Amazon AWS Elastic Kubernetes Service 샘플 이벤트 메시지

이 샘플 이벤트 메시지를 사용하여 QRadar와의 성공적인 통합을 확인하십시오.

중요: 형식화 문제로 인해 메시지 형식을 텍스트 편집기에 붙여넣은 후 캐리지 리턴 또는 줄 바꾸기 문자를 제거하십시오.

Amazon Web Services 프로토콜을 사용할 때 표시되는 Amazon AWS Elastic Kubernetes Service 샘플 메시지

샘플 1: 다음 샘플 이벤트 메시지는 감시 역할이 유형 역할의 오브젝트로 변경되었음을 표시합니다.

{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"Request","auditID":"8716c01c-7a52-4100-8e97-1b9640c72a2f","stage":"ResponseComplete","requestURI":"/apis/rbac.authorization.k8s.io/v1/roles?allowWatchBookmarks=true&resourceVersion=1575982&timeout=6m33s&timeoutSeconds=393&watch=true","verb":"watch","user":{"username":"system:kube-controller-manager","groups":["system:authenticated"]},"sourceIPs":["10.0.46.47"],"userAgent":"kube-controller-manager/v1.18.9 (linux/amd64) kubernetes/d1db3c4/shared-informers","objectRef":{"resource":"roles","apiGroup":"rbac.authorization.k8s.io","apiVersion":"v1"},"responseStatus":{"metadata":{},"status":"Success","message":"Connection closed early","code":200},"requestReceivedTimestamp":"2021-03-29T19:15:03.945243Z","stageTimestamp":"2021-03-29T19:21:36.945705Z","annotations":{"authorization.k8s.io/decision":"allow","authorization.k8s.io/reason":"RBAC: allowed by ClusterRoleBinding \"system:kube-controller-manager\" of ClusterRole \"system:kube-controller-manager\" to User \"system:kube-controller-manager\""}}
표 1. Amazon의 ‘ AWS Elastic Kubernetes Service ’ 이벤트에서 강조 표시된 수치
QRadar® 필드 이름 이벤트 페이로드에서 강조표시된 값
이벤트 ID Watch
이벤트 카테고리 roles
소스 IP 10.0.46.47
username system:kube-controller-manager
디바이스 시간 2021-03-29T19:21:36.945705Z

샘플 2: 다음 샘플 이벤트는 지정된 임대가 대체되었음을 표시합니다.

{LogStreamName: kube-apiserver-audit-e5c612db6e0f317f383ed50f22c28423,Timestamp: 1616696002054,Message: {"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"Metadata","auditID":"e4b88806-2ebf-45b7-8e92-998a33fb0689","stage":"ResponseComplete","requestURI":"/apis/coordination.k8s.io/v1/namespaces/kube-system/leases/kube-controller-manager?timeout=10s","verb":"update","user":{"username":"system:kube-controller-manager","groups":["system:authenticated"]},"sourceIPs":["10.0.184.90"],"userAgent":"kube-controller-manager/v1.18.9 (linux/amd64) kubernetes/d1db3c4/leader-election","objectRef":{"resource":"leases","namespace":"kube-system","name":"kube-controller-manager","uid":"a047cca1-2cda-4e10-9f5c-205de4effe90","apiGroup":"coordination.k8s.io","apiVersion":"v1","resourceVersion":"36409"},"responseStatus":{"metadata":{},"code":200},"requestReceivedTimestamp":"2021-03-25T18:13:21.066654Z","stageTimestamp":"2021-03-25T18:13:21.071075Z","annotations":{"authorization.k8s.io/decision":"allow","authorization.k8s.io/reason":"RBAC: allowed by ClusterRoleBinding \"system:kube-controller-manager\" of ClusterRole \"system:kube-controller-manager\" to User \"system:kube-controller-manager\""}},IngestionTime: 1616696007143,EventId: 36053525605289394950164595066735255382191488289159053312}
표 2. 아마존 ‘ AWS Elastic Kubernetes Service ’ 행사에서 강조된 분야
QRadar 필드 이름 페이로드에서 강조표시된 값
이벤트 ID update
이벤트 카테고리 leases
소스 IP 10.0.184.90
username system:kube-controller-manager
디바이스 시간 2021-03-25T18:13:21.071075Z

예제 3: 다음 예제 이벤트는 노드 인증 요청이 Kubernetes 인증기에 의해 처리됨을 보여줍니다.

{LogStreamName: authenticator-aaaaaa11aaa1a1111111aa1aa1a1a11a,Timestamp: 1776943525723,Message: time="2026-04-23T11:25:20Z" level=info msg="access granted" arn="arn:aws:iam::111111111111:role/test-eks-node-group-11111111111111111111111111" client="10.0.0.1:47824" groups="[system:nodes]" method=POST path=/authenticate stsendpoint=sts.eu-central-1.amazonaws.com uid="aws-iam-authenticator:111111111111:AAAA111A1AAA1111111" username="system:node:test-node-10-0-0-1.eu-central-1.compute.test",IngestionTime: 1776943526118,EventId: 39627164799327269086252886580858378240981231158840197122}
표 3. 아마존 ‘ AWS Elastic Kubernetes Service ’ 행사에서 강조된 분야
QRadar 필드 이름 페이로드에서 강조표시된 값
이벤트 ID access granted
이벤트 카테고리 Kubernetes Authenticator
소스 IP 10.0.0.1
소스 포트 47824
username system:node:test-node-10-0-0-1.eu-central-1.compute.test
디바이스 시간 2026-04-23T11:25:20Z

예제 4: 다음 예제 이벤트는 ‘ Kubernetes ’ 컨트롤러 관리자가 리소스의 상태를 성공적으로 업데이트했음을 보여줍니다.

{LogStreamName: kube-controller-manager-aaaaaa11aaa1a1111111aa1aa1a1a11a,Timestamp: 1776943544000,Message: I0423 11:25:44.573551      11 horizontal.go:1452] "Successfully updated status" HPA="test-namespace/test-ingress-controller",IngestionTime: 1776943553776,EventId: 39627165206917989079797085772143041875195205433467207680}
표 4. 아마존 ‘ AWS Elastic Kubernetes Service ’ 행사에서 강조된 분야
QRadar 필드 이름 페이로드에서 강조표시된 값
이벤트 ID Successfully updated status
이벤트 카테고리 Kubernetes Control Manager
소스 IP 127.0.0.1
디바이스 시간 1776943544000