EventGen | EventGen ์„ค์ • ๋ฐฉ๋ฒ• ์†Œ๊ฐœ
๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

Splunk/Splunk Dev

EventGen | EventGen ์„ค์ • ๋ฐฉ๋ฒ• ์†Œ๊ฐœ

728x90
๋ฐ˜์‘ํ˜•

๐Ÿ“˜ Eventgen Configuration — ์–ด๋–ป๊ฒŒ ์„ค์ •ํ• ๊นŒ?

Eventgen์„ ์„ค์น˜ํ•˜๋ฉด ๋ณดํ†ต ์ด๋Ÿฐ ์งˆ๋ฌธ์ด ๋– ์˜ค๋ฆ…๋‹ˆ๋‹ค:

  • ์–ผ๋งˆ๋‚˜ ๋งŽ์€ ๋ฐ์ดํ„ฐ๋ฅผ ์ƒ์„ฑํ•ด์•ผ ํ•˜์ง€?
  • ๋ฐ์ดํ„ฐ๋Š” ์–ด๋””๋กœ ๋ณด๋‚ด์•ผ ํ•˜์ง€?
  • ์ „์†ก ๋ฐฉ์‹์€ ์–ด๋–ค ๊ฑฐ๋ฅผ ์จ์•ผ ํ• ๊นŒ? (ํŒŒ์ผ? TCP? HEC?)
  • ๊ทธ๋ฆฌ๊ณ  ์–ด๋–ค ํ˜•ํƒœ์˜ ๋กœ๊ทธ๋ฅผ ๋งŒ๋“ค์–ด์•ผ ํ•˜์ง€?

์ด์ œ ๋ฐ”๋กœ "Eventgen์„ ์–ด๋–ป๊ฒŒ ๊ตฌ์„ฑํ•  ๊ฒƒ์ธ๊ฐ€"์˜ ๋‹จ๊ณ„๋กœ ๋„˜์–ด๊ฐ‘๋‹ˆ๋‹ค ๐Ÿ˜Ž


๐Ÿงฉ Eventgen ๊ตฌ์„ฑ ์š”์†Œ๋Š” 2๊ฐœ๋งŒ ๊ธฐ์–ตํ•˜๋ฉด ๋

Eventgen์˜ ๊ตฌ์„ฑ์€ ์‚ฌ์‹ค ๋‘ ๊ฐ€์ง€ ํ•ต์‹ฌ ๊ฐœ๋…์œผ๋กœ ์ •๋ฆฌ๋ฉ๋‹ˆ๋‹ค:

  1. eventgen.conf
  2. Sample Files

1๏ธโƒฃ eventgen.conf

eventgen.conf๋Š” INI ํ˜•์‹์˜ ์„ค์ • ํŒŒ์ผ์ด๋ฉฐ,
Eventgen์ด ๋™์ž‘ํ•  ๋ฐฉ์‹์„ ์ •์˜ํ•˜๋Š” ์ œ์–ด ํŒŒ์ผ์ž…๋‹ˆ๋‹ค.

์—ฌ๊ธฐ์—๋Š” ๋‹ค์Œ ๋‚ด์šฉ๋“ค์ด ํฌํ•จ๋ฉ๋‹ˆ๋‹ค:

  • ์–ด๋–ค ํ”Œ๋Ÿฌ๊ทธ์ธ์„ ์‚ฌ์šฉํ• ์ง€
  • ์–ผ๋งˆ๋‚˜ ๋งŽ์€ ์ด๋ฒคํŠธ๋ฅผ ์ƒ์„ฑํ• ์ง€
  • ์–ด๋””๋กœ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณด๋‚ผ์ง€ (ํŒŒ์ผ, ๋„คํŠธ์›Œํฌ, HEC ๋“ฑ)
  • ์ƒ˜ํ”Œ๋ณ„ ์„ค์ •๊ณผ global ์„ค์ •

ํŒŒ์ผ ๊ตฌ์กฐ ์ž์ฒด๊ฐ€ ์กฐ๊ธˆ ๊ธธ์–ด์„œ, ์ฒ˜์Œ์—๋Š” ํŠœํ† ๋ฆฌ์–ผ์„ ๋”ฐ๋ผ๊ฐ€๋Š” ๊ฒƒ์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค ๐Ÿ™ƒ

ํ•œ ์ค„ ์š”์•ฝ:
eventgen.conf = ์–ธ์ œ / ์–ผ๋งˆ๋‚˜ / ์–ด๋””๋กœ ๋ณด๋‚ผ์ง€ ์ •์˜


2๏ธโƒฃ Sample Files

Sample ํŒŒ์ผ์€ Eventgen์ด ์ฝ์–ด์„œ ๊ฐ€๊ณตํ•  raw ์ด๋ฒคํŠธ ํ…œํ”Œ๋ฆฟ์ž…๋‹ˆ๋‹ค.

Sample์—๋Š” ๋‹ค์Œ ์š”์†Œ๊ฐ€ ํฌํ•จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

  • ํ† ํฐ(token)
  • ์น˜ํ™˜ ๋ฌธ์ž์—ด(replacement strings)
  • ํƒ€์ž„์Šคํƒฌํ”„ ์ฒ˜๋ฆฌ

์˜ˆ๋ฅผ ๋“ค์–ด ์‹ค์‹œ๊ฐ„ timestamp๋ฅผ ์ƒ์„ฑํ•˜๊ฑฐ๋‚˜
IP/์‚ฌ์šฉ์ž๋ช…/hostname ๊ฐ™์€ ๊ฐ’์„ ๋ฌด์ž‘์œ„ ์น˜ํ™˜ํ•  ์ˆ˜ ์žˆ์–ด์š”.

ํ•œ ์ค„ ์š”์•ฝ:
sample = ์ด๋ฒคํŠธ ์ž์ฒด์˜ payload ํ˜•์‹


๐Ÿ”— ๋‘ ๊ตฌ์„ฑ ์š”์†Œ์˜ ๊ด€๊ณ„

๋‘ ๊ตฌ์„ฑ ์š”์†Œ์˜ ๊ด€๊ณ„๋ฅผ ์ •๋ฆฌํ•˜๋ฉด ์•„์ฃผ ๊ฐ„๋‹จํ•ด์ ธ์š”:

sample = event ํ…œํ”Œ๋ฆฟ
eventgen.conf = ํ…œํ”Œ๋ฆฟ์„ ์–ธ์ œ/์–ผ๋งˆ๋‚˜/์–ด๋””๋กœ ๋ณด๋‚ผ์ง€ ์ •์˜

 

Splunk ๊ด€์ ์œผ๋กœ ๋ณด๋ฉด ๋” ์ง๊ด€์ ์ž…๋‹ˆ๋‹ค:

  • sample → sourcetype์˜ raw ํ˜•ํƒœ
  • eventgen.conf → output routing ์„ค์ •

๊ทธ๋ž˜์„œ ES·UEBA·MITRE ๊ธฐ๋ฐ˜ ํƒ์ง€ ์‹œ๋‚˜๋ฆฌ์˜ค ๋งŒ๋“ค ๋•Œ ์•„์ฃผ ํŽธํ•จ โœจ


๐Ÿ“ฆ ํŒจํ‚ค์ง€๋กœ ๋ฌถ์–ด์„œ ์“ฐ๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์•„์š”

์‹ค์ „์—์„œ๋Š” ์œ„ ๊ตฌ์„ฑ ์š”์†Œ๋“ค์ด ์ปค์Šคํ…€ sample๊ณผ ํ•จ๊ป˜ ๋ฒˆ๋“ค ํ˜•ํƒœ๋กœ ์ œ๊ณต๋˜๊ฑฐ๋‚˜ ๋ฐฐํฌ๋ฉ๋‹ˆ๋‹ค.
์˜ˆ๋ฅผ ๋“ค์–ด ์•„๋ž˜์ฒ˜๋Ÿผ์š”:

bundle/
 โ”œโ”€ default/
 โ”‚   โ””โ”€ eventgen.conf
 โ””โ”€ samples/
     โ”œโ”€ users.sample
     โ”œโ”€ hosts.sample
     โ””โ”€ firewall.logs

 

์—ฌ๊ธฐ์„œ ์‚ฌ์‹ค์ƒ ๊ตฌ์กฐ๋Š” Splunk TA(Add-on) ๊ตฌ์กฐ์™€ ๊ฑฐ์˜ ๋™์ผํ•ฉ๋‹ˆ๋‹ค:

 

๋””๋ ‰ํ† ๋ฆฌ ์—ญํ• 
default/ eventgen.conf ํฌํ•จ
samples/ raw ํ…œํ”Œ๋ฆฟ ํŒŒ์ผ๋“ค

 

์ฆ‰ ์ •๋ฆฌํ•˜๋ฉด:

ํ…œํ”Œ๋ฆฟ(sample) → eventgen.conf → output ์ œ์–ด

 


๐Ÿง ๋งˆ๋ฌด๋ฆฌ ํ•œ ์ค„

Eventgen = “๋กœ๊ทธ ์ƒ์„ฑ ๊ณต์žฅ” + “์ „์†ก ์ œ์–ด ์„ผํ„ฐ”
์ƒ˜ํ”Œ์„ ๋งŒ๋“ค๊ณ  eventgen.conf๋งŒ ์ž˜ ์—ฎ์–ด์ฃผ๋ฉด ๋!

728x90
๋ฐ˜์‘ํ˜•

'Splunk > Splunk Dev' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

EventGen | Stanza Configuration Settings  (0) 2026.01.27
EventGen | Global Settings  (0) 2026.01.27
EventGen | Config ๊ธฐ๋ณธ ๊ฐœ๋… & Stanza  (0) 2026.01.27
EventGen | EventGen ์ด๋ž€?  (0) 2026.01.27
[ Splunk Dev ] Custom Command ๋งŒ๋“ค๊ธฐ : ๊ฐœ์š”  (0) 2024.04.08