본문 바로가기
WIKI 기술 지식 베이스

설정 (Setup)

원문 보기 위키 갱신

네트워크 경로(Network Path)를 설정하는 방법을 안내해요. 서비스와 엔드포인트 사이의 네트워크 경로를 모니터링하고 추적하도록 환경을 구성해, 네트워크 인프라의 병목 현상, 지연 문제, 잠재적 장애 지점을 식별할 수 있어요. 개별 네트워크 경로를 수동 구성하거나, 자동으로 발견하거나, 필요에 따라 두 방법을 동시에 사용할 수 있어요.

출처: 문서

본문

개요

네트워크 경로를 설정한다는 것은 서비스와 엔드포인트 사이의 네트워크 경로를 모니터링하고 추적하도록 환경을 구성하는 것이에요. 이는 네트워크 인프라의 병목 현상, 지연 문제, 잠재적 장애 지점을 식별하는 데 도움이 돼요. 네트워크 경로를 사용하면 개별 네트워크 경로를 수동으로 구성하거나, 자동으로 발견하거나, 요구 사항에 따라 두 방법을 동시에 사용할 수 있어요.

참고: 네트워크 구성이 아웃바운드 트래픽을 제한하는 경우 Agent proxy configuration 문서의 설정 지침을 따르세요.

설정

이 페이지는 네트워크 모니터링에서 Agent 기반 구성을 위한 네트워크 경로 설정을 다룹니다. Synthetic Monitoring에서 네트워크 경로 테스트를 만들려면 Network Path Testing in Synthetic Monitoring을 참고하세요.

Datadog은 세 가지 Agent 기반 수집 방법을 제공해요. 하나의 방법만 사용하거나 여러 방법을 결합할 수 있어요.

Method When to use
Scheduled tests Agent 구성에서 정의한 특정 소스-대상 쌍을 모니터링해요. 중요 API나 파트너 서비스 같은 알려진 엔드포인트 세트를 추적하는 데 가장 적합해요.
Dynamic tests Cloud Network Monitoring이 관찰한 트래픽을 기반으로 경로를 자동으로 발견하고 모니터링해요. 모든 대상을 수동으로 나열하지 않고 광범위한 가시성을 얻는 데 가장 적합해요.
Dynamic Tests for NetFlow NetFlow Monitoring에서 관찰된 대상 IP로 Agent 호스트에서 네트워크 경로 테스트를 자동으로 실행해요. 개별 대상을 수동으로 구성하지 않고 NetFlow 트래픽에 홉 단위 경로 가시성을 추가하는 데 가장 적합해요.

예약 테스트 (Scheduled tests)

/etc/datadog-agent/conf.d/network_path.d/conf.yaml에 있는 Agent 구성 파일에 정의해 특정 네트워크 경로를 모니터링할 수 있어요.

시작하려면 예제 구성을 복사하고 .example 확장자를 제거한 뒤 원하는 설정으로 업데이트하거나, 아래의 환경별 구성 중 하나를 사용해요. 대규모 환경에서 성능 최적화를 하려면 워커 수를 늘려요.

Linux 탭

Agent v7.59+가 필요해요.

  1. /etc/datadog-agent/system-probe.yaml에 다음을 추가해 system-probe traceroute 모듈을 활성화해요.

    traceroute:
      enabled: true
    
  2. /etc/datadog-agent/conf.d/network_path.d/conf.yaml 파일을 만들거나 편집해 이 Agent에서 새 대상을 모니터링하도록 network_path를 활성화해요.

    init_config:
      min_collection_interval: 60 # in seconds, default 60 seconds
    instances:
      # configure the endpoints you want to monitor, one check instance per endpoint
      # warning: Do not set the port when using UDP. Setting the port when using UDP can cause traceroute calls to fail and falsely report an unreachable destination.
    
      - hostname: api.datadoghq.eu # endpoint hostname or IP
        protocol: TCP
        port: 443
        tags:
          - "tag_key:tag_value"
          - "tag_key2:tag_value2"
        min_collection_interval: 120 # set min_collection_interval at the instance level
        ## optional configs:
        # max_ttl: 30 # max traceroute TTL, default is 30
        # timeout: 1000 # timeout in milliseconds per hop, default is 1s
        # tcp_method: syn # TCP probing method, default is syn, options: syn, sack, prefer_sack
        # traceroute_queries: 3 # number of traceroutes to send per check run, default is 3
        # e2e_queries: 50 # number of end-to-end probes to send per check run, default is 50
    
      # more endpoints
      - hostname: 1.1.1.1 # endpoint hostname or IP
        protocol: UDP
        tags:
          - "tag_key:tag_value"
          - "tag_key2:tag_value2"
    
  3. 이 구성 변경 후 Agent를 재시작해 네트워크 경로를 보기 시작해요.

macOS 탭

Agent v7.75+가 필요해요.

  1. /opt/datadog-agent/etc/system-probe.yaml에 다음을 추가해 system-probe traceroute 모듈을 활성화해요.

    traceroute:
      enabled: true
    
  2. /opt/datadog-agent/etc/conf.d/network_path.d/conf.yaml 파일을 만들거나 편집해 이 Agent에서 새 대상을 모니터링하도록 network_path를 활성화해요.

    init_config:
      min_collection_interval: 60 # in seconds, default 60 seconds
    instances:
      # configure the endpoints you want to monitor, one check instance per endpoint
      # warning: Do not set the port when using UDP. Setting the port when using UDP can cause traceroute calls to fail and falsely report an unreachable destination.
    
      - hostname: api.datadoghq.eu # endpoint hostname or IP
        protocol: TCP
        port: 443
        tags:
          - "tag_key:tag_value"
          - "tag_key2:tag_value2"
        min_collection_interval: 120 # set min_collection_interval at the instance level
        ## optional configs:
        # max_ttl: 30 # max traceroute TTL, default is 30
        # timeout: 1000 # timeout in milliseconds per hop, default is 1s
        # tcp_method: syn # TCP probing method, default is syn, options: syn, sack, prefer_sack
        # traceroute_queries: 3 # number of traceroutes to send per check run, default is 3
        # e2e_queries: 50 # number of end-to-end probes to send per check run, default is 50
    
      # more endpoints
      - hostname: 1.1.1.1 # endpoint hostname or IP
        protocol: UDP
        tags:
          - "tag_key:tag_value"
          - "tag_key2:tag_value2"
    
  3. 이 구성 변경 후 Agent를 재시작해 네트워크 경로를 보기 시작해요.

Windows 탭

Agent v7.72+가 필요해요.

  1. %ProgramData%\Datadog\system-probe.yaml에 다음을 추가해 system-probe traceroute 모듈을 활성화해요.

    traceroute:
      enabled: true
    
  2. %ProgramData%\Datadog\conf.d\network_path.d\conf.yaml 파일을 만들거나 편집해 이 Agent에서 새 대상을 모니터링하도록 network_path를 활성화해요.

    init_config:
      min_collection_interval: 60 # in seconds, default 60 seconds
    instances:
      # configure the endpoints you want to monitor, one check instance per endpoint
      # warning: Do not set the port when using UDP. Setting the port when using UDP can cause traceroute calls to fail and falsely report an unreachable destination.
    
      - hostname: api.datadoghq.eu # endpoint hostname or IP
        protocol: TCP
        port: 443
        tags:
          - "tag_key:tag_value"
          - "tag_key2:tag_value2"
        min_collection_interval: 120 # set min_collection_interval at the instance level
        ## optional configs:
        # max_ttl: 30 # max traceroute TTL, default is 30
        # timeout: 1000 # timeout in milliseconds per hop, default is 1s
        # tcp_method: syn # TCP probing method, default is syn, options: syn, sack, prefer_sack, syn_socket (Windows only)
        # traceroute_queries: 3 # number of traceroutes to send per check run, default is 3
        # e2e_queries: 50 # number of end-to-end probes to send per check run, default is 50
    
      # more endpoints
      - hostname: 1.1.1.1 # endpoint hostname or IP
        protocol: TCP
        tags:
          - "tag_key:tag_value"
          - "tag_key2:tag_value2"
    
  3. 이 구성 변경 후 Agent를 재시작해 네트워크 경로를 보기 시작해요.

Helm 탭

Agent v7.59+가 필요해요.

Helm chart v3.109.1+가 필요해요. 자세한 내용은 Datadog Helm Chart documentation과 Kubernetes and Integrations 문서를 참고하세요.

Helm을 사용해 Linux Kubernetes 노드에서 네트워크 경로를 활성화하려면 values.yaml 파일에 다음을 추가해요.

datadog:
  traceroute:
    enabled: true
  confd:
    network_path.yaml: |-
      init_config:
        min_collection_interval: 60 # in seconds, default 60 seconds
      instances:
        # configure the endpoints you want to monitor, one check instance per endpoint
        # warning: Do not set the port when using UDP. Setting the port when using UDP can cause traceroute calls to fail and falsely report an unreachable destination.

        - hostname: api.datadoghq.eu # endpoint hostname or IP
          protocol: TCP
          port: 443
          tags:
            - "tag_key:tag_value"
            - "tag_key2:tag_value2"
          min_collection_interval: 120 # set min_collection_interval at the instance level
          ## optional configs:
          # max_ttl: 30 # max traceroute TTL, default is 30
          # timeout: 1000 # timeout in milliseconds per hop, default is 1s
          # tcp_method: syn # TCP probing method, default is syn, options: syn, sack, prefer_sack
          # traceroute_queries: 3 # number of traceroutes to send per check run, default is 3
          # e2e_queries: 50 # number of end-to-end probes to send per check run, default is 50

        # more endpoints
        - hostname: 1.1.1.1 # endpoint hostname or IP
          protocol: UDP
          tags:
            - "tag_key:tag_value"
            - "tag_key2:tag_value2"

Autodiscovery (Kubernetes) 탭

Datadog Autodiscovery를 사용하면 Kubernetes 애노테이션을 통해 서비스별로 네트워크 경로를 활성화할 수 있어요.

Helm chart v3.109.1+가 필요해요. 자세한 내용은 Datadog Helm Chart documentation을 참고하세요.

  1. 네트워크 경로 통합이 의존하는 Datadog values.yaml 파일에서 traceroute 모듈을 활성화해요.

    datadog:
      traceroute:
        enabled: true
    
  2. 모듈이 활성화되면 Datadog은 Kubernetes 파드에 추가된 네트워크 경로 애노테이션을 자동으로 감지해요. 자세한 내용은 Kubernetes and Integrations을 참고해요.

    apiVersion: v1
    kind: Pod
    # (...)
    metadata:
      name: '<POD_NAME>'
      annotations:
        ad.datadoghq.com/<CONTAINER_NAME>.checks: |
          {
            "network_path": {
              "init_config": {
                "min_collection_interval": 300
              },
              "instances": [
                {
                  "protocol": "TCP",
                  "port": 443,
                  "source_service": "<CONTAINER_NAME>",
                  "tags": [
                    "tag_key:tag_value",
                    "tag_key2:tag_value2"
                  ],
                  "hostname": "api.datadoghq.eu"
                },
                {
                  "protocol": "UDP",
                  "source_service": "<CONTAINER_NAME>",
                  "tags": [
                    "tag_key:tag_value",
                    "tag_key2:tag_value2"
                  ],
                  "hostname": "1.1.1.1"
                }
              ]
            }
          }
        # (...)
    spec:
      containers:
        - name: '<CONTAINER_NAME>'
    # (...)
    

파드를 간접적으로 정의하는 경우(deployment, ReplicaSet, ReplicationController 사용), spec.template.metadata 아래에 파드 애노테이션을 추가해요.

워커 수 늘리기

개별 경로에 대한 네트워크 경로 모니터링은 Agent 통합으로 실행돼요. 동시 워커 수는 datadog.yaml 파일의 check_runners 설정으로 제어돼요.

워커 수를 늘리려면 datadog.yaml 파일에 다음 구성을 추가해요.

## @param check_runners - integer - optional - default: 4
## @env DD_CHECK_RUNNERS - integer - optional - default: 4
## The `check_runners` refers to the number of concurrent check runners available for check instance execution.
## The scheduler attempts to spread the instances over the collection interval and will _at most_ be
## running the number of check runners instances concurrently.
##
## The level of concurrency has effects on the Agent's: RSS memory, CPU load, resource contention overhead, etc.
#
check_runners: <NUMBER_OF_WORKERS>

동적 테스트 (Dynamic tests)

사전 요구 사항: CNM이 활성화되어 있어야 해요.

실제 네트워크 트래픽을 기반으로 경로를 자동으로 발견하고 모니터링하도록 동적 테스트를 구성해, 개별 엔드포인트를 수동으로 구성할 필요를 없앨 수 있어요. 도메인 또는 IP를 포함·제외하는 필터 구문을 참고해요.

Linux 탭

Agent v7.73+가 필요해요.

  1. /etc/datadog-agent/system-probe.yaml에 다음을 추가해 system-probe traceroute 모듈을 활성화해요.

    traceroute:
      enabled: true
    
  2. /etc/datadog-agent/datadog.yaml 파일을 만들거나 편집해 CNM 연결을 모니터링하도록 network_path를 활성화해요.

    network_path:
      connections_monitoring:
        enabled: true
      # collector:
        # workers: <NUMBER OF WORKERS> # default 4
    

추가 구성 옵션은 예제 구성을 참고하거나 다음을 사용해요.

network_path:
  connections_monitoring:
    ## @param enabled - boolean - optional - default: false
    ## Enable network path collection for CNM connections. Required for dynamic tests.
    #
    enabled: true
  collector:
    ## @param workers - integer - optional - default: 4
    ## Number of workers that can collect paths in parallel
    #
    # workers: <NUMBER OF WORKERS> # default 4

    # @param pathtest_interval - string - optional - default: "30m"
    # @env DD_NETWORK_PATH_COLLECTOR_PATHTEST_INTERVAL - string - optional - default: "30m"
    # The `pathtest_interval` refers to the traceroute run interval for monitored connections.
    # pathtest_interval: "30m"

    # @param pathtest_ttl - string - optional - default: "70m"
    # @env DD_NETWORK_PATH_COLLECTOR_PATHTEST_TTL - string - optional - default: "70m"
    # The `pathtest_ttl` refers to the duration (time-to-live) a connection will be monitored when it's not seen anymore.
    # The TTL is reset each time the connection is seen again.
    # pathtest_ttl: "70m"

    ## @param filters - list - optional
    ## Include or exclude specific domains or IP ranges from dynamic monitoring.
    ## Filters are applied sequentially, with later filters taking precedence.
    ## See the "Filter syntax" section for details and examples: https://docs.datadoghq.com/network_monitoring/network_path/setup/#filter-syntax
    #
    # filters:
    #   - match_domain: '*.example.com'
    #     type: exclude
    #   - match_ip: 10.0.0.0/8
    #     type: exclude
    #   - match_domain: 'api.datadoghq.com'
    #     type: include
  1. 이 구성 변경 후 Agent를 재시작해 네트워크 경로를 보기 시작해요.

macOS 탭

Agent v7.79+가 필요해요.

  1. /opt/datadog-agent/etc/system-probe.yaml에 다음을 추가해 system-probe traceroute 모듈을 활성화해요.

    traceroute:
      enabled: true
    
  2. /opt/datadog-agent/etc/datadog.yaml 파일에 추가 구성 세부 정보를 추가하거나 예제 구성 파일을 참고해요.

    network_path:
      connections_monitoring:
        ## Enable network path collection for CNM connections. Required for dynamic tests.
        enabled: true
      collector:
        ## @param workers - integer - optional - default: 4
        ## Number of workers that can collect paths in parallel
        #
        # workers: <NUMBER OF WORKERS> # default 4
    
        # @param pathtest_interval - string - optional - default: "30m"
        # @env DD_NETWORK_PATH_COLLECTOR_PATHTEST_INTERVAL - string - optional - default: "30m"
        # The `pathtest_interval` refers to the traceroute run interval for monitored connections.
        # pathtest_interval: "30m"
    
        # @param pathtest_ttl - string - optional - default: "70m"
        # @env DD_NETWORK_PATH_COLLECTOR_PATHTEST_TTL - string - optional - default: "70m"
        # The `pathtest_ttl` refers to the duration (time-to-live) a connection will be monitored when it's not seen anymore.
        # The TTL is reset each time the connection is seen again.
        # pathtest_ttl: "70m"
    
        ## @param filters - list - optional
        ## Include or exclude specific domains or IP ranges from dynamic monitoring.
        ## Filters are applied sequentially, with later filters taking precedence.
        ## See the "Filter syntax" section for details and examples: https://docs.datadoghq.com/network_monitoring/network_path/setup/#filter-syntax
        #
        # filters:
        #   - match_domain: '*.example.com'
        #     type: exclude
        #   - match_ip: 10.0.0.0/8
        #     type: exclude
        #   - match_domain: 'api.datadoghq.com'
        #     type: include
    
  3. 이 구성 변경 후 Agent를 재시작해 네트워크 경로를 보기 시작해요.

Windows 탭

Agent v7.73+가 필요해요.

  1. %ProgramData%\Datadog\system-probe.yaml에 다음을 추가해 system-probe traceroute 모듈을 활성화해요.

    traceroute:
      enabled: true
    
  2. %ProgramData%\Datadog\datadog.yaml 파일을 만들거나 편집해 CNM 연결을 모니터링하도록 network_path를 활성화해요.

    중요 알림(레벨: info): End User Devices에서 네트워크 경로를 활성화하는 경우 이 단계를 건너뛰세요.

    network_path:
      connections_monitoring:
        enabled: true
      # collector:
        # workers: <NUMBER OF WORKERS> # default 4
    

추가 구성 옵션은 예제 구성을 참고하거나 다음을 사용해요.

network_path:
  connections_monitoring:
    ## @param enabled - boolean - optional - default: false
    ## Enable network path collection for CNM connections. Required for dynamic tests.
    #
    enabled: true
  collector:
    ## @param workers - integer - optional - default: 4
    ## Number of workers that can collect paths in parallel
    #
    # workers: <NUMBER OF WORKERS> # default 4

    # @param pathtest_interval - string - optional - default: "30m"
    # @env DD_NETWORK_PATH_COLLECTOR_PATHTEST_INTERVAL - string - optional - default: "30m"
    # The `pathtest_interval` refers to the traceroute run interval for monitored connections.
    # pathtest_interval: "30m"

    # @param pathtest_ttl - string - optional - default: "70m"
    # @env DD_NETWORK_PATH_COLLECTOR_PATHTEST_TTL - string - optional - default: "70m"
    # The `pathtest_ttl` refers to the duration (time-to-live) a connection will be monitored when it's not seen anymore.
    # The TTL is reset each time the connection is seen again.
    # pathtest_ttl: "70m"

    ## @param filters - list - optional
    ## Include or exclude specific domains or IP ranges from dynamic monitoring.
    ## Filters are applied sequentially, with later filters taking precedence.
    ## See the "Filter syntax" section for details and examples: https://docs.datadoghq.com/network_monitoring/network_path/setup/#filter-syntax
    #
    # filters:
    #   - match_domain: '*.example.com'
    #     type: exclude
    #   - match_ip: 10.0.0.0/8
    #     type: exclude
    #   - match_domain: 'api.datadoghq.com'
    #     type: include
  1. 이 구성 변경 후 Agent를 재시작해 네트워크 경로를 보기 시작해요.

Helm 탭

Agent v7.73+ 및 Helm chart v3.124.0+가 필요해요. 필터 구성에는 추가로 Agent v7.83.2+ 및 Helm chart v3.249.0+가 필요해요.

Helm을 사용해 Linux Kubernetes 노드에서 네트워크 경로를 활성화하려면 values.yaml 파일에 다음을 추가해요. 자세한 내용은 Datadog Helm Chart documentation과 Kubernetes and Integrations 문서를 참고해요.

# Network Path filters require Agent v7.83.2+.
# agents:
#   image:
#     tag: "<AGENT_VERSION>"

datadog:
  ## Set to true to enable the Traceroute Module of the System Probe
  traceroute:
    enabled: true

  ## Enable Cloud Network Monitoring, which is required for dynamic tests.
  networkMonitoring:
    enabled: true

  networkPath:
    connectionsMonitoring:
      enabled: true

    ## @param collector - custom object - optional
    ## Configuration related to Network Path Collector.
    #
    # collector:
      ## @param workers - integer - optional - default: 4
      ## @env DD_NETWORK_PATH_COLLECTOR_WORKERS - integer - optional - default: 4
      ## The `workers` refers to the number of concurrent workers available for network path execution.
      #
      # workers: 4

      ## @param pathtestInterval - string - optional - default: 30m
      ## @env DD_NETWORK_PATH_COLLECTOR_PATHTEST_INTERVAL - string - optional - default: 30m
      ## The `pathtestInterval` refers to the traceroute run interval for monitored connections.
      #
      # pathtestInterval: 30m

      ## @param pathtestTTL - string - optional - default: 70m
      ## @env DD_NETWORK_PATH_COLLECTOR_PATHTEST_TTL - string - optional - default: 70m
      ## The `pathtestTTL` refers to the duration (time-to-live) a connection will be monitored when it's not seen anymore.
      ## The TTL is reset each time the connection is seen again.
      #
      # pathtestTTL: 70m

      ## @param filters - list - optional
      ## Include or exclude specific domains or IP ranges from dynamic monitoring.
      ## Filters are applied sequentially, with later filters taking precedence.
      ## See the "Filter syntax" section for details and examples: https://docs.datadoghq.com/network_monitoring/network_path/setup/#filter-syntax
      #
      # filters:
      #   - match_domain: '*.example.com'
      #     type: exclude
      #   - match_ip: 10.0.0.0/8
      #     type: exclude
      #   - match_domain: 'api.datadoghq.com'
      #     type: include

NetFlow용 동적 테스트 (실험적)

NetFlow용 동적 테스트는 실험적이며 Agent v7.81+가 필요해요. 이 기능을 활성화하려면 Datadog Support 또는 계정 팀에 문의하세요.

NetFlow 레코드에서 관찰된 대상 IP로 Agent 호스트에서 네트워크 경로 테스트를 실행하도록 NetFlow용 동적 테스트를 구성해요. NetFlow용 동적 테스트는 Cloud Network Monitoring 또는 network_path.connections_monitoring.enabled가 필요하지 않아요.

NetFlow용 동적 테스트는 NetFlow 트래픽을 수집하는 Datadog Agent에서 실행돼요. NetFlow 내보내기, 라우터 또는 원래 플로우 소스에서는 실행되지 않아요. 조사하려는 경로를 대표하는 traceroute가 실행되도록 Agent를 관찰된 플로우 소스에 충분히 가깝게 배포해요.

사전 요구 사항:

  • NetFlow Monitoring이 구성되고 플로우를 수신하고 있어야 해요.
  • Agent v7.81+가 필요해요.

Linux 탭

  1. /etc/datadog-agent/system-probe.yaml에 다음을 추가해 system-probe traceroute 모듈을 활성화해요.

    traceroute:
      enabled: true
    
  2. /etc/datadog-agent/datadog.yaml에서 NetFlow용 동적 테스트를 활성화해요.

    network_path:
      netflow_monitoring:
        enabled: true
      collector:
        monitor_ip_without_domain: true
    

monitor_ip_without_domain: true는 NetFlow용 동적 테스트가 관찰된 대상 IP 주소를 타깃으로 하고 네트워크 경로 수집기가 기본적으로 IP 전용 대상을 건너뛰기 때문에 필요해요.

  1. 이 구성 변경 후 Agent를 재시작해요.

Windows 탭

  1. %ProgramData%\Datadog\system-probe.yaml에 다음을 추가해 system-probe traceroute 모듈을 활성화해요.

    traceroute:
      enabled: true
    
  2. %ProgramData%\Datadog\datadog.yaml에서 NetFlow용 동적 테스트를 활성화해요.

    network_path:
      netflow_monitoring:
        enabled: true
      collector:
        monitor_ip_without_domain: true
    

monitor_ip_without_domain: true는 NetFlow용 동적 테스트가 관찰된 대상 IP 주소를 타깃으로 하고 네트워크 경로 수집기가 기본적으로 IP 전용 대상을 건너뛰기 때문에 필요해요.

  1. 이 구성 변경 후 Agent를 재시작해요.

Agent가 경로를 보고한 후 Network Path UI를 열고 origin:netflow로 필터링해 NetFlow 트래픽에서 생성된 경로를 확인해요.

필터 구문

도메인과 IP를 포함·제외하도록 필터를 구성해 다음을 할 수 있어요.

  • 내부 네트워크의 모니터링 오버헤드 줄이기
  • 외부 트래픽 패턴에 집중하기
  • 모니터링이 필요 없는 알려진 인프라 범위 제외하기

같은 network_path.collector.filters 목록이 동적 테스트와 NetFlow용 동적 테스트에 적용돼요. NetFlow용 동적 테스트는 관찰된 대상 IP 주소를 타깃으로 하므로 match_ip 필터를 사용해요.

Helm 구성의 경우 values.yaml의 datadog.networkPath.collector.filters에 같은 필터 목록을 추가해요.

동적 테스트에서 특정 도메인이나 IP 범위를 포함·제외하려면 /etc/datadog-agent/datadog.yaml 파일에 다음을 추가해요.

network_path:
  collector:
    filters:
      # exclude single domain
      - match_domain: 'api.slack.com'
        type: exclude

      # exclude domain using `*` wildcard
      - match_domain: '*.datadoghq.com'
        type: exclude
      - match_domain: '*.zoom.us'
        match_domain_strategy: wildcard      # use simple wildcard matching (wildcard matching is the default)
        type: exclude

      # exclude single IP or using CIDR notation
      - match_ip: 10.10.10.10
        type: exclude
      - match_ip: 10.20.0.0/24
        type: exclude

      # exclude using regex
      - match_domain: '.*\.zoom\.us'
        match_domain_strategy: regex         # use regex matching strategy
        type: exclude

      # include
      - match_domain: 'api.datadoghq.com'
        type: include

참고: 필터는 순차적으로 적용되며, 나중 필터가 앞선 필터보다 우선해요.

예를 들어 *.datadoghq.com과 일치하는 모든 도메인은 무시되지만 api.datadoghq.com은 예외예요.

network_path:
  collector:
    filters:
      - match_domain: '*.datadoghq.com'
        type: exclude
      - match_domain: 'api.datadoghq.com'
        type: include

소스 공용 IP 확인

소스 공용 IP 확인은 Agent v7.75+에서 사용할 수 있어요.

네트워크 경로는 인터넷으로 향하는 트래픽에 대한 정확한 경로 시각화를 제공하기 위해 소스 호스트의 공용 IP 주소를 확인해요. Agent는 HTTPS를 통해 외부 IP 확인 서비스에 접촉해 호스트의 공용 IP를 판단해요.

이 기능은 네트워크 경로가 작동하는 데 필수가 아니에요. 이러한 서비스에 도달할 수 없으면 네트워크 경로는 정상적으로 계속 작동하지만, 소스 공용 IP는 확인되지 않고 경로 시각화에 소스 IP 메타데이터가 표시되지 않아요.

네트워크가 아웃바운드 트래픽을 제한하고 소스 공용 IP 확인을 원하면 방화벽 허용 목록에 다음 URL을 추가해요.

URL Provider
https://icanhazip.com Cloudflare
https://ipinfo.io/ip IPinfo
https://checkip.amazonaws.com Amazon
https://api.ipify.org ipify
https://whatismyip.akamai.com Akamai

Agent는 각 서비스를 순서대로 시도하고 첫 번째 성공 응답을 사용해요. 모든 요청은 HTTPS(포트 443)로 이루어져요.

문제 해결

다음 가이드를 사용해 네트워크 경로 문제를 해결해요. 추가 도움이 필요하면 Datadog Support에 문의해요.

UI에 네트워크 경로 데이터가 없는 경우

Network Path UI에 데이터가 나타나지 않으면 기능이 완전히 활성화되지 않았을 수 있어요. 네트워크 경로는 다음이 필요해요.

  1. system-probe.yaml 파일에서 traceroute 모듈이 활성화되어 있어야 해요.

    traceroute:
      enabled: true
    
  2. 최소 하나의 네트워크 경로 기능이 활성 상태여야 해요. 예를 들어:

    • conf.d/network_path.d 파일을 통해 구성된 예약 테스트.
    • network_path.connections_monitoring.enabled와 Cloud Network Monitoring을 모두 활성화해 구성한 동적 테스트.
    • network_path.netflow_monitoring.enabled와 NetFlow Monitoring을 활성화해 구성한 NetFlow용 동적 테스트.

UI에 NetFlow용 동적 테스트 데이터가 없는 경우

Network Path UI에 origin:netflow 경로가 나타나지 않으면 다음을 확인해요.

  1. Agent가 7.81+ 버전인지.
  2. NetFlow Monitoring이 활성화되고 플로우를 수신하는지.
  3. system-probe.yaml에서 traceroute 모듈이 활성화되었는지.
  4. datadoghq.com에서 network_path.netflow_monitoring.enabled 및 network_path.collector.monitor_ip_without_domain이 true로 설정되었는지.
  5. network_path.collector.filters 구성이 모니터링하려는 대상 IP를 제외하지 않는지.

NetFlow용 동적 테스트는 대상 필터가 평가되기 전에 Agent 호스트에 할당된 소스 IP가 있는 NetFlow 레코드를 자동으로 건너뛰어요. 이는 자체 예약 루프를 방지하기 위한 예상 동작이에요. Agent 소스 트래픽이 다른 소스 IP에서 나타나는 NAT 또는 앨리어스 사례의 경우 network_path.collector.source_excludes를 사용해 해당 소스 IP를 제외해요.

그런 다음 네트워크 경로 UI를 origin:netflow로 필터링해요.

오류: status code: 404

다음 같은 오류가 발생하면:

Error: failed to trace path: traceroute request failed: Probe Path <path>, url: <url>, status code: 404
  • 이는 traceroute 모듈이 활성화되지 않았다는 것을 나타내요. system-probe.yaml 파일에서 traceroute 모듈이 활성화되었는지 확인해요.

더 알아보기 (Learn more)