: 중앙 기관이 ZPA Public Service Edge 또는 ZPA Private Service Edge로부터 요청을 수신한 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampAppLearnStart
    description: ZPA 서비스가 애플리케이션을 학습하는 프로세스를 시작한 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampZENFirstRxClient
    description: ZPA Public Service Edge가 Zscaler Client Connector로부터 첫 번째 바이트를 수신한 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampZENFirstTxClient
    description: ZPA Public Service Edge가 Zscaler Client Connector로 첫 번째 바이트를 보낸 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampZENLastRxClient
    description: ZPA Public Service Edge가 Zscaler Client Connector로부터 마지막 바이트를 수신한 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampZENLastTxClient
    description: ZPA Public Service Edge가 Zscaler Client Connector로 마지막 바이트를 보낸 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampConnectorZENSetupComplete
    description: ZPA Public Service Edge가 App Connector로부터 데이터 연결 설정 요청을 수신한 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampZENFirstRxConnector
    description: ZPA Public Service Edge가 App Connector로부터 첫 번째 바이트를 수신한 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampZENFirstTxConnector
    description: ZPA Public Service Edge가 App Connector로 첫 번째 바이트를 보낸 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampZENLastRxConnector
    description: 커넥터로부터 마지막으로 수신한 패킷의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampZENLastTxConnector
    description: ZPA Public Service Edge가 App Connector로 마지막 바이트를 보낸 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: ZENTotalBytesRxClient
    description: ZPA Public Service Edge가 Zscaler Client Connector로부터 수신한 총 바이트 수.
    유형: bigint
  - name: ZENBytesRxClient
    description: 세션 동안 클라이언트로부터 수신한 바이트 수.
    유형: bigint
  - name: ZENTotalBytesTxClient
    description: ZPA Public Service Edge가 Zscaler Client Connector로 전송한 총 바이트 수.
    유형: bigint
  - name: ZENBytesTxClient
    description: 마지막 트랜잭션 로그 이후 Zscaler Client Connector로 전송된 추가 바이트 수.
    유형: bigint
  - name: ZENTotalBytesRxConnector
    description: 커넥터로부터 수신한 총 바이트 수.
    유형: bigint
  - name: ZENBytesRxConnector
    description: ZPA Public Service Edge가 App Connector로부터 수신한 총 바이트 수.
    유형: bigint
  - name: ZENTotalBytesTxConnector
    description: ZPA Public Service Edge가 App Connector로 전송한 총 바이트 수.
    유형: bigint
  - name: ZENBytesTxConnector
    description: 마지막 트랜잭션 로그 이후 App Connector가 전송한 추가 바이트 수.
    유형: bigint
  - name: Idp
    description: ZPA Admin Portal에 구성된 ID 공급자(IdP)의 이름.
    유형: string
  - name: ClientToClient
    description: 클라이언트-대-클라이언트 연결의 상태.
    유형: string
  - name: ClientCity
    description: 클라이언트의 도시.
    유형: string
  - name: MicroTenantID
    description: 애플리케이션에 액세스하는 사용자의 Microtenant ID.
    유형: string
  - name: AppMicroTenantID
    description: 애플리케이션의 Microtenant ID.
    유형: string
  - name: CAProcessingTime
    description: 중앙 기관이 연결을 처리하는 데 걸린 시간(마이크로초).
    유형: bigint
  - name: ConnectorZENSetupTime
    description: App Connector와 ZPA Public Service Edge 간 연결을 설정하는 데 걸린 시간(마이크로초).
    유형: bigint
  - name: ConnectionSetupTime
    description: 전체 연결을 설정하는 데 걸린 시간(마이크로초).
    유형: bigint
  - name: AppLearnTime
    description: ZPA가 애플리케이션을 학습하는 데 걸린 시간(마이크로초).
    유형: bigint
  - name: Platform
    description: 클라이언트 장치의 플랫폼(예: Windows, Mac, Linux).
    유형: string
  - name: Hostname
    description: 클라이언트 장치의 호스트 이름.
    유형: string
    지표:
      - 호스트 이름
  - name: PRAApprovalID
    description: 권한 있는 원격 액세스 승인 ID.
    유형: string
  - name: PRACapabilityPolicyID
    description: PRA 기능 정책의 ID.
    유형: string
  - name: PRAConsoleType
    description: PRA 콘솔 유형(예: SSH, RDP).
    유형: string
  - name: PRACredentialUserName
    description: 사용된 PRA 자격 증명의 사용자 이름.
    유형: string
    지표:
      - username
  - name: PRACredentialLoginType
    description: PRA 자격 증명의 로그인 유형(예: 사용자 이름-비밀번호).
    유형: string
  - name: PRACredentialPolicyID
    description: PRA 자격 증명 정책의 ID.
    유형: string
  - name: PRAConnectionID
    description: PRA 연결의 ID.
    유형: string
  - name: PRAErrorStatus
    description: PRA 세션의 오류 상태.
    유형: string
  - name: PRAFileTransferList
    description: PRA 세션 중 수행된 파일 전송 목록(JSON 인코딩).
    유형: string
  - name: PRARecordingStatus
    description: PRA 세션의 녹화 상태.
    유형: string
  - name: PRASharedUserList
    description: PRA 세션을 공유하는 사용자 목록(JSON 인코딩).
    유형: string
  - name: PRASessionType
    description: PRA 세션 유형(예: PRA).
    유형: string
  - name: PRASharedMode
    description: PRA 세션의 공유 모드(예: control, view).
    유형: string
```

### Zscaler.ZPA.UserStatus

User Status log는 ZPA 환경 내 사용자 연결 및 상태에 대한 자세한 정보를 제공합니다. 이는 사용자의 실시간 액세스 동작을 모니터링하고, 연결 문제를 진단하며, 사용자 관점에서 전체 시스템 상태를 추적하는 데 도움이 됩니다.

참조: [User Status 로그 형식](https://help.zscaler.com/zpa/about-user-status-log-fields)

```yaml
schema: Zscaler.ZPA.UserStatus
description: Zscaler ZPA User Status log
referenceURL: https://help.zscaler.com/zpa/about-user-status-log-fields
필드:
  - name: LogTimestamp
    필수: true
    description: 로그가 생성된 타임스탬프.
    유형: timestamp
    시간 형식:
      - '%a %b %e %H:%M:%S %Y'
    이벤트 시간 여부: true
  - name: Customer
    필수: true
    description: 고객 이름.
    유형: string
  - name: Username
    필수: true
    description: 사용자 이름.
    유형: string
    지표:
      - username
  - name: SessionID
    description: TLS 세션 ID.
    유형: string
  - name: SessionStatus
    description: 세션 상태.
    유형: string
  - 이름: Version
    description: Zscaler Client Connector 버전.
    유형: string
  - name: ZEN
    description: 연결에 대해 선택된 ZPA Public Service Edge.
    유형: string
  - name: CertificateCN
    description: 인증서의 일반 이름.
    유형: string
  - name: PrivateIP
    description: Zscaler Client Connector의 개인 IP 주소.
    유형: string
    지표:
      - ip
  - name: PublicIP
    필수: true
    description: Zscaler Client Connector의 공용 IP 주소.
    유형: string
    지표:
      - ip
  - name: Latitude
    description: Zscaler Client Connector 위치의 위도 좌표.
    유형: float
  - name: Longitude
    description: Zscaler Client Connector 위치의 경도 좌표.
    유형: float
  - name: CountryCode
    description: Zscaler Client Connector 위치의 국가 코드.
    유형: string
  - name: TimestampAuthentication
    description: Zscaler Client Connector가 인증된 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampUnAuthentication
    description: Zscaler Client Connector의 인증이 해제된 시점의 타임스탬프.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TotalBytesRx
    설명: 수신된 총 바이트 수입니다.
    유형: bigint
  - 이름: TotalBytesTx
    설명: 전송된 총 바이트 수입니다.
    유형: bigint
  - name: Idp
    description: ZPA Admin Portal에 구성된 ID 공급자(IdP)의 이름.
    유형: string
  - name: Hostname
    설명: Zscaler Client Connector가 보고한 장치 이름입니다.
    유형: string
    지표:
      - 호스트 이름
  - name: Platform
    설명: Zscaler Client Connector가 보고한 장치의 플랫폼입니다.
    유형: string
  - 이름: ClientType
    설명: 요청의 클라이언트 유형입니다.
    유형: string
  - 이름: TrustedNetworks
    설명: 이 장치에 대해 Zscaler Client Connector가 확인한 신뢰할 수 있는 네트워크의 고유 ID입니다.
    유형: array
    요소:
      유형: string
  - 이름: TrustedNetworksNames
    설명: 이 장치에 대해 Zscaler Client Connector가 확인한 신뢰할 수 있는 네트워크의 이름입니다.
    유형: array
    요소:
      유형: string
  - 이름: SAMLAttributes
    설명: IdP에서 보고한 SAML 속성 목록입니다.
    유형: string
  - 이름: PosturesHit
    설명: Zscaler Client Connector가 이 장치에 대해 확인한 포스처 프로필입니다.
    유형: array
    요소:
      유형: string
  - 이름: PosturesMiss
    설명: Zscaler Client Connector가 이 장치에 대해 확인하지 못한 포스처 프로필입니다.
    유형: array
    요소:
      유형: string
  - 이름: ZENLatitude
    설명: ZPA Public Service Edge의 위도 좌표입니다.
    유형: float
  - 이름: ZENLongitude
    설명: ZPA Public Service Edge의 경도 좌표입니다.
    유형: float
  - 이름: ZENCountryCode
    설명: ZPA Public Service Edge의 국가 코드입니다.
    유형: string
  - 이름: FQDNRegistered
    설명: 클라이언트 간 연결에 대한 호스트 이름의 상태입니다.
    유형: string
  - 이름: FQDNRegisteredError
    설명: 등록된 호스트 이름의 상태입니다.
    유형: string
  - 이름: City
    description: 클라이언트의 도시.
    유형: string
  - name: MicroTenantID
    description: 애플리케이션에 액세스하는 사용자의 Microtenant ID.
    유형: string

```

### Zscaler.ZPA.AppConnectorStatus

App Connector Status 로그는 App Connector의 상태, 상태 정보 및 운영 동작에 대한 자세한 정보를 제공합니다. 이러한 로그를 모니터링하면 관리자가 App Connector가 효율적으로 작동하는지 확인하고, 문제를 해결하고, 서비스 안정성을 유지하며, 공격이나 애플리케이션 오용과 같은 잠재적 보안 사고를 탐지하는 데 도움이 됩니다.

참조: [App Connector Status 로그의 형식](https://help.zscaler.com/zpa/about-connector-status-log-fields)

```yaml
스키마: Zscaler.ZPA.AppConnectorStatus
설명: Zscaler ZPA App Connector Status 로그
referenceURL: https://help.zscaler.com/zpa/about-connector-status-log-fields
필드:
  - name: LogTimestamp
    필수: true
    description: 로그가 생성된 타임스탬프.
    유형: timestamp
    시간 형식:
      - '%a %b %e %H:%M:%S %Y'
    이벤트 시간 여부: true
  - name: Customer
    필수: true
    description: 고객 이름.
    유형: string
  - name: SessionID
    description: TLS 세션 ID.
    유형: string
  - 이름: SessionType
    설명: 세션 유형입니다.
    유형: string
  - name: SessionStatus
    description: 세션 상태.
    유형: string
  - 이름: Version
    설명: App Connector 패키지 버전입니다.
    유형: string
  - name: Platform
    설명: 호스트 플랫폼입니다.
    유형: string
  - name: ZEN
    description: 연결에 대해 선택된 ZPA Public Service Edge.
    유형: string
  - name: Connector
    필수: true
    description: App Connector 이름.
    유형: string
  - 이름: ConnectorGroup
    필수: true
    설명: App Connector 그룹 이름입니다.
    유형: string
  - name: PrivateIP
    설명: App Connector의 개인 IP 주소입니다.
    유형: string
    지표:
      - ip
  - name: PublicIP
    설명: App Connector의 공용 IP 주소입니다.
    유형: string
    지표:
      - ip
  - name: Latitude
    설명: App Connector 위치의 위도 좌표입니다.
    유형: float
  - name: Longitude
    설명: App Connector 위치의 경도 좌표입니다.
    유형: float
  - name: CountryCode
    설명: 국가 코드입니다.
    유형: string
  - name: TimestampAuthentication
    설명: App Connector가 인증된 시각의 타임스탬프입니다.
    유형: timestamp
    시간 형식:
      - rfc3339
  - name: TimestampUnAuthentication
    설명: App Connector의 인증 해제 시각의 타임스탬프입니다.
    유형: timestamp
    시간 형식:
      - rfc3339
  - 이름: CPUUtilization
    설명: CPU 사용률(%)입니다.
    유형: bigint
  - 이름: MemUtilization
    설명: 메모리 사용률(%)입니다.
    유형: bigint
  - 이름: ServiceCount
    설명: App Connector가 모니터링 중인 서비스 수입니다.
    유형: bigint
  - 이름: InterfaceDefRoute
    설명: 기본 경로로 가는 인터페이스 이름입니다.
    유형: string
  - 이름: DefRouteGW
    설명: 기본 경로에 대한 게이트웨이의 IP 주소입니다.
    유형: string
    지표:
      - ip
  - 이름: PrimaryDNSResolver
    설명: 기본 DNS 확인자의 IP 주소입니다.
    유형: string
    지표:
      - ip
  - 이름: HostStartTime
    설명: 호스트가 시작된 시점의 초 단위 시간입니다.
    유형: bigint
  - 이름: ConnectorStartTime
    설명: App Connector가 시작된 시점의 초 단위 시간입니다.
    유형: bigint
  - 이름: NumOfInterfaces
    설명: App Connector 호스트의 인터페이스 수입니다.
    유형: bigint
  - 이름: BytesRxInterface
    설명: 인터페이스에서 수신된 바이트 수입니다.
    유형: bigint
  - 이름: PacketsRxInterface
    설명: 인터페이스에서 수신된 패킷 수입니다.
    유형: bigint
  - 이름: ErrorsRxInterface
    설명: 인터페이스에서 수신된 오류 수입니다.
    유형: bigint
  - 이름: DiscardsRxInterface
    설명: 인터페이스에서 수신된 폐기 수입니다.
    유형: bigint
  - 이름: BytesTxInterface
    설명: 인터페이스에서 전송된 바이트 수입니다.
    유형: bigint
  - 이름: PacketsTxInterface
    설명: 인터페이스에서 전송된 패킷 수입니다.
    유형: bigint
  - 이름: ErrorsTxInterface
    설명: 인터페이스에서 전송된 오류 수입니다.
    유형: bigint
  - 이름: DiscardsTxInterface
    설명: 인터페이스에서 전송된 폐기 수입니다.
    유형: bigint
  - name: TotalBytesRx
    설명: 수신된 총 바이트 수입니다.
    유형: bigint
  - 이름: TotalBytesTx
    설명: 전송된 총 바이트 수입니다.
    유형: bigint
  - name: MicroTenantID
    description: 애플리케이션에 액세스하는 사용자의 Microtenant ID.
    유형: string


```

### Zscaler.ZPA.AppConnectorMetrics

App Connector Metrics 로그는 App Connector의 운영 상태와 성능에 대한 자세한 정보를 제공합니다. 이러한 로그를 모니터링하면 관리자가 리소스 고갈(예: DDoS 공격), 무단 액세스, 데이터 유출 시도, 손상된 커넥터와 같은 주요 보안 사례를 진단하는 데 도움이 됩니다.

참조: [App Connector Metrics 로그의 형식](https://help.zscaler.com/zpa/about-app-connector-metrics-log-fields)

```yaml
스키마: Zscaler.ZPA.AppConnectorMetrics
설명: Zscaler ZPA App Connector Metrics 로그
referenceURL: https://help.zscaler.com/zpa/about-app-connector-metrics-log-fields
필드:
  - name: LogTimestamp
    필수: true
    description: 로그가 생성된 타임스탬프.
    유형: timestamp
    시간 형식:
      - '%a %b %e %H:%M:%S %Y'
    이벤트 시간 여부: true
  - name: Connector
    필수: true
    description: App Connector 이름.
    유형: string
  - 이름: CPUUtilization
    설명: 지난 5분 동안의 최대 CPU 사용량입니다.
    유형: bigint
  - 이름: SystemMemoryUtilization
    설명: 전체 VM의 메모리 사용률입니다.
    유형: bigint
  - 이름: ProcessMemoryUtilization
    설명: App Connector 프로세스의 메모리 사용률입니다.
    유형: bigint
  - 이름: AppCount
    필수: true
    설명: 이 App Connector를 통해 액세스하도록 구성된 애플리케이션 수입니다.
    유형: bigint
  - 이름: ServiceCount
    설명: 이 App Connector를 통해 액세스하도록 구성된 서비스 수입니다.
    유형: bigint
  - 이름: TargetCount
    설명: 이 App Connector를 통해 액세스하도록 구성된 대상 수입니다.
    유형: bigint
  - 이름: AliveTargetCount
    설명: 이 App Connector를 통해 액세스 가능한 활성 대상 수입니다.
    유형: bigint
  - 이름: ActiveConnectionsToPublicSE
    설명: ZPA Public Service Edge에 대한 활성 Microtunnel(M-tunnel) 연결 수입니다.
    유형: bigint
  - 이름: DisconnectedConnectionsToPublicSE
    설명: ZPA Public Service Edge에 대한 연결이 끊긴 Microtunnel(M-tunnel) 연결 수입니다.
    유형: bigint
  - 이름: ActiveConnectionsToPrivateSE
    설명: ZPA Private Service Edge에 대한 활성 Microtunnel(M-tunnel) 연결 수입니다.
    유형: bigint
  - 이름: DisconnectedConnectionsToPrivateSE
    설명: ZPA Private Service Edge에 대한 연결이 끊긴 Microtunnel(M-tunnel) 연결 수입니다.
    유형: bigint
  - 이름: TransmittedBytesToPublicSE
    설명: App Connector가 ZPA Public Service Edge로 전송한 바이트 수입니다.
    유형: bigint
  - 이름: ReceivedBytesFromPublicSE
    설명: App Connector가 ZPA Public Service Edge에서 수신한 바이트 수입니다.
    유형: bigint
  - 이름: TransmittedBytesToPrivateSE
    설명: App Connector가 ZPA Private Service Edge로 전송한 바이트 수입니다.
    유형: bigint
  - 이름: ReceivedBytesFromPrivateSE
    설명: App Connector가 ZPA Private Service Edge에서 수신한 바이트 수입니다.
    유형: bigint
  - 이름: AppConnectionsCreated
    설명: 생성된 애플리케이션 Microtunnel(MTunnel) 연결 수입니다.
    유형: bigint
  - 이름: AppConnectionsCleared
    설명: 해제된 애플리케이션 Microtunnel(MTunnel) 연결 수입니다.
    유형: bigint
  - 이름: AppConnectionsActive
    설명: 활성 애플리케이션 Microtunnel(MTunnel) 연결 수입니다.
    유형: bigint
  - 이름: UsedTCPPortsIPv4
    설명: IPv4 연결에 사용된 TCP 포트 수입니다.
    유형: bigint
  - 이름: UsedUDPPortsIPv4
    설명: IPv4 연결에 사용된 UDP 포트 수입니다.
    유형: bigint
  - 이름: UsedTCPPortsIPv6
    설명: IPv6 연결에 사용된 TCP 포트 수입니다.
    유형: bigint
  - 이름: UsedUDPPortsIPv6
    설명: IPv6 연결에 사용된 UDP 포트 수입니다.
    유형: bigint
  - 이름: AvailablePorts
    설명: 사용 가능한 포트 수입니다.
    유형: bigint
  - 이름: SystemMaximumFileDescriptors
    설명: App Connector 시스템 파일 디스크립터의 총 수입니다.
    유형: bigint
  - 이름: SystemUsedFileDescriptors
    설명: 사용 중인 App Connector 시스템 파일 디스크립터 수입니다.
    유형: bigint
  - 이름: ProcessMaximumFileDescriptors
    설명: App Connector 프로세스 파일 디스크립터의 총 수입니다.
    유형: bigint
  - 이름: ProcessUsedFileDescriptors
    설명: 사용 중인 App Connector 프로세스 파일 디스크립터 수입니다.
    유형: bigint
  - 이름: AvailableDiskBytes
    설명: App Connector에서 사용할 수 있는 여유 바이트 수입니다.
    유형: bigint
  - name: MicroTenantID
    설명: App Connector의 Microtenant ID입니다.
    유형: string
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.panther.com/ko/data-onboarding/supported-logs/zscaler/zpa.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
