> For the complete documentation index, see [llms.txt](https://docs.panther.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.panther.com/ko/resources/help/operations.md).

# 작업

## 데이터 수집 볼륨 평가

다음을 사용할 수 있습니다 [Panther API 메트릭 작업](/ko/panther/api/graphql/metrics.md) Panther가 특정 기간 동안 수집하거나 처리한 총 바이트 수와 이벤트 수를 측정합니다. 데이터 수집 볼륨을 평가하는 다른 방법은 아래 섹션을 참조하세요.

### Panther의 SaaS 배포

이 데이터에 액세스하는 데 도움이 필요하면 Panther 계정 팀에 문의하세요.

### Panther의 자체 호스팅 및 CPaaS 배포

{% hint style="warning" %}
아래 정보는 다음에 적용됩니다 [자체 호스팅](/ko/system-configuration/panther-deployment-types/legacy-configurations/self-hosted-deployments.md) 및 CPaaS 배포 유형입니다.
{% endhint %}

Panther 로그 분석 CloudWatch 대시보드는 로그 처리의 운영과 관련된 측면에 대한 깊이 있는 통찰을 제공합니다. 수집 볼륨을 이해하는 것은 Panther 실행 비용을 예측하는 데 매우 중요합니다.

Panther Console의 대시보드에서 수집된 로그의 볼륨을 볼 수 있습니다. 이는 AWS 청구서와 함께 사용하여 데이터 규모가 커질수록 비용을 예측하는 데 사용할 수 있습니다. 비용 추정에는 한 달치 데이터를 사용하는 것을 권장합니다.

CloudWatch 대시보드를 보려면:

1. AWS 콘솔에 로그인합니다.
2. 다음을 클릭합니다 **CloudWatch** 서비스 메뉴에서.
3. 다음을 클릭합니다 **대시보드** CloudWatch 콘솔의 왼쪽 사이드바에서.\
   ![The image shows the AWS CloudWatch sidebar menu.](/files/17e15b44713c99e649ed3f9162ac7f6303af62ee)
4. 다음으로 시작하는 대시보드 이름을 클릭합니다 `PantherLogAnalysis`\
   ![The image shows a list of Dashboards in AWS CloudWatch.](/files/c6338534a5051889557449eb5a294eb9e8d2b4d1)
5. "Input MBytes (Uncompressed) by Log Type"라는 제목의 타일 오른쪽 상단에 있는 세 점 아이콘을 클릭합니다. 드롭다운 메뉴에서 **CloudWatch Insights에서 보기**.\
   ![In AWS CloudWatch, there is a tile labeled "Input MBytes (Uncompressed) by Log Type". On the right side of the tile, there is a 3 dots icon. It is expanded to show a dropdown menu, with the option "View in CloudWatch Logs Insights" highlighted.](/files/13a8b24218c815e23ef877460329c0c5e5a904fb)
6. 기간을 4주로 설정한 다음 **적용**.
7. Logs Insights 페이지 상단에서 **쿼리 실행**.

<figure><img src="/files/6ee04bffaeb6f4e1c9f2e6690e99b01f958cd72e" alt="The AWS CloudWatch Logs Insights page is displayed. A query is entered into the text field at the top of the page."><figcaption></figcaption></figure>

## `s3sns` 도구

Panther는 `s3sns`, S3 객체를 나열하고 S3 알림을 Panther 로그 프로세서 SNS 주제로 게시하는 운영 도구를 제공합니다. 이 도구는 Linux, Mac(Darwin 포함) 및 Windows용 정적으로 컴파일된 실행 파일입니다.

이 도구를 사용하려면 [AWS 자격 증명](https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html) 이 충분한 권한으로 환경에 설정되어 있어야 합니다. 이를 안전하게 관리하기 위한 도구로는 다음과 같은 것을 권장합니다. [AWS Vault](https://github.com/99designs/aws-vault).

{% hint style="warning" %}
Panther 팀 구성원의 구체적인 안내가 없는 한 이 도구를 실행하지 마세요.
{% endhint %}

### 최신 버전의 `s3sns` 도구

최신 버전에 대한 다운로드 링크를 찾으세요 `s3sns` 아래에 있습니다. 다음 명령을 `-h` 플래그와 함께 실행하면 사용법이 설명됩니다.

<details>

<summary><strong><code>s3sns</code> 최신 다운로드 링크</strong></summary>

다음 링크에서 최신 버전을 다운로드하세요:

* [Darwin amd64](https://panther-community-us-east-1.s3.amazonaws.com/latest/tools/darwin-amd64-s3sns.zip)
* [Darwin arm64](https://panther-community-us-east-1.s3.amazonaws.com/latest/tools/darwin-arm64-s3sns.zip)
* [Linux amd64](https://panther-community-us-east-1.s3.amazonaws.com/latest/tools/linux-amd64-s3sns.zip)
* [Linux arm64](https://panther-community-us-east-1.s3.amazonaws.com/latest/tools/linux-arm64-s3sns.zip)
* [Windows amd64](https://panther-community-us-east-1.s3.amazonaws.com/latest/tools/windows-amd64-s3sns.exe.zip)
* [Windows arm64](https://panther-community-us-east-1.s3.amazonaws.com/latest/tools/windows-arm64-s3sns.exe.zip)

</details>

### 특정 버전의 `s3sns` 도구

최신 버전의 `s3sns` 도구를 다운로드하려면 위의 다운로드 링크를 사용하세요. 특정 버전의 도구를 다운로드하려면 아래 지침을 따르세요.

#### 1단계: Panther 버전 확인

1. Panther 콘솔에 로그인합니다.
2. 오른쪽 상단에서 사용자 아이콘을 클릭합니다. 드롭다운 메뉴 하단에 있는 Panther 버전을 확인하세요.

   <figure><img src="/files/edf9ee37ef23ff3a16cf7297db93b55859d0d762" alt="" width="215"><figcaption></figcaption></figure>

#### 2단계: 다운로드 링크 구성

특정 버전의 `s3sns`, S3 다운로드 URL을 다음 형식으로 수동 구성합니다:

`https://panther-community-us-east-1.s3.amazonaws.com/{version}/tools/{os}-{arch}-s3sns{windows file extension}.zip`\
\
아래 설명에 따라 다운로드 URL의 자리 표시자 텍스트를 바꾸세요:

* `version`: Panther 버전, 예: `v1.114.90`. 반드시 포함하세요 `v` 를 버전 번호 앞에.
  * `latest` 은 `version` 도구의 최신 버전을 다운로드하는 데 대체할 수 있습니다.
* `os`: 다음 중 하나를 사용하세요: `darwin`, `linux` , 또는 `windows`
* `arch`: 사용 `amd64` 또는 `arm64`
* `{windows file extension}`: 만약 `os` 값이 `windows`, 다음을 추가하세요 `.exe` 여기에. 만약 `os` 값이 `darwin` 또는 `linux`, 여기에 아무것도 추가하지 마세요.

**다음을 사용하는 도구 링크 예시 `{version}`**\
`https://panther-community-us-east-1.s3.amazonaws.com/v1.114.90/tools/darwin-amd64-s3sns.zip`

**다음을 사용하는 다운로드 링크 예시 `latest`**

`https://panther-community-us-east-1.s3.amazonaws.com/latest/tools/darwin-amd64-s3sns.zip`

## 모니터링

{% hint style="warning" %}
아래 정보는 레거시 [자체 호스팅](/ko/system-configuration/panther-deployment-types/legacy-configurations/self-hosted-deployments.md) 및 CPaaS 배포 유형에 적용됩니다. Panther는 더 이상 새 계정에 대해 이러한 배포 유형을 지원하지 않습니다.
{% endhint %}

### 가시성

Panther는 시스템 운영 상태를 파악할 수 있도록 5개의 CloudWatch 대시보드를 제공합니다:

* **PantherOverview** 모든 Panther 구성 요소의 모든 오류와 성능에 대한 개요입니다.
* **PantherCloudSecurity**: CloudSecurity용 인프라를 모니터링하는 구성 요소의 세부 정보입니다.
* **PantherAlertProcessing**: CloudSecurity 및 로그 처리를 위한 알림을 전달하는 구성 요소의 세부 정보입니다.
* **PantherLogAnalysis**: 로그를 처리하고 규칙을 실행하는 구성 요소의 세부 정보입니다.
* **PantherRemediation**: 인프라 문제를 수정하는 구성 요소의 세부 정보입니다.

### 알람

Panther는 각 구성 요소의 상태를 모니터링하기 위해 CloudWatch 알람을 사용합니다. 편집하세요 `deployments/panther_config.yml` 파일에서 직접 생성한 SNS 주제를 Panther CloudWatch 알람과 연결하여 알림을 받으세요. 이 값이 비어 있으면 Panther는 기본 Panther SNS 주제인 `panther-alarms`:

```yaml
MonitoringParameterValues:
  # 이는 Panther 시스템 알람과 연결하려는 SNS 주제의 arn입니다.
  # 이 값이 설정되지 않으면 알람은 `panther-alarms` SNS 주제와 연결됩니다.
  AlarmSNSTopicARN: 'arn:aws:sns:us-east-1:05060362XXX:MyAlarmSNSTopic'
```

팀에 알람이 전송되도록 구성하려면 아래 가이드를 따르세요:

* [SNS 이메일 및 SMS 통합](https://docs.aws.amazon.com/sns/latest/dg/sns-user-notifications.html)
* [PagerDuty 통합](https://support.pagerduty.com/docs/aws-cloudwatch-integration-guide)

  참고: Pager Duty는 [복합 CloudWatch 알람을 처리할 수 없습니다](https://community.pagerduty.com/forum/t/composite-alarm-in-cloudwatch-not-triggering-pd-integration/1798), 이는 Panther가 온콜 직원에게 중복 호출을 보내지 않기 위해 사용하는 방식입니다. 대안으로 다음을 사용할 수 있습니다. `사용자 지정 이벤트 변환기`.

  다음을 따르세요 [지침 ](https://www.pagerduty.com/docs/guides/custom-event-transformer/)아래 코드를 사용하여:

  ```javascript
     var details = JSON.parse(PD.inputRequest.rawBody);

     var description = "unknown event";
     if ("AlarmDescription" in details) {  // CloudWatch 이벤트처럼 보입니다 ...
       var descLines = details.AlarmDescription.split("\n");
       description = (descLines.length > 1)? descLines[0] + " " + descLines[1] : descLines[0];
     }

     var normalized_event = {
       event_type: PD.Trigger,
       description: description,
       incident_key: description,
       details: details
     };

     PD.emitGenericEvents([normalized_event]);
  ```

  SNS 주제를 구성할 때 사용하세요 `RawMessageDelivery: true` Pager Duty 구독을 생성할 때


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.panther.com/ko/resources/help/operations.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
