2252 ๋‹จ์–ด
11 ๋ถ„
๐Ÿ” AWS Monitoring, Troubleshooting & Audit

๐Ÿ” AWS Monitoring, Troubleshooting & Audit#

CloudWatch ยท EventBridge ยท CloudTrail ยท AWS Config

๋ฆฌ์†Œ์Šค ์ƒํƒœ ๋ชจ๋‹ˆํ„ฐ๋ง, API ๊ฐ์‚ฌ, ๊ทœ์ • ์ค€์ˆ˜ ๊ด€๋ฆฌ์˜ 3๋Œ€ ์ถ•


๋ชฉ์ฐจ#

  1. ์„ธ ์„œ๋น„์Šค ํ•œ๋ˆˆ์— ๋น„๊ต
  2. Amazon CloudWatch
  3. Amazon EventBridge (๊ตฌ: CloudWatch Events)
  4. AWS CloudTrail
  5. AWS Config
  6. CloudWatch vs. CloudTrail vs. Config ๋น„๊ต
  7. ๐Ÿ“Œ ์‹œํ—˜ ์ž์ฃผ ์ถœ์ œ ํฌ์ธํŠธ

์„ธ ์„œ๋น„์Šค ํ•œ๋ˆˆ์— ๋น„๊ต#

์„œ๋น„์Šคํ•ต์‹ฌ ์—ญํ• ์ฃผ์š” ์งˆ๋ฌธ
CloudWatch์„ฑ๋Šฅ ๋ชจ๋‹ˆํ„ฐ๋ง + ๋กœ๊ทธ + ์•Œ๋žŒโ€์ง€๊ธˆ CPU๊ฐ€ ์–ผ๋งˆ๋‚˜ ๋˜๋‚˜?โ€
CloudTrailAPI ํ˜ธ์ถœ ๊ฐ์‚ฌ ๊ธฐ๋กโ€๋ˆ„๊ฐ€ ์–ธ์ œ ์–ด๋–ค API๋ฅผ ํ˜ธ์ถœํ–ˆ๋‚˜?โ€
AWS Config์„ค์ • ๋ณ€๊ฒฝ ๊ธฐ๋ก + ๊ทœ์ • ์ค€์ˆ˜ ํ‰๊ฐ€โ€๋ฆฌ์†Œ์Šค ์„ค์ •์ด ์–ด๋–ป๊ฒŒ ๋ฐ”๋€Œ์—ˆ๋‚˜? ๊ทœ์ • ์ค€์ˆ˜ํ•˜๋‚˜?โ€

๐Ÿ“Œ ๋ฆฌ์†Œ์Šค ์‚ญ์ œ ์›์ธ ์กฐ์‚ฌ โ†’ CloudTrail ๋จผ์ € ํ™•์ธ


Amazon CloudWatch#

CloudWatch Metrics#

  • AWS ๋ชจ๋“  ์„œ๋น„์Šค์—์„œ ์ง€ํ‘œ(Metric) ์ œ๊ณต
  • Namespace ๋‹จ์œ„๋กœ ์ง€ํ‘œ ๊ทธ๋ฃนํ™”
  • Dimension: ์ง€ํ‘œ์˜ ์†์„ฑ (Instance ID, ํ™˜๊ฒฝ ๋“ฑ), ์ง€ํ‘œ๋‹น ์ตœ๋Œ€ 30๊ฐœ Dimension
  • ์ง€ํ‘œ์— Timestamp ํฌํ•จ
  • Custom Metrics ์ƒ์„ฑ ๊ฐ€๋Šฅ (์˜ˆ: RAM ์‚ฌ์šฉ๋ฅ  โ€” ๊ธฐ๋ณธ ์ œ๊ณต ์•ˆ ๋จ)

CloudWatch Metric Streams#

  • CloudWatch Metrics๋ฅผ Near real-time์œผ๋กœ ๋Œ€์ƒ์— ์ง€์† ์ŠคํŠธ๋ฆฌ๋ฐ
  • ๋Œ€์ƒ: Kinesis Data Firehose (โ†’ S3, Redshift ๋“ฑ)
  • 3rd party: Datadog, Dynatrace, New Relic, Splunk, Sumo Logic

CloudWatch Logs#

ํ•ญ๋ชฉ๋‚ด์šฉ
Log Group์ž„์˜ ์ด๋ฆ„, ๋ณดํ†ต ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋‹จ์œ„
Log Stream์ธ์Šคํ„ด์Šค/๋กœ๊ทธํŒŒ์ผ/์ปจํ…Œ์ด๋„ˆ ๋‹จ์œ„
๋งŒ๋ฃŒ ์ •์ฑ…์˜๊ตฌ ๋ณด์กด ~ 1์ผ~10๋…„ ์„ค์ • ๊ฐ€๋Šฅ
๊ธฐ๋ณธ ์•”ํ˜ธํ™”ํ™œ์„ฑํ™”๋จ (KMS ์ปค์Šคํ…€ ํ‚ค ์„ค์ • ๊ฐ€๋Šฅ)

CloudWatch Logs ์ „์†ก ๋Œ€์ƒ:

  • Amazon S3 (Export)
  • Kinesis Data Streams
  • Kinesis Data Firehose
  • AWS Lambda
  • OpenSearch

์ฃผ์š” Log Sources:

  • SDK, CloudWatch Logs Agent, CloudWatch Unified Agent
  • Elastic Beanstalk, ECS, Lambda, VPC Flow Logs, API Gateway, CloudTrail, Route 53

CloudWatch Logs Agent vs. Unified Agent#

ํ•ญ๋ชฉCloudWatch Logs AgentCloudWatch Unified Agent
๋ฒ„์ „๊ตฌ๋ฒ„์ „์‹ ๋ฒ„์ „ (๊ถŒ์žฅ)
๋กœ๊ทธ ์ „์†กCloudWatch Logs๋งŒCloudWatch Logs
์‹œ์Šคํ…œ ์ง€ํ‘œโŒโœ… (RAM, Process ๋“ฑ ์ถ”๊ฐ€ ์ˆ˜์ง‘)
์„ค์ • ๊ด€๋ฆฌ-SSM Parameter Store ์ค‘์•™ ๊ด€๋ฆฌ

Unified Agent ์ˆ˜์ง‘ ์ง€ํ‘œ: CPU, Disk metrics/IO, RAM, Netstat, Processes, Swap Space โ†’ EC2 ๊ธฐ๋ณธ Out-of-the-box Metrics(Disk, CPU, Network)๋ณด๋‹ค ์ƒ์„ธํ•œ ์ˆ˜์ค€

CloudWatch Logs Insights#

  • CloudWatch Logs์—์„œ SQL ์œ ์‚ฌ ์ฟผ๋ฆฌ๋กœ ๋กœ๊ทธ ๋ถ„์„
  • AWS ์„œ๋น„์Šค ๋ฐ JSON ๋กœ๊ทธ์—์„œ ํ•„๋“œ ์ž๋™ ๊ฒ€์ƒ‰
  • ์—ฌ๋Ÿฌ Log Group, ์—ฌ๋Ÿฌ ๊ณ„์ • ๋™์‹œ ์ฟผ๋ฆฌ ๊ฐ€๋Šฅ
  • ์ฟผ๋ฆฌ ์ €์žฅ ๋ฐ Dashboard ์ถ”๊ฐ€ ๊ฐ€๋Šฅ
  • โš ๏ธ Query Engine โ€” ์‹ค์‹œ๊ฐ„ ์—”์ง„ ์•„๋‹˜ (๊ณผ๊ฑฐ ๋ฐ์ดํ„ฐ๋งŒ ์กฐํšŒ)

CloudWatch Logs S3 Export#

  • ๋กœ๊ทธ ๋ฐ์ดํ„ฐ๋ฅผ S3๋กœ ๋‚ด๋ณด๋‚ด๊ธฐ (API: CreateExportTask)
  • ๋ฐ์ดํ„ฐ ๊ฐ€์šฉ๊นŒ์ง€ ์ตœ๋Œ€ 12์‹œ๊ฐ„ ์†Œ์š”
  • Near real-time ๋˜๋Š” ์‹ค์‹œ๊ฐ„ ์•„๋‹˜ โ†’ ์‹ค์‹œ๊ฐ„์ด ํ•„์š”ํ•˜๋ฉด Subscriptions Filter ์‚ฌ์šฉ

CloudWatch Logs Subscriptions#

  • ์‹ค์‹œ๊ฐ„ ๋กœ๊ทธ ์ด๋ฒคํŠธ ์ฒ˜๋ฆฌ ๋ฐ ๋ถ„์„์šฉ
  • ๋Œ€์ƒ: Kinesis Data Streams, Kinesis Data Firehose, Lambda
  • Subscription Filter: ํŠน์ • ์กฐ๊ฑด์˜ ๋กœ๊ทธ๋งŒ ๋Œ€์ƒ์œผ๋กœ ์ „๋‹ฌ
  • Cross-Account Subscription: ๋‹ค๋ฅธ ๊ณ„์ •์˜ KDS/KDF๋กœ ์ „๋‹ฌ ๊ฐ€๋Šฅ

CloudWatch Alarms#

Alarm States:

  • OK / INSUFFICIENT_DATA / ALARM

Alarm Targets:

  • EC2 Instance: ์ค‘์ง€/์ข…๋ฃŒ/์žฌ๋ถ€ํŒ…/๋ณต๊ตฌ
  • Auto Scaling Action ํŠธ๋ฆฌ๊ฑฐ
  • SNS Topic ์•Œ๋ฆผ โ†’ ์ด๋ฅผ ํ†ตํ•ด ์‚ฌ์‹ค์ƒ ๋ชจ๋“  ๊ฒƒ ๊ฐ€๋Šฅ

Composite Alarms:

  • ์—ฌ๋Ÿฌ ์•Œ๋žŒ ์ƒํƒœ๋ฅผ AND/OR ์กฐ๊ฑด์œผ๋กœ ์กฐํ•ฉ
  • โ€œ์•Œ๋žŒ ๋…ธ์ด์ฆˆ(Alarm Noise)โ€ ๊ฐ์†Œ์— ํšจ๊ณผ์ 

EC2 Instance Recovery:

  • StatusCheckFailed_System Alarm โ†’ ๋ณต๊ตฌ ์‹คํ–‰
  • ๋ณต๊ตฌ ํ›„: Private/Public/Elastic IP, Metadata, Placement Group ๋™์ผ ์œ ์ง€

์•Œ๋žŒ ํ…Œ์ŠคํŠธ (CLI):

Terminal window
aws cloudwatch set-alarm-state \
--alarm-name "myalarm" \
--state-value ALARM \
--state-reason "testing purposes"

CloudWatch ํŠนํ™” Insights ์„œ๋น„์Šค#

์„œ๋น„์Šค๋Œ€์ƒ๊ธฐ๋Šฅ
Container InsightsECS, EKS, EC2 Kubernetes, Fargate์ปจํ…Œ์ด๋„ˆ ๋ฉ”ํŠธ๋ฆญ + ๋กœ๊ทธ ์ˆ˜์ง‘ (EKS: ์ปจํ…Œ์ด๋„ˆํ™”๋œ CW Agent ํ•„์š”)
Lambda InsightsLambda (Lambda Layer ํ˜•ํƒœ)Cold Start, ์‹œ์Šคํ…œ ๋ฉ”ํŠธ๋ฆญ, ์ง„๋‹จ ์ •๋ณด
Contributor InsightsVPC Flow Logs, DNS ๋“ฑ ๋ชจ๋“  CW LogsTop-N ๊ธฐ์—ฌ์ž ํŒŒ์•… (์˜ˆ: ์ƒ์œ„ IP, ์ตœ๋‹ค ์˜ค๋ฅ˜ URL)
Application InsightsEC2 ๊ธฐ๋ฐ˜ ์•ฑ (Java, .NET ๋“ฑ) + AWS ์„œ๋น„์Šค๋ฌธ์ œ ์ž๋™ ๊ฐ์ง€ ๋Œ€์‹œ๋ณด๋“œ, SageMaker ๊ธฐ๋ฐ˜

CloudWatch Network Synthetic Monitor#

  • On-premises โ†” AWS ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ฐ„ ๋„คํŠธ์›Œํฌ ์„ฑ๋Šฅ ๋ฌธ์ œ ๊ฐ์ง€
  • Agent ์„ค์น˜ ๋ถˆํ•„์š”
  • ICMP/TCP ํŠธ๋ž˜ํ”ฝ ํ…Œ์ŠคํŠธ (Direct Connect ๋˜๋Š” Site-to-Site VPN ๊ฒฝ์œ )
  • ํŒจํ‚ท ์†์‹ค, ์ง€์—ฐ, Jitter ์ธก์ • โ†’ CloudWatch Metrics๋กœ ๋ฐœํ–‰

Amazon EventBridge (๊ตฌ: CloudWatch Events)#

ํ•ต์‹ฌ ๊ธฐ๋Šฅ#

๊ธฐ๋Šฅ์„ค๋ช…
Cron JobsํŠน์ • ์‹œ๊ฐ„/์ฃผ๊ธฐ ๊ธฐ๋ฐ˜ ์Šค์ผ€์ค„ ์‹คํ–‰
Event PatternํŠน์ • ์ด๋ฒคํŠธ ๋ฐœ์ƒ ์‹œ ๊ทœ์น™ ํŠธ๋ฆฌ๊ฑฐ
๋Œ€์ƒLambda, SQS, SNS, KDS, Step Functions, ECS Task, API Gateway, Batch ๋“ฑ

Event Bus ์œ ํ˜•#

์œ ํ˜•์„ค๋ช…
Default Event BusAWS ์„œ๋น„์Šค ์ด๋ฒคํŠธ ์ˆ˜์‹ 
Partner Event BusSaaS ํŒŒํŠธ๋„ˆ ์ด๋ฒคํŠธ (Zendesk, Datadog ๋“ฑ)
Custom Event Bus์ปค์Šคํ…€ ์•ฑ ์ด๋ฒคํŠธ
  • Event Bus๋Š” Resource-based Policy๋กœ ๋‹ค๋ฅธ ๊ณ„์ •์— ๊ณต์œ  ๊ฐ€๋Šฅ
  • ์ด๋ฒคํŠธ ์•„์นด์ด๋ธŒ(Archive) + Replay ๊ฐ€๋Šฅ

Schema Registry#

  • EventBridge๊ฐ€ Event Bus์˜ ์ด๋ฒคํŠธ ์Šคํ‚ค๋งˆ๋ฅผ ์ž๋™ ๋ถ„์„/์ถ”๋ก 
  • ์Šคํ‚ค๋งˆ ๊ธฐ๋ฐ˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ฝ”๋“œ ์ž๋™ ์ƒ์„ฑ (์ด๋ฒคํŠธ ๊ตฌ์กฐ ์‚ฌ์ „ ํŒŒ์•…)
  • ์Šคํ‚ค๋งˆ ๋ฒ„์ €๋‹ ์ง€์›

EventBridge Resource-based Policy#

  • ํŠน์ • Event Bus์˜ ๊ถŒํ•œ ๊ด€๋ฆฌ
  • ๋‹ค๋ฅธ ๊ณ„์ •/๋ฆฌ์ „์˜ ์ด๋ฒคํŠธ ํ—ˆ์šฉ/๊ฑฐ๋ถ€
  • Use Case: AWS Organization ์ „์ฒด ์ด๋ฒคํŠธ๋ฅผ ๋‹จ์ผ ๊ณ„์ •/๋ฆฌ์ „์œผ๋กœ ์ง‘๊ณ„

EventBridge ๋ณด์•ˆ (Target ๋ณ„ ๊ถŒํ•œ)#

Target ์œ ํ˜•๊ถŒํ•œ ๋ฐฉ์‹
Lambda, SNS, SQS, S3, API GatewayResource-based Policy
Kinesis Streams, EC2 ASG, SSM Run Command, ECS TaskIAM Role

AWS CloudTrail#

  • AWS ๊ณ„์ • ๋‚ด ๋ชจ๋“  API ํ˜ธ์ถœ ๊ธฐ๋ก (๊ธฐ๋ณธ ํ™œ์„ฑํ™”)
  • ์ฝ˜์†”, SDK, CLI, AWS ์„œ๋น„์Šค๋ฅผ ํ†ตํ•œ ํ˜ธ์ถœ ํฌํ•จ
  • ๋กœ๊ทธ ๋Œ€์ƒ: CloudWatch Logs ๋˜๋Š” S3
  • Trail์€ ๋ชจ๋“  ๋ฆฌ์ „ ๋˜๋Š” ๋‹จ์ผ ๋ฆฌ์ „ ์ ์šฉ ๊ฐ€๋Šฅ

CloudTrail ์ด๋ฒคํŠธ ์œ ํ˜•#

์œ ํ˜•๊ธฐ๋ณธ ๊ธฐ๋ก์„ค๋ช…
Management Eventsโœ…๋ฆฌ์†Œ์Šค ์ž‘์—… (IAM, EC2 ์„œ๋ธŒ๋„ท ์ƒ์„ฑ, ๋กœ๊น… ์„ค์ • ๋“ฑ)
Data EventsโŒ (๊ณ ๋ณผ๋ฅจ)S3 Object ๋ ˆ๋ฒจ ์ž‘์—… (GetObject, DeleteObject ๋“ฑ), Lambda ์‹คํ–‰
CloudTrail Insights Events๋ณ„๋„ ํ™œ์„ฑํ™”๋น„์ •์ƒ์ ์ธ ํ™œ๋™ ์ž๋™ ๊ฐ์ง€

CloudTrail Insights#

  • ๋น„์ •์ƒ ํ™œ๋™ ๊ฐ์ง€:
    • ๋ถ€์ •ํ™•ํ•œ ๋ฆฌ์†Œ์Šค ํ”„๋กœ๋น„์ €๋‹
    • ์„œ๋น„์Šค ํ•œ๋„ ๋„๋‹ฌ
    • IAM ์ž‘์—… ๊ธ‰์ฆ
    • ์ฃผ๊ธฐ์  ์œ ์ง€๋ณด์ˆ˜ ๋ˆ„๋ฝ
  • ์ •์ƒ Management Event๋กœ Baseline ์ƒ์„ฑ โ†’ Write Event ์ง€์† ๋ถ„์„
  • ์ด์ƒ ํƒ์ง€ ๊ฒฐ๊ณผ: CloudTrail ์ฝ˜์†” + S3 ์ด๋ฒคํŠธ + EventBridge ์ด๋ฒคํŠธ ์ƒ์„ฑ

CloudTrail ์ด๋ฒคํŠธ ๋ณด์กด#

  • ๊ธฐ๋ณธ ๋ณด์กด: 90์ผ
  • 90์ผ ์ด์ƒ ๋ณด์กด: S3 ๋กœ๊ทธ ์ €์žฅ + Athena ๋ถ„์„ ์กฐํ•ฉ

CloudTrail + EventBridge ํŒจํ„ด#

[์‚ฌ์šฉ์ž API ํ˜ธ์ถœ]
โ”‚
โ–ผ
[CloudTrail ๊ธฐ๋ก]
โ”‚
โ–ผ
[EventBridge ์ด๋ฒคํŠธ]
โ”‚
โ–ผ
[SNS ์•Œ๋ฆผ ๋˜๋Š” ์ž๋™ํ™”]

์˜ˆ์‹œ:

  • DeleteTable (DynamoDB) โ†’ CloudTrail โ†’ EventBridge โ†’ SNS ๊ฒฝ๋ณด
  • AssumeRole (IAM) โ†’ CloudTrail โ†’ EventBridge โ†’ SNS ๊ฒฝ๋ณด
  • AuthorizeSecurityGroupIngress (EC2) โ†’ CloudTrail โ†’ EventBridge โ†’ SNS ๊ฒฝ๋ณด

AWS Config#

  • ๋ฆฌ์†Œ์Šค ์„ค์ • ๋ณ€๊ฒฝ ๊ธฐ๋ก ๋ฐ ๊ทœ์ • ์ค€์ˆ˜(Compliance) ํ‰๊ฐ€
  • ๋ฆฌ์ „๋ณ„ ์„œ๋น„์Šค (๋ฆฌ์ „ ๊ฐ„ ์ง‘๊ณ„ ๊ฐ€๋Šฅ)
  • ์„ค์ • ๋ฐ์ดํ„ฐ๋ฅผ S3์— ์ €์žฅ โ†’ Athena๋กœ ๋ถ„์„ ๊ฐ€๋Šฅ

๋‹ตํ•  ์ˆ˜ ์žˆ๋Š” ์งˆ๋ฌธ๋“ค:

  • SSH๊ฐ€ ์ œํ•œ ์—†์ด ์—ด๋ ค ์žˆ๋Š” Security Group์ด ์žˆ๋‚˜?
  • Public Access๊ฐ€ ์—ด๋ฆฐ S3 Bucket์ด ์žˆ๋‚˜?
  • ALB ์„ค์ •์ด ์‹œ๊ฐ„์— ๋”ฐ๋ผ ์–ด๋–ป๊ฒŒ ๋ฐ”๋€Œ์—ˆ๋‚˜?

Config Rules#

  • AWS Managed Rules: 75๊ฐœ ์ด์ƒ ๊ธฐ๋ณธ ์ œ๊ณต
  • Custom Rules: Lambda ๊ธฐ๋ฐ˜ ์ปค์Šคํ…€ ํ‰๊ฐ€ ๋กœ์ง
  • ํŠธ๋ฆฌ๊ฑฐ: ์„ค์ • ๋ณ€๊ฒฝ ์‹œ ๋˜๋Š” ์ฃผ๊ธฐ์  ํ‰๊ฐ€
  • โš ๏ธ Config Rules๋Š” ์˜ˆ๋ฐฉ(Deny) ๊ธฐ๋Šฅ ์—†์Œ โ€” ๊ทœ์ • ์ค€์ˆ˜ ํ‰๊ฐ€๋งŒ

๊ฐ€๊ฒฉ: Free Tier ์—†์Œ, ๋ฆฌ์ „๋‹น ์„ค์ • ํ•ญ๋ชฉ 0.003,๊ทœ์น™ํ‰๊ฐ€0.003, ๊ทœ์น™ ํ‰๊ฐ€ 0.001

Config ๋ฆฌ์†Œ์Šค ๋ทฐ#

  • ํŠน์ • ๋ฆฌ์†Œ์Šค์˜ ๊ทœ์ • ์ค€์ˆ˜ ๋ณ€ํ™” ํƒ€์ž„๋ผ์ธ
  • ํŠน์ • ๋ฆฌ์†Œ์Šค์˜ ์„ค์ • ๋ณ€๊ฒฝ ํƒ€์ž„๋ผ์ธ
  • ํŠน์ • ๋ฆฌ์†Œ์Šค ๊ด€๋ จ CloudTrail API ํ˜ธ์ถœ ํƒ€์ž„๋ผ์ธ

Config Rules โ€” Remediations (์ž๋™ ์ˆ˜์ •)#

  • ๋น„์ค€์ˆ˜ ๋ฆฌ์†Œ์Šค๋ฅผ SSM Automation Document๋กœ ์ž๋™ ์ˆ˜์ •
  • AWS Managed Automation Document ๋˜๋Š” Custom Document (Lambda ํ˜ธ์ถœ ๊ฐ€๋Šฅ)
  • Remediation Retry ์„ค์ • ๊ฐ€๋Šฅ (์ž๋™ ์ˆ˜์ • ํ›„์—๋„ ๋น„์ค€์ˆ˜ ์‹œ)

์˜ˆ์‹œ:

IAM Access Key ๋งŒ๋ฃŒ (NON_COMPLIANT)
โ†’ Auto Remediation: AWSConfigRemediation-RevokeUnusedIAMUserCredentials

Config Rules โ€” Notifications#

  • EventBridge: ๋น„์ค€์ˆ˜ ๋ฆฌ์†Œ์Šค ๋ฐœ์ƒ ์‹œ ํŠธ๋ฆฌ๊ฑฐ โ†’ ์ž๋™ํ™”
  • SNS: ์„ค์ • ๋ณ€๊ฒฝ + ๊ทœ์ • ์ค€์ˆ˜ ์ƒํƒœ ์•Œ๋ฆผ (SNS Filtering ๋˜๋Š” ํด๋ผ์ด์–ธํŠธ ์ธก ํ•„ํ„ฐ ํ™œ์šฉ)

CloudWatch vs. CloudTrail vs. Config ๋น„๊ต#

ํ•ญ๋ชฉCloudWatchCloudTrailConfig
๋ชฉ์ ์„ฑ๋Šฅ ๋ชจ๋‹ˆํ„ฐ๋ง + ์•Œ๋žŒ + ๋กœ๊ทธAPI ํ˜ธ์ถœ ๊ฐ์‚ฌ ๊ธฐ๋ก์„ค์ • ๋ณ€๊ฒฝ ๊ธฐ๋ก + ๊ทœ์ • ์ค€์ˆ˜
์งˆ๋ฌธโ€CPU๊ฐ€ ๋†’์€๊ฐ€?""๋ˆ„๊ฐ€ API๋ฅผ ํ˜ธ์ถœํ–ˆ๋Š”๊ฐ€?""์„ค์ •์ด ๋ฐ”๋€Œ์—ˆ๋Š”๊ฐ€? ๊ทœ์ •์— ๋งž๋Š”๊ฐ€?โ€
๋ฒ”์œ„๋ฆฌ์ „ (๊ธ€๋กœ๋ฒŒ ์ง‘๊ณ„ ๊ฐ€๋Šฅ)๊ธ€๋กœ๋ฒŒ ์„œ๋น„์Šค๋ฆฌ์ „ (์ง‘๊ณ„ ๊ฐ€๋Šฅ)

ELB ๊ด€์ ์—์„œ ์„ธ ์„œ๋น„์Šค ์—ญํ• #

์„œ๋น„์ŠคELB์—์„œ์˜ ์—ญํ• 
CloudWatchIncoming Connection ๋ชจ๋‹ˆํ„ฐ๋ง, ์—๋Ÿฌ ์ฝ”๋“œ ๋น„์œจ ์‹œ๊ฐํ™”, ์„ฑ๋Šฅ ๋Œ€์‹œ๋ณด๋“œ
ConfigSecurity Group ๊ทœ์น™ ์ถ”์ , ์„ค์ • ๋ณ€๊ฒฝ ์ด๋ ฅ, SSL ์ธ์ฆ์„œ ์ƒ์‹œ ๋ถ€์ฐฉ ์—ฌ๋ถ€ ๊ทœ์ • ์ค€์ˆ˜
CloudTrailAPI ํ˜ธ์ถœ ์ถ”์  (๋ˆ„๊ฐ€ LB ์„ค์ •์„ ๋ณ€๊ฒฝํ–ˆ๋Š”๊ฐ€?)

๐Ÿ“Œ ์‹œํ—˜ ์ž์ฃผ ์ถœ์ œ ํฌ์ธํŠธ#

ํฌ์ธํŠธ๋‚ด์šฉ
EC2 ๊ธฐ๋ณธ ๋ฏธ์ œ๊ณต ์ง€ํ‘œRAM (Unified Agent๋กœ ์ถ”๊ฐ€ ์ˆ˜์ง‘ ํ•„์š”)
Custom MetricRAM, ํ”„๋กœ์„ธ์Šค ๋“ฑ ์ง์ ‘ ํ‘ธ์‹œ ํ•„์š”
CW Logs โ†’ S3 ExportAPI: CreateExportTask, ์ตœ๋Œ€ 12์‹œ๊ฐ„ ์†Œ์š” (Near real-time ์•„๋‹˜)
CW Logs ์‹ค์‹œ๊ฐ„ ์ „์†กSubscription Filter โ†’ KDS/KDF/Lambda
Cross-Account LogsCross-Account Subscription ์‚ฌ์šฉ
CW Alarm ํ…Œ์ŠคํŠธset-alarm-state CLI ๋ช…๋ น์œผ๋กœ ๊ฐ•์ œ ALARM
Composite AlarmAND/OR ์กฐ๊ฑด ์กฐํ•ฉ, ์•Œ๋žŒ ๋…ธ์ด์ฆˆ ๊ฐ์†Œ
EC2 Recovery๋™์ผ Private/Public/Elastic IP, Metadata, Placement Group ์œ ์ง€
Container Insights + EKS์ปจํ…Œ์ด๋„ˆํ™”๋œ CW Agent ํ•„์š”
Lambda Insights ๋ฐฐํฌLambda Layer ํ˜•ํƒœ
Contributor InsightsTop-N ๊ธฐ์—ฌ์ž ํŒŒ์•…
EventBridge Target ๊ถŒํ•œLambda/SNS/SQS: Resource-based Policy / Kinesis/ECS: IAM Role
EventBridge Replayโœ… ์•„์นด์ด๋ธŒ๋œ ์ด๋ฒคํŠธ ์žฌ์ƒ ๊ฐ€๋Šฅ
CloudTrail ๊ธฐ๋ณธ ๋ณด์กด90์ผ
90์ผ ์ด์ƒ CloudTrail ๋ณด์กดS3 + Athena
CloudTrail Data Events๊ธฐ๋ณธ ๋น„ํ™œ์„ฑํ™” (๊ณ ๋ณผ๋ฅจ)
CloudTrail Insights๋น„์ •์ƒ ํ™œ๋™ โ†’ CloudTrail ์ฝ˜์†” + S3 + EventBridge
๋ฆฌ์†Œ์Šค ์‚ญ์ œ ์›์ธ ์กฐ์‚ฌCloudTrail ๋จผ์ €
Config Rules ๊ธฐ๋Šฅ๊ทœ์ • ์ค€์ˆ˜ ํ‰๊ฐ€๋งŒ (Deny/์ฐจ๋‹จ ๋ถˆ๊ฐ€)
Config Auto RemediationSSM Automation Document
Config ์„œ๋น„์Šค ๋ฒ”์œ„๋ฆฌ์ „๋ณ„ (๋ฆฌ์ „ ๊ฐ„ ์ง‘๊ณ„ ๊ฐ€๋Šฅ)