> For the complete documentation index, see [llms.txt](https://docs.plura.io/ko/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.plura.io/ko/fn/comm/newfilter/capp.md).

# 응용프로그램 > 사용자정의

{% hint style="info" %}
**비정형 데이터 수집 및 이상 징후 탐지**

응용 프로그램 로그와 같은 비정형 데이터를 수집하여 이상 징후를 탐지할 수 있습니다.&#x20;

문자열 매칭 방식을 통해 원하는 사용자 정의 탐지 방법을 제공합니다.
{% endhint %}

## 필터 등록 절차 <a href="#id-0" id="id-0"></a>

<figure><img src="/files/8EM8kUBDWp1RSSv43ZeU" alt=""><figcaption></figcaption></figure>

### 1. 메뉴 위치 <a href="#id-1" id="id-1"></a>

* 웹페이지 왼쪽 네비게이션 바에서 **필터 > 등록** 메뉴를 클릭합니다.<br>

  <figure><img src="https://qubitsec.github.io/docs/images/Manual/common/regi/custom/2.png" alt=""><figcaption></figcaption></figure>

### 2. 등록 버튼 클릭 <a href="#id-2" id="id-2"></a>

<figure><img src="https://qubitsec.github.io/docs/images/Manual/common/regi/custom/3.png" alt=""><figcaption></figcaption></figure>

### 3. 그룹 선택 <a href="#id-3" id="id-3"></a>

### 4. 태그 선택 <a href="#id-4" id="id-4"></a>

<figure><img src="https://qubitsec.github.io/docs/images/Manual/common/regi/custom/4.png" alt=""><figcaption></figcaption></figure>

### 5. 필터명 입력 <a href="#id-5" id="id-5"></a>

* 등록할 필터의 이름을 입력합니다.

### 6. 필터 설명 입력 <a href="#id-6" id="id-6"></a>

### 7. 필터 위험도 지정 (Very High/High/Middle/Low) <a href="#id-7" id="id-7"></a>

* 필터의 위험도를 설정합니다.

### 8. 필터 동작 시간 설정 (24시간/시간 설정) <a href="#id-8" id="id-8"></a>

<figure><img src="https://qubitsec.github.io/docs/images/Manual/common/regi/custom/5.png" alt=""><figcaption></figcaption></figure>

* 예를 들어, 퇴근 시간 이후부터 출근 시간까지 필터가 동작하도록 설정하려면 "시간 설정"을 선택한 후 원하는 시간을 입력합니다.

### 9. 동작 설정 <a href="#id-9" id="id-9"></a>

* 화면 하단의 정보 입력 영역에서 **추가** 버튼을 클릭하여 필터가 포함할 데이터 값이나 제외할 값을 입력합니다.
* 필터를 등록할 때는 과탐이나 오탐이 발생할 수 있으므로, 담당자와 확인 후 등록하는 것을 권장합니다.

<figure><img src="/files/FU2nronPgx2msx2LhYHg" alt=""><figcaption></figcaption></figure>

### 10. 동영상 <a href="#id-10" id="id-10"></a>

{% embed url="<https://youtu.be/y9NnH2fjzEU>" %}
<https://youtu.be/y9NnH2fjzEU>
{% endembed %}
