{"id":57859,"date":"2025-05-20T05:00:00","date_gmt":"2025-05-20T13:00:00","guid":{"rendered":"https:\/\/www.sumologic.com\/blog\/sumo-logic-cloud-siem%e3%81%a7slack%e7%92%b0%e5%a2%83%e3%82%92%e4%bf%9d%e8%ad%b7"},"modified":"2026-02-25T04:27:47","modified_gmt":"2026-02-25T12:27:47","slug":"monitor-slack-audit-logs-cloud-siem","status":"publish","type":"blog","link":"https:\/\/www.sumologic.com\/ja\/blog\/monitor-slack-audit-logs-cloud-siem","title":{"rendered":"Sumo Logic Cloud SIEM\u3067Slack\u74b0\u5883\u3092\u4fdd\u8b77"},"content":{"rendered":"\n<section class=\"e-stn e-stn-0d652506f82b000a392973813b918ee25d5b4211 e-stn--glossary-inner-content e-stn--table-of-content\"><div class=\"container\">\n<div class=\"wp-block-b3rg-row e-row row\">\n<div class=\"wp-block-b3rg-column e-col e-col-1f7b3997080fc292474d26ff00c905d99d3520fa e-col--content-wrapper  col-sm-12 col-lg-12 col-xl-12\">\n<div class=\"e-div e-div-a1b32f66e1749758df41d5aea14f647cd10e362c e-div--card-btn-link\"><div class=\"e-img \">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"293\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/Header-blog-ThreatLabs_Slack_700x200_V2-1024x293.webp\" alt=\"Sumo Logic: Slack&#x74B0;&#x5883;&#x306E;&#x4FDD;&#x8B77;\" class=\"wp-image-25562\" title=\"\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/Header-blog-ThreatLabs_Slack_700x200_V2-1024x293.webp 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/Header-blog-ThreatLabs_Slack_700x200_V2-300x86.webp 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/Header-blog-ThreatLabs_Slack_700x200_V2-768x219.webp 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/Header-blog-ThreatLabs_Slack_700x200_V2-575x164.webp 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/Header-blog-ThreatLabs_Slack_700x200_V2.webp 1400w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<p>Slack\u306f\u3001\u793e\u5185\u5916\u30b3\u30df\u30e5\u30cb\u30b1\u30fc\u30b7\u30e7\u30f3\u304b\u3089\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u306b\u81f3\u308b\u307e\u3067\u3001\u591a\u304f\u306e\u7d44\u7e54\u306b\u3068\u3063\u3066\u4e0d\u53ef\u6b20\u306a\u3082\u306e\u3068\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u3057\u304b\u3057\u3001\u5c0e\u5165\u304c\u9032\u3080\u306b\u3064\u308c\u3001\u30ea\u30b9\u30af\u3082\u9ad8\u307e\u3063\u3066\u3044\u307e\u3059\u3002Slack\u306b\u306f\u77e5\u7684\u8ca1\u7523\u3001\u8a8d\u8a3c\u60c5\u5831\u3001\u8cb4\u91cd\u306a\u5075\u5bdf\u60c5\u5831\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u591a\u3044\u305f\u3081\u3001\u30cf\u30c3\u30ab\u30fc\u304cSlack\u3092\u6a19\u7684\u306b\u3059\u308b\u30b1\u30fc\u30b9\u304c\u5897\u3048\u3066\u3044\u307e\u3059\u3002   <\/p>\n\n\n\n<p><a href=\"https:\/\/www.sumologic.com\/ja\/solutions\/cloud-siem\" target=\"_blank\" data-type=\"link\" data-id=\"https:\/\/www.sumologic.com\/solutions\/cloud-siem\" rel=\"noreferrer noopener\">Sumo Logic Cloud SIEM \u306f\u3001\u00a0<\/a><a href=\"https:\/\/www.sumologic.com\/glossary\/audit-log\">\u76e3\u67fb\u30ed\u30b0<\/a>\u00a0\u3092\u76e3\u8996\u3057\u3066\u4e0d\u5be9\u306a\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u691c\u77e5\u3059\u308b\u3053\u3068\u3067\u3001\u00a0\u5185\u90e8\u304a\u3088\u3073\u7b2c\u4e09\u8005\u304b\u3089\u306e\u8105\u5a01\u306b\u5bfe\u3057\u3066 Slack \u306e\u5229\u7528\u3092\u4fdd\u8b77\u3057\u3001\u8cb4\u793e\u3068\u305d\u306e\u30c7\u30fc\u30bf\u306e\u5b89\u5168\u3092\u78ba\u4fdd\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-a-10-stolen-slack-cookie-led-to-a-major-breach\">\u76d7\u307e\u308c\u305f10\u30c9\u30eb\u306eSlack\u30af\u30c3\u30ad\u30fc\u304c\u3001\u3044\u304b\u306b\u3057\u3066\u5927\u898f\u6a21\u306a\u4fb5\u5bb3\u3092\u5f15\u304d\u3053\u3057\u305f\u304b<\/h2>\n\n\n\n<p>\u4f8b\u3068\u3057\u3066\u00a0<a href=\"https:\/\/www.ea.com\/news\/ea-statement-on-june-11-security-incident\" target=\"_blank\" rel=\"noreferrer noopener\">Electronic Arts\uff08EA\uff09<\/a>\u00a0\u306e\u60c5\u5831\u6f0f\u3048\u3044\u4e8b\u4ef6\u3092\u53d6\u308a\u4e0a\u3052\u307e\u3057\u3087\u3046\u3002\u3053\u306e\u30c7\u30fc\u30bf\u4fb5\u5bb3\u3067\u306f\u3001\u00a0<a href=\"https:\/\/www.vice.com\/en\/article\/how-ea-games-was-hacked-slack\/\" target=\"_blank\" rel=\"noreferrer noopener\">\u653b\u6483\u8005\u306f\u76d7\u307e\u308c\u305f Slack \u306e\u30af\u30c3\u30ad\u30fc\u3092 10\u30c9\u30eb\u3067\u8cfc\u5165\u3057\u307e\u3057\u305f<\/a>\u3002\u305d\u306e\u8cfc\u5165\u306b\u3088\u3063\u3066\u793e\u5185\u306e Slack \u30c1\u30e3\u30f3\u30cd\u30eb\u3078\u306e\u30a2\u30af\u30bb\u30b9\u6a29\u3092\u5f97\u305f\u653b\u6483\u8005\u306f\u3001 EA \u306e IT \u30c1\u30fc\u30e0\u306b\u30bd\u30fc\u30b7\u30e3\u30eb\u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u653b\u6483\u3092\u884c\u3044\u3001EA \u306e\u793e\u5185\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u3078\u306e\u30a2\u30af\u30bb\u30b9\u30fb\u30c8\u30fc\u30af\u30f3\u3092\u53d6\u5f97\u3057\u307e\u3057\u305f\u3002\u653b\u6483\u8005\u306f\u305d\u306e\u5f8c\u3001\u300eFIFA 21\u300f\u306e\u30b2\u30fc\u30e0\u306e\u30bd\u30fc\u30b9\u30b3\u30fc\u30c9\u3084\u72ec\u81ea\u306e\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u30ad\u30c3\u30c8\u3092\u542b\u3080 780GB \u306e\u30c7\u30fc\u30bf\u3092\u76d7\u307f\u51fa\u3057\u307e\u3057\u305f\u3002\u00a0<\/p>\n\n\n\n<p>EA \u3060\u3051\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u3002\u00a0<a href=\"https:\/\/www.wsj.com\/business\/media\/internal-disney-communications-leaked-online-after-hack-b57baaeb\" target=\"_blank\" rel=\"noreferrer noopener\">Disney<\/a>\u3001\u00a0<a href=\"https:\/\/www.cpomagazine.com\/cyber-security\/rockstar-gta6-leak-came-from-cyber-attack-that-breached-internal-slack-channel\/\" target=\"_blank\" rel=\"noreferrer noopener\">Rockstar<\/a>\u3001\u00a0<a href=\"https:\/\/www.cpomagazine.com\/cyber-security\/major-cybersecurity-incident-at-uber-network-breach-began-with-social-engineering-by-teenage-culprit-sensitive-information-stored-in-plaintext\/\" target=\"_blank\" rel=\"noreferrer noopener\">Uber<\/a>\u3084\u00a0<a href=\"https:\/\/mashable.com\/article\/slack-key-to-twitter-hack\" target=\"_blank\" rel=\"noreferrer noopener\">Twitter<\/a>\u00a0\u306a\u3069\u306e\u6709\u540d\u4f01\u696d\u3082\u3001Slack \u304c\u653b\u6483\u6210\u529f\u306e\u4e3b\u8981\u306a\u8981\u56e0\u3068\u306a\u3063\u305f\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u306e\u88ab\u5bb3\u3092\u53d7\u3051\u3066\u3044\u307e\u3059\u3002\u00a0<\/p>\n\n\n\n<p>Slack\u304c\u653b\u6483\u8005\u306b\u3068\u3063\u3066\u91cd\u8981\u306a\u62e0\u70b9\u3001\u3042\u308b\u3044\u306f\u6700\u7d42\u76ee\u6a19\u3068\u306a\u308b\u7406\u7531\u306f\u3001\u7406\u89e3\u306b\u96e3\u304f\u306a\u3044\u3068\u3044\u3048\u308b\u3067\u3057\u3087\u3046\u3002\u306a\u305c\u306a\u3089Slack\u306f\u3001\u521d\u671f\u30a2\u30af\u30bb\u30b9\u3084\u767a\u898b\u3001\u8cc7\u683c\u60c5\u5831\u306e\u76d7\u96e3\u3001\u62bd\u51fa\u306a\u3069\u3001\u3055\u307e\u3056\u307e\u306a\u6226\u8853\u3092\u5b9f\u884c\u3059\u308b\u306e\u306b\u683c\u597d\u306e\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u3067\u3042\u308b\u304b\u3089\u3067\u3059\u3002\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-slack-s-audit-logs-are-key-for-better-security\">Slack\u306e\u76e3\u67fb\u30ed\u30b0\u304c\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5411\u4e0a\u306e\u9375\u3068\u306a\u308b\u7406\u7531<\/h2>\n\n\n\n<p>Slack\u304c\u653b\u6483\u306e\u305f\u3081\u306e\u9b45\u529b\u7684\u306a\u30bf\u30fc\u30b2\u30c3\u30c8\u3067\u3042\u308b\u3053\u3068\u3092\u3088\u304f\u7406\u89e3\u3057\u3001\u60aa\u610f\u306e\u3042\u308b\u52d5\u4f5c\u304c\u898b\u3089\u308c\u306a\u3044\u304b\u3001\u7d99\u7d9a\u7684\u306aSlack\u74b0\u5883\u306e\u76e3\u8996\u304c\u5fc5\u8981\u3068\u306a\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u76e3\u8996\u3092\u59cb\u3081\u308b 1\u3064\u306e\u65b9\u6cd5\u306f\u3001\u30ed\u30b0\u3092\u6d3b\u7528\u3059\u308b\u3053\u3068\u3067\u3059\u3002\u00a0<a href=\"https:\/\/help.sumologic.com\/docs\/integrations\/saas-cloud\/slack\/#log-types\" target=\"_blank\" rel=\"noreferrer noopener\">Slack \u306b\u306f\u3001\u76e3\u67fb\u30ed\u30b0\u3084\u30a2\u30af\u30bb\u30b9\u30ed\u30b0\u306a\u3069\u3001\u8907\u6570\u7a2e\u985e\u306e\u30ed\u30b0\u304c\u7528\u610f\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/a>\u672c\u8a18\u4e8b\u3067\u306f\u3001Slack \u304c\u300c\u7d99\u7d9a\u7684\u306a\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u306e\u78ba\u4fdd\u3001\u4e0d\u9069\u5207\u306a\u30b7\u30b9\u30c6\u30e0\u30a2\u30af\u30bb\u30b9\u306e\u9632\u6b62\u3001\u305d\u3057\u3066\u4f01\u696d\u5185\u306e\u4e0d\u5be9\u306a\u884c\u52d5\u3092\u76e3\u67fb\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u300d\u305f\u3081\u306b\u751f\u6210\u3057\u3066\u3044\u308b\u00a0<a href=\"https:\/\/api.slack.com\/admins\/audit-logs#what\" target=\"_blank\" rel=\"noreferrer noopener\">\u76e3\u67fb\u30ed\u30b0<\/a>\u306b\u7126\u70b9\u3092\u5f53\u3066\u3066\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u76e3\u67fb\u30ed\u30b0\u3068\u3001\u3053\u308c\u3089\u306bAPI\u7d4c\u7531\u3067\u30a2\u30af\u30bb\u30b9\u3059\u308b\u305f\u3081\u306e\u6a5f\u80fd\u306f\u3001\u00a0<a href=\"https:\/\/www.sumologic.com\/ja\/solutions\/cloud-siem\">Sumo Logic\u306e\u3088\u3046\u306aSIEM\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3<\/a>\u00a0\u304c\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u76e3\u8996\u3084\u7d71\u5408\u3092\u5b9f\u884c\u3059\u308b\u4e0a\u3067\u4e0d\u53ef\u6b20\u3068\u306a\u308a\u307e\u3059\u3002\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"use-slack-s-audit-logs-to-perform-threat-detection\">Slack\u306e\u76e3\u67fb\u30ed\u30b0\u3092\u4f7f\u7528\u3057\u3066\u8105\u5a01\u691c\u51fa\u3092\u5b9f\u884c<\/h3>\n\n\n\n<p>\u00a0<a href=\"https:\/\/slack.engineering\/slack-audit-logs-and-anomalies\/\" target=\"_blank\" rel=\"noreferrer noopener\">Slack \u76e3\u67fb\u30ed\u30b0<\/a>\u00a0\u306e\u6709\u7528\u306a\u6a5f\u80fd\u306e 1\u3064\u304c\u300c\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u300d\u3067\u3059\u3002\u3053\u308c\u306f\u3001Slack \u304c\u901a\u5e38\u3068\u7570\u306a\u308b\u64cd\u4f5c\u3084\u6319\u52d5\u3092\u691c\u77e5\u3057\u305f\u3068\u304d\u306b\u81ea\u52d5\u7684\u306b\u751f\u6210\u3055\u308c\u307e\u3059\u3002\u3059\u3079\u3066\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u306b\u5bfe\u5fdc\u304c\u5fc5\u8981\u306a\u308f\u3051\u3067\u306f\u306a\u304f\u3001\u30a4\u30d9\u30f3\u30c8\u306e\u7a2e\u985e\u3054\u3068\u306b\u78ba\u4fe1\u5ea6\u30ec\u30d9\u30eb\u3082\u7570\u306a\u308a\u307e\u3059\u3002\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u304c\u30c8\u30ea\u30ac\u30fc\u3055\u308c\u305f\u969b\u306b\u3001\u305d\u308c\u3092\u7cbe\u67fb\u3057\u3001\u5bfe\u5fdc\u304c\u5fc5\u8981\u304b\u3069\u3046\u304b\u5224\u65ad\u3059\u308b\u305f\u3081\u306b\u3001\u8ffd\u52a0\u306e\u8abf\u67fb\u304c\u5fc5\u8981\u306b\u306a\u308b\u3053\u3068\u304c\u591a\u3044\u3067\u3057\u3087\u3046\u3002<\/p>\n\n\n\n<p>Slack\u306f\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u306e\u4fe1\u983c\u30ec\u30d9\u30eb\u3092\u63d0\u4f9b\u3057\u3066\u3044\u307e\u305b\u3093\u304c\u3001\u4e00\u90e8\u306e\u30a4\u30d9\u30f3\u30c8\u306b\u95a2\u3057\u3066\u306f\u3001\u4fb5\u5bb3\u6307\u6a19\u306e\u4fe1\u983c\u5ea6\u304c\u9ad8\u3044\u3068\u307f\u306a\u3055\u308c\u308b\u3053\u3068\u3092\u660e\u78ba\u306b\u3057\u3066\u3044\u307e\u3059\u3002\u00a0<\/p>\n\n\n\n<p>\u00a0<a href=\"https:\/\/slack.com\/help\/articles\/37193054707603-Configure-audit-log-anomaly-event-responses-in-Slack\" target=\"_blank\" rel=\"noreferrer noopener\">\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u5bfe\u5fdc\u6a5f\u80fd<\/a>\u00a0\u3092\u898b\u308b\u3068\u3001Slack \u304c\u3069\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u3092\u9ad8\u78ba\u4fe1\u5ea6\u3068\u307f\u306a\u3057\u3066\u3044\u308b\u304b\u306b\u3064\u3044\u3066\u306e\u624b\u304c\u304b\u308a\u3082\u5f97\u3089\u308c\u307e\u3059\u3002\u3053\u306e\u6a5f\u80fd\u306f\u3001\u7279\u5b9a\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u304c\u30e6\u30fc\u30b6\u30fc\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305f\u5834\u5408\u3001\u305d\u306e\u30e6\u30fc\u30b6\u30fc\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u81ea\u52d5\u7684\u306b\u7d42\u4e86\u3057\u307e\u3059\u3002\u30c7\u30d5\u30a9\u30eb\u30c8\u3067\u5bfe\u8c61\u3068\u306a\u3063\u3066\u3044\u308b 2\u3064\u306e\u30a4\u30d9\u30f3\u30c8\u306f\u300cTor \u306e\u51fa\u53e3\u30ce\u30fc\u30c9\u304b\u3089 Slack \u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066\u3044\u308b\u5834\u5408\u300d\u3068\u300c\u30c7\u30fc\u30bf\u30b9\u30af\u30ec\u30a4\u30d4\u30f3\u30b0\u300d\u3067\u3042\u308a\u3001Slack \u306e\u30a8\u30f3\u30b8\u30cb\u30a2\u30ea\u30f3\u30b0\u30c1\u30fc\u30e0\u304c\u3053\u308c\u3089 2\u3064\u306e\u691c\u77e5\u3092\u9ad8\u78ba\u4fe1\u5ea6\u3068\u8003\u3048\u3066\u3044\u308b\u3053\u3068\u304c\u3046\u304b\u304c\u3048\u307e\u3059\u3002<\/p>\n\n\n\n<p>Slack\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u306f\u3001SIEM\u3067\u53d6\u308a\u8fbc\u3093\u3067\u5206\u6790\u3067\u304d\u308b\u305f\u3081\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30c1\u30fc\u30e0\u306b\u3068\u3063\u3066\u7279\u306b\u6709\u7528\u3067\u3059\u3002Sumo Logic Cloud SIEM\u306fSlack\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u3092\u5b8c\u5168\u306b\u30b5\u30dd\u30fc\u30c8\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30a4\u30d9\u30f3\u30c8\u306f\u00a0<a href=\"https:\/\/help.sumologic.com\/docs\/cse\/rules\/normalized-threat-rules\/\" target=\"_blank\" rel=\"noreferrer noopener\">\u8105\u5a01\u30a2\u30e9\u30fc\u30c8<\/a>\u00a0\u3068\u3057\u3066\u6b63\u898f\u5316\u3055\u308c\u3001\u300c\u6b63\u898f\u5316\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b7\u30b0\u30ca\u30eb\u300d\uff08MATCH-S00402\uff09\u3068\u3044\u3046\u30eb\u30fc\u30eb\u3092\u30c8\u30ea\u30ac\u30fc\u3057\u307e\u3059\u3002\u3064\u307e\u308a\u3001\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u306f\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u306e\u00a0<a href=\"https:\/\/help.sumologic.com\/docs\/cse\/get-started-with-cloud-siem\/insight-generation-process\/#understanding-entity-activity-scores\" target=\"_blank\" rel=\"noreferrer noopener\">\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u30b9\u30b3\u30a2<\/a>\u306b\u8ca2\u732e\u3067\u304d\u307e\u3059\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u30a2\u30ca\u30ea\u30b9\u30c8\u306f\u4e0d\u5be9\u306a\u6319\u52d5\u3092\u793a\u3059\u30e6\u30fc\u30b6\u3084\u30b7\u30b9\u30c6\u30e0\u3092\u8fc5\u901f\u306b\u7279\u5b9a\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"705\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img1-1-1024x705.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img1-1-300x206.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img1-1-768x528.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img1-1-575x396.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img1-1.png 1404w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img1-1-1024x705.png\" alt=\"blog slack env img1 1\" title=\"\"><\/p>\n\n\n\n<p><em>Sumo Cloud SIEM\u30b7\u30b0\u30ca\u30eb\u3068\u3057\u3066\u6e21\u3055\u308c\u308bSlack\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8<\/em><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"748\" height=\"1024\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img2-1-748x1024.png 748w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img2-1-219x300.png 219w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img2-1-768x1051.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img2-1-575x787.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img2-1.png 1046w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img2-1-748x1024.png\" alt=\"blog slack env img2 1\" title=\"\"><\/p>\n\n\n\n<p><em>Slack\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u5bfe\u5fdc\u306b\u304a\u3051\u308b\u30c7\u30d5\u30a9\u30eb\u30c8\u8a2d\u5b9a<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-to-collect-and-ingest-slack-audit-logs-with-sumo-logic\">Sumo Logic\u3067Slack\u306e\u76e3\u67fb\u30ed\u30b0\u3092\u53ce\u96c6\u3057\u3066\u53d6\u308a\u8fbc\u3080\u65b9\u6cd5<\/h2>\n\n\n\n<p>Sumo Logic\u3067Slack\u306e\u76e3\u67fb\u30ed\u30b0\u3092\u53ce\u96c6\u3059\u308b\u65b9\u6cd5\u306f\u975e\u5e38\u306b\u7c21\u5358\u3067\u3059\u3002<a href=\"https:\/\/help.sumologic.com\/docs\/send-data\/hosted-collectors\/cloud-to-cloud-integration-framework\/slack-source\/\" target=\"_blank\" rel=\"noreferrer noopener\">\u00a0\u8a73\u7d30\u30ac\u30a4\u30c9<\/a>\u00a0\u3067\u306fSlack\u304b\u3089\u30ed\u30b0\u3092\u53ce\u96c6\u3059\u308b\u65b9\u6cd5\u3092\u8aac\u660e\u3057\u3066\u3044\u307e\u3059\u304c\u3001\u3053\u3053\u3067\u306f\u624b\u9806\u306e\u6982\u8981\u3060\u3051\u3092\u3054\u7d39\u4ecb\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Slack Enterprise Grid\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u6301\u3063\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002Enterprise Grid\u30a2\u30ab\u30a6\u30f3\u30c8\u306a\u3057\u3067\u306fSlack\u306e\u76e3\u67fb\u30ed\u30b0\u306e\u53ce\u96c6\u304c\u3067\u304d\u307e\u305b\u3093\u3002<\/li>\n\n\n\n<li>\u00a0<code>auditlogs:read<\/code>\u00a0\u6a29\u9650\u3092\u6301\u3064Slack\u30a2\u30d7\u30ea\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<\/li>\n\n\n\n<li>Enterprise Grid\u3067\u30a2\u30d7\u30ea\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3059\u3002<\/li>\n\n\n\n<li>Sumo Logic Slack Cloud-to-Cloud Connector\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3001\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/li>\n\n\n\n<li>\u91cd\u8981\uff1a\u300cSIEM\u306b\u8ee2\u9001\u300d\u30c1\u30a7\u30c3\u30af\u30dc\u30c3\u30af\u30b9\u304c\u9078\u629e\u3055\u308c\u3066\u304a\u308a\u3001Slack\u306e\u30ed\u30b0\u30bd\u30fc\u30b9\u304cSIEM\u306b\u30ed\u30b0\u3092\u8ee2\u9001\u3059\u308b\u3088\u3046\u306b\u8a2d\u5b9a\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u3054\u78ba\u8a8d\u304f\u3060\u3055\u3044\u3002\u00a0\u00a0<\/li>\n<\/ol>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"784\" height=\"1024\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img3-1-784x1024.png\" alt=\"blog slack env img3 1\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img3-1-784x1024.png 784w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img3-1-230x300.png 230w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img3-1-768x1003.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img3-1-575x751.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img3-1.png 812w\" title=\"\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-security-analysts-can-use-slack-logs-for-threat-detection-investigation-and-response\">\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30a2\u30ca\u30ea\u30b9\u30c8\u304c\u8105\u5a01\u306e\u691c\u51fa\u3001\u8abf\u67fb\u3001\u304a\u3088\u3073\u5bfe\u5fdc\u306bSlack\u306e\u30ed\u30b0\u3092\u6d3b\u7528\u3059\u308b\u65b9\u6cd5\u00a0<\/h2>\n\n\n\n<p>Slack\u306f\u3001\u81ea\u793e\u306e\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u4e0a\u3067\u3069\u306e\u3088\u3046\u306a\u52d5\u4f5c\u304c\u7570\u5e38\u3068\u307f\u306a\u3055\u308c\u308b\u3079\u304d\u304b\u306b\u3064\u3044\u3066\u72ec\u81ea\u306e\u5b9a\u7fa9\u3092\u884c\u3063\u3066\u3044\u308b\u305f\u3081\u3001\u7570\u5e38\u306a\u52d5\u4f5c\u306e\u691c\u51fa\u3084\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u306e\u751f\u6210\u306f\u9867\u5ba2\u306b\u3068\u3063\u3066\u975e\u5e38\u306b\u4fa1\u5024\u306e\u3042\u308b\u30b5\u30fc\u30d3\u30b9\u3068\u306a\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u305f\u3060\u3057\u3001Slack Engineering\u306f\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u751f\u6210\u306b\u304a\u3051\u308b\u691c\u51fa\u57fa\u6e96\u3092\u516c\u958b\u3057\u3066\u3044\u307e\u305b\u3093\u3002\u305d\u306e\u7406\u7531\u306f\u60f3\u50cf\u306b\u96e3\u304f\u3042\u308a\u307e\u305b\u3093\u3002\u57fa\u6e96\u304c\u516c\u958b\u3055\u308c\u3066\u3044\u308c\u3070\u3001\u653b\u6483\u8005\u304c\u9632\u5fa1\u3092\u56de\u907f\u3059\u308b\u30c6\u30af\u30cb\u30c3\u30af\u3092\u8003\u6848\u3057\u3084\u3059\u304f\u306a\u308b\u304b\u3089\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u3057\u304b\u3057\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30a2\u30ca\u30ea\u30b9\u30c8\u306b\u3068\u3063\u3066\u306f\u3001\u3053\u308c\u306f\u7269\u4e8b\u3092\u96e3\u3057\u304f\u3057\u307e\u3059\u3002\u30a2\u30e9\u30fc\u30c8\u304c\u30c8\u30ea\u30ac\u30fc\u3055\u308c\u305f\u7406\u7531\u3092\u6b63\u78ba\u306b\u77e5\u3089\u306a\u3051\u308c\u3070\u3001\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u3092\u30c8\u30ea\u30ac\u30fc\u3057\u305f\u76e3\u67fb\u30ed\u30b0\u3092\u691c\u7d22\u3059\u308b\u305f\u3081\u306e\u30af\u30a8\u30ea\u306e\u7b56\u5b9a\u306b\u591a\u304f\u306e\u6642\u9593\u3092\u8cbb\u3084\u3059\u3053\u3068\u306b\u306a\u308b\u3067\u3057\u3087\u3046\u3002\u5206\u6790\u306e\u30c1\u30e5\u30fc\u30cb\u30f3\u30b0\u3084\u507d\u9670\u6027\u306e\u8a55\u4fa1\u3082\u540c\u69d8\u306e\u7406\u7531\u3067\u96e3\u3057\u304f\u306a\u308a\u3001\u63a8\u6e2c\u304c\u5fc5\u8981\u306b\u306a\u308b\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u3002<\/p>\n\n\n\n<p>\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u691c\u51fa\u306e\u7406\u7531\u306b\u3088\u3063\u3066\u306f\u3001\u30a4\u30d9\u30f3\u30c8\u306e\u30c8\u30ea\u30ac\u30fc\u3068\u306a\u3063\u305f\u539f\u56e0\u304c\u4ed6\u306e\u7406\u7531\u3088\u308a\u3082\u660e\u78ba\u306b\u793a\u3055\u308c\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u308c\u306b\u5bfe\u3057\u3001\u300cexcessive_downloads\u300d\u306a\u3069\u306e\u30b1\u30fc\u30b9\u306f\u66d6\u6627\u306b\u306a\u308a\u304c\u3061\u3067\u3001\u30a4\u30d9\u30f3\u30c8\u306b\u81f3\u308b\u307e\u3067\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u691c\u7d22\u3057\u3001\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u5185\u5bb9\u3092\u78ba\u8a8d\u3059\u308b\u304b\u3001\u4ee5\u524d\u306e\u671f\u9593\u3068\u6bd4\u8f03\u3059\u308b\u3053\u3068\u3067\u3001\u30e6\u30fc\u30b6\u30fc\u306b\u3088\u308b\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u91cf\u306e\u300c\u6b63\u5e38\u300d\u6027\u3092\u8a55\u4fa1\u3059\u308b\u5fc5\u8981\u304c\u751f\u3058\u307e\u3059\u3002\u00a0<\/p>\n\n\n\n<p>\u305d\u308c\u3067\u306f\u3001\u5b9f\u969b\u306b\u3053\u308c\u3089\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u3092\u8abf\u67fb\u3059\u308b\u65b9\u6cd5\u3092\u6398\u308a\u4e0b\u3052\u3066\u3044\u304d\u307e\u3057\u3087\u3046\u3002\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"investigating-potential-cookie-theft-in-slack\">Slack\u306b\u304a\u3051\u308b\u6f5c\u5728\u7684\u306a\u30af\u30c3\u30ad\u30fc\u76d7\u96e3\u306e\u8abf\u67fb\u00a0<\/h2>\n\n\n\n<p>EA \u306e\u60c5\u5831\u6f0f\u3048\u3044\u306e\u4f8b\u306b\u623b\u308a\u307e\u3057\u3087\u3046\u3002\u3053\u3053\u3067\u306f\u653b\u6483\u8005\u304c\u76d7\u307e\u308c\u305f\u30af\u30c3\u30ad\u30fc\u3092\u4f7f\u3063\u3066\u793e\u5185\u30b7\u30b9\u30c6\u30e0\u306b\u30a2\u30af\u30bb\u30b9\u3057\u307e\u3057\u305f\u3002\u76d7\u307e\u308c\u305f\u30af\u30c3\u30ad\u30fc\u304c\u518d\u5229\u7528\u3055\u308c\u305f\u5834\u5408\u3001\u3069\u306e Slack \u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u304c\u767a\u751f\u3059\u308b\u3068\u8003\u3048\u3089\u308c\u308b\u3067\u3057\u3087\u3046\u304b\uff1f \u3082\u3057\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u304c\u30ed\u30b0\u3068\u3057\u3066\u8a18\u9332\u3055\u308c\u3066\u3044\u308b\u306a\u3089\u3001\u305d\u308c\u3089\u3092\u3069\u306e\u3088\u3046\u306b\u8abf\u67fb\u3067\u304d\u308b\u3067\u3057\u3087\u3046\u304b\uff1f<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"understanding-slack-session-ids\">Slack\u30bb\u30c3\u30b7\u30e7\u30f3ID\u3092\u7406\u89e3\u3059\u308b\u3068\u3044\u3046\u3053\u3068<\/h3>\n\n\n\n<p>\u30e6\u30fc\u30b6\u30fc\u304c Slack \u306b\u30ed\u30b0\u30a4\u30f3\u3059\u308b\u305f\u3073\u306b\u3001\u30bb\u30c3\u30b7\u30e7\u30f3 ID \u304c\u751f\u6210\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u30bb\u30c3\u30b7\u30e7\u30f3\u306f\u3001\u30c7\u30d0\u30a4\u30b9\u4e0a\u306e\u30af\u30c3\u30ad\u30fc\u3068\u3057\u3066\u4fdd\u6301\u3055\u308c\u307e\u3059\u3002\u901a\u5e38\u3001\u5404\u30bb\u30c3\u30b7\u30e7\u30f3 ID \u306f 1\u3064\u306e\u30c7\u30d0\u30a4\u30b9\u306b\u5bfe\u5fdc\u3057\u3066\u3044\u308b\u3068\u8003\u3048\u3089\u308c\u307e\u3059\u3002\u3082\u3057\u30af\u30c3\u30ad\u30fc\u304c\u76d7\u307e\u308c\u3001\u5225\u306e\u30c7\u30d0\u30a4\u30b9\u3067\u4f7f\u7528\u3055\u308c\u305f\u5834\u5408\u3001\u6b21\u306e\u3088\u3046\u306a\u8a3c\u62e0\u306b\u5dee\u7570\u304c\u73fe\u308c\u308b\u53ef\u80fd\u6027\u304c\u9ad8\u304f\u306a\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u6587\u5b57\u5217<\/li>\n\n\n\n<li>IP\u30a2\u30c9\u30ec\u30b9\u3068\u5834\u6240<\/li>\n\n\n\n<li>TLS\u30cf\u30f3\u30c9\u30b7\u30a7\u30a4\u30af\uff08ja3\u30d5\u30a3\u30f3\u30ac\u30fc\u30d7\u30ea\u30f3\u30c8\uff09\u00a0<\/li>\n<\/ul>\n\n\n\n<p>\u3053\u308c\u3089\u306e\u30b7\u30b0\u30ca\u30eb\u306f\u3001\u4e0d\u5be9\u306a\u30af\u30c3\u30ad\u30fc\u518d\u5229\u7528\u306e\u7279\u5b9a\u306b\u5f79\u7acb\u3061\u307e\u3059\u304c\u3001Slack \u306e\u76e3\u67fb\u30ed\u30b0\u306f\u5bfe\u8a71\u7684\u306a\u30a2\u30af\u30b7\u30e7\u30f3\u306b\u5bfe\u3057\u3066\u306e\u307f\u751f\u6210\u3055\u308c\u308b\u3053\u3068\u306b\u8981\u6ce8\u610f\u3067\u3059\u3002\u30e1\u30c3\u30bb\u30fc\u30b8\u3092\u30af\u30ea\u30c3\u30af\u3084\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u305b\u305a\u306b\u95b2\u89a7\u3060\u3051\u3068\u3044\u3063\u305f\u53d7\u52d5\u7684\u306a\u30a2\u30af\u30bb\u30b9\u3067\u306f\u3001\u30ed\u30b0\u304c\u8a18\u9332\u3055\u308c\u306a\u3044\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002\u305d\u306e\u305f\u3081\u3001\u30af\u30c3\u30ad\u30fc\u518d\u5229\u7528\u306e\u691c\u77e5\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u884c\u52d5\u5185\u5bb9\u306b\u5927\u304d\u304f\u4f9d\u5b58\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u3053\u308c\u3089\u306e\u9055\u3044\u306f\u3001\u540c\u3058\u30bb\u30c3\u30b7\u30e7\u30f3ID\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305f\u30ed\u30b0\u306b\u53cd\u6620\u3055\u308c\u307e\u3059\u3002<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"186\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img4-1-1024x186.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img4-1-300x55.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img4-1-768x140.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img4-1-575x105.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img4-1.png 1230w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img4-1-1024x186.png\" alt=\"blog slack env img4 1\" title=\"\"><\/p>\n\n\n\n<p><em>Sumo Logic Cloud SIEM\u30ec\u30b3\u30fc\u30c9\u306b\u8868\u793a\u3055\u308c\u308bSlack\u30bb\u30c3\u30b7\u30e7\u30f3ID\u306e\u4f8b<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"anomaly-events-that-could-signal-cookie-theft\">Cookie\u306e\u76d7\u96e3\u3092\u793a\u5506\u3059\u308b\u7570\u5e38\u30a4\u30d9\u30f3\u30c8<\/h3>\n\n\n\n<p>Cookie\u306e\u76d7\u96e3\u306b\u3088\u3063\u3066\u30c8\u30ea\u30ac\u30fc\u3055\u308c\u308b\u00a0<a href=\"https:\/\/api.slack.com\/admins\/audit-logs-anomaly\" target=\"_blank\" rel=\"noreferrer noopener\">Slack\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8<\/a>\u00a0\u3068\u3057\u3066\u306f\u3001\u3044\u304f\u3064\u304b\u306e\u5019\u88dc\u304c\u3042\u308a\u307e\u3059\u3002\u00a0<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>asn<\/code><\/li>\n\n\n\n<li><code>ip_address<\/code><\/li>\n\n\n\n<li><code>session_fingerprint<\/code><\/li>\n\n\n\n<li><code>tor<\/code><\/li>\n\n\n\n<li><code>unexpected_client<\/code><\/li>\n\n\n\n<li><code>unexpected_user_agent<\/code><\/li>\n\n\n\n<li><code>user_agent<\/code><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"hunt-for-potential-cookie-theft-using-sumo-logic\">Sumo Logic\u3092\u6d3b\u7528\u3057\u305f\u6f5c\u5728\u7684\u306aCookie\u76d7\u96e3\u306e\u8ffd\u8de1<\/h3>\n\n\n\n<p>\u4ee5\u4e0a\u306e\u77e5\u8b58\u3092\u5143\u306b\u3001\u307e\u305a\u306f\u5e83\u7bc4\u56f2\u306b\u308f\u305f\u308b\u8abf\u67fb\u3092\u884c\u3044\u3001\u904e\u53bb2\u9031\u9593\u306b\u81ea\u793e\u74b0\u5883\u5185\u3067\u767a\u751f\u3057\u305fSlack\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u3092\u3059\u3079\u3066\u691c\u7d22\u3057\u307e\u3059\u3002\u6b21\u306e\u691c\u7d22\u3067\u306f\u3001Slack\u306b\u304a\u3051\u308b\u3059\u3079\u3066\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u304c\u8fd4\u3055\u308c\u3001\u7406\u7531\u5225\u306b\u30b0\u30eb\u30fc\u30d7\u5316\u3055\u308c\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">_index=sec_record_notification metadata_vendor=\"Slack\" metadata_deviceEventId=\"anomaly\"\n| count by threat_signalName<\/pre>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"635\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img5-1-1024x635.png\" alt=\"blog slack env img5 1\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img5-1-1024x635.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img5-1-300x186.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img5-1-768x476.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img5-1-575x356.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img5-1.png 1094w\" title=\"\"><\/p>\n\n\n\n<p><em>\u56f34\uff1a\u7406\u7531\u5225\u306b\u30b0\u30eb\u30fc\u30d7\u5316\u3055\u308c\u305fSlack\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8<\/em><\/p>\n\n\n\n<p>\u3053\u3061\u3089\u306e\u4f8b\u3067\u306f\u3001323\u4ef6\u306e\u691c\u7d22\u7d50\u679c\u304c\u8fd4\u3055\u308c\u307e\u3057\u305f\u3002\u6ce8\u76ee\u3059\u3079\u304d\u70b9\u306f2\u3064\u3042\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u00a0<code>asn|ip_address<\/code>\u00a0\u3084\u00a0<code>unexpected_user_agent|user_agent<\/code>\u306a\u3069\u306e\u7d50\u679c\u304b\u3089\u660e\u3089\u304b\u306a\u3088\u3046\u306b\u3001\u7570\u5e38\u306b\u306f\u8907\u6570\u306e\u7406\u7531\u304c\u5272\u308a\u5f53\u3066\u3089\u308c\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002<\/li>\n\n\n\n<li>\u7570\u5e38\u306e\u7406\u7531\u3068\u3057\u3066\u6700\u3082\u591a\u3044\u306e\u306fasn|ip_address\u3067\u3059\u3002\u3053\u308c\u3089\u306e\u30a4\u30d9\u30f3\u30c8\u306f\u3001\u00a0<a href=\"https:\/\/api.slack.com\/admins\/audit-logs-anomaly#exclude\" target=\"_blank\" rel=\"noreferrer noopener\">\u9664\u5916\u30ea\u30b9\u30c8\u306bAPI\u7d4c\u7531<\/a>\u3067\u4fe1\u983c\u6027\u306e\u3042\u308b\u81ea\u5f8b\u30b7\u30b9\u30c6\u30e0\u756a\u53f7\uff08ASN\uff09\u3068IP\u30a2\u30c9\u30ec\u30b9\u7bc4\u56f2\u306e\u8ffd\u52a0\u3067\u8abf\u6574\u304c\u53ef\u80fd\u3067\u3059\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u6b21\u306b\u3001\u00a0<code>unexpected_user_agent<\/code>\u00a0\u304a\u3088\u3073\u00a0<code>user_agent<\/code>\u306e\u7406\u7531\u304c\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305f\u30a4\u30d9\u30f3\u30c8\u306b\u7126\u70b9\u3092\u7d5e\u308b\u3053\u3068\u3067\u3001\u76d7\u307e\u308c\u305fCookie\u306e\u8ffd\u8de1\u3092\u7d9a\u884c\u3057\u307e\u3059\u3002\u6b21\u306e\u30af\u30a8\u30ea\u3092\u4f7f\u7528\u3057\u3001\u3053\u308c\u3089\u306e\u30a4\u30d9\u30f3\u30c8\u304a\u3088\u3073\u30bb\u30c3\u30b7\u30e7\u30f3ID\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">_index=sec_record_notification metadata_vendor=\"Slack\" metadata_deviceEventId=\"anomaly\"\n| where threat_signalName = \"Anomaly Event : unexpected_user_agent|user_agent\"\n| count by sessionId<\/pre>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"810\" height=\"410\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img6-1.png\" alt=\"blog slack env img6 1\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img6-1.png 810w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img6-1-300x152.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img6-1-768x389.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img6-1-575x291.png 575w\" title=\"\"><\/p>\n\n\n\n<p><em>\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u00a0<code>unexpected_user_agent<\/code>\u00a0\u306e\u30bb\u30c3\u30b7\u30e7\u30f3ID<\/em><\/p>\n\n\n\n<p>\u8abf\u67fb\u3059\u3079\u304d\u7570\u5e38\u304c\u898b\u3064\u304b\u308a\u6b21\u7b2c\u3001\u8a73\u7d30\u3092\u6398\u308a\u4e0b\u3052\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u306e\u8a73\u7d30\u3092\u78ba\u8a8d\u3059\u308b\u3053\u3068\u3067\u3001\u30a4\u30d9\u30f3\u30c8\u304c\u30c8\u30ea\u30ac\u30fc\u3055\u308c\u305f\u7406\u7531\u306b\u3064\u3044\u3066\u306e\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u3092\u5f97\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"857\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img7-1-1024x857.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img7-1-300x251.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img7-1-768x643.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img7-1-575x481.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img7-1.png 1432w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img7-1-1024x857.png\" alt=\"blog slack env img7 1\" title=\"\"><\/p>\n\n\n\n<p><em>\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u00a0<code>unexpected_user_agent|user_agent<\/code>\u00a0\u306e\u8a73\u7d30<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"analyzing-the-anomaly-event\">\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u306e\u5206\u6790<\/h3>\n\n\n\n<p>\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u306e\u00a0<code>details<\/code>\u00a0\u30e1\u30bf\u30c7\u30fc\u30bf\u306b\u306f\u3001\u30a4\u30d9\u30f3\u30c8\u304c\u30c8\u30ea\u30ac\u30fc\u3055\u308c\u305f\u7406\u7531\uff08IP\u30a2\u30c9\u30ec\u30b9\u3068\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u306e\u5909\u66f4\uff09\u304c\u8868\u793a\u3055\u308c\u307e\u3059\u3002\u00a0<\/p>\n\n\n\n<p><strong>IP\u30a2\u30c9\u30ec\u30b9\u306e\u5909\u66f4<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u73fe\u5728\u306eIP\u30a2\u30c9\u30ec\u30b9\uff1a\u00a0<code>172.59.222.55<\/code><\/li>\n\n\n\n<li>\u4ee5\u524d\u306eIP\u30a2\u30c9\u30ec\u30b9\uff1a\u00a0<code>204.16.138.54<\/code><\/li>\n<\/ul>\n\n\n\n<p>IP\u30a2\u30c9\u30ec\u30b9\u306e\u5909\u66f4\u304c\u3001\u30c7\u30d0\u30a4\u30b9\u304c\u30e6\u30fc\u30b6\u30fc\u306e\u3082\u306e\u304b\u3089\u653b\u6483\u8005\u306e\u3082\u306e\u306b\u5909\u308f\u3063\u305f\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u308b\u306e\u3067\u3057\u3087\u3046\u304b\uff1f\u305d\u306e\u53ef\u80fd\u6027\u304c\u306a\u3044\u3068\u306f\u3044\u3048\u307e\u305b\u3093\u304c\u3001\u30c7\u30d0\u30a4\u30b9\u304c\u30e2\u30d0\u30a4\u30eb\u7aef\u672b\u3067\u3042\u308b\u3053\u3068\u3001\u307e\u305fgeoIP\u60c5\u5831\u306b\u304a\u3044\u3066\u4e21\u65b9\u306e\u30a2\u30c9\u30ec\u30b9\u304c\u30ce\u30fc\u30b9\u30ab\u30ed\u30e9\u30a4\u30ca\u5dde\u30b7\u30e3\u30fc\u30ed\u30c3\u30c8\u306e\u5468\u8fba\u5730\u57df\u3092\u8868\u793a\u3057\u3066\u3044\u308b\u3053\u3068\u304b\u3089\u3001\u30c7\u30d0\u30a4\u30b9\u306e\u5909\u66f4\u306f\u7591\u308f\u308c\u307e\u305b\u3093\u3002<\/p>\n\n\n\n<p><strong>\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u306e\u5909\u66f4<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u73fe\u5728\u306e\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\uff1a<code>\u300cAppleCoreMedia\/1.0.0.21F90 (iPhone; U; CPU OS 17_5_1 like Mac OS X; en_us)<\/code>\u300d<\/li>\n\n\n\n<li>\u4ee5\u524d\u306e\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\uff1a\u300c<code>com.tinyspeck.chatlyio\/25.04.10 (iPhone; iOS 17.5.1; Scale\/3.00)<\/code>\u300d<\/li>\n<\/ul>\n\n\n\n<p>\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u306e\u5909\u66f4\u306f\u30c7\u30d0\u30a4\u30b9\u304c\u5909\u66f4\u3055\u308c\u305f\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u308b\u3067\u3057\u3087\u3046\u304b\uff1f<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u6587\u5b57\u5217\u304c\u507d\u88c5\u3055\u308c\u3066\u3044\u306a\u3044\u3068\u4eee\u5b9a\u3059\u308b\u3068\u3001\u30c7\u30d0\u30a4\u30b9\u306fOS\u30d0\u30fc\u30b8\u30e7\u30f318.4\u3092\u642d\u8f09\u3057\u305fiPhone\u3067\u3059\u3002\u00a0<\/li>\n\n\n\n<li>Tiny Speck\u306fSlack\u3092\u958b\u767a\u3057\u305f\u4f1a\u793e\u306e\u5143\u306e\u540d\u524d\u3067\u3059\u3002\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u306e\u6587\u5b57\u5217\u00a0<code>com.tinyspeck.chatlyio\/25.04.10<\/code>\u00a0\u306f\u3001\u304a\u305d\u3089\u304fSlack iOS\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u306b\u5bfe\u5fdc\u3057\u3066\u3044\u307e\u3059\u3002<br\/><code>AppleCoreMedia<\/code>\u00a0\u306fiOS\u304c\u30b9\u30c8\u30ea\u30fc\u30df\u30f3\u30b0\u3068\u30e1\u30c7\u30a3\u30a2\u518d\u751f\u3092\u51e6\u7406\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3059\u308b\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u3067\u3059\u3002<\/li>\n\n\n\n<li>\u3053\u306e\u3053\u3068\u304b\u3089\u3001AppleCoreMedia\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u306fSlack\u5185\u3067\u30e1\u30c7\u30a3\u30a2\u30d5\u30a1\u30a4\u30eb\uff08\u30d3\u30c7\u30aa\u306a\u3069\uff09\u304c\u30b9\u30c8\u30ea\u30fc\u30df\u30f3\u30b0\u3055\u308c\u305f\u3068\u304d\u306b\u8868\u793a\u3055\u308c\u3001Tiny Speck\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u306fSlack\u306e\u4e00\u822c\u7684\u306a\u4f7f\u7528\u6cd5\u3092\u53cd\u6620\u3059\u308b\u3082\u306e\u3067\u3042\u308b\u3001\u3068\u8003\u3048\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u3053\u306e\u52d5\u4f5c\u306f\u516c\u958b\u6587\u66f8\u304b\u3089\u306f\u78ba\u8a8d\u3067\u304d\u307e\u305b\u3093\u304c\u3001\u5f53\u793e\u306e\u30ed\u30b0\u5206\u6790\u3067\u306f\u3053\u306e\u89e3\u91c8\u304c\u88cf\u4ed8\u3051\u3089\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n\n\n\n<li>AppleCoreMedia\u306f\u3001iOS\u306b\u304a\u3051\u308b\u30e1\u30c7\u30a3\u30a2\u306e\u30b9\u30c8\u30ea\u30fc\u30df\u30f3\u30b0\u306b\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002<\/li>\n<\/ul>\n\n\n\n<p>\u3064\u307e\u308a\u3001Tiny Speck\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u306fSlack\u306e\u901a\u5e38\u4f7f\u7528\u306b\u9069\u3057\u3066\u304a\u308a\u3001AppleCoreMedia\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u306fSlack\u306b\u304a\u3051\u308b\u30e1\u30c7\u30a3\u30a2\u30b9\u30c8\u30ea\u30fc\u30df\u30f3\u30b0\u5411\u3051\u3067\u3042\u308b\u3068\u3044\u3046\u3053\u3068\u3067\u3057\u3087\u3046\u304b\uff1f<\/p>\n\n\n\n<p>\u7570\u5e38\u306a\u30a4\u30d9\u30f3\u30c8\u306b\u8ca2\u732e\u3057\u305f\u500b\u3005\u306e\u30ed\u30b0\u3092\u30ec\u30d3\u30e5\u30fc\u3059\u308b\u3053\u3068\u3067\u3001\u3053\u306e\u7406\u8ad6\u3092\u30c6\u30b9\u30c8\u3067\u304d\u307e\u3059\u3002\u30bb\u30c3\u30b7\u30e7\u30f3 ID \u3092\u691c\u7d22\u3057\u3001\u30a2\u30af\u30b7\u30e7\u30f3\u306b\u95a2\u9023\u3059\u308b\u30e6\u30fc\u30b6\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u3092\u8abf\u3079\u308b\u3053\u3068\u304b\u3089\u59cb\u3081\u307e\u3057\u3087\u3046\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">(_index=sec_record_notification OR _index=sec_record_audit) metadata_vendor=\"Slack\" sessionId=8475310491012\n| fields action, http_userAgent<\/pre>\n\n\n\n<p>\u30bb\u30c3\u30b7\u30e7\u30f3\u306f\u9577\u6642\u9593\u7d9a\u304f\u53ef\u80fd\u6027\u304c\u3042\u308b\u305f\u3081\u3001\u691c\u7d22\u6642\u306b\u8a2d\u5b9a\u3059\u308b\u6642\u9593\u7bc4\u56f2\u306b\u306f\u4f59\u88d5\u3092\u6301\u305f\u305b\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u672c\u7a3f\u3067\u8abf\u67fb\u3055\u308c\u305f\u30bb\u30c3\u30b7\u30e7\u30f3\u306f\u300190\u65e5\u4ee5\u4e0a\u306b\u3082\u53ca\u3076\u3082\u306e\u3067\u3057\u305f\u3002<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"387\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img8-1-1024x387.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img8-1-300x113.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img8-1-768x290.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img8-1-1536x581.png 1536w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img8-1-575x217.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img8-1.png 1600w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img8-1-1024x387.png\" alt=\"blog slack env img8 1\" title=\"\"><\/p>\n\n\n\n<p><em>\u76e3\u67fb\u3055\u308c\u305fSlack\u30a2\u30af\u30b7\u30e7\u30f3\u3068\u95a2\u9023\u3059\u308b\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u6587\u5b57\u5217<\/em><\/p>\n\n\n\n<p>2025\u5e744\u67089\u65e5\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u306e\u524d\u306e\u6570\u65e5\u9593\u306b\u7126\u70b9\u3092\u5f53\u3066\u307e\u3059\u3002\u7570\u5e38\u767a\u751f\u306e1\u6642\u9593\u306b\u3001\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u306fTiny Speck\uff08Slack\uff09\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u304b\u3089AppleCoreMedia\u306b\u5909\u66f4\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u306a\u305c\u3067\u3057\u3087\u3046\u304b\uff1f\u304a\u305d\u3089\u304f\u00a0<code>file_downloaded<\/code>\u00a0\u30a2\u30af\u30b7\u30e7\u30f3\u306b\u95a2\u4fc2\u3059\u308b\u30d5\u30a1\u30a4\u30eb\u30bf\u30a4\u30d7\u304c\u30b9\u30c8\u30ea\u30fc\u30df\u30f3\u30b0\u3092\u5fc5\u8981\u3068\u3057\u305f\u305f\u3081\u3067\u3059\u3002\u691c\u7d22\u7d50\u679c\u306e\u8868\u793a\u306b\u00a0<code>file_mimetype<\/code>\u00a0\u30d5\u30a3\u30fc\u30eb\u30c9\u3092\u8ffd\u52a0\u3059\u308b\u305f\u3081\u3001\u30d5\u30a3\u30fc\u30eb\u30c9\u4e00\u89a7\u306e\u300c\u975e\u8868\u793a\u30d5\u30a3\u30fc\u30eb\u30c9\u300d\u30bb\u30af\u30b7\u30e7\u30f3\u304b\u3089\u8a72\u5f53\u30d5\u30a3\u30fc\u30eb\u30c9\u540d\u3092\u9078\u629e\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"664\" height=\"738\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img9-1.png 664w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img9-1-270x300.png 270w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img9-1-575x639.png 575w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img9-1.png\" alt=\"blog slack env img9 1\" title=\"\"><\/p>\n\n\n\n<p><em>\u30d5\u30a3\u30fc\u30eb\u30c98\uff1a\u691c\u7d22\u7d50\u679c\u306e\u8868\u793a\u3078\u306efile_mimeType\u30d5\u30a3\u30fc\u30eb\u30c9\u306e\u8ffd\u52a0<\/em><\/p>\n\n\n\n<p>\u00a0<code>file_mimeType<\/code>\u00a0\u306e\u8868\u793a\u306b\u3088\u308a\u3001MP4\u30d5\u30a1\u30a4\u30eb\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u969b\u306e\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u304cAppleCoreMedia\u3067\u3042\u308a\u3001JPG\u30d5\u30a1\u30a4\u30eb\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u6642\u306fTiny Speck\u3067\u3042\u308b\u3053\u3068\u304c\u660e\u3089\u304b\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"351\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img10-1-1024x351.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img10-1-300x103.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img10-1-768x263.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img10-1-1536x526.png 1536w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img10-1-575x197.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img10-1.png 1600w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img10-1-1024x351.png\" alt=\"blog slack env img10 1\" title=\"\"><\/p>\n\n\n\n<p><em>\u56f39\uff1a\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u30bf\u30a4\u30d7\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u305f\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u6587\u5b57\u5217\u306e\u5206\u6790<\/em><\/p>\n\n\n\n<p>\u3053\u306e\u4f8b\u306b\u304a\u3044\u3066\u3001Slack\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u306f\u60aa\u610f\u306e\u3042\u308b\u52d5\u4f5c\u3092\u767a\u898b\u3057\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u304c\u5909\u66f4\u3055\u308c\u305f\u30bb\u30c3\u30b7\u30e7\u30f3\u304c\u3042\u308a\u307e\u3057\u305f\u304c\u3001\u3053\u308c\u306f\u8907\u6570\u306e\u30c7\u30d0\u30a4\u30b9\u304c\u540c\u3058\u30bb\u30c3\u30b7\u30e7\u30f3\u30af\u30c3\u30ad\u30fc\u3092\u4f7f\u7528\u3057\u3066\u3044\u305f\u3053\u3068\u306b\u3088\u308b\u3082\u306e\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u3067\u3057\u305f\u3002\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"using-slack-anomaly-event-types-for-custom-analytic-content\">\u30ab\u30b9\u30bf\u30e0\u5206\u6790\u30b3\u30f3\u30c6\u30f3\u30c4\u306b\u304a\u3051\u308bSlack\u306e\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u30bf\u30a4\u30d7\u306e\u4f7f\u7528<\/h2>\n\n\n\n<p>Slack \u306f\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u89b3\u70b9\u304b\u3089\u3001\u7570\u5e38\u691c\u77e5\u306e\u6b63\u78ba\u306a\u30ed\u30b8\u30c3\u30af\u306f\u516c\u958b\u3057\u3066\u3044\u307e\u305b\u3093\u3002\u3057\u304b\u3057\u3001\u00a0<a href=\"https:\/\/api.slack.com\/admins\/audit-logs-anomaly\" target=\"_blank\" rel=\"noreferrer noopener\">\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u306e\u7a2e\u985e<\/a>\u00a0\u305d\u306e\u3082\u306e\u304c\u3001\u30c0\u30c3\u30b7\u30e5\u30dc\u30fc\u30c9\u306e\u8a2d\u8a08\u3001\u30cf\u30f3\u30c6\u30a3\u30f3\u30b0\u3001\u305d\u3057\u3066\u72ec\u81ea\u306e\u30ab\u30b9\u30bf\u30e0\u5206\u6790\u3092\u884c\u3046\u969b\u306e\u826f\u3044\u30d2\u30f3\u30c8\u306b\u306a\u308a\u307e\u3059\u3002\u00a0<\/p>\n\n\n\n<p>\u3053\u308c\u3089\u306f\u6b21\u306e\u3088\u3046\u306a\u30a4\u30d9\u30f3\u30c8\u306e\u76e3\u8996\u306b\u4f7f\u7528\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6a19\u6e96\u5916\u306e\u7ba1\u7406\u30a2\u30af\u30b7\u30e7\u30f3\u00a0<a href=\"https:\/\/help.sumologic.com\/docs\/cse\/rules\/write-first-seen-rule\/\" target=\"_blank\" rel=\"noreferrer noopener\">\uff08First Seen\u30eb\u30fc\u30eb\uff09<\/a><\/li>\n\n\n\n<li>\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3001\u30d5\u30a1\u30a4\u30eb\u5171\u6709\u3001\u307e\u305f\u306f\u30e1\u30c3\u30bb\u30fc\u30b8\u524a\u9664\u306e\u6025\u5897\u00a0<a href=\"https:\/\/help.sumologic.com\/docs\/cse\/rules\/write-outlier-rule\/\" target=\"_blank\" rel=\"noreferrer noopener\">\uff08Outlier\u30eb\u30fc\u30eb\uff09\u00a0<\/a><\/li>\n<\/ul>\n\n\n\n<p>\u30af\u30c3\u30ad\u30fc\u7a83\u53d6\u306e\u8a71\u306b\u623b\u308b\u3068\u3001\u8907\u6570\u306e\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u6587\u5b57\u5217\u304c\u95a2\u4e0e\u3057\u3066\u3044\u308b Slack \u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u3069\u306e\u3088\u3046\u306b\u30cf\u30f3\u30c8\u3067\u304d\u308b\u3067\u3057\u3087\u3046\u304b\uff1f\u305d\u306e\u305f\u3081\u306b\u306f \u00a0<a href=\"https:\/\/help.sumologic.com\/docs\/search\/search-query-language\/group-aggregate-operators\/count-count-distinct-and-count-frequent\/#count_distinct\" target=\"_blank\" rel=\"noreferrer noopener\">count_distinct<\/a>\u6f14\u7b97\u5b50\u3092\u4f7f\u7528\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">(_index=sec_record_notification OR _index=sec_record_audit) metadata_vendor=\"Slack\" metadata_product=\"Slack\"\u00a0\n| count_distinct(http_userAgent) by sessionId\n| sort by _count_distinct<\/pre>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"698\" height=\"616\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img11-1.png\" alt=\"blog slack env img11 1\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img11-1.png 698w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img11-1-300x265.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img11-1-575x507.png 575w\" title=\"\"><\/p>\n\n\n\n<p><em><code>sessionId\u3054\u3068\u306b\u7570\u306a\u308b\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u6587\u5b57\u5217\u306e\u6570<\/code><\/em><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\u95a2\u5fc3\u306e\u3042\u308b\u30bb\u30c3\u30b7\u30e7\u30f3\u304c\u898b\u3064\u304b\u3063\u305f\u3089\u3001\u6b21\u306e\u3088\u3046\u306a\u30af\u30a8\u30ea\u3092\u4f7f\u7528\u3057\u3066\u3059\u3079\u3066\u306e\u30ed\u30b0\u3092\u8fd4\u305b\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">(_index=sec_record_notification OR _index=sec_record_audit) metadata_vendor=\"Slack\" sessionId=[insert session ID here]\n| count by http_userAgent<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"stay-ahead-of-slack-based-threats\">Slack\u30d9\u30fc\u30b9\u306e\u8105\u5a01\u3092\u5148\u53d6\u308a<\/h2>\n\n\n\n<p>Slack\u306f\u8c4a\u5bcc\u306a\u4f01\u696d\u60c5\u5831\u6e90\u3067\u3042\u308b\u305f\u3081\u3001\u30cf\u30c3\u30ab\u30fc\u306b\u3068\u3063\u3066\u683c\u597d\u306e\u6a19\u7684\u3068\u306a\u308a\u307e\u3059\u3002\u7570\u5e38\u30a4\u30d9\u30f3\u30c8\u3092\u542b\u3080Slack\u306e\u76e3\u67fb\u30ed\u30b0\u3092\u76e3\u8996\u3059\u308b\u3053\u3068\u306f\u3001\u4fb5\u5bb3\u3092\u65e9\u671f\u306b\u767a\u898b\u3059\u308b\u305f\u3081\u306b\u975e\u5e38\u306b\u91cd\u8981\u3067\u3059\u3002\u00a0<\/p>\n\n\n\n<p>Sumo Logic\u3092\u4f7f\u7528\u3059\u308b\u3068\u3001\u3053\u308c\u3089\u306e\u30ed\u30b0\u3092\u7c21\u5358\u306b\u53ce\u96c6\u3001\u5206\u6790\u3001\u304a\u3088\u3073\u5bfe\u51e6\u3067\u304d\u308b\u305f\u3081\u3001\u4f01\u696d\u30c1\u30fc\u30e0\u306f\u8105\u5a01\u306b\u5bfe\u3057\u5148\u624b\u3092\u6253\u3066\u307e\u3059\u3002\u00a0<\/p>\n\n\n\n<p>Sumo Logic Cloud SIEM\u306e\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001\u00a0<a href=\"https:\/\/www.sumologic.com\/ja\/demo\/complete-threat-detection-investigation-and-response-demo\">\u30a4\u30f3\u30bf\u30e9\u30af\u30c6\u30a3\u30d6\u306aCloud SIEM\u30c7\u30e2\u3092\u3054\u89a7\u304f\u3060\u3055\u3044\u3002\u00a0<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div><\/section>\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":332,"featured_media":45919,"template":"","meta":{"_acf_changed":false,"show_custom_date":false,"custom_date":"","featured":false,"featured_image":0,"learn_more_label":"","image_alt_text":"","learn_more_type":"","show_popup":false,"learn_more_link_file":0,"event_date":false,"event_start_date":"","event_end_date":"","place_holder_image_url":"","post_reading_time":"2","notification_enabled":false,"notification_text":"","notification_logo":"","notification_expiration_time":0,"is_enable_transparent_header":false,"selected_taxonomy_terms":{"blog-category":[322],"blog-tag":[],"translation_priority":[221]},"selected_primary_terms":[],"learn_more_link":[],"featured_page_list":[],"notification_enabled_post_list":[],"_gspb_post_css":"","_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"57841,62284,62286","_relevanssi_noindex_reason":"","inline_featured_image":false,"footnotes":""},"blog-category":[322],"blog-tag":[],"class_list":["post-57859","blog","type-blog","status-publish","has-post-thumbnail","hentry","blog-category-cloud-siem"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.sumologic.com\/ja\/wp-json\/wp\/v2\/blog\/57859","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sumologic.com\/ja\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/www.sumologic.com\/ja\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/www.sumologic.com\/ja\/wp-json\/wp\/v2\/users\/332"}],"version-history":[{"count":9,"href":"https:\/\/www.sumologic.com\/ja\/wp-json\/wp\/v2\/blog\/57859\/revisions"}],"predecessor-version":[{"id":70216,"href":"https:\/\/www.sumologic.com\/ja\/wp-json\/wp\/v2\/blog\/57859\/revisions\/70216"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sumologic.com\/ja\/wp-json\/wp\/v2\/media\/45919"}],"wp:attachment":[{"href":"https:\/\/www.sumologic.com\/ja\/wp-json\/wp\/v2\/media?parent=57859"}],"wp:term":[{"taxonomy":"blog-category","embeddable":true,"href":"https:\/\/www.sumologic.com\/ja\/wp-json\/wp\/v2\/blog-category?post=57859"},{"taxonomy":"blog-tag","embeddable":true,"href":"https:\/\/www.sumologic.com\/ja\/wp-json\/wp\/v2\/blog-tag?post=57859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}