{"id":46623,"date":"2023-04-04T23:36:10","date_gmt":"2022-11-07T17:44:36","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/"},"modified":"2024-04-29T21:56:30","modified_gmt":"2024-04-29T13:56:30","slug":"46623-2","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/","title":{"rendered":""},"content":{"rendered":"<h1>\u4f1d\u3048\u305f\u3044\u3053\u3068<\/h1>\n<p>Microsoft\u793e\u304c\u4e2d\u5fc3\u3068\u306a\u3063\u3066\u958b\u767a\u3057\u3066\u3044\u308b\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2 MSTICpy\u306b\u3064\u3044\u3066\u66f8\u304b\u308c\u3066\u3044\u308bQiita\u306e\u8a18\u4e8b\u304c\u307b\u3068\u3093\u3069\u306a\u304b\u3063\u305f\u305f\u3081\u3001<br \/>\n\u307e\u305a\u306fMSTICpy\u3067\u4f55\u304c\u3067\u304d\u308b\u304b\u306e\u6a5f\u80fd\u7d39\u4ecb\u3092\u3057\u3001\u30af\u30a4\u30c3\u30af\u30b9\u30bf\u30fc\u30c8\u6982\u8981(Quick Start Overview)\u306e\u30da\u30fc\u30b8\u3067\u7d39\u4ecb\u3055\u308c\u3066\u3044\u308b\u6a5f\u80fd\u306b\u3064\u3044\u3066\u3001\u30c8\u30ec\u30fc\u30b9\u5b9f\u884c\u3057\u305f\u30c8\u30e9\u30b7\u30e5\u30fc\u30dd\u30a4\u30f3\u30c8\u3092\u5171\u6709\u3067\u304d\u308c\u3070\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n<p>\u203b msticpy\u306e\u300c\u30d0\u30fc\u30b8\u30e7\u30f3 2.4.0\u300d\u3092\u5bfe\u8c61\u306b\u30c6\u30b9\u30c8\u3057\u305f\u7d50\u679c\u3067\u3059\u306e\u3067\u3054\u6ce8\u610f\u304f\u3060\u3055\u3044\u3002<\/p>\n<h1>MSTICpy 101<\/h1>\n<p>MSTICPy\u3068\u306f\u3001\u300cMicrosoft Threat Intelligence Center (MSTIC) on Python and Jupyter notebooks\u300d\u306e\u7565\u3068\u3055\u308c\u3066\u304a\u308a\u3001Python\u3067\u66f8\u304b\u308c\u305f\u4e3b\u306bJupyter\u30ce\u30fc\u30c8\u30d6\u30c3\u30af\u4e0a\u3067\u5229\u7528\u3067\u304d\u308b\u30c4\u30fc\u30eb\u96c6\u3067\u3059\u3002<br \/>\n\u60c5\u5831\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u305f\u3081\u306e\u4fb5\u5bb3\u8abf\u67fb\u30fb\u8105\u5a01\u30cf\u30f3\u30c6\u30a3\u30f3\u30b0\u3092\u884c\u3046\u305f\u3081\u306e\u6a5f\u80fd\u304c\u305f\u304f\u3055\u3093\u7d44\u307f\u8fbc\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>2019\u5e743\u6708\u3054\u308d\u3088\u308aGitHub\u306b\u516c\u958b\u3055\u308c\u30012023\u5e744\u6708\u73fe\u5728\u3082\u6d3b\u767a\u306b\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3055\u308c\u3066\u3044\u307e\u3059\u3002<br \/>\n\u307e\u305fBlackHat USA 2020\u3067\u3082\u5bfe\u5916\u7684\u306b\u767a\u8868\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<h1>MSTICpy\u306e\u6a5f\u80fd<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u8907\u6570\u306e\u60c5\u5831\u30bd\u30fc\u30b9\u304b\u3089\u30ed\u30b0\u30c7\u30fc\u30bf\u3092\u7167\u4f1a<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3001\u30b8\u30aa\u30ed\u30b1\u30fc\u30b7\u30e7\u30f3\u3001Azure\u30ea\u30bd\u30fc\u30b9\u30c7\u30fc\u30bf\u3067\u30c7\u30fc\u30bf\u3092\u30a8\u30f3\u30ea\u30c3\u30c1\u30e1\u30f3\u30c8<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u30ed\u30b0\u304b\u3089IoA\uff08Indicators of Activity\uff09\u3092\u62bd\u51fa\u3057\u3001\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305f\u30c7\u30fc\u30bf\u3092\u89e3\u51cd\u30fb\u30c7\u30b3\u30fc\u30c9<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u7570\u5e38\u306a\u30bb\u30c3\u30b7\u30e7\u30f3\u306e\u691c\u51fa\u3084\u6642\u7cfb\u5217\u5206\u89e3\u306a\u3069\u3001\u9ad8\u5ea6\u306a\u5206\u6790<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u30a4\u30f3\u30bf\u30e9\u30af\u30c6\u30a3\u30d6\u306a\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3\u3001\u30d7\u30ed\u30bb\u30b9\u30c4\u30ea\u30fc\u3001\u591a\u6b21\u5143\u30e2\u30fc\u30d5\u30c1\u30e3\u30fc\u30c8\u3092\u7528\u3044\u3066\u30c7\u30fc\u30bf\u3092\u53ef\u8996\u5316<\/ul>\n<p>\u7d30\u304b\u3044\u3068\u3053\u308d\u306f\u4eca\u56de\u306e\u6295\u7a3f\u3067\u306f\u89e6\u308c\u307e\u305b\u3093\u304c<br \/>\n\u5927\u304d\u304f\u5206\u5272\u3059\u308b\u3068\u4ee5\u4e0b\u306e\uff14\u3064\u306e\u30b8\u30e3\u30f3\u30eb\u306b\u5206\u985e\u3055\u308c\u3001\u30e9\u30a4\u30d6\u30e9\u30ea\u5316\u3055\u308c\u3066\u3044\u308b\u305f\u3081\u6b32\u3057\u3044\u6a5f\u80fd\u3060\u3051\u65ad\u7247\u7684\u306b\u5229\u7528\u3067\u304d\u308b\u306e\u304cMSTICpy\u306e\u3044\u3044\u3068\u3053\u308d\u3067\u3059\u3002<\/p>\n<p>\u30c7\u30fc\u30bf\u53d6\u308a\u8fbc\u307f -&gt; \u30c7\u30fc\u30bf\u306e\u52a0\u5de5(\u30a8\u30f3\u30ea\u30c3\u30c1\u30e1\u30f3\u30c8\u3084\u30c7\u30b3\u30fc\u30c9) -&gt; \u6a5f\u68b0\u5b66\u7fd2\u3067\u306e\u7d71\u8a08\u5206\u6790 -&gt; \u30b0\u30e9\u30d5\u306b\u3088\u308b\u53ef\u8996\u5316<\/p>\n<p>\u4f8b\u3048\u3070\u3001\u30c7\u30fc\u30bf\u306e\u30a8\u30f3\u30ea\u30c3\u30c1\u30e1\u30f3\u30c8\u3060\u3051\u884c\u3044\u3001\u5206\u6790\u3068\u53ef\u8996\u5316\u306f\u5225\u306e\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0(Splunk\u3084Sentinel)\u3067\u3084\u308b\u306a\u3069\u306e\u5f79\u5272\u5206\u62c5\u3067\u3082\u5b9f\u88c5\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u307e\u305f\u305d\u306e\u9006\u3068\u3057\u3066Splunk\u3084Sentinel\u306e\u30c7\u30fc\u30bf\u3092Jupyter\u30ce\u30fc\u30c8\u30d6\u30c3\u30af\u306b\u6301\u3063\u3066\u304d\u3066MSTICpy\u3067\u52a0\u5de5\u3057\u3001\u5206\u6790\u30fb\u53ef\u8996\u5316\u3057\u305f\u308a\u3001\u3082\u3057\u304f\u306fSplunk\u3084Sentinel\u306b\u52a0\u5de5\u6e08\u307f\u30c7\u30fc\u30bf\u3092\u8fd4\u3059\u3053\u3068\u3082\u3067\u304d\u307e\u3059\u3002<\/p>\n<h1>\u516c\u5f0f\u30ea\u30d5\u30a1\u30ec\u30f3\u30b9<\/h1>\n<p>Github\u306emsticpy\u516c\u5f0f\u30ec\u30dd\u30b8\u30c8\u30ea<\/p>\n<p>\u516c\u5f0f\u30ec\u30dd\u30b8\u30c8\u30ea\u4e0a\u306e\u30b5\u30f3\u30d7\u30ebJupyter\u30ce\u30fc\u30c8\u30d6\u30c3\u30af<\/p>\n<p>\u516c\u5f0f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8<\/p>\n<h2>\u304a\u3059\u3059\u3081\u52c9\u5f37\u65b9\u6cd5<\/h2>\n<p>\u3053\u308c\u3089\u306e\u8c4a\u5bcc\u306a\u516c\u5f0f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u304c\u516c\u958b\u3055\u308c\u3066\u304a\u308a\u3001\u516c\u5f0f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u8a18\u8f09\u306e\u4e00\u3064\u4e00\u3064\u306e\u6a5f\u80fd\u306b\u3064\u3044\u3066\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3092\u3057\u3066\u3044\u304f\u3068\u826f\u3044\u3067\u3057\u3087\u3046\u3002<\/p>\n<p>\u516c\u5f0f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306e\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u306b\u76f8\u5f53\u3059\u308b\u3082\u306e\u306f\u3053\u3061\u3089\u3067\u3059\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u4ee5\u4e0b\u3067\u306f\u3053\u306e\u901a\u308a\u306b\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u3092\u5b9f\u65bd\u3057\u3001\u52d5\u304f\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b\u76ee\u7684\u3067\u8aac\u660e\u3057\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<h1>\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\uff08\u30af\u30a4\u30c3\u30af\u30b9\u30bf\u30fc\u30c8\uff09<\/h1>\n<p>Jupyter\u30ce\u30fc\u30c8\u30d6\u30c3\u30af\u3067\u30ce\u30fc\u30c8\u30d6\u30c3\u30af\u30d5\u30a1\u30a4\u30eb\u3092\u4f5c\u6210\u3057\u3001\u5b9f\u884c\u3057\u3066\u3044\u304d\u307e\u3059\u3002<br \/>\n\u306a\u304a\u3001Jupyter\u306e\u6a5f\u80fd\u3092\u5fc5\u8981\u3068\u3057\u306a\u3044\u65ad\u7247\u7684\u306aMSTICpy\u306e\u95a2\u6570\u5229\u7528\u3082\u53ef\u80fd\u3067\u3059\u3002<br \/>\n\u3057\u304b\u3057\u306a\u304c\u3089Jupyter\u30ce\u30fc\u30c8\u30d6\u30c3\u30af\u306b\u306fpandas\u30c7\u30fc\u30bf\u30d5\u30ec\u30fc\u30e0\u304c\u30c7\u30d5\u30a9\u30eb\u30c8\u5b9f\u88c5\u3055\u308c\u3066\u304a\u308a<br \/>\n\u30c7\u30fc\u30bf\u30d7\u30ed\u30c3\u30c8\u3082\u5bb9\u6613\u306b\u884c\u3048\u308b\u3053\u3068\u304b\u3089\u3001API\u3068\u9023\u643a\u3055\u305b\u308b\u3088\u3046\u306a\u9593\u63a5\u30c4\u30fc\u30eb\u4ee5\u5916\u306f\u30ce\u30fc\u30c8\u30d6\u30c3\u30af\u3067\u5b9f\u88c5\u3059\u308b\u3053\u3068\u3092\u304a\u85a6\u3081\u3057\u307e\u3059\u3002<\/p>\n<p>\u3053\u3053\u304b\u3089\u306fPython\u306e\u30e9\u30a4\u30d6\u30e9\u30ea\u540d\u306emsticpy\u3068\u5c0f\u6587\u5b57\u3067\u8868\u73fe\u3057\u307e\u3059\u3002<\/p>\n<h2>\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/h2>\n<p>msticpy Python\u30e9\u30a4\u30d6\u30e9\u30ea\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306b\u306f\u3001Python \u30d0\u30fc\u30b8\u30e7\u30f3 3.8\u4ee5\u4e0a\u304c\u5fc5\u8981\u3067\u3059\u3002<br \/>\n\u307e\u305f\u30e9\u30a4\u30d6\u30e9\u30ea\u306e\u6700\u65b0\u30d0\u30fc\u30b8\u30e7\u30f3\u306f2023\u5e744\u670817\u65e5\u73fe\u5728\u306b\u304a\u3044\u3066 2.4.0 \u3067\u3059\u3002<br \/>\n\u6700\u65b0\u30d0\u30fc\u30b8\u30e7\u30f3\u306b\u306a\u308b\u306b\u3064\u308c\u3001\u30d0\u30b0\u306e\u4fee\u6b63\u3060\u3051\u3067\u306f\u306a\u304f\u53ef\u8996\u5316\u306e\u7a2e\u985e\u3084\u5206\u6790\u6a5f\u80fd\u3082\u5897\u3048\u3066\u3044\u3063\u3066\u3044\u308b\u305f\u3081\u3001<br \/>\n\u5229\u7528\u3059\u308b\u5834\u5408\u306f\u3001\u6700\u65b0\u30d0\u30fc\u30b8\u30e7\u30f3\u3092\u5229\u7528\u3059\u308b\u3068\u826f\u3044\u3067\u3057\u3087\u3046\u3002<\/p>\n<p>\u305f\u3060\u3057\u30d0\u30fc\u30b8\u30e7\u30f3 1\u7cfb\u304b\u3089\u30d0\u30fc\u30b8\u30e7\u30f3 2\u7cfb\u306b\u30a2\u30c3\u30d7\u30b0\u30ec\u30fc\u30c9\u3055\u308c\u305f\u969b\u306b<br \/>\n\u521d\u671f\u5316\u95a2\u6570\u306a\u3069\u306e\u4ed5\u69d8\u304c\u5927\u304d\u304f\u7570\u306a\u308a\u65e2\u5b58\u30b3\u30fc\u30c9\u306e\u4fee\u6b63\u3092\u4f59\u5100\u306a\u304f\u3055\u308c\u308b\u3053\u3068\u304c\u3042\u308a\u307e\u3057\u305f\u3002<br \/>\n\u305d\u306e\u70b9\u306f\u6ce8\u610f\u304c\u5fc5\u8981\u3067\u3059\u3002<\/p>\n<p>\u306a\u304a\u3001Python\u306evenv\u3084conda\u3092\u4f7f\u3063\u305f\u4eee\u60f3\u74b0\u5883\u306e\u4f5c\u6210\u3082\u542b\u3081\u305f\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306f\u3053\u3061\u3089\u3092\u53c2\u7167\u304f\u3060\u3055\u3044\u3002<br \/>\nhttps:\/\/msticpy.readthedocs.io\/en\/latest\/getting_started\/Installing.html<\/p>\n<p>\u4ee5\u4e0b\u3067\u306fPython3.9.12\u306b2023\u5e744\u670817\u65e5\u3067\u306e\u6700\u65b0\u306e2.4.0\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3059\u3002<\/p>\n<p>\u79c1\u306f IDE\u306bVSCode\u306bJupyter\u62e1\u5f35\u6a5f\u80fd\u3092\u5c0e\u5165\u3057\u3066\u5229\u7528\u3057\u3066\u3044\u307e\u3059\u3001\u7406\u7531\u306fPylance\u306e\u9759\u7684\u306a\u81ea\u52d5\u30b3\u30fc\u30c9\u30c1\u30a7\u30c3\u30af\u304c\u7d20\u6674\u3089\u3057\u3044\u304b\u3089\u3067\u3059\u3002<br \/>\n\u79c1\u306e\u5b9f\u884c\u4f8b\u3067\u306f\u3001Anaconda\u3067&#8221;msticpy&#8221;\u3068\u3044\u3046\u4eee\u60f3Python\u74b0\u5883\u3092\u4f5c\u3063\u3066\u5206\u96e2\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<pre class=\"post-pre\"><code>!pip install msticpy==2.4.0\r\n<\/code><\/pre>\n<p>\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306e\u624b\u9806\u3068\u5b9f\u884c\u7d50\u679c\u306f\u3053\u3061\u3089\u306e\u30ce\u30fc\u30c8\u30d6\u30c3\u30af\u30d5\u30a1\u30a4\u30eb\u306b\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u3053\u3053\u304b\u3089\u306f\u8a73\u3057\u304f\u306fGitHub\u306e\u30ce\u30fc\u30c8\u30d6\u30c3\u30af\u30d5\u30a1\u30a4\u30eb\u3092\u307f\u3066\u3044\u305f\u3060\u304f\u3068\u3057\u3066\u3001\u516c\u5f0f\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u901a\u308a\u884c\u304b\u306a\u3044\u30c8\u30e9\u30b7\u30e5\u30fc\u3092\u66f8\u3044\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<h3>\u30c8\u30e9\u30b7\u30e5\u30fc\u30dd\u30a4\u30f3\u30c8 (1) \u8ffd\u52a0\u306e\u4f9d\u5b58\u30e2\u30b8\u30e5\u30fc\u30eb<\/h3>\n<p>help\u3092\u8868\u793a\u3057\u3088\u3046\u3068\u3059\u308b\u3068\u4ee5\u4e0b\u306e\u30e2\u30b8\u30e5\u30fc\u30eb\u304c\u8db3\u308a\u306a\u3044\u30a8\u30e9\u30fc\u304c\u51fa\u305f\u306e\u3067\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3057\u305f\u3002<\/p>\n<pre class=\"post-pre\"><code>!pip install azure-mgmt-resource\r\n!pip install azure-identity\r\n!pip install msticpy\\[azure]\r\n<\/code><\/pre>\n<p>msticpy\\[azure] \u306e\u30d0\u30c3\u30af\u30b9\u30e9\u30c3\u30b7\u30e5\u306fMacOS\u306a\u3069zsh\u74b0\u5883\u306b\u304a\u3044\u3066\u5fc5\u8981\u3067\u3059\u3002<\/p>\n<h2>\u30af\u30a4\u30c3\u30af\u30b9\u30bf\u30fc\u30c8\u306e\u5b9f\u884c\u30c6\u30b9\u30c8\u7d50\u679c<\/h2>\n<p>\u5b9f\u884c\u7d50\u679c\u306e\u8a73\u7d30\u306f\u3053\u3061\u3089\u3067\u3059\u3002<\/p>\n<div>\n<p>\u300cRunning a data query\u300d\u3067\u306f\u4ee5\u4e0b\u3092\u53c2\u8003\u306b Splunk \u304b\u3089\u306e\u30c7\u30fc\u30bf\u53d6\u5f97\u306b\u3064\u3044\u3066\u5b9f\u884c\u3057\u3066\u3044\u307e\u3059\u3002\u5229\u7528\u30c7\u30fc\u30bf\u306fSplunk\u5185\u90e8\u306e_internal\u30ed\u30b0\u3068botsv2\u306e\u30c7\u30fc\u30bf\u3067\u3059\u3002<br \/>\n\u53c2\u8003: https:\/\/msticpy.readthedocs.io\/en\/latest\/data_acquisition\/SplunkProvider.html<\/p>\n<\/div>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d658637434c4406d072fc\/41-1.png\" alt=\"viz2.png\" \/><\/div>\n<div>\n<p>\u300cEnriching data with Context and Pivot Functions\u300d\u3067\u306f\u4ee5\u4e0b\u3092\u53c2\u8003\u306b Virustotal \u304b\u3089\u306e\u30eb\u30c3\u30af\u30a2\u30c3\u30d7\u306e\u307f\u5b9f\u884c\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\n\u53c2\u8003: https:\/\/msticpy.readthedocs.io\/en\/latest\/data_acquisition\/TIProviders.html#listing-available-providers<\/p>\n<\/div>\n<h3>\u30c8\u30e9\u30b7\u30e5\u30fc\u30dd\u30a4\u30f3\u30c8(2) Splunk\u3068\u306e\u63a5\u7d9a<\/h3>\n<ul class=\"post-ul\">Splunk\u5074\u306e\u30e6\u30fc\u30b6\u30fc\u306fadmin\u304bsplunk-system-role\u306e\u30e6\u30fc\u30b6\u30fc\u3092\u9078\u5b9a\u3057\u3001REST API(\u901a\u5e388089\u30dd\u30fc\u30c8)\u3078\u306e\u758e\u901a\u304c\u3068\u308c\u308b\u3088\u3046\u306b\u3057\u3066\u304a\u304f\u3053\u3068<\/ul>\n<h3>\u30c8\u30e9\u30b7\u30e5\u30fc\u30dd\u30a4\u30f3\u30c8 (3) \u7d44\u307f\u8fbc\u307f\u30af\u30a8\u30ea\u95a2\u6570\u306e\u5229\u7528<\/h3>\n<ul class=\"post-ul\">\u3044\u304f\u3064\u304b\u306e\u7d44\u307f\u8fbc\u307f\u30af\u30a8\u30ea\u95a2\u6570\u306f\u5229\u7528\u3055\u308c\u308b\u30c7\u30fc\u30bf\u30d5\u30a3\u30fc\u30eb\u30c9\u540d\u3082\u56fa\u5b9a\u3055\u308c\u3066\u3044\u308b\u305f\u3081\u3001rename \u306a\u3069\u3067\u30d5\u30a3\u30fc\u30eb\u30c9\u540d\u306e\u4e8b\u524d\u5909\u63db\u304c\u5fc5\u8981\u3060\u3063\u305f\u308a\u3057\u307e\u3059\u3002\u307e\u305f\u306f\u7d44\u307f\u8fbc\u307f\u30af\u30a8\u30ea\u95a2\u6570\u5185\u306e\u30aa\u30d7\u30b7\u30e7\u30f3\u3067\u30d5\u30a3\u30fc\u30eb\u30c9\u3092\u5408\u308f\u305b\u307e\u3057\u3087\u3046\u3002<\/ul>\n<p>Splunk\u306b\u95a2\u3057\u3066\u306f\u307e\u3060\u307e\u3060\u7d44\u307f\u8fbc\u307f\u30af\u30a8\u30ea\u95a2\u6570\u304c\u5c11\u306a\u304f\u3001Adhoc\u30b5\u30fc\u30c1\u95a2\u6570(exec_query)\u306e\u65b9\u304c\u4f7f\u3044\u52dd\u624b\u304c\u826f\u3044\u3068\u611f\u3058\u307e\u3059\u3002<\/p>\n<h3>\u30c8\u30e9\u30b7\u30e5\u30fc\u30dd\u30a4\u30f3\u30c8 (4) \u74b0\u5883\u306e\u30ea\u30ed\u30fc\u30c9<\/h3>\n<ul class=\"post-ul\">python kernel\u3068msticpy\u306e\u521d\u671f\u5316\u3092msticpyconfig.yaml\u3092\u4fee\u6b63\u3059\u308b\u305f\u3073\u306b\u5ff5\u306e\u70ba\u306b\u884c\u3046\u3053\u3068\u3002<\/ul>\n<pre class=\"post-pre\"><code># 1. restart python kernel\r\n\r\n# 2. msticpy init again\r\nimport msticpy as mp\r\nmp.init_notebook()\r\n<\/code><\/pre>\n<ul class=\"post-ul\">\u3082\u3057\u304f\u306f\u3001\u4ee5\u4e0b\u3067mscitpyconfig.yaml\u306e\u30ea\u30ed\u30fc\u30c9\u304c\u3067\u304d\u307e\u3059\u3002<\/ul>\n<pre class=\"post-pre\"><code>import msticpy as mp\r\nmp.settings.refresh_config()\r\n<\/code><\/pre>\n<h1>\u3042\u3068\u304c\u304d<\/h1>\n<p>\u4eca\u56de\u306f\u3001MSTICpy\u306e\u7d39\u4ecb\u3068\u30af\u30a4\u30c3\u30af\u30b9\u30bf\u30fc\u30c8\u306e\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u5b9f\u884c\u30c6\u30b9\u30c8\u3092\u66f8\u304d\u307e\u3057\u305f\u3002<br \/>\n\u4e00\u3064\u4e00\u3064\u306e\u6a5f\u80fd\u304c\u3059\u3054\u304f\u5965\u6df1\u3044\u306e\u3067\u3001\u6642\u9593\u304c\u3042\u308c\u3070\u4e00\u3064\u4e00\u3064\u4e01\u5be7\u306bQiita\u306b\u66f8\u3044\u3066\u3044\u304d\u305f\u3044\u3068\u3053\u308d\u3067\u3059\u3002<\/p>\n<p>\u3054\u4e00\u8aad\u3044\u305f\u3060\u304d\u3042\u308a\u304c\u3068\u3046\u3054\u3056\u3044\u307e\u3057\u305f\uff01<br \/>\nHappy msticpying!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4f1d\u3048\u305f\u3044\u3053\u3068 Microsoft\u793e\u304c\u4e2d\u5fc3\u3068\u306a\u3063\u3066\u958b\u767a\u3057\u3066\u3044\u308b\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2 MSTICpy\u306b\u3064\u3044\u3066 [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-46623","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>- Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:description\" content=\"\u4f1d\u3048\u305f\u3044\u3053\u3068 Microsoft\u793e\u304c\u4e2d\u5fc3\u3068\u306a\u3063\u3066\u958b\u767a\u3057\u3066\u3044\u308b\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2 MSTICpy\u306b\u3064\u3044\u3066 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2022-11-07T17:44:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-29T13:56:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d658637434c4406d072fc\/41-1.png\" \/>\n<meta name=\"author\" content=\"\u6e05, \u626c\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u6e05, \u626c\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/\",\"name\":\"- Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2022-11-07T17:44:36+00:00\",\"dateModified\":\"2024-04-29T13:56:30+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461\",\"name\":\"\u6e05, \u626c\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g\",\"caption\":\"\u6e05, \u626c\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/qingyang\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"- Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/","og_locale":"zh_CN","og_type":"article","og_description":"\u4f1d\u3048\u305f\u3044\u3053\u3068 Microsoft\u793e\u304c\u4e2d\u5fc3\u3068\u306a\u3063\u3066\u958b\u767a\u3057\u3066\u3044\u308b\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2 MSTICpy\u306b\u3064\u3044\u3066 [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2022-11-07T17:44:36+00:00","article_modified_time":"2024-04-29T13:56:30+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d658637434c4406d072fc\/41-1.png"}],"author":"\u6e05, \u626c","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u6e05, \u626c","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"1 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/","name":"- Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2022-11-07T17:44:36+00:00","dateModified":"2024-04-29T13:56:30+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/"]}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461","name":"\u6e05, \u626c","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g","caption":"\u6e05, \u626c"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/qingyang\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/46623-2\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/46623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=46623"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/46623\/revisions"}],"predecessor-version":[{"id":87873,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/46623\/revisions\/87873"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=46623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=46623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=46623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}