Cloudflare 로그 샘플 이벤트 메시지
이 샘플 이벤트 메시지를 사용하여 IBM QRadar와의 성공적인 통합을 확인하십시오.
Cloudflare 로그 샘플 메시지
예 1: HTTP 다음의 샘플 이벤트 메시지는 호스트 이름 host.domain.test 에 대한 GET 요청이 전송되고 서버 응답이 상태 코드 200임을 보여줍니다.
{"ClientIP":"10.0.0.1","ClientRequestHost":"host.domain.test","ClientRequestMethod":"GET","ClientRequestURI":"/cdn-cgi/images/cf-icon-cloud.png","EdgeEndTimestamp":"2020-10-13T19:49:36Z","EdgeResponseBytes":1895,"EdgeResponseStatus":200,"EdgeStartTimestamp":"2020-10-13T19:49:36Z","RayID":"5e1b95b9ea390cc5","SecurityAction":"unknown","WAFFlags":"0","WAFMatchedVar":"","SecurityRuleID":"","SecurityRuleDescription":"","CacheCacheStatus":"unknown","CacheResponseBytes":0,"CacheResponseStatus":0,"CacheTieredFill":false,"ClientASN":855,"ClientCountry":"xx","ClientDeviceType":"desktop","ClientIPClass":"noRecord","ClientRequestBytes":1049,"ClientRequestPath":"/cdn-cgi/images/cf-icon-cloud.png","ClientRequestProtocol":"HTTP/1.1","ClientRequestReferer":"http://host.domain.test/cdn-cgi/styles/main.css","ClientRequestUserAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36","ClientSSLCipher":"NONE","ClientSSLProtocol":"none","ClientSrcPort":53851,"ClientXRequestedWith":"","EdgeColoCode":"EWR","EdgeColoID":11,"EdgePathingOp":"unknown","EdgePathingSrc":"undef","EdgePathingStatus":"cloudflareInternalEndpoint","EdgeRequestHost":"","EdgeResponseCompressionRatio":1,"EdgeResponseContentType":"image/png","EdgeServerIP":"","SecurityActions":[],"SecurityRuleIDs":[],"SecuritySources":[],"OriginIP":"","OriginResponseBytes":0,"OriginResponseHTTPExpires":"","OriginResponseHTTPLastModified":"","OriginResponseStatus":0,"OriginResponseTime":0,"OriginSSLProtocol":"unknown","ParentRayID":"00","WorkerCPUTime":0,"WorkerStatus":"unknown","WorkerSubrequest":false,"WorkerSubrequestCount":0,"ZoneID":304427638}
| QRadar 필드 이름 | 이벤트 페이로드에서 강조표시된 값 |
|---|---|
| 이벤트 ID | ClientRequestMethod + EdgeResponseStatus 샘플에 나와 있는 HTTP 이벤트의 경우, 이벤트 ID는 " ClientRequestMethod " 필드와 " EdgeResponseStatus " 필드를 사용하여 구성됩니다. 필드 사이에 밑줄과 함께 연결됩니다. |
| 소스 IP | ClientIP |
| 소스 포트 | ClientSrcPort |
| 디바이스 시간 | EdgeStartTimestamp |
예제 2 : 다음 예제 이벤트 메시지는 HTTP 이 호스트 이름 host.domain.test 로 전송되고 서버 응답이 상태 코드 200임을 보여줍니다.
{"ClientRequestMethod":"POST","ClientIP":"10.0.0.1","ClientSrcPort":53851,"CacheCacheStatus":"dynamic","ClientCountry":"xx","ClientDeviceType":"desktop","ClientIPClass":"noRecord","ClientMTLSAuthCertFingerprint":"","ClientMTLSAuthStatus":"unknown","ClientRegionCode":"xx","ClientRequestBytes":2935,"ClientRequestHost":"host.domain.test","ClientRequestPath":"/console/test/QRadar.getAlertMessages","ClientRequestProtocol":"HTTP/2","ClientRequestReferer":"https://host.domain.test/console/qradar/jsp/test.jsp","ClientRequestScheme":"https","ClientRequestSource":"eyeball","ClientRequestURI":"/console/test/QRadar.getAlertMessages","ClientRequestUserAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15) Firefox/108.0","ClientSSLCipher":"None","ClientSSLProtocol":"TLSv1.3","ClientXRequestedWith":"","EdgeRequestHost":"host.domain.test","EdgeResponseBodyBytes":50,"EdgeResponseBytes":805,"EdgeServerIP":"10.0.0.1","SecurityActions":["allow"],"SecurityRuleIDs":["66668d0ae9c2222222222a600d17448"],"SecuritySources":["firewallRules"],"OriginIP":"10.0.0.1","OriginResponseStatus":200,"OriginSSLProtocol":"TLSv1.2","ParentRayID":"00","RayID":"78b4476e33333af2","SecurityAction":"unknown","WAFAttackScore":0,"SecurityRuleID":"","SecurityRuleDescription":"","WAFSQLiAttackScore":0,"WAFXSSAttackScore":0,"EdgeEndTimestamp":"2023-01-19T11:37:33Z","EdgeStartTimestamp":"2023-01-19T11:37:33Z","EdgeResponseStatus":200}
| QRadar 필드 이름 | 이벤트 페이로드에서 강조표시된 값 |
|---|---|
| 이벤트 ID | ClientRequestMethod + EdgeResponseStatus 샘플에 나와 있는 HTTP 이벤트의 경우, 이벤트 ID는 " ClientRequestMethod " 필드와 " EdgeResponseStatus " 필드를 사용하여 구성됩니다. 필드 사이에 밑줄과 함께 연결됩니다. |
| 소스 IP | ClientIP |
| 소스 포트 | ClientSrcPort |
| 디바이스 시간 | EdgeStartTimestamp |
샘플 3: HTTP 다음의 샘플 이벤트 메시지는 호스트 이름 host.domain.test 에 대한 GET Forbidden 요청이 전송되고 서버 응답이 상태 코드 403임을 보여줍니다.
{"ClientRequestMethod":"GET","ClientIP":"10.0.0.1","ClientSrcPort":53851,"CacheCacheStatus":"unknown","ClientCountry":"xx","ClientDeviceType":"desktop","ClientIPClass":"noRecord","ClientMTLSAuthCertFingerprint":"","ClientMTLSAuthStatus":"unknown","ClientRegionCode":"xx","ClientRequestBytes":2927,"ClientRequestHost":"host.domain.test","ClientRequestPath":"/api/gui_app_framework/test","ClientRequestUserAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15) Firefox/108.0","ClientSSLCipher":"None","ClientSSLProtocol":"TLSv1.3","ClientXRequestedWith":"","EdgeRequestHost":"","EdgeResponseBodyBytes":1751,"EdgeResponseBytes":2166,"EdgeServerIP":"","SecurityActions":["allow","block"],"SecurityRuleIDs":["66668d0ae9c2222222222a600d17448","111106BNULL"],"SecuritySources":["firewallRules","waf"],"OriginIP":"","OriginResponseStatus":0,"OriginSSLProtocol":"unknown","ParentRayID":"00","RayID":"78b4476e33333af2","SecurityAction":"drop","WAFAttackScore":0,"SecurityRuleID":"111106BNULL","SecurityRuleDescription":"SQLi - IS NULL","WAFSQLiAttackScore":0,"WAFXSSAttackScore":0,"EdgeEndTimestamp":"2023-01-19T13:06:18Z","EdgeStartTimestamp":"2023-01-19T13:06:18Z","EdgeResponseStatus":403}
| QRadar 필드 이름 | 이벤트 페이로드에서 강조표시된 값 |
|---|---|
| 이벤트 ID | ClientRequestMethod + EdgeResponseStatus 샘플에 나와 있는 HTTP 이벤트의 경우, 이벤트 ID는 " ClientRequestMethod " 필드와 " EdgeResponseStatus " 필드를 사용하여 구성됩니다. 필드 사이에 밑줄과 함께 연결됩니다. |
| 소스 IP | ClientIP |
| 소스 포트 | ClientSrcPort |
| 디바이스 시간 | EdgeStartTimestamp |
샘플 4: HTTP 다음의 샘플 이벤트 메시지는 호스트 이름 host.domain.test 에 대한 GET Not Modified 요청이 전송되고 서버 응답이 상태 코드 304임을 보여줍니다.
{"ClientRequestMethod":"GET","ClientIP":"10.0.0.1","ClientSrcPort":53851,"CacheCacheStatus":"miss","ClientCountry":"xx","ClientDeviceType":"desktop","ClientIPClass":"noRecord","ClientMTLSAuthCertFingerprint":"","ClientMTLSAuthStatus":"unknown","ClientRegionCode":"xx","ClientRequestBytes":2682,"ClientRequestHost":"host.domain.test","ClientRequestPath":"/console/test/1057/static/js/test.js","ClientRequestProtocol":"HTTP/2","ClientRequestReferer":"https://host.domain.test/console/plugins/1057/","ClientRequestScheme":"https","ClientRequestSource":"eyeball","ClientRequestURI":"/console/test/1057/static/js/test.js","ClientRequestUserAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15) Firefox/108.0","ClientSSLCipher":"None","ClientSSLProtocol":"TLSv1.3","ClientXRequestedWith":"","EdgeRequestHost":"host.domain.test","EdgeResponseBodyBytes":0,"EdgeResponseBytes":366,"EdgeServerIP":"10.0.0.1","SecurityActions":["allow"],"SecurityRuleIDs":["6666d0ae9c2222222222a600d17448"],"SecuritySources":["firewallRules"],"OriginIP":"10.0.0.1","OriginResponseStatus":304,"OriginSSLProtocol":"TLSv1.2","ParentRayID":"00","RayID":"78b4476e33333af2","SecurityAction":"unknown","WAFAttackScore":0,"SecurityRuleID":"","SecurityRuleDescription":"","WAFSQLiAttackScore":0,"WAFXSSAttackScore":0,"EdgeEndTimestamp":"2023-01-19T13:06:15Z","EdgeStartTimestamp":"2023-01-19T13:06:14Z","EdgeResponseStatus":304}
| QRadar 필드 이름 | 이벤트 페이로드에서 강조표시된 값 |
|---|---|
| 이벤트 ID | ClientRequestMethod + EdgeResponseStatus 샘플에 나와 있는 HTTP 이벤트의 경우, 이벤트 ID는 " ClientRequestMethod " 필드와 " EdgeResponseStatus " 필드를 사용하여 구성됩니다. 필드 사이에 밑줄과 함께 연결됩니다. |
| 소스 IP | ClientIP |
| 소스 포트 | ClientSrcPort |
| 디바이스 시간 | EdgeStartTimestamp |
예 5: 다음의 샘플 이벤트 메시지는 호스트 이름 host.domain.test 으로 전송된 POST 방화벽 요청( HTTP )과 서버 응답(status code 200)을 보여줍니다.
{"Action":"allow","ClientIP":"10.0.0.1","ClientASN":45116,"ClientASNDescription":"GTPL-AS-AP Gujarat Telelink Pvt Ltd","ClientCountry":"xx","ClientIPClass":"noRecord","ClientRefererHost":"host.domain.test","ClientRefererPath":"/console/test/jsp/test.jsp","ClientRefererQuery":"","ClientRefererScheme":"https","ClientRequestHost":"host.domain.test","ClientRequestMethod":"POST","ClientRequestPath":"/console/test/QRadar.getIngressNewVersion","ClientRequestProtocol":"HTTP/2","ClientRequestQuery":"","ClientRequestScheme":"https","ClientRequestUserAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15) Firefox/108.0","EdgeColoCode":"BOM","EdgeResponseStatus":200,"Kind":"firewall","MatchIndex":0,"Metadata":{"filter":"007b761e8a762222222f4528222ebe67","type":"customer"},"OriginResponseStatus":200,"OriginatorRayID":"00","RayID":"78b4476e33333af2","RuleID":"6538d0a111114f6aad22222600d17448","Source":"firewallrules","Datetime":"2023-01-19T11:58:00Z"}
| QRadar 필드 이름 | 이벤트 페이로드에서 강조표시된 값 |
|---|---|
| 이벤트 ID | ClientRequestMethod + EdgeResponseStatus 샘플에 표시된 방화벽 요청 이벤트의 경우 이벤트 ID는 ClientRequestMethod 필드 및 EdgeResponseStatus 필드를 사용하여 구성됩니다. 필드 사이에 밑줄과 함께 연결됩니다. |
| 소스 IP | ClientIP |
| 디바이스 시간 | Datetime |
예제 6: 다음 예제 이벤트 메시지는 HTTP 방화벽 규칙과 일치하고 방화벽에 의해 연결 요청이 거부되었음을 보여줍니다.
{"Datetime":"2020-11-12T02:52:18Z","RayName":"5f0cf4c5fc8ce76c","Source":"firewallrules","RuleId":"6e40b9ea4da54b22a112626996d3111f","Action":"drop","EdgeColoName":"EWR","ClientIP":"10.0.0.1","ClientCountryName":"xx","ClientASNDescription":"ASN-DESCRIPTION","UserAgent":"curl/7.29.0","ClientRequestHTTPMethodName":"GET","ClientRequestHTTPHost":"host.domain.test"}
| QRadar 필드 이름 | 이벤트 페이로드에서 강조표시된 값 |
|---|---|
| 이벤트 ID | Action |
| 소스 IP | ClientIP |
| 디바이스 시간 | Datetime |