コンテンツにスキップ

サポートされている CEL マクロ🔗

注意

Taegis XDRでは、アラート および インベスティゲーション という用語が、最近 検出 および ケース に変更されました。SophosとTaegisテクノロジーのプラットフォーム統合作業が進行中のため、引き続き旧用語が参照されている場合があります。詳細については、Taegis用語の更新をご覧ください。

Secureworks® Taegis™ XDR の自動化プラットフォームでは、Google の Common Expression Language (CEL) を使用して、コネクター、プレイブック入力、プレイブックトリガー、テンプレート内にロジックとデータ操作を埋め込むことができます。

XDR は、データの操作と評価を可能にする Google の Common Expression Language (CEL) マクロを多数サポートしています。多くのマクロは組み込みですが、一般的な問題に対処するためにカスタム構築されたものもあります。

これらの例では、次のデータ構造を使用します。

{
    "plant": {
        "type": "tree",
        "name": "white oak",
        "uses": [
            "lumber",
            "firewood",
            "furniture"
        ],
        "traits": {
            "produces_fruit": yes,
            "genus": "Quercus",
            "height": 100,
            "extinct": false,
            "related_to": [
                {
                    "name": "chestnut",
                    "genus": "Castanea"
                },
                {
                    "name": "beech",
                    "genus": "Fagus"
                }
           ]
        },
        "locations": [
            "usa",
            "europe",
            "new york",
            "New York",
            "new york  ",
            "usa",
            "worldwide",
            "eu"
        ]
    }
}

使用可能なマクロ🔗

? (オプション演算子)🔗

? は、CEL 式における安全なナビゲーション、安全なインデックス指定、および条件付き包含のためのオプション演算子です。

? 演算子は、次の機能を提供します。

  • 安全なフィールドナビゲーション (obj.?field): エラーなしでフィールドにアクセスします。
  • 安全なマップインデックス指定 (map[?key]): マップ値に安全にアクセスします。
  • 安全なリストインデックス指定 (list[?index]): リスト要素に安全にアクセスします。
  • オプションのマップフィールド ({?key: value}): 条件付きでマップフィールドを含めます。
  • オプションのリスト要素 ([?element]): 条件付きでリスト要素を含めます。

最初の ? 演算子の後は、後続のアクセスは自動的に安全になります (viral chaining): obj.?field.subfield == obj.?field.?subfield。

注意🔗

  • ? 演算子は、.orValue() または .hasValue() を必要とするオプション値を返します。
  • 安全なナビゲーションでは、フィールド、キー、またはインデックスが存在しなくてもエラーは発生しません。
  • オプションのフィールド/要素構文には、オプション型の値が必要です。
  • optional.of()、optional.none()、または optional.ofNonZeroValue() とともに使用します。

例🔗

{'name': 'John'}.?name.orValue('Unknown')
{'name': 'John'}.?name.orValue('Unknown')

出力: 'John'

安全なフィールドナビゲーション。

{}.?name.orValue('Unknown')
{}.?name.orValue('Unknown')

出力: 'Unknown'

フィールドが存在しない場合は optional.none() を返します。

{'a': 1, 'b': 2}[?'a'].orValue(0)
{'a': 1, 'b': 2}[?'a'].orValue(0)

出力: 1

安全なマップインデックス指定。

{'a': 1}[?'c'].orValue(0)
{'a': 1}[?'c'].orValue(0)

出力: 0

キーが存在しない場合は optional.none() を返します。

[1, 2, 3][?0].orValue(0)
[1, 2, 3][?0].orValue(0)

出力: 1

安全なリストインデックス指定。

[1, 2, 3][?10].orValue(0)
[1, 2, 3][?10].orValue(0)

出力: 0

範囲外のインデックスは optional.none() を返します。

{?'key': optional.of(5)}.size()
{?'key': optional.of(5)}.size()

出力: 1

オプションのマップフィールドが含まれます。

{?'key': optional.none()}.size()
{?'key': optional.none()}.size()

出力: 0

オプションのマップフィールドは省略されます。

[1, ?optional.of(2), 3].size()
[1, ?optional.of(2), 3].size()

出力: 3

オプションのリスト要素が含まれます。

[1, ?optional.none(), 3].size()
[1, ?optional.none(), 3].size()

出力: 2

オプションのリスト要素は省略されます。

abs🔗

指定された引数の絶対値を返します。

入力と出力🔗

abs(double) -> double
abs(int) -> int
abs(uint) -> uint

例🔗

abs(-1.0)
abs(-1.0)

出力: 1.0

abs(1.0)
abs(1.0)

出力: 1.0

alertAttackTechniqueIds🔗

アラートレコードを解析し、攻撃手法 ID の値を返します。

入力と出力🔗

alertAttackTechniqueIds(map) -> list

例🔗

alertAttackTechniqueIds(inputs)
alertAttackTechniqueIds(inputs)

出力: ["T1096", "T1214"]

alertConfidence🔗

アラートレコードを解析し、信頼度の値を返します。

入力と出力🔗

alertConfidence(map) -> double

例🔗

alertConfidence(inputs)
alertConfidence(inputs)

出力: 0.5

alertCreatedAtNanos🔗

アラートレコードを解析し、アラートが作成された時刻のナノ秒値を返します。

入力と出力🔗

alertCreatedAtNanos(map) -> int

例🔗

alertCreatedAtNanos(inputs)
alertCreatedAtNanos(inputs)

出力: 796357058

alertCreatedAtSeconds🔗

アラートレコードを解析し、created_at の値をエポックからの秒数として返します。

入力と出力🔗

alertCreatedAtSeconds(map) -> int

例🔗

alertCreatedAtSeconds(inputs)
alertCreatedAtSeconds(inputs)

出力: 1636029855

alertDescription🔗

アラートレコードを解析し、説明の値を返します。

入力と出力🔗

alertDescription(map) -> string

例🔗

alertDescription(inputs)
alertDescription(inputs)

出力: "This is a sample Taegis Watchlist Alert"

alertDestinationIPs🔗

アラートレコードを解析し、エンティティが destinationIPAddress とラベル付けされているアラートエンティティフィールドから、一意の IP アドレス値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

alertDestinationIPs(map) -> list

例🔗

alertDestinationIPs(inputs)
alertDestinationIPs(inputs)

出力: ["192.168.0.1", "192.168.0.2"]

alertDetectorId🔗

アラートレコードを解析し、検知機 ID の値を返します。

入力と出力🔗

alertDetectorId(map) -> string

例🔗

alertDetectorId(inputs)
alertDetectorId(inputs)

出力: "app:event-filter"

alertDetectorName🔗

アラートレコードを解析し、検知機名の値を返します。

入力と出力🔗

alertDetectorName(map) -> string

例🔗

alertDetectorName(inputs)
alertDetectorName(inputs)

出力: "Taegis Watchlist"

alertDomains🔗

アラートレコードを解析し、エンティティが ipdomain、topprivateipdomain、domainname、authdomainname、sourceauthdomainname、または targetauthdomainname とラベル付けされているアラートエンティティフィールドから、一意のドメイン名値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

alertDomains(map) -> list

例🔗

alertDomains(inputs)
alertDomains(inputs)

出力: ["example.com", "a.example.com"]

alertEnrichment🔗

アラートレコードとエンリッチメントデータを解析し、指定されたパスに一致する最初の値を返します。

入力と出力🔗

alertEnrichment(map, string) -> any

例🔗

alertEnrichment(inputs, 'rare_program_rare_ip.programs')
alertEnrichment(inputs, 'rare_program_rare_ip.programs')

出力: ["foo.exe", "bar.exe"]

alertEnrichment(inputs, 'doesnotexist')
alertEnrichment(inputs, 'doesnotexist')

出力: []

alertEntities🔗

アラートレコードを解析し、エンティティ値を返します。

入力と出力🔗

alertEntities(map) -> list

例🔗

alertEntities(inputs)
alertEntities(inputs)

出力: ["hostname:abc", "sensorId:12345", "fileName:c:\\windows\\syswow64\\cmd.exe"]

alertEntity🔗

アラートレコードを解析し、指定されたエンティティ名に一致するエンティティ値を返します (大文字と小文字を区別しません)。

入力と出力🔗

alertEntity(map, string) -> list

例🔗

alertEntity(inputs, 'username')
alertEntity(inputs, 'username')

出力: ["sample_user","another_sample_user"]

alertEventIds🔗

アラートレコードを解析し、イベント ID 値のリストを返します。

入力と出力🔗

alertEventIds(map) -> list

例🔗

alertEventIds(inputs)
alertEventIds(inputs)

出力: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

alertGroupKey🔗

アラートレコードを解析し、group_key の値を返します。

入力と出力🔗

alertGroupKey(map) -> string

例🔗

alertGroupKey(inputs)
alertGroupKey(inputs)

出力: "12345:app:event-filter:80c0809b-153f-4b81-bb7c-52fcb83c7127"

alertHostnames🔗

アラートレコードを解析し、エンティティが hostname、sourcehostname、desthostname、workstationname、または computername とラベル付けされているアラートエンティティフィールドから、一意の値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

alertHostnames(map) -> list

例🔗

alertHostnames(inputs)
alertHostnames(inputs)

出力: ["sample_hostname", "another_sample_hostname"]

alertIPs🔗

アラートレコードを解析し、エンティティが ipAddress とラベル付けされているアラートエンティティフィールドから、一意の IP アドレス値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

alertIPs(map) -> list

例🔗

alertIPs(inputs)
alertIPs(inputs)

出力: ["192.168.0.1", "192.168.0.2"]

alertId🔗

アラートレコードを解析し、ID または UUID を返します。

入力と出力🔗

alertId(map) -> string

例🔗

alertId(inputs)
alertId(inputs)

出力: "alert://priv:endpoint-redcloak:12345:1678899090095:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"

alertInvestigationIds🔗

アラートレコードを解析し、アラートに関連付けられた調査 ID のリストを返します。

入力と出力🔗

alertInvestigationIds(map) -> list

例🔗

alertInvestigationIds(inputs)
alertInvestigationIds(inputs)

出力: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

alertMitreAttackInfo🔗

アラートレコードを解析し、mitre_attack_info 値のリストを返します。

入力と出力🔗

alertMitreAttackInfo(map) -> list

例🔗

alertMitreAttackInfo(inputs)
alertMitreAttackInfo(inputs)

出力: [{"description":"Adversaries may attempt...","technique":"Process Discovery","technique_id":"T1057"}]

alertObservationIds🔗

アラートレコードを解析し、観測 ID 値のリストを返します。

入力と出力🔗

alertObservationIds(map) -> list

例🔗

alertObservationIds(inputs)
alertObservationIds(inputs)

出力: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

alertReferences🔗

アラートレコードを解析し、アラートに関連付けられた参照のリストを返します。

入力と出力🔗

alertReferences(map) -> list

例🔗

alertReferences(inputs)
alertReferences(inputs)

出力: [{"description": "External Alert Ref","url": "https://example.com/alert/29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"}]

alertResolution🔗

アラートレコードを解析し、解決値を返します。

入力と出力🔗

alertResolution(map) -> string

例🔗

alertResolution(inputs)
alertResolution(inputs)

出力: "open"

alertResolutionReason🔗

アラートレコードを解析し、解決理由の値を返します。

入力と出力🔗

alertResolutionReason(map) -> string

例🔗

alertResolutionReason(inputs)
alertResolutionReason(inputs)

出力: "Valid activity for this user."

alertRuleId🔗

アラートレコードを解析し、ルール ID を返します。

入力と出力🔗

alertRuleId(map) -> string

例🔗

alertRuleId(inputs)
alertRuleId(inputs)

出力: "267658fe-65f1-4145-8753-d45fbf9ed6d3"

alertSensorIds🔗

アラートレコードを解析し、センサー ID 値のリストを返します。

入力と出力🔗

alertSensorIds(map) -> list

例🔗

alertSensorIds(inputs)
alertSensorIds(inputs)

出力: ["12345", "1234-12345-123"]

alertSensorTypes🔗

アラートレコードを解析し、一意のセンサータイプ値のリストを返します (大文字)。

入力と出力🔗

alertSensorTypes(map) -> list

例🔗

alertSensorTypes(inputs)
alertSensorTypes(inputs)

出力: ["ENDPOINT_REDCLOAK", "ENDPOINT_TAEGIS"]

alertSeverity🔗

アラートレコードを解析し、重大度の値を返します。

入力と出力🔗

alertSeverity(map) -> double

例🔗

alertSeverity(inputs)
alertSeverity(inputs)

出力: 0.75

alertSeverityNice🔗

アラートレコードを解析し、人が読みやすい重大度の値を単語で返します (Informational、Low、Medium、High、Critical)。

入力と出力🔗

alertSeverityNice(map) -> string

例🔗

alertSeverityNice(inputs)
alertSeverityNice(inputs)

出力: "High"

alertSourceIPs🔗

アラートレコードを解析し、エンティティが sourceIPAddress とラベル付けされているアラートエンティティフィールドから、一意の IP アドレス値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

alertSourceIPs(map) -> list

例🔗

alertSourceIPs(inputs)
alertSourceIPs(inputs)

出力: ["192.168.0.1", "192.168.0.2"]

alertStatus🔗

アラートレコードを解析し、ステータス値を返します。

入力と出力🔗

alertStatus(map) -> string

例🔗

alertStatus(inputs)
alertStatus(inputs)

出力: "open"

alertTags🔗

アラートレコードを解析し、タグのリストを返します。

入力と出力🔗

alertTags(map) -> list

例🔗

alertTags(inputs)
alertTags(inputs)

出力: ["alertRule:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "compactor:handler"]

alertTenantId🔗

アラートレコードを解析し、テナント ID を返します。

入力と出力🔗

alertTenantId(map) -> string

例🔗

alertTenantId(inputs)
alertTenantId(inputs)

出力: "12345"

alertThirdPartyDetail🔗

アラートレコードとサードパーティ詳細データを解析し、指定されたパスに一致する最初の値を返します。

入力と出力🔗

alertThirdPartyDetail(map, string) -> list

例🔗

alertThirdPartyDetail(inputs, 'userStates.0.aadUserId')
alertThirdPartyDetail(inputs, 'userStates.0.aadUserId')

出力: ["F86DBD0D-6571-44A0-BAE1-43B83CF430AD"]

alertTitle🔗

アラートレコードを解析し、タイトル値を返します。

入力と出力🔗

alertTitle(map) -> string

例🔗

alertTitle(inputs)
alertTitle(inputs)

出力: "Taegis Watchlist Alert"

alertUpdatedAtNanos🔗

アラートレコードを解析し、アラートが変更された時刻のナノ秒値を返します。

入力と出力🔗

alertUpdatedAtNanos(map) -> int

例🔗

alertUpdatedAtNanos(inputs)
alertUpdatedAtNanos(inputs)

出力: 796357058

alertUpdatedAtSeconds🔗

アラートレコードを解析し、updated_at の値をエポックからの秒数として返します。

入力と出力🔗

alertUpdatedAtSeconds(map) -> int

例🔗

alertUpdatedAtSeconds(inputs)
alertUpdatedAtSeconds(inputs)

出力: 1697207995554

alertUsernames🔗

アラートレコードを解析し、エンティティが username とラベル付けされているアラートエンティティフィールドから、小文字の一意なユーザー名値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

alertUsernames(map) -> list

例🔗

alertUsernames(inputs)
alertUsernames(inputs)

出力: ["sample_user", "another_sample_user"]

all🔗

リストまたはマップを反復処理し、条件がリスト内のすべての要素に対して真であることを検証します。

入力と出力🔗

all(list, predicate) -> bool
all(map, predicate) -> bool

例🔗

[1,2,3,4].all(x, x > 0)
[1,2,3,4].all(x, x > 0)

出力: true

[1,2,3,0].all(x, x > 0)
[1,2,3,0].all(x, x > 0)

出力: false

append🔗

既存のリストに要素を追加します。

入力と出力🔗

append(list, any) -> list

例🔗

append([1, 2, 3], 4)
append([1, 2, 3], 4)

出力: [1, 2, 3, 4]

append([], "newElement")
append([], "newElement")

出力: ["newElement"]

assetTags🔗

資産から資産タグのキー/値ペアのリストを返します。デフォルトでは、キーと値の両方を返します。必要に応じて、キーのみまたは値のみを返すこともできます。

入力と出力🔗

assetTags(map) -> list
assetTags(map, string) -> list

例🔗

assetTags(inputs)
assetTags(inputs)

出力: ["t1:v1", "t2:v2"]

assetTags(inputs, "keys")
assetTags(inputs, "keys")

出力: ["t1", "t2"]

assetTags(inputs, "values")
assetTags(inputs, "values")

出力: ["v1", "v2"]

base64.decode🔗

base64 でエンコードされた文字列をバイト列にデコードします。

入力と出力🔗

base64.decode(string) -> bytes

base64 でエンコードされた文字列を元のバイト列にデコードします。

入力が空の場合は空のバイト列を返します。

入力は有効な base64 エンコード文字列である必要があります。

ユースケース🔗

エンコードされた認証情報をデコードする。
base64.decode('dXNlcm5hbWU6cGFzc3dvcmQ=')

出力: b'username:password'

Basic Authentication の認証情報をデコードします。

文字列に変換する。
string(base64.decode('aGVsbG8='))

出力: "hello"

デコードしてバイト列を文字列に変換します。

API レスポンスをデコードする。
string(base64.decode(api_response.encoded_data))

base64 でエンコードされた API レスポンスデータをデコードします。

エンコードを検証する。
base64.decode(base64.encode(b'test'))

出力: b'test'

エンコードとデコードの往復が正しく機能することを確認します。

エンコードされた入力を処理する。
string(base64.decode(input.encoded_value))

ユーザー指定の base64 入力をデコードします。

空入力の処理。
base64.decode('')

出力: b''

空文字列は空のバイト列を生成します。

文字列操作と連結する。
string(base64.decode('aGVsbG8=')).upperAscii()

出力: "HELLO"

デコードし、文字列に変換してから大文字にします。

JSON を扱う。
string(base64.decode('eyJrZXkiOiJ2YWx1ZSJ9'))

出力: '{"key":"value"}'

base64 でエンコードされた JSON をデコードします。

エラー処理🔗

  • 無効な base64 文字列はエラーの原因になります。
  • パディング文字 (=) は自動的に処理されます。
  • 入力内の空白はデコードエラーの原因になる場合があります。

注意🔗

  • 入力は有効な base64 エンコード文字列である必要があります。
  • 出力は常に bytes 型です。
  • bytes から文字列を取得するには string() 変換を使用します。
  • 標準の base64 デコード (RFC 4648) を使用します。
  • これはカスタム decodeBase64() 関数と共存します。

一般的なパターン🔗

デコードして文字列として使用する:

string(base64.decode(encoded_input))

最も一般的なパターン: デコードして文字列に変換します。

デコードして処理する:

cel.bind(decoded, base64.decode(input), decoded.size() > 0 ? string(decoded) : 'empty')

デコードし、サイズを確認してから変換するか、デフォルト値を返します。

往復検証:

string(base64.decode(base64.encode(b'test'))) == 'test'

エンコードとデコードが正しく機能することを検証します。

例🔗

base64.decode('aGVsbG8=')
base64.decode('aGVsbG8=')

出力: b'hello'

base64.decode('aGVsbG8gd29ybGQ=')
base64.decode('aGVsbG8gd29ybGQ=')

出力: b'hello world'

base64.decode('dGVzdDEyMw==')
base64.decode('dGVzdDEyMw==')

出力: b'test123'

base64.decode('')
base64.decode('')

出力: b''

base64.encode🔗

バイト列を base64 エンコード文字列にエンコードします。

入力と出力🔗

base64.encode(bytes) -> string

標準の base64 エンコードを使用して、バイト列を base64 エンコード文字列にエンコードします。

入力が空の場合は空文字列を返します。

出力は URL セーフな base64 文字列です。

ユースケース🔗

送信用にテキストをエンコードする。
base64.encode(b'username:password')

出力: "dXNlcm5hbWU6cGFzc3dvcmQ="

Basic Authentication 用に認証情報をエンコードします。

バイナリデータをエンコードする。
base64.encode(file_content)

バイナリファイルの内容をテキスト表現に変換します。

データのシリアル化。
base64.encode(b'{"key": "value"}')

URL パラメーター用に JSON データをエンコードします。

安全な文字列エンコード。
base64.encode(b'data with special chars: !@#$%')

特殊文字を含む文字列をエンコードします。

往復エンコード。
string(base64.decode(base64.encode(b'test')))

出力: "test"

エンコードとデコードが正しく機能することを確認します。

文字列変換を扱う。
base64.encode(bytes(input.text))

文字列をバイト列に変換してからエンコードします。

空入力の処理。
base64.encode(b'')

出力: ""

空のバイト列は空文字列を生成します。

注意🔗

  • 入力は bytes 型である必要があります。b'...' 構文または bytes() 変換を使用します。
  • 出力は常に文字列です。
  • 標準の base64 エンコード (RFC 4648) を使用します。
  • パディング文字 (=) は必要に応じて含まれます。
  • これはカスタム encodeBase64() 関数と共存します。

例🔗

base64.encode(b'hello')
base64.encode(b'hello')

出力: "aGVsbG8="

base64.encode(b'hello world')
base64.encode(b'hello world')

出力: "aGVsbG8gd29ybGQ="

base64.encode(b'test123')
base64.encode(b'test123')

出力: "dGVzdDEyMw=="

base64.encode(b'')
base64.encode(b'')

出力: ""

caseArchivedAt🔗

ケースレコードを解析し、アーカイブされた日時を返します。

入力と出力🔗

caseArchivedAt(map) -> string

例🔗

caseArchivedAt(inputs)
caseArchivedAt(inputs)

出力: "2024-06-20T17:57:46.700164Z"

caseAssetEvidence🔗

ケースレコードを解析し、資産証拠オブジェクトのリストを返します。

入力と出力🔗

caseAssetEvidence(map) -> list

例🔗

caseAssetEvidence(inputs)
caseAssetEvidence(inputs)

出力: [, ...]

caseAssigneeId🔗

ケースレコードを解析し、担当者の ID を返します。

入力と出力🔗

caseAssigneeId(map) -> string

例🔗

caseAssigneeId(inputs)
caseAssigneeId(inputs)

出力: "dac1ed31-111-4809-9cc9-9f99b6e"

caseChangeAfter🔗

delta.changes からフィールドの after 値を含むオプションを返します。デフォルト値を指定するには .orValue() を、存在確認には .hasValue() を使用します。

入力と出力🔗

caseChangeAfter(map, string) -> optional

例🔗

caseChangeAfter(inputs, 'severity').orValue(0)
caseChangeAfter(inputs, 'severity').orValue(0)

出力: 6

caseChangeAfter(inputs, 'severity').hasValue()
caseChangeAfter(inputs, 'severity').hasValue()

出力: true

caseChangeAfter(inputs, 'nonexistent').orValue(0)
caseChangeAfter(inputs, 'nonexistent').orValue(0)

出力: 0

caseChangeAfter(inputs, 'nonexistent').hasValue()
caseChangeAfter(inputs, 'nonexistent').hasValue()

出力: false

caseChangeBefore🔗

delta.changes からフィールドの before 値を含むオプションを返します。デフォルト値を指定するには .orValue() を、存在確認には .hasValue() を使用します。

入力と出力🔗

caseChangeBefore(map, string) -> optional

例🔗

caseChangeBefore(inputs, 'severity').orValue(0)
caseChangeBefore(inputs, 'severity').orValue(0)

出力: 4

caseChangeBefore(inputs, 'severity').hasValue()
caseChangeBefore(inputs, 'severity').hasValue()

出力: true

caseChangeBefore(inputs, 'nonexistent').orValue(0)
caseChangeBefore(inputs, 'nonexistent').orValue(0)

出力: 0

caseChangeBefore(inputs, 'nonexistent').hasValue()
caseChangeBefore(inputs, 'nonexistent').hasValue()

出力: false

caseChanges🔗

ケースレコードから delta.changes マップを返します。各キーはフィールド名で、各値は before と after エントリーを持つマップです。

入力と出力🔗

caseChanges(map) -> map

例🔗

caseChanges(inputs)
caseChanges(inputs)

出力: {"severity": {"before": 4, "after": 6}, "title": {"before": "Original Case Title", "after": "Updated Case Title"}}

caseCloseReason🔗

ケースレコードを解析し、クローズされた理由を返します。

入力と出力🔗

caseCloseReason(map) -> string

例🔗

caseCloseReason(inputs)
caseCloseReason(inputs)

出力: "reason for closing"

caseClosedAt🔗

ケースレコードを解析し、クローズされた日時 (RFC3339) を返します。未設定の場合は空文字列を返します。

入力と出力🔗

caseClosedAt(map) -> string

例🔗

caseClosedAt(inputs)
caseClosedAt(inputs)

出力: "2026-03-09T11:57:04.205591Z"

caseComment🔗

ケースレコードを解析し、それに関連付けられたコメントを返します。

入力と出力🔗

caseComment(map) -> string

例🔗

caseComment(inputs)
caseComment(inputs)

出力: "This is a sample comment for the case."

caseCommentAuthorId🔗

ケースレコードを解析し、コメント作成者の ID を返します。

入力と出力🔗

caseCommentAuthorId(map) -> string

例🔗

caseCommentAuthorId(inputs)
caseCommentAuthorId(inputs)

出力: "dac1ed31-111-4809-9cc9-9f99b6e"

caseCommentCreatedAt🔗

ケースレコードを解析し、コメントが作成された日時を返します。

入力と出力🔗

caseCommentCreatedAt(map) -> string

例🔗

caseCommentCreatedAt(inputs)
caseCommentCreatedAt(inputs)

出力: "2024-06-20T17:57:46.700164Z"

caseCommentMentions🔗

ケースレコードを解析し、コメント内のメンションのリストを返します。

入力と出力🔗

caseCommentMentions(map) -> list

例🔗

caseCommentMentions(inputs)
caseCommentMentions(inputs)

出力: ["@secureworks", "@dac1ed31-111-4809-9cc9-9f99b6e"]

caseCommentOperation🔗

ケースレコードを解析し、コメントの操作タイプを返します。

入力と出力🔗

caseCommentOperation(map) -> string

例🔗

caseCommentOperation(inputs)
caseCommentOperation(inputs)

出力: "create"

caseContributorIds🔗

ケースレコードを解析し、コントリビューター ID のリストを返します。

入力と出力🔗

caseContributorIds(map) -> list

例🔗

caseContributorIds(inputs)
caseContributorIds(inputs)

出力: ["dac1ed31-111-4809-9cc9-9f99b6e", "ff0197b0@clients"]

caseCreatedAt🔗

ケースレコードを解析し、作成日時を返します。

入力と出力🔗

caseCreatedAt(map) -> string

例🔗

caseCreatedAt(inputs)
caseCreatedAt(inputs)

出力: "2024-06-20T17:57:45.592464Z"

caseCreatedById🔗

ケースレコードを解析し、作成したユーザーの ID を返します。

入力と出力🔗

caseCreatedById(map) -> string

例🔗

caseCreatedById(inputs)
caseCreatedById(inputs)

出力: "dac1ed31-111-4809-9cc9-9f99b6e"

caseCreatedByPartner🔗

ケースレコードを解析し、テナントの親によって作成された場合は true を返します。

入力と出力🔗

caseCreatedByPartner(map) -> bool

例🔗

caseCreatedByPartner(inputs)
caseCreatedByPartner(inputs)

出力: false

caseDetectionEvidence🔗

ケースレコードを解析し、検出証拠オブジェクトのリストを返します。

入力と出力🔗

caseDetectionEvidence(map) -> list

例🔗

caseDetectionEvidence(inputs)
caseDetectionEvidence(inputs)

出力: [{id, isGenesis}, ...]

caseEventEvidence🔗

ケースレコードを解析し、イベント証拠オブジェクトのリストを返します。

入力と出力🔗

caseEventEvidence(map) -> list

例🔗

caseEventEvidence(inputs)
caseEventEvidence(inputs)

出力: [, ...]

caseFieldChanged🔗

ケースレコードを解析し、指定されたフィールドが変更された場合は true を返します。

入力と出力🔗

caseFieldChanged(map, string) -> bool

例🔗

caseFieldChanged(inputs, 'priority')
caseFieldChanged(inputs, 'priority')

出力: true

caseFieldChanged(inputs, 'nonexistent_field')
caseFieldChanged(inputs, 'nonexistent_field')

出力: false

caseFileId🔗

ケースレコードを解析し、delta.file からファイル ID を返します (ファイル追加イベント)。

入力と出力🔗

caseFileId(map) -> string

例🔗

caseFileId(inputs)
caseFileId(inputs)

出力: "f1e2d3c4-b5a6-7890-1234-567890abcdef"

caseFileName🔗

ケースレコードを解析し、delta.file からファイル名を返します (ファイル追加イベント)。

入力と出力🔗

caseFileName(map) -> string

例🔗

caseFileName(inputs)
caseFileName(inputs)

出力: "evidence.pdf"

caseFileSize🔗

ケースレコードを解析し、delta.file からファイルサイズを返します (ファイル追加イベント)。

入力と出力🔗

caseFileSize(map) -> int

例🔗

caseFileSize(inputs)
caseFileSize(inputs)

出力: 102400

caseFileStatus🔗

ケースレコードを解析し、delta.file からファイルライフサイクルステータスを返します (ファイル追加/削除イベント)。

入力と出力🔗

caseFileStatus(map) -> string

例🔗

caseFileStatus(inputs)
caseFileStatus(inputs)

出力: "SCHEDULED"

caseFileUploadedById🔗

ケースレコードを解析し、delta.file からファイルをアップロードしたユーザー ID を返します (ファイル追加/削除イベント)。

入力と出力🔗

caseFileUploadedById(map) -> string

例🔗

caseFileUploadedById(inputs)
caseFileUploadedById(inputs)

出力: "auth0user123"

caseId🔗

ケースレコードを解析し、ID を返します。

入力と出力🔗

caseId(map) -> string

例🔗

caseId(inputs)
caseId(inputs)

出力: "a251201f-9a26-4cd5-81f6-20509999933d"

caseIncidentAdvisorId🔗

ケースレコードを解析し、インシデントアドバイザー ID を返します。

入力と出力🔗

caseIncidentAdvisorId(map) -> string

例🔗

caseIncidentAdvisorId(inputs)
caseIncidentAdvisorId(inputs)

出力: "adv-123"

caseKeyFindings🔗

ケースレコードを解析し、主な発見事項の内容を返します。

オプションの第 2 引数を指定すると、keyFindings オブジェクトから特定のフィールド (documentType や documentVersion など) を返します。

入力と出力🔗

caseKeyFindings(map) -> string
caseKeyFindings(map, string) -> string

例🔗

caseKeyFindings(inputs)
caseKeyFindings(inputs)

出力: "Sample Case Key Findings"

caseKeyFindings(inputs, 'documentType')
caseKeyFindings(inputs, 'documentType')

出力: "DOCUMENT_TYPE_MARKDOWN"

caseKeyFindings(inputs, 'documentVersion')
caseKeyFindings(inputs, 'documentVersion')

出力: "1"

caseLinkCreatedAt🔗

ケース変更イベント (delta.link) または単独のリンクレコードから、リンク作成タイムスタンプを返します。

入力と出力🔗

caseLinkCreatedAt(map) -> string

例🔗

caseLinkCreatedAt(inputs)
caseLinkCreatedAt(inputs)

出力: "2026-04-30T18:53:00.483028Z"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkCreatedAt(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkCreatedAt(l))

出力: ["2026-04-30T18:53:00.483028Z"]

caseLinkIsInternal🔗

ケース変更イベント (delta.link) または単独のリンクレコードから、リンクが内部リンクかどうかを返します。

入力と出力🔗

caseLinkIsInternal(map) -> bool

例🔗

caseLinkIsInternal(inputs)
caseLinkIsInternal(inputs)

出力: false

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkIsInternal(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkIsInternal(l))

出力: [false]

caseLinkReference🔗

ケース変更イベント (delta.link) または単独のリンクレコードから、リンク参照を返します。

入力と出力🔗

caseLinkReference(map) -> string

例🔗

caseLinkReference(inputs)
caseLinkReference(inputs)

出力: "EXT-12345"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkReference(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkReference(l))

出力: ["EXT-12345"]

caseLinkTitle🔗

ケース変更イベント (delta.link) または単独のリンクレコードから、リンクタイトルを返します。

入力と出力🔗

caseLinkTitle(map) -> string

例🔗

caseLinkTitle(inputs)
caseLinkTitle(inputs)

出力: "External Ticket"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkTitle(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkTitle(l))

出力: ["External Ticket"]

caseLinkType🔗

ケース変更イベント (delta.link) または単独のリンクレコードから、リンクタイプを返します。

入力と出力🔗

caseLinkType(map) -> string

例🔗

caseLinkType(inputs)
caseLinkType(inputs)

出力: "External"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External')
caseLinks(inputs).filter(l, caseLinkType(l) == 'External')

出力: []

caseLinkUrl🔗

ケース変更イベント (delta.link) または単独のリンクレコードから、リンク URL を返します。

入力と出力🔗

caseLinkUrl(map) -> string

例🔗

caseLinkUrl(inputs)
caseLinkUrl(inputs)

出力: "https://example.com/tickets/EXT-12345"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkUrl(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkUrl(l))

出力: ["https://example.com/tickets/EXT-12345"]

ケースレコードを解析し、リンクオブジェクトの完全なリストを返します。

入力と出力🔗

caseLinks(map) -> list

例🔗

caseLinks(inputs)
caseLinks(inputs)

出力: [, ]

caseLinksReference🔗

ケースレコードを解析し、すべてのリンクから参照文字列のリストを返します。

入力と出力🔗

caseLinksReference(map) -> list

例🔗

caseLinksReference(inputs)
caseLinksReference(inputs)

出力: ["EXT-12345", "JIRA-456"]

caseLinksTitle🔗

ケースレコードを解析し、すべてのリンクからタイトル文字列のリストを返します。

入力と出力🔗

caseLinksTitle(map) -> list

例🔗

caseLinksTitle(inputs)
caseLinksTitle(inputs)

出力: ["External Ticket", "Jira Ticket"]

caseLinksType🔗

ケースレコードを解析し、すべてのリンクからタイプ文字列のリストを返します (例: External または Jira)。

入力と出力🔗

caseLinksType(map) -> list

例🔗

caseLinksType(inputs)
caseLinksType(inputs)

出力: ["External", "Jira"]

caseLinksUrl🔗

ケースレコードを解析し、すべてのリンクから URL 文字列のリストを返します。

入力と出力🔗

caseLinksUrl(map) -> list

例🔗

caseLinksUrl(inputs)
caseLinksUrl(inputs)

出力: ["https://example.com/tickets/EXT-12345", "https://jira.example.com/..."]

caseManagedBy🔗

ケースレコードを解析し、managed-by の値 (PROVIDER、CUSTOMER、UNKNOWN) を返します。

入力と出力🔗

caseManagedBy(map) -> string

例🔗

caseManagedBy(inputs)
caseManagedBy(inputs)

出力: "CUSTOMER"

casePrimaryStatusId🔗

ケースレコードを解析し、プライマリステータス ID を返します。

入力と出力🔗

casePrimaryStatusId(map) -> string

例🔗

casePrimaryStatusId(inputs)
casePrimaryStatusId(inputs)

出力: "8dafe9bc-cbf6-4b27-aff4-8959682f859c"

casePrimaryStatusName🔗

ケースレコードを解析し、プライマリステータス名を返します。

入力と出力🔗

casePrimaryStatusName(map) -> string

例🔗

casePrimaryStatusName(inputs)
casePrimaryStatusName(inputs)

出力: "draft"

casePrimaryStatusTitle🔗

ケースレコードを解析し、プライマリステータスタイトルを返します。

入力と出力🔗

casePrimaryStatusTitle(map) -> string

例🔗

casePrimaryStatusTitle(inputs)
casePrimaryStatusTitle(inputs)

出力: "Draft"

casePrimaryVerdictId🔗

ケースレコードを解析し、プライマリ判定 ID を返します。

入力と出力🔗

casePrimaryVerdictId(map) -> string

例🔗

casePrimaryVerdictId(inputs)
casePrimaryVerdictId(inputs)

出力: "pv-1"

casePrimaryVerdictName🔗

ケースレコードを解析し、プライマリ判定名を返します。

入力と出力🔗

casePrimaryVerdictName(map) -> string

例🔗

casePrimaryVerdictName(inputs)
casePrimaryVerdictName(inputs)

出力: "confirmed"

casePrimaryVerdictTitle🔗

ケースレコードを解析し、プライマリ判定タイトルを返します。

入力と出力🔗

casePrimaryVerdictTitle(map) -> string

例🔗

casePrimaryVerdictTitle(inputs)
casePrimaryVerdictTitle(inputs)

出力: "Confirmed"

casePriority🔗

ケースレコードを解析し、ケースの優先度を単語 (Low、Medium、High、Critical) で返します。

オプションの第 2 引数に true を指定すると、優先度を整数 (1-4) で返します。

入力と出力🔗

casePriority(map) -> string
casePriority(map, bool) -> int

例🔗

casePriority(inputs)
casePriority(inputs)

出力: "High"

casePriority(inputs, true)
casePriority(inputs, true)

出力: 3

caseProcessingStatus🔗

ケースレコードを解析し、処理ステータスマップを返します。

入力と出力🔗

caseProcessingStatus(map) -> map

例🔗

caseProcessingStatus(inputs)
caseProcessingStatus(inputs)

出力: {"alerts": "SUCCESS", "assets": "SUCCESS", "events": "SUCCESS"}

caseRiskScore🔗

ケースレコードを解析し、リスクスコアを返します。

入力と出力🔗

caseRiskScore(map) -> double

例🔗

caseRiskScore(inputs)
caseRiskScore(inputs)

出力: 7.2

caseRuleId🔗

ケースレコードを解析し、それを作成した自動ケースルール ID を返します。

入力と出力🔗

caseRuleId(map) -> string

例🔗

caseRuleId(inputs)
caseRuleId(inputs)

出力: "12345"

caseSearchEvidence🔗

ケースレコードを解析し、検索証拠オブジェクトのリストを返します。

入力と出力🔗

caseSearchEvidence(map) -> list

例🔗

caseSearchEvidence(inputs)
caseSearchEvidence(inputs)

出力: [, ...]

caseSecondaryStatusId🔗

ケースレコードを解析し、セカンダリステータス ID を返します。

入力と出力🔗

caseSecondaryStatusId(map) -> string

例🔗

caseSecondaryStatusId(inputs)
caseSecondaryStatusId(inputs)

出力: "ss-1"

caseSecondaryStatusName🔗

ケースレコードを解析し、セカンダリステータス名を返します。

入力と出力🔗

caseSecondaryStatusName(map) -> string

例🔗

caseSecondaryStatusName(inputs)
caseSecondaryStatusName(inputs)

出力: "under_review"

caseSecondaryStatusReason🔗

ケースレコードを解析し、セカンダリステータス理由のリストを返します。

入力と出力🔗

caseSecondaryStatusReason(map) -> list

例🔗

caseSecondaryStatusReason(inputs)
caseSecondaryStatusReason(inputs)

出力: ["reason1", "reason2"]

caseSecondaryStatusTitle🔗

ケースレコードを解析し、セカンダリステータスタイトルを返します。

入力と出力🔗

caseSecondaryStatusTitle(map) -> string

例🔗

caseSecondaryStatusTitle(inputs)
caseSecondaryStatusTitle(inputs)

出力: "Under Review"

caseSecondaryVerdictId🔗

ケースレコードを解析し、セカンダリ判定 ID を返します。

入力と出力🔗

caseSecondaryVerdictId(map) -> string

例🔗

caseSecondaryVerdictId(inputs)
caseSecondaryVerdictId(inputs)

出力: "sv-1"

caseSecondaryVerdictName🔗

ケースレコードを解析し、セカンダリ判定名を返します。

入力と出力🔗

caseSecondaryVerdictName(map) -> string

例🔗

caseSecondaryVerdictName(inputs)
caseSecondaryVerdictName(inputs)

出力: "malicious"

caseSecondaryVerdictTitle🔗

ケースレコードを解析し、セカンダリ判定タイトルを返します。

入力と出力🔗

caseSecondaryVerdictTitle(map) -> string

例🔗

caseSecondaryVerdictTitle(inputs)
caseSecondaryVerdictTitle(inputs)

出力: "Malicious"

caseSeverity🔗

ケースレコードを解析し、重大度を単語 (Informational、Low、Medium、High、Critical) で返します。

inputs.case では重大度値 2、4、6、8、10 を使用します。V1/V2 レコードでは優先度値 1-4 を使用します。

オプションの第 2 引数に false を指定すると、生の数値を返します。

入力と出力🔗

caseSeverity(map) -> string
caseSeverity(map, bool) -> int

例🔗

caseSeverity(inputs)
caseSeverity(inputs)

出力: "Medium"

caseSeverity(inputs, false)
caseSeverity(inputs, false)

出力: 6

caseShortId🔗

ケースレコードを解析し、短縮 ID を返します。

入力と出力🔗

caseShortId(map) -> string

例🔗

caseShortId(inputs)
caseShortId(inputs)

出力: "INV41773"

caseSourceId🔗

ケースレコードを解析し、ソース ID を返します。

入力と出力🔗

caseSourceId(map) -> string

例🔗

caseSourceId(inputs)
caseSourceId(inputs)

出力: "src-auto-001"

caseSourceName🔗

ケースレコードを解析し、ソース名を返します。

入力と出力🔗

caseSourceName(map) -> string

例🔗

caseSourceName(inputs)
caseSourceName(inputs)

出力: "auto_case_rule"

caseSourceTitle🔗

ケースレコードを解析し、ソース表示タイトルを返します。

入力と出力🔗

caseSourceTitle(map) -> string

例🔗

caseSourceTitle(inputs)
caseSourceTitle(inputs)

出力: "Auto-Generated"

caseStatus🔗

ケースレコードを解析し、ステータスを返します。

入力と出力🔗

caseStatus(map) -> string
caseStatus(map, string) -> string

例🔗

caseStatus(inputs)
caseStatus(inputs)

出力: "OPEN"

caseStatus(inputs, 'v1')
caseStatus(inputs, 'v1')

出力: "Open"

caseTags🔗

ケースレコードを解析し、タグのリストを返します。

入力と出力🔗

caseTags(map) -> list

例🔗

caseTags(inputs)
caseTags(inputs)

出力: ["automation", "playbook"]

caseTenantId🔗

ケースレコードを解析し、テナントの ID を返します。

入力と出力🔗

caseTenantId(map) -> string

例🔗

caseTenantId(inputs)
caseTenantId(inputs)

出力: "12345"

caseThirdPartyId🔗

ケースレコードを解析し、それに関連付けられたサードパーティレコードの ID を返します。

入力と出力🔗

caseThirdPartyId(map) -> string

例🔗

caseThirdPartyId(inputs)
caseThirdPartyId(inputs)

出力: "bdf9f35a8383121055c9e330ceaad3b8"

caseThirdPartyType🔗

ケースレコードを解析し、それに関連付けられたサードパーティレコードのタイプを返します。

入力と出力🔗

caseThirdPartyType(map) -> string

例🔗

caseThirdPartyType(inputs)
caseThirdPartyType(inputs)

出力: "SNOW"

caseTitle🔗

ケースレコードを解析し、タイトルを返します。

入力と出力🔗

caseTitle(map) -> string

例🔗

caseTitle(inputs)
caseTitle(inputs)

出力: "Taegis Watchlist Case"

caseType🔗

ケースレコードを解析し、タイプを返します。

オプションの第 2 引数に 'v1' または 'v2' を指定すると、タイプを変換します。デフォルトは 'v2' です。

入力と出力🔗

caseType(map) -> string
caseType(map, string) -> string

例🔗

caseType(inputs)
caseType(inputs)

出力: "SECURITY_INVESTIGATION"

caseType(inputs, 'v1')
caseType(inputs, 'v1')

出力: "Security Investigation"

caseTypeId🔗

ケースレコードを解析し、構造化されたタイプオブジェクトから生のタイプ ID を返します。

タイプが存在しない場合、またはオブジェクトでない場合は空文字列を返します。

入力と出力🔗

caseTypeId(map) -> string

例🔗

caseTypeId(inputs)
caseTypeId(inputs)

出力: "00000006-0000-4000-a000-000000000001"

caseTypeTitle🔗

ケースレコードを解析し、構造化されたタイプオブジェクトからタイプ表示タイトルを返します。

タイプが存在しない場合、またはオブジェクトでない場合は空文字列を返します。

入力と出力🔗

caseTypeTitle(map) -> string

例🔗

caseTypeTitle(inputs)
caseTypeTitle(inputs)

出力: "Investigation"

caseUpdatedAt🔗

ケースレコードを解析し、最終更新日時を返します。

入力と出力🔗

caseUpdatedAt(map) -> string

例🔗

caseUpdatedAt(inputs)
caseUpdatedAt(inputs)

出力: "2024-06-20T17:57:46.700164Z"

caseUpdatedById🔗

ケースレコードを解析し、最後に更新したユーザーの ID を返します。

入力と出力🔗

caseUpdatedById(map) -> string

例🔗

caseUpdatedById(inputs)
caseUpdatedById(inputs)

出力: "dac1ed31-111-4809-9cc9-9f99b6e"

cel.bind🔗

式内にローカル変数バインディングを作成し、高コストな処理の再計算を回避します。

入力と出力🔗

cel.bind(var_name, value, expression) -> any

式内で参照できるローカル変数を作成します。

変数は第 3 引数 (expression) のスコープ内でのみ使用できます。

これは次の場合に役立ちます。

  • 高コストな処理の繰り返し計算を回避する。
  • 複雑な式を読みやすくする。
  • より明確なロジックのために中間値を作成する。

変数名は識別子として指定します (文字列ではありません)。

値には任意の CEL 式を指定できます。

式は、その変数がスコープ内にある状態で評価されます。

ユースケース🔗

繰り返し計算を回避する。
cel.bind(name, inputs.user.name.uppercase(), name + ' - ' + string(name.size()))

高コストな処理の繰り返しを避け、可読性を向上させます。

複雑な条件を簡略化する。
cel.bind(withTax, inputs.price * 1.2, withTax > 100 ? withTax * 0.9 : withTax)

中間値を計算して再利用します。

複数のバインディングを連結する。
cel.bind(x, 5, cel.bind(y, x * 2, cel.bind(z, y + 3, x + y + z)))

出力: 26

ネストした変数バインディングを作成します。

リストを扱う。
cel.bind(nums, [1, 2, 3, 4, 5], cel.bind(doubled, nums.map(n, n * 2), doubled.filter(n, n > 5)))

出力: [6, 8, 10]

すべての値を 2 倍にしてから、結果をフィルタリングします。

複雑なオブジェクトアクセス。
cel.bind(user, inputs.users[0], user.name + ' (' + user.email + ')')

オブジェクトに 1 回アクセスし、それを複数回再利用します。

例🔗

cel.bind(x, 10, x * x)
cel.bind(x, 10, x * x)

出力: 100

cel.bind(user, 'John', 'Hello ' + user)
cel.bind(user, 'John', 'Hello ' + user)

出力: "Hello John"

cel.bind(list, [1,2,3], list.size() + list[0])
cel.bind(list, [1,2,3], list.size() + list[0])

出力: 4

charAt🔗

文字列内の指定されたインデックス位置の文字を返します。

入力と出力🔗

string.charAt(int) -> string

0 ベースの指定インデックス位置にある文字を返します (1 文字の文字列として)。

インデックスが範囲外の場合は空文字列を返します。

例🔗

'hello'.charAt(0)
'hello'.charAt(0)

出力: "h"

'hello'.charAt(4)
'hello'.charAt(4)

出力: "o"

collect🔗

指定されたパス引数に一致するマップ値のリストを返します。

入力と出力🔗

collect(list, string) -> list

例🔗

[{\"a\": \"value1\"}, {\"b\": \"value2\"}, {\"a\": \"value3\"}].collect('a')
[{\"a\": \"value1\"}, {\"b\": \"value2\"}, {\"a\": \"value3\"}].collect('a')

出力: ["value1", "value3"]

contains🔗

文字列またはリスト内のいずれかの要素が、指定された文字列またはリストに一致する場合に true を返します (大文字と小文字を区別します)。

オプションの第 2 引数に true を指定すると、大文字と小文字を無視して一致を判定します。

入力と出力🔗

contains(string, string) -> bool
contains(string, string, bool) -> bool
contains(string, list) -> bool
contains(string, list, bool) -> bool
contains(list, string) -> bool
contains(list, string, bool) -> bool
contains(list, list) -> bool
contains(list, list, bool) -> bool

例🔗

"apple".contains("app")
"apple".contains("app")

出力: true

"apple".contains("APP", true)
"apple".contains("APP", true)

出力: true

"apple".contains(["app"])
"apple".contains(["app"])

出力: true

"apple".contains(["APP"], true)
"apple".contains(["APP"], true)

出力: true

["apple", "banana"].contains("app")
["apple", "banana"].contains("app")

出力: true

["apple", "banana"].contains("APP", true)
["apple", "banana"].contains("APP", true)

出力: true

["apple", "banana"].contains(["app"])
["apple", "banana"].contains(["app"])

出力: true

["apple", "banana"].contains(["APP"], true)
["apple", "banana"].contains(["APP"], true)

出力: true

count🔗

指定された文字列引数に一致するリスト要素の数、またはそれに一致するマップ内のキーの数を返します。

入力と出力🔗

count(list, string) -> int

例🔗

count([{"a": "value1"}, {"b": "value2"}, {"a": "value3"}], "a")
count([{"a": "value1"}, {"b": "value2"}, {"a": "value3"}], "a")

出力: 2

アラート、調査、または資産の Taegis Sharelink を返します。

入力と出力🔗

createShareLink(map) -> string

例🔗

createShareLink(inputs)
createShareLink(inputs)

出力: "https://ctpx.secureworks.com/share/14f-ca9d-ad47-34db-2243b945ce2112f"

decodeBase64🔗

デコードされた base64 入力文字列を返します。

入力と出力🔗

decodeBase64(string) -> string

例🔗

decodeBase64("aGVsbG8gd29ybGQ=")
decodeBase64("aGVsbG8gd29ybGQ=")

出力: "hello world"

decodeJSON🔗

入力文字列をデコードした JSON オブジェクトを返します。

入力と出力🔗

decodeJSON(string) -> any

例🔗

decodeJSON('{"key": "value"}')
decodeJSON('{"key": "value"}')

出力: {"key":"value"}

decodeYAML🔗

YAML 入力を任意のデータ型にデコードします。

入力と出力🔗

decodeYAML(string) -> any

例🔗

decodeYAML("key: value")
decodeYAML("key: value")

出力: {"key":"value"}

detectionAttackTechniqueIds🔗

検出レコードを解析し、攻撃手法 ID の値を返します。

入力と出力🔗

detectionAttackTechniqueIds(map) -> list

例🔗

detectionAttackTechniqueIds(inputs)
detectionAttackTechniqueIds(inputs)

出力: ["T1096", "T1214"]

detectionConfidence🔗

検出レコードを解析し、信頼度の値を返します。

入力と出力🔗

detectionConfidence(map) -> double

例🔗

detectionConfidence(inputs)
detectionConfidence(inputs)

出力: 0.5

detectionCreatedAtNanos🔗

検出レコードを解析し、検出が作成された時刻のナノ秒値を返します。

入力と出力🔗

detectionCreatedAtNanos(map) -> int

例🔗

detectionCreatedAtNanos(inputs)
detectionCreatedAtNanos(inputs)

出力: 796357058

detectionCreatedAtSeconds🔗

検出レコードを解析し、created_at の値をエポックからの秒数として返します。

入力と出力🔗

detectionCreatedAtSeconds(map) -> int

例🔗

detectionCreatedAtSeconds(inputs)
detectionCreatedAtSeconds(inputs)

出力: 1636029855

detectionDescription🔗

検出レコードを解析し、説明の値を返します。

入力と出力🔗

detectionDescription(map) -> string

例🔗

detectionDescription(inputs)
detectionDescription(inputs)

出力: "This is a sample Taegis Watchlist Detection"

detectionDestinationIPs🔗

検出レコードを解析し、エンティティが destinationIPAddress とラベル付けされている検出エンティティフィールドから、一意の IP アドレス値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

detectionDestinationIPs(map) -> list

例🔗

detectionDestinationIPs(inputs)
detectionDestinationIPs(inputs)

出力: ["192.168.0.1", "192.168.0.2"]

detectionDetectorId🔗

検出レコードを解析し、検知機 ID の値を返します。

入力と出力🔗

detectionDetectorId(map) -> string

例🔗

detectionDetectorId(inputs)
detectionDetectorId(inputs)

出力: "app:event-filter"

detectionDetectorName🔗

検出レコードを解析し、検知機名の値を返します。

入力と出力🔗

detectionDetectorName(map) -> string

例🔗

detectionDetectorName(inputs)
detectionDetectorName(inputs)

出力: "Taegis Watchlist"

detectionDomains🔗

検出レコードを解析し、エンティティが ipdomain、topprivateipdomain、domainname、authdomainname、sourceauthdomainname、または targetauthdomainname とラベル付けされている検出エンティティフィールドから、一意のドメイン名値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

detectionDomains(map) -> list

例🔗

detectionDomains(inputs)
detectionDomains(inputs)

出力: ["example.com", "a.example.com"]

detectionEnrichment🔗

検出レコードとエンリッチメントデータを解析し、指定されたパスに一致する最初の値を返します。

入力と出力🔗

detectionEnrichment(map, string) -> any

例🔗

detectionEnrichment(inputs, 'rare_program_rare_ip.programs')
detectionEnrichment(inputs, 'rare_program_rare_ip.programs')

出力: ["foo.exe", "bar.exe"]

detectionEnrichment(inputs, 'doesnotexist')
detectionEnrichment(inputs, 'doesnotexist')

出力: []

detectionEntities🔗

検出レコードを解析し、エンティティ値を返します。

入力と出力🔗

detectionEntities(map) -> list

例🔗

detectionEntities(inputs)
detectionEntities(inputs)

出力: ["hostname:abc", "sensorId:12345", "fileName:c:\\windows\\syswow64\\cmd.exe"]

detectionEntity🔗

検出レコードを解析し、指定されたエンティティ名に一致するエンティティ値を返します (大文字と小文字を区別しません)。

入力と出力🔗

detectionEntity(map, string) -> list

例🔗

detectionEntity(inputs, 'username')
detectionEntity(inputs, 'username')

出力: ["sample_user", "another_sample_user"]

detectionEventIds🔗

検出レコードを解析し、イベント ID 値のリストを返します。

入力と出力🔗

detectionEventIds(map) -> list

例🔗

detectionEventIds(inputs)
detectionEventIds(inputs)

出力: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

detectionGroupKey🔗

検出レコードを解析し、group_key の値を返します。

入力と出力🔗

detectionGroupKey(map) -> string

例🔗

detectionGroupKey(inputs)
detectionGroupKey(inputs)

出力: "12345:app:event-filter:80c0809b-153f-4b81-bb7c-52fcb83c7127"

detectionHostnames🔗

検出レコードを解析し、エンティティが hostname、sourcehostname、desthostname、workstationname、または computername とラベル付けされている検出エンティティフィールドから、一意の値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

detectionHostnames(map) -> list

例🔗

detectionHostnames(inputs)
detectionHostnames(inputs)

出力: ["sample_hostname", "another_sample_hostname"]

detectionIPs🔗

検出レコードを解析し、エンティティが ipAddress とラベル付けされている検出エンティティフィールドから、一意の IP アドレス値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

detectionIPs(map) -> list

例🔗

detectionIPs(inputs)
detectionIPs(inputs)

出力: ["192.168.0.1", "192.168.0.2"]

detectionId🔗

検出レコードを解析し、ID または UUID を返します。

入力と出力🔗

detectionId(map) -> string

例🔗

detectionId(inputs)
detectionId(inputs)

出力: "detection://priv:endpoint-redcloak:12345:1678899090095:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"

detectionInvestigationIds🔗

検出レコードを解析し、検出に関連付けられた調査 ID のリストを返します。

入力と出力🔗

detectionInvestigationIds(map) -> list

例🔗

detectionInvestigationIds(inputs)
detectionInvestigationIds(inputs)

出力: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

detectionMitreAttackInfo🔗

検出レコードを解析し、mitre_attack_info 値のリストを返します。

入力と出力🔗

detectionMitreAttackInfo(map) -> list

例🔗

detectionMitreAttackInfo(inputs)
detectionMitreAttackInfo(inputs)

出力: [{"description":"Adversaries may attempt...","technique":"Process Discovery","technique_id":"T1057"}]

detectionObservationIds🔗

検出レコードを解析し、観測 ID 値のリストを返します。

入力と出力🔗

detectionObservationIds(map) -> list

例🔗

detectionObservationIds(inputs)
detectionObservationIds(inputs)

出力: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

detectionReferences🔗

検出レコードを解析し、検出に関連付けられた参照のリストを返します。

入力と出力🔗

detectionReferences(map) -> list

例🔗

detectionReferences(inputs)
detectionReferences(inputs)

出力: [{"description": "External Detection Ref", "url": "https://example.com/detection/29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"}]

detectionResolution🔗

検出レコードを解析し、解決値を返します。

入力と出力🔗

detectionResolution(map) -> string

例🔗

detectionResolution(inputs)
detectionResolution(inputs)

出力: "open"

detectionResolutionReason🔗

検出レコードを解析し、解決理由の値を返します。

入力と出力🔗

detectionResolutionReason(map) -> string

例🔗

detectionResolutionReason(inputs)
detectionResolutionReason(inputs)

出力: "Valid activity for this user."

detectionRuleId🔗

検出レコードを解析し、ルール ID を返します。

入力と出力🔗

detectionRuleId(map) -> string

例🔗

detectionRuleId(inputs)
detectionRuleId(inputs)

Output* "267658fe-65f1-4145-8753-d45fbf9ed6d3"

detectionSensorIds🔗

検出レコードを解析し、センサー ID 値のリストを返します。

入力と出力🔗

detectionSensorIds(map) -> list

例🔗

detectionSensorIds(inputs)
detectionSensorIds(inputs)

出力: ["12345", "1234-12345-123"]

detectionSensorTypes🔗

検出レコードを解析し、一意のセンサータイプ値のリストを返します (大文字)。

入力と出力🔗

detectionSensorTypes(map) -> list

例🔗

detectionSensorTypes(inputs)
detectionSensorTypes(inputs)

出力: ["ENDPOINT_REDCLOAK", "ENDPOINT_TAEGIS"]

detectionSeverity🔗

検出レコードを解析し、重大度の値を返します。

入力と出力🔗

detectionSeverity(map) -> double

例🔗

detectionSeverity(inputs)
detectionSeverity(inputs)

出力: 0.75

detectionSeverityNice🔗

検出レコードを解析し、人が読みやすい重大度の値を単語 (Informational、Low、Medium、High、Critical) で返します。

入力と出力🔗

detectionSeverityNice(map) -> string

例🔗

detectionSeverityNice(inputs)
detectionSeverityNice(inputs)

出力: "High"

detectionSourceEntities🔗

検出の source_entities フィールドからソースエンティティのリストを返します。

入力と出力🔗

detectionSourceEntities(map) -> list

例🔗

detectionSourceEntities(inputs)
detectionSourceEntities(inputs)

出力: [{"id": "...", "display_name": "...", "perspective": "SOURCE", ...}]

detectionSourceEntityProperties🔗

source_entities を property_type でフィルタリングし、指定されたプロパティキーの値を返します。

入力と出力🔗

detectionSourceEntityProperties(map, string, list) -> list

例🔗

detectionSourceEntityProperties(inputs, "EntityUser", ["user_name", "original_user_name"])
detectionSourceEntityProperties(inputs, "EntityUser", ["user_name", "original_user_name"])

出力: ["jdoe", "jdoe"]

detectionSourceIPs🔗

検出レコードを解析し、エンティティが sourceIPAddress とラベル付けされている検出エンティティフィールドから、一意の IP アドレス値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

detectionSourceIPs(map) -> list

例🔗

detectionSourceIPs(inputs)
detectionSourceIPs(inputs)

出力: ["192.168.0.1", "192.168.0.2"]

detectionStatus🔗

検出レコードを解析し、ステータス値を返します。

入力と出力🔗

detectionStatus(map) -> string

例🔗

detectionStatus(inputs)
detectionStatus(inputs)

出力: "open"

detectionTags🔗

検出レコードを解析し、タグのリストを返します。

入力と出力🔗

detectionTags(map) -> list

例🔗

detectionTags(inputs)
detectionTags(inputs)

出力: ["detectionRule:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "compactor:handler"]

detectionTargetEntities🔗

検出の target_entities フィールドからターゲットエンティティのリストを返します。

入力と出力🔗

detectionTargetEntities(map) -> list

例🔗

detectionTargetEntities(inputs)
detectionTargetEntities(inputs)

出力: [{"id": "...", "display_name": "...", "perspective": "TARGET", ...}]

detectionTargetEntityProperties🔗

target_entities を property_type でフィルタリングし、指定されたプロパティキーの値を返します。

入力と出力🔗

detectionTargetEntityProperties(map, string, list) -> list

例🔗

detectionTargetEntityProperties(inputs, "EntityFileHash", ["hash_value"])
detectionTargetEntityProperties(inputs, "EntityFileHash", ["hash_value"])

出力: ["abc123def456"]

detectionTenantId🔗

検出レコードを解析し、テナント ID を返します。

入力と出力🔗

detectionTenantId(map) -> string

例🔗

detectionTenantId(inputs)
detectionTenantId(inputs)

出力: "12345"

detectionThirdPartyDetail🔗

検出レコードとサードパーティ詳細データを解析し、指定されたパスに一致する最初の値を返します。

入力と出力🔗

detectionThirdPartyDetail(map, string) -> list

例🔗

detectionThirdPartyDetail(inputs, 'userStates.0.aadUserId')
detectionThirdPartyDetail(inputs, 'userStates.0.aadUserId')

出力: ["F86DBD0D-6571-44A0-BAE1-43B83CF430AD"]

detectionTitle🔗

検出レコードを解析し、タイトル値を返します。

入力と出力🔗

detectionTitle(map) -> string

例🔗

detectionTitle(inputs)
detectionTitle(inputs)

出力: "Taegis Watchlist Detection"

detectionUpdatedAtNanos🔗

検出レコードを解析し、検出が変更された時刻のナノ秒値を返します。

入力と出力🔗

detectionUpdatedAtNanos(map) -> int

例🔗

detectionUpdatedAtNanos(inputs)
detectionUpdatedAtNanos(inputs)

出力: 796357058

detectionUpdatedAtSeconds🔗

検出レコードを解析し、updated_at の値をエポックからの秒数として返します。

入力と出力🔗

detectionUpdatedAtSeconds(map) -> int

例🔗

detectionUpdatedAtSeconds(inputs)
detectionUpdatedAtSeconds(inputs)

出力: 1697207995554

detectionUsernames🔗

検出レコードを解析し、エンティティが username とラベル付けされている検出エンティティフィールドから、小文字の一意なユーザー名値のリストを返します (大文字と小文字を区別しません)。

入力と出力🔗

detectionUsernames(map) -> list

例🔗

detectionUsernames(inputs)
detectionUsernames(inputs)

出力: ["sample_user", "another_sample_user"]

distinct🔗

リストから重複要素を削除し、各要素の最初の出現を保持します。

入力と出力🔗

list.distinct() -> list

元のリストから一意の要素のみを含む新しいリストを返します。

各要素の最初の出現は、出現した順序で保持されます。

重複は削除されます。

ユースケース🔗

ユーザー入力から重複を削除する。
user_tags.distinct()

重複したタグを整理します。

一意の値を取得する。
results.map(r, r.category).distinct()

結果からすべての一意なカテゴリを取得します。

ID の重複を排除する。
id_list.distinct()

重複した ID がないことを確認します。

データを整理する。
inputs.values.distinct()

重複を削除します。

集合のような操作を使用する。
list1.distinct().size() == list1.size()

リストに重複がないかどうかを確認します。

フィルターと組み合わせる。
items.filter(i, i.active).map(i, i.id).distinct()

アクティブな項目の一意な ID を取得します。

順序を保持する。
[3, 1, 2, 1, 3].distinct()

出力: [3, 1, 2]

各要素の最初の出現順序を保持します。

注意🔗

  • 最初の出現順序を保持します。
  • 比較可能な任意の型で動作します。
  • 空のリストは空のままです。
  • 出力はソートされません。

例🔗

[1, 2, 2, 3, 3, 3].distinct()
[1, 2, 2, 3, 3, 3].distinct()

出力: [1, 2, 3]

重複した数値を削除します。

['b', 'b', 'c', 'a', 'c'].distinct()
['b', 'b', 'c', 'a', 'c'].distinct()

出力: ['b', 'c', 'a']

重複した文字列を削除し、その順序を保持します。

[1, 2, 3].distinct()
[1, 2, 3].distinct()

出力: [1, 2, 3]

リストはすでに一意です。

[1, 1, 1].distinct()
[1, 1, 1].distinct()

出力: [1]

すべての重複要素を削除します。

[].distinct()
[].distinct()

出力: []

空のリストは空のままです。

domains🔗

指定されたユーザー名引数が、指定された 1 つ以上のドメイン内にある場合に true を返します。

入力と出力🔗

domains(map) -> list

例🔗

domains(inputs)
domains(inputs)

出力: ["example.com","foo.com"]

encodeBase64🔗

文字列入力を base64 文字列としてエンコードして返します。

入力と出力🔗

encodeBase64(string) -> string

例🔗

encodeBase64("hello world")
encodeBase64("hello world")

出力: "aGVsbG8gd29ybGQ="

encodeJSON🔗

文字列入力を JSON 文字列としてエンコードして返します。

入力と出力🔗

encodeJSON(string) -> string

例🔗

encodeJSON({"key":"value"})
encodeJSON({"key":"value"})

出力: "{\"key\":\"value\"}"

encodeYAML🔗

任意の値を YAML 文字列としてエンコードします。

入力と出力🔗

encodeYAML(string) -> string

例🔗

encodeYAML({"key":"value"})
encodeYAML({"key":"value"})

出力: "key: value\n"

entityValue🔗

エンティティレコードを解析し、指定されたエンティティプロパティの値のリストを返します。

入力と出力🔗

entityValue(map, string) -> list

例🔗

entityValue(inputs, "username")
entityValue(inputs, "username")

出力: ["john"]

entityValue(inputs, "nonexistent")
entityValue(inputs, "nonexistent")

出力: []

entityValues🔗

エンティティレコードを解析し、エンティティに関連付けられた値のリストを返します。

入力と出力🔗

entityValues(map) -> list

例🔗

entityValues(inputs)
entityValues(inputs)

出力: ["example.com", "john@example.com", "john"]

exists🔗

リストまたはマップを反復処理し、条件が少なくとも 1 つの要素に対して真であることを検証します。

入力と出力🔗

exists(list, predicate) -> bool
exists(map, predicate) -> bool

例🔗

[1, 2, 3].exists(i, i % 2 != 0)
[1, 2, 3].exists(i, i % 2 != 0)

出力: true

{"x": "foo", "y": "bar"}.exists(key, key.startsWith("z"))
{"x": "foo", "y": "bar"}.exists(key, key.startsWith("z"))

出力: false

exists_one🔗

リストまたはマップを反復処理し、条件がちょうど 1 つの要素に対して真であることを検証します。

入力と出力🔗

exists_one(list, predicate) -> bool
exists_one(map, predicate) -> bool

例🔗

[1, 2, 2].exists_one(i, i < 2)
[1, 2, 2].exists_one(i, i < 2)

出力: true

{"a": "hello", "aa": "hellohello"}.exists_one(k, k.startsWith("a"))
{"a": "hello", "aa": "hellohello"}.exists_one(k, k.startsWith("a"))

出力: false

filehashes🔗

アラートまたはエンティティから、見つかったファイルハッシュのリストを返します。

入力と出力🔗

filehashes(map) -> list

例🔗

filehashes(inputs)
filehashes(inputs)

出力: ["445362b51bf855f62f9af7bb8362c8b27c7bc1ceb1dc88fd41a72de19b779969", "2e5a8590cf6848968fc23de3fa1e25f1", "9785001b0dcf755eddb8af294a373c0b87b2498660f724e76c4d53f9c217c7a3"]

filter🔗

リストを反復処理し、指定された条件に一致する要素を返します。

入力と出力🔗

filter(list, predicate) -> list

例🔗

["a", "ab", "c"].filter(x, x.contains("a"))
["a", "ab", "c"].filter(x, x.contains("a"))

出力: ["a", "ab"]

["a", "ab", "c"].filter(x, x.contains("d"))
["a", "ab", "c"].filter(x, x.contains("d"))

出力: []

findingCheck🔗

ID の発見事項レコードを解析し、チェックマップを返します。第 2 引数を指定すると、特定のエントリーを返します。

入力と出力🔗

findingCheck(map) -> map
findingCheck(map, string) -> any

例🔗

findingCheck(inputs)
findingCheck(inputs)

出力: {'autoResolutionDisabled':false,'category':'CONFIGURATION', ... }

findingCheck(inputs, "module")
findingCheck(inputs, "module")

出力: "IDENTITY"

findingCheck(inputs, "id")
findingCheck(inputs, "id")

出力: "e98c0bf1-f226-4465-940f-696a79e7bdc6"

findingCheck(inputs, "title")
findingCheck(inputs, "title")

出力: "Application shall not have unclaimed DNS names that are susceptible to takeover"

findingCheck(inputs, "description")
findingCheck(inputs, "description")

出力: "Threat actors can exploit vulnerabilities in Microsoft Entra ID applications by registering unclaimed subdomains, also known as dangling Fully Qualified Domain Names (FQDNs)."

findingCheck(inputs, "enabled")
findingCheck(inputs, "enabled")

出力: true

findingClosedAt🔗

ID の発見事項レコードを解析し、クローズ日時のタイムスタンプを返します。

入力と出力🔗

findingClosedAt(map) -> string

例🔗

findingClosedAt(inputs)
findingClosedAt(inputs)

出力: "2025-04-28T16:57:49.591956Z"

findingConfidenceScore🔗

ID の発見事項レコードを解析し、信頼度スコアを返します。

入力と出力🔗

findingConfidenceScore(map) -> double

例🔗

findingConfidenceScore(inputs)
findingConfidenceScore(inputs)

出力: "1.0"

findingFieldChanged🔗

発見事項レコードを解析し、指定されたフィールドが変更された場合は true を返します。

入力と出力🔗

findingFieldChanged(map, string) -> bool

例🔗

findingFieldChanged(inputs, 'status')
findingFieldChanged(inputs, 'status')

出力: true

findingFieldChanged(inputs, 'nonexistent_field')
findingFieldChanged(inputs, 'nonexistent_field')

出力: false

findingFirstSeen🔗

ID の発見事項レコードを解析し、初回確認タイムスタンプを返します。

入力と出力🔗

findingFirstSeen(map) -> string

例🔗

findingFirstSeen(inputs)
findingFirstSeen(inputs)

出力: "2025-03-12T16:57:49.591956Z"

findingId🔗

ID の発見事項レコードを解析し、ID を返します。

入力と出力🔗

findingId(map) -> string

例🔗

findingId(inputs)
findingId(inputs)

出力: "f1234567-89ab-cdef-0123-456789abcdef"

findingIdentityCity🔗

ID の発見事項レコードを解析し、ID データから市区町村を返します。

入力と出力🔗

findingIdentityCity(map) -> string

例🔗

findingIdentityCity(inputs)
findingIdentityCity(inputs)

出力: "New York"

findingIdentityCompanyName🔗

ID の発見事項レコードを解析し、ID データから会社名を返します。

入力と出力🔗

findingIdentityCompanyName(map) -> string

例🔗

findingIdentityCompanyName(inputs)
findingIdentityCompanyName(inputs)

出力: "Example Corp"

findingIdentityCountry🔗

ID の発見事項レコードを解析し、ID データから国を返します。

入力と出力🔗

findingIdentityCountry(map) -> string

例🔗

findingIdentityCountry(inputs)
findingIdentityCountry(inputs)

出力: "United States"

findingIdentityCreatedAt🔗

ID の発見事項レコードを解析し、ID データから作成タイムスタンプを返します。

入力と出力🔗

findingIdentityCreatedAt(map) -> string

例🔗

findingIdentityCreatedAt(inputs)
findingIdentityCreatedAt(inputs)

出力: "2024-01-15T10:30:00Z"

findingIdentityDepartment🔗

ID の発見事項レコードを解析し、ID データから部門を返します。

入力と出力🔗

findingIdentityDepartment(map) -> string

例🔗

findingIdentityDepartment(inputs)
findingIdentityDepartment(inputs)

出力: "Engineering"

findingIdentityDisplayName🔗

ID の発見事項レコードを解析し、ID データから表示名を返します。

入力と出力🔗

findingIdentityDisplayName(map) -> string

例🔗

findingIdentityDisplayName(inputs)
findingIdentityDisplayName(inputs)

出力: "John Doe"

findingIdentityEmails🔗

ID の発見事項レコードを解析し、ID データからメールアドレスを返します。

入力と出力🔗

findingIdentityEmails(map) -> list

例🔗

findingIdentityEmails(inputs)
findingIdentityEmails(inputs)

出力: ["john.doe@example.com", "j.doe@example.com"]

findingIdentityEmployeeId🔗

ID の発見事項レコードを解析し、ID データから従業員 ID を返します。

入力と出力🔗

findingIdentityEmployeeId(map) -> string

例🔗

findingIdentityEmployeeId(inputs)
findingIdentityEmployeeId(inputs)

出力: "EMP12345"

findingIdentityEmployeeType🔗

ID の発見事項レコードを解析し、ID データから雇用形態を返します。

入力と出力🔗

findingIdentityEmployeeType(map) -> string

例🔗

findingIdentityEmployeeType(inputs)
findingIdentityEmployeeType(inputs)

出力: "Full-time"

findingIdentityExternalCreatedAt🔗

ID の発見事項レコードを解析し、ID データから外部作成タイムスタンプを返します。

入力と出力🔗

findingIdentityExternalCreatedAt(map) -> string

例🔗

findingIdentityExternalCreatedAt(inputs)
findingIdentityExternalCreatedAt(inputs)

出力: "2024-01-15T10:30:00Z"

findingIdentityExternalId🔗

ID の発見事項レコードを解析し、ID データから外部 ID を返します。

入力と出力🔗

findingIdentityExternalId(map) -> string

例🔗

findingIdentityExternalId(inputs)
findingIdentityExternalId(inputs)

出力: "ext-12345-abcd"

findingIdentityExternalUpdatedAt🔗

ID の発見事項レコードを解析し、ID データから外部更新タイムスタンプを返します。

入力と出力🔗

findingIdentityExternalUpdatedAt(map) -> string

例🔗

findingIdentityExternalUpdatedAt(inputs)
findingIdentityExternalUpdatedAt(inputs)

出力: "2024-01-20T15:45:00Z"

findingIdentityField🔗

発見事項を解析し、指定された ID フィールドの値を返します。

入力と出力🔗

findingIdentityField(map, string) -> bool

例🔗

findingIdentityField(inputs, 'status')
findingIdentityField(inputs, 'status')

出力: "ACTIVE"

findingIdentityField(inputs, 'nonexistent_field')
findingIdentityField(inputs, 'nonexistent_field')

出力:

findingIdentityGivenName🔗

ID の発見事項レコードを解析し、ID データから名を返します。

入力と出力🔗

findingIdentityGivenName(map) -> string

例🔗

findingIdentityGivenName(inputs)
findingIdentityGivenName(inputs)

出力: "John"

findingIdentityHasMfa🔗

ID の発見事項レコードを解析し、ID データから MFA が有効かどうかを返します。

入力と出力🔗

findingIdentityHasMfa(map) -> bool

例🔗

findingIdentityHasMfa(inputs)
findingIdentityHasMfa(inputs)

出力: true

findingIdentityHasPasswordlessMfa🔗

ID の発見事項レコードを解析し、ID データからパスワードレス MFA が有効かどうかを返します。

入力と出力🔗

findingIdentityHasPasswordlessMfa(map) -> bool

例🔗

findingIdentityHasPasswordlessMfa(inputs)
findingIdentityHasPasswordlessMfa(inputs)

出力: false

findingIdentityHireDate🔗

ID の発見事項レコードを解析し、ID データから入社日を返します。

入力と出力🔗

findingIdentityHireDate(map) -> string

例🔗

findingIdentityHireDate(inputs)
findingIdentityHireDate(inputs)

出力: "2023-06-01"

findingIdentityIsAdmin🔗

ID の発見事項レコードを解析し、その ID が管理者権限を持つかどうかを返します。

入力と出力🔗

findingIdentityIsAdmin(map) -> bool

例🔗

findingIdentityIsAdmin(inputs)
findingIdentityIsAdmin(inputs)

出力: false

findingIdentityIsGuest🔗

ID の発見事項レコードを解析し、その ID がゲストユーザーかどうかを返します。

入力と出力🔗

findingIdentityIsGuest(map) -> bool

例🔗

findingIdentityIsGuest(inputs)
findingIdentityIsGuest(inputs)

出力: false

findingIdentityLastActiveAt🔗

ID の発見事項レコードを解析し、ID データから最終アクティブタイムスタンプを返します。

入力と出力🔗

findingIdentityLastActiveAt(map) -> string

例🔗

findingIdentityLastActiveAt(inputs)
findingIdentityLastActiveAt(inputs)

出力: "2024-09-01T14:30:00Z"

findingIdentityLastPasswordChangeAt🔗

ID の発見事項レコードを解析し、ID データから最終パスワード変更タイムスタンプを返します。

入力と出力🔗

findingIdentityLastPasswordChangeAt(map) -> string

例🔗

findingIdentityLastPasswordChangeAt(inputs)
findingIdentityLastPasswordChangeAt(inputs)

出力: "2024-08-15T09:00:00Z"

findingIdentityLeaveDate🔗

ID の発見事項レコードを解析し、ID データから退職日を返します。

入力と出力🔗

findingIdentityLeaveDate(map) -> string

例🔗

findingIdentityLeaveDate(inputs)
findingIdentityLeaveDate(inputs)

出力: "2025-01-31"

findingIdentityLocation🔗

ID の発見事項レコードを解析し、ID データから所在地を返します。

入力と出力🔗

findingIdentityLocation(map) -> string

例🔗

findingIdentityLocation(inputs)
findingIdentityLocation(inputs)

出力: "New York Office"

findingIdentityManager🔗

ID の発見事項レコードを解析し、ID データからマネージャーを返します。

入力と出力🔗

findingIdentityManager(map) -> string

例🔗

findingIdentityManager(inputs)
findingIdentityManager(inputs)

出力: "Jane Smith"

findingIdentityMfaMethods🔗

ID の発見事項レコードを解析し、ID データから MFA 方法を返します。

入力と出力🔗

findingIdentityMfaMethods(map) -> list

例🔗

findingIdentityMfaMethods(inputs)
findingIdentityMfaMethods(inputs)

出力: ["SMS", "Authenticator App"]

findingIdentityOfficeLocation🔗

ID の発見事項レコードを解析し、ID データからオフィス所在地を返します。

入力と出力🔗

findingIdentityOfficeLocation(map) -> string

例🔗

findingIdentityOfficeLocation(inputs)
findingIdentityOfficeLocation(inputs)

出力: "Building A, Floor 5"

findingIdentityOfficeZipCode🔗

ID の発見事項レコードを解析し、ID データからオフィス郵便番号を返します。

入力と出力🔗

findingIdentityOfficeZipCode(map) -> string

例🔗

findingIdentityOfficeZipCode(inputs)
findingIdentityOfficeZipCode(inputs)

出力: "10001"

findingIdentityPhoneNumbers🔗

ID の発見事項レコードを解析し、ID データから電話番号を返します。

入力と出力🔗

findingIdentityPhoneNumbers(map) -> list

例🔗

findingIdentityPhoneNumbers(inputs)
findingIdentityPhoneNumbers(inputs)

出力: ["+1-555-0123", "+1-555-0124"]

findingIdentityPrimaryDomain🔗

ID の発見事項レコードを解析し、ID データからプライマリドメインを返します。

入力と出力🔗

findingIdentityPrimaryDomain(map) -> string

例🔗

findingIdentityPrimaryDomain(inputs)
findingIdentityPrimaryDomain(inputs)

出力: "example.com"

findingIdentityPrimaryEntityId🔗

ID の発見事項レコードを解析し、ID データからプライマリエンティティ ID を返します。

入力と出力🔗

findingIdentityPrimaryEntityId(map) -> string

例🔗

findingIdentityPrimaryEntityId(inputs)
findingIdentityPrimaryEntityId(inputs)

出力: "entity-12345-abcd"

findingIdentityPrimaryMfaMethod🔗

ID の発見事項レコードを解析し、ID データからプライマリ MFA 方法を返します。

入力と出力🔗

findingIdentityPrimaryMfaMethod(map) -> string

例🔗

findingIdentityPrimaryMfaMethod(inputs)
findingIdentityPrimaryMfaMethod(inputs)

出力: "Authenticator App"

findingIdentityPrimaryUsername🔗

ID の発見事項レコードを解析し、ID データからプライマリユーザー名を返します。

入力と出力🔗

findingIdentityPrimaryUsername(map) -> string

例🔗

findingIdentityPrimaryUsername(inputs)
findingIdentityPrimaryUsername(inputs)

出力: "john.doe"

findingIdentityProperties🔗

ID の発見事項レコードを解析し、ID データからプロパティマップを返します。

入力と出力🔗

findingIdentityProperties(map) -> map

例🔗

findingIdentityProperties(inputs)
findingIdentityProperties(inputs)

出力: {"customAttribute1": "value1", "customAttribute2": "value2"}

findingIdentityProviderId🔗

ID の発見事項レコードを解析し、ID データからプロバイダー ID を返します。

入力と出力🔗

findingIdentityProviderId(map) -> string

例🔗

findingIdentityProviderId(inputs)
findingIdentityProviderId(inputs)

出力: "provider-azure-ad-12345"

findingIdentityRaw🔗

ID の発見事項レコードを解析し、生の ID データを返します。

入力と出力🔗

findingIdentityRaw(map) -> map

例🔗

findingIdentityRaw(inputs)
findingIdentityRaw(inputs)

出力: {"id": "user-123", "displayName": "John Doe", "mail": "john.doe@example.com"}

findingIdentityRegion🔗

ID の発見事項レコードを解析し、ID データからリージョンを返します。

入力と出力🔗

findingIdentityRegion(map) -> string

例🔗

findingIdentityRegion(inputs)
findingIdentityRegion(inputs)

出力: "North America"

findingIdentityStatus🔗

ID の発見事項レコードを解析し、ID データからステータスを返します。

入力と出力🔗

findingIdentityStatus(map) -> string

例🔗

findingIdentityStatus(inputs)
findingIdentityStatus(inputs)

出力: "ACTIVE"

findingIdentitySurname🔗

ID の発見事項レコードを解析し、ID データから姓を返します。

入力と出力🔗

findingIdentitySurname(map) -> string

例🔗

findingIdentitySurname(inputs)
findingIdentitySurname(inputs)

出力: "Doe"

findingIdentityTenant🔗

ID の発見事項レコードを解析し、ID データからテナントを返します。

入力と出力🔗

findingIdentityTenant(map) -> int

例🔗

findingIdentityTenant(inputs)
findingIdentityTenant(inputs)

出力: 12345

findingIdentityTitle🔗

ID の発見事項レコードを解析し、ID データから役職を返します。

入力と出力🔗

findingIdentityTitle(map) -> string

例🔗

findingIdentityTitle(inputs)
findingIdentityTitle(inputs)

出力: "Software Engineer"

findingIdentityUpdatedAt🔗

ID の発見事項レコードを解析し、ID データから更新タイムスタンプを返します。

入力と出力🔗

findingIdentityUpdatedAt(map) -> string

例🔗

findingIdentityUpdatedAt(inputs)
findingIdentityUpdatedAt(inputs)

出力: "2024-09-01T12:00:00Z"

findingIdentityUsageLocation🔗

ID の発見事項レコードを解析し、ID データから利用場所を返します。

入力と出力🔗

findingIdentityUsageLocation(map) -> string

例🔗

findingIdentityUsageLocation(inputs)
findingIdentityUsageLocation(inputs)

出力: "US"

findingIdentityUsernames🔗

ID の発見事項レコードを解析し、ID データからユーザー名を返します。

入力と出力🔗

findingIdentityUsernames(map) -> list

例🔗

findingIdentityUsernames(inputs)
findingIdentityUsernames(inputs)

出力: ["john.doe", "jdoe", "john.doe@example.com"]

findingIdentityZipCode🔗

ID の発見事項レコードを解析し、ID データから郵便番号を返します。

入力と出力🔗

findingIdentityZipCode(map) -> string

例🔗

findingIdentityZipCode(inputs)
findingIdentityZipCode(inputs)

出力: "10001"

findingLastModified🔗

ID の発見事項レコードを解析し、最終変更タイムスタンプを返します。

入力と出力🔗

findingLastModified(map) -> string

例🔗

findingLastModified(inputs)
findingLastModified(inputs)

出力: "2025-04-28T16:57:49.591956Z"

findingLastSeen🔗

ID の発見事項レコードを解析し、最終確認タイムスタンプを返します。

入力と出力🔗

findingLastSeen(map) -> string

例🔗

findingLastSeen(inputs)
findingLastSeen(inputs)

出力: "2025-04-22T16:57:49.591956Z"

findingOtherReferences🔗

ID の発見事項レコードを解析し、その他の参照リストを返します。オプションの第 2 引数を指定すると、特定のエントリーのリストを返します。

入力と出力🔗

findingOtherReferences(map) -> list
findingOtherReferences(map, string) -> list

例🔗

findingOtherReferences(inputs)
findingOtherReferences(inputs)

出力: [{"type":"microsoft.graph.servicePrincipal","id":"e98c0bf1-f226-4465-940f-696a79e7bdc6","logicalType":"IDENTITY_SERVICE_PRINCIPAL","derivedType":"APP","displayName":"soanceawebapp","externalLink":"https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"}]

findingOtherReferences(inputs, 'type')
findingOtherReferences(inputs, 'type')

出力: ["microsoft.graph.application"]

findingOtherReferences(inputs, 'id')
findingOtherReferences(inputs, 'id')

出力: ["7fcde2b0-9fda-472a-8be3-3666f92f7aa1"]

findingOtherReferences(inputs, 'logicalType')
findingOtherReferences(inputs, 'logicalType')

出力: ["UNKNOWN"]

findingOtherReferences(inputs, 'derivedType')
findingOtherReferences(inputs, 'derivedType')

出力: ["APP"]

findingOtherReferences(inputs, 'displayName')
findingOtherReferences(inputs, 'displayName')

出力: ["soanceawebapp"]

findingOtherReferences(inputs, 'externalLink')
findingOtherReferences(inputs, 'externalLink')

出力: ["https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"]

findingPrimaryReference🔗

ID の発見事項レコードを解析し、プライマリ参照マップを返します。オプションの第 2 引数を指定すると、特定のエントリーを返します。

入力と出力🔗

findingPrimaryReference(map) -> map
findingPrimaryReference(map, string) -> string

例🔗

findingPrimaryReference(inputs)
findingPrimaryReference(inputs)

出力: {"type":"microsoft.graph.servicePrincipal","id":"e98c0bf1-f226-4465-940f-696a79e7bdc6","logicalType":"IDENTITY_SERVICE_PRINCIPAL","derivedType":"APP","displayName":"soanceawebapp","externalLink":"https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"}

findingPrimaryReference(inputs, 'type')
findingPrimaryReference(inputs, 'type')

出力: "microsoft.graph.servicePrincipal"

findingPrimaryReference(inputs, 'id')
findingPrimaryReference(inputs, 'id')

出力: "e98c0bf1-f226-4465-940f-696a79e7bdc6"

findingPrimaryReference(inputs, 'logicalType')
findingPrimaryReference(inputs, 'logicalType')

出力: "IDENTITY_SERVICE_PRINCIPAL"

findingPrimaryReference(inputs, 'derivedType')
findingPrimaryReference(inputs, 'derivedType')

出力: "APP"

findingPrimaryReference(inputs, 'displayName')
findingPrimaryReference(inputs, 'displayName')

出力: "soanceawebapp"

findingPrimaryReference(inputs, 'externalLink')
findingPrimaryReference(inputs, 'externalLink')

出力: "https://portal.azure.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/e98c0bf1-f226-4465-940f-696a79e7bdc6/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"

findingResult🔗

ID の発見事項レコードを解析し、結果を返します。

入力と出力🔗

findingResult(map) -> string

例🔗

findingResult(inputs)
findingResult(inputs)

出力: "{\"replyUrls\":[\"https://soanceawebapp.azurewebsites.net/.auth/login/aad/callback\"]}"

findingSeverity🔗

ID の発見事項レコードを解析し、重大度ラベル (INFO、LOW、MEDIUM、HIGH、CRITICAL) を返します。

オプションの第 2 引数に true を指定すると、重大度を double (0.0-1.0) として返します。

入力と出力🔗

findingSeverity(map) -> string
findingSeverity(map, bool) -> double

例🔗

findingSeverity(inputs)
findingSeverity(inputs)

出力: "CRITICAL"

findingSeverity(inputs, true)
findingSeverity(inputs, true)

出力: "0.800000011920929"

findingSource🔗

ID の発見事項レコードを解析し、ソースマップを返します。オプションの第 2 引数を指定すると、特定のエントリーを返します。

入力と出力🔗

findingSource(map) -> map
findingSource(map, string) -> any

例🔗

findingSource(inputs)
findingSource(inputs)

出力: {'id':'63258f26-1d39-4d69-9e85-e409244d9c97','resolved':{...},'type':'IDENTITY_PROVIDER'}

findingSource(inputs, 'type')
findingSource(inputs, 'type')

出力: "IDENTITY_PROVIDER"

findingSource(inputs, 'id')
findingSource(inputs, 'id')

出力: "e98c0bf1-f226-4465-940f-696a79e7bdc6"

findingSource(inputs, 'resolved')
findingSource(inputs, 'resolved')

出力: {'createdAt':'2025-02-03T08:32:21.80852Z','disabledAt':null,'expiration':'2026-06-06T05:00:03Z',...}

findingStatus🔗

ID の発見事項レコードを解析し、ステータスを返します。

入力と出力🔗

findingStatus(map) -> string

例🔗

findingStatus(inputs)
findingStatus(inputs)

出力: "OPEN"

findingStatusComments🔗

ID の発見事項レコードを解析し、ステータスコメントを返します。

入力と出力🔗

findingStatusComments(map) -> string

例🔗

findingStatusComments(inputs)
findingStatusComments(inputs)

出力: "issue resolved"

findingTenantId🔗

ID の発見事項レコードを解析し、テナント ID を返します。

入力と出力🔗

findingTenantId(map) -> string

例🔗

findingTenantId(inputs)
findingTenantId(inputs)

出力: "12345"

findingsStatusCommentsUserId🔗

ID の発見事項レコードを解析し、ステータスコメントを追加したユーザー ID を返します。

入力と出力🔗

findingsStatusCommentsUserId(map) -> string

例🔗

findingsStatusCommentsUserId(inputs)
findingsStatusCommentsUserId(inputs)

出力: "3f59db3b-6b9c-4fb8-a26d-4c53fb334b4e"

first (オプション要素)🔗

リストの最初の要素を含むオプションを返します。リストが空の場合は optional.none() を返します。

入力と出力🔗

list.first() -> optional(T)

リストの最初の要素を含むオプションを返します。リストが空の場合は optional.none() を返します。

ユースケース🔗

安全な先頭アクセス。
[1, 2, 3].first().orValue(0)

最初の要素を取得するか、デフォルト値を返します。

空かどうかを確認する。
items.first().hasValue()

リストに要素があるかどうかを確認します。

最初の項目を処理する。
tasks.first().optMap(t, t.priority)

最初のタスクの優先度を取得します。

条件付きアクセス。
results.first().orValue('No results')

最初の結果に安全にアクセスするか、メッセージを返します。

連結処理。
data.filter(x, x > 0).first().orValue(-1)

データをフィルタリングしてから、最初の結果を取得します。

検証。
!items.first().hasValue() ? 'Empty list' : 'Has items'

リストが空かどうかを確認します。

注意🔗

  • T が要素型である optional(T) を返します。
  • 空のリストに対して安全に optional.none() を返します。
  • list[?0] よりも表現力があります。
  • デフォルト値を指定するには .orValue() を使用します。
  • 元のリストは変更しません。

例🔗

[1, 2, 3].first().orValue(0)
[1, 2, 3].first().orValue(0)

出力: 1

最初の要素を取得します。

[].first().hasValue()
[].first().hasValue()

出力: false

空のリストを確認します。

[].first().orValue(99)
[].first().orValue(99)

出力: 99

空のリストにデフォルト値を使用します。

['a', 'b', 'c'].first().value()
['a', 'b', 'c'].first().value()

出力: 'a'

最初の文字列を取り出します。

first (リスト要素)🔗

リストの先頭 N 個の要素を返します。

入力と出力🔗

first(list, int) -> list

例🔗

first(["a", "c", "b"], 1)
first(["a", "c", "b"], 1)

出力: ["a"]

flatten🔗

すべてのネストされたリストを 1 つのトップレベルリストに結合したリストを返します。

入力と出力🔗

flatten(list) -> list

例🔗

flatten([["row1col1", "row1col2"], ["row2col1", "row2col2"]])
flatten([["row1col1", "row1col2"], ["row2col1", "row2col2"]])

出力: ["row1col1", "row1col2", "row2col1", "row2col2"]

format (文字列)🔗

指定された引数を使用して、printf スタイルの書式で文字列をフォーマットします。

入力と出力🔗

string.format(list) -> string

リストの値を使用して、printf スタイルの書式指定子で文字列をフォーマットします。

一般的な書式指定子:

  • %s: 文字列。
  • %d: 整数。
  • %f: 浮動小数点数。
  • %%: リテラルのパーセント記号。

例🔗

'Hello %s'.format(['World'])
'Hello %s'.format(['World'])

出力: "Hello World"

'Value: %d, Name: %s'.format([42, 'test'])
'Value: %d, Name: %s'.format([42, 'test'])

出力: "Value: 42, Name: test"

'Pi: %.2f'.format([3.14159])
'Pi: %.2f'.format([3.14159])

出力: "Pi: 3.14"

format (タイムスタンプ)🔗

指定された形式を使用してタイムスタンプの文字列表現を返します。サポートされている形式の一覧については、Constants を参照してください。

入力と出力🔗

format(timestamp, string) -> string

例🔗

"1/1/2012".toTimestamp().format("layout")
"1/1/2012".toTimestamp().format("layout")

出力: 2012-01-01T00:00:00Z

"1/1/2012".toTimestamp().format("dateonly")
"1/1/2012".toTimestamp().format("dateonly")

出力: 2012-01-01

"1/1/2012".toTimestamp().format("Mon")
"1/1/2012".toTimestamp().format("Mon")

出力: Sun

generateString🔗

第 1 引数で指定された長さと、第 2 引数で指定された文字またはアルファベットを使用して、ランダムに生成された文字列を返します。

入力と出力🔗

generateString(int, string) -> string

例🔗

generateString(5, "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890")
generateString(5, "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890")

出力: aPsd2

groupBy🔗

1 つ以上のパスでグループ化されたマップ要素のリストと、各グループの対応する件数を返します。

第 1 引数はグループ化するリストです。第 2 引数はグループ化に使用するパスのリストです。オプションの第 3 引数は、リストを昇順 (asc) または降順 (desc) に並べ替えます。デフォルトは昇順です。

入力と出力🔗

groupBy(list, list, string) -> list

例🔗

groupBy([{"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test1", "title": "test"}}], ["amap.host", "amap.title"], "asc")
groupBy([{"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test1", "title": "test"}}], ["amap.host", "amap.title"], "asc")

出力: [{"amap.host": "test1", "amap.title": "test", "count": 1}, {"amap.host": "test", "amap.title": "test", "count": 2}]

has🔗

キーが存在し、定義されており、null 以外の値を持つことを検証します。

このマクロは、1 つ以上のパスについてマップを確認することもサポートしています。オプションの第 3 引数は、パスで使用する区切り文字を指定します。

入力と出力🔗

has(map, string) -> bool

例🔗

has(inputs, "key")
has(inputs, "key")

出力: true

hasValue🔗

optional に値が含まれている場合は true を返します。そうでない場合は false を返します。

入力と出力🔗

optional(T).hasValue() -> bool

optional に値が含まれているかどうかを確認します。

ユースケース🔗

アクセス前に確認する。
obj.?field.hasValue() ? obj.field : 'default'

アクセスする前に値があることを安全に確認します。

入力を検証する。
input.?userId.hasValue()

フィールドが存在するかどうかを確認します。

ガード節を使用する。
!optional.none().hasValue()

出力: true

optional が空であることを確認します。

オプショナルチェーン。
data[?'key'].hasValue() && data['key'] > 10

比較する前に値が存在することを確認します。

存在する値をフィルタリングする。
items.filter(i, i.?metadata.hasValue())

メタデータを持つ項目のみを保持します。

注意事項🔗

  • ブール値 (true または false) を返します。
  • 任意の optional に対して安全に呼び出せます。
  • エラーを回避するため、.value() を呼び出す前に使用してください。
  • 条件式とともによく使用されます。
  • エラーを確認する代替手段を提供します。

例🔗

optional.of(42).hasValue()
optional.of(42).hasValue()

出力: true

optional には値があります。

optional.none().hasValue()
optional.none().hasValue()

出力: false

optional には値がありません。

{'a': 1}[?'a'].hasValue()
{'a': 1}[?'a'].hasValue()

出力: true

キーが存在します。

{'a': 1}[?'b'].hasValue()
{'a': 1}[?'b'].hasValue()

出力: false

キーがありません。

[1, 2, 3][?0].hasValue()
[1, 2, 3][?0].hasValue()

出力: true

インデックスが存在します。

[1, 2, 3][?10].hasValue()
[1, 2, 3][?10].hasValue()

出力: false

インデックスが範囲外です。

hostnames🔗

アラート、エンティティ、または資産を解析し、見つかったホスト名を返します。

入力と出力🔗

hostnames(map) -> list

例🔗

hostnames(inputs)
hostnames(inputs)

出力: ["alert_hostname", "entity_hostname", "asset_hostname"]

indexOf🔗

部分文字列が最初に出現するインデックスを返します。

入力と出力🔗

string.indexOf(string) -> int
string.indexOf(string, int) -> int

部分文字列が最初に出現する位置の 0 ベースのインデックスを返します。

部分文字列が見つからない場合は -1 を返します。

省略可能な 2 番目の引数は、検索の開始位置を指定します。

例🔗

'hello world'.indexOf('world')
'hello world'.indexOf('world')

出力: 6

'hello world'.indexOf('o')
'hello world'.indexOf('o')

出力: 4

'hello world'.indexOf('o', 5)
'hello world'.indexOf('o', 5)

出力: 7

'hello world'.indexOf('xyz')
'hello world'.indexOf('xyz')

出力: -1

investigationArchivedAt🔗

調査レコードを解析し、アーカイブされた日時を返します。

入力と出力🔗

investigationArchivedAt(map) -> string

例🔗

investigationArchivedAt(inputs)
investigationArchivedAt(inputs)

出力: "2024-06-20T17:57:46.700164Z"

investigationAssigneeId🔗

調査レコードを解析し、担当者の ID を返します。

入力と出力🔗

investigationAssigneeId(map) -> string

例🔗

investigationAssigneeId(inputs)
investigationAssigneeId(inputs)

出力: "dac1ed31-111-4809-9cc9-9f99b6e"

investigationCloseReason🔗

調査レコードを解析し、クローズされた理由を返します。

入力と出力🔗

investigationCloseReason(map) -> string

例🔗

investigationCloseReason(inputs)
investigationCloseReason(inputs)

出力: "reason for closing"

investigationComment🔗

調査レコードを解析し、それに関連付けられたコメントを返します。

入力と出力🔗

investigationComment(map) -> string

例🔗

investigationComment(inputs)
investigationComment(inputs)

出力: "This is a sample comment for the investigation."

investigationCommentAuthorId🔗

調査レコードを解析し、コメントの作成者の ID を返します。

入力と出力🔗

investigationCommentAuthorId(map) -> string

例🔗

investigationCommentAuthorId(inputs)
investigationCommentAuthorId(inputs)

出力: "dac1ed31-111-4809-9cc9-9f99b6e"

investigationCommentCreatedAt🔗

調査レコードを解析し、コメントが作成された日時を返します。

入力と出力🔗

investigationCommentCreatedAt(map) -> string

例🔗

investigationCommentCreatedAt(inputs)
investigationCommentCreatedAt(inputs)

出力: "2024-06-20T17:57:46.700164Z"

investigationCommentMentions🔗

調査レコードを解析し、コメント内のメンションのリストを返します。

入力と出力🔗

investigationCommentMentions(map) -> list

例🔗

investigationCommentMentions(inputs)
investigationCommentMentions(inputs)

出力: ["@secureworks", "@dac1ed31-111-4809-9cc9-9f99b6e"]

investigationCommentOperation🔗

調査レコードを解析し、コメントの操作タイプを返します。

入力と出力🔗

investigationCommentOperation(map) -> string

例🔗

investigationCommentOperation(inputs)
investigationCommentOperation(inputs)

出力: "create"

investigationContributorIds🔗

調査レコードを解析し、投稿者 ID のリストを返します。

入力と出力🔗

investigationContributorIds(map) -> list

例🔗

investigationContributorIds(inputs)
investigationContributorIds(inputs)

出力: ["dac1ed31-111-4809-9cc9-9f99b6e", "ff0197b0@clients"]

investigationCreatedAt🔗

調査レコードを解析し、作成日時を返します。

入力と出力🔗

investigationCreatedAt(map) -> string

例🔗

investigationCreatedAt(inputs)
investigationCreatedAt(inputs)

出力: "2024-06-20T17:57:45.592464Z"

investigationCreatedById🔗

調査レコードを解析し、それを作成したユーザーの ID を返します。

入力と出力🔗

investigationCreatedById(map) -> string

例🔗

investigationCreatedById(inputs)
investigationCreatedById(inputs)

出力: "dac1ed31-111-4809-9cc9-9f99b6e"

investigationCreatedByPartner🔗

調査レコードを解析し、テナントの親によって作成された場合は true を返します。

入力と出力🔗

investigationCreatedByPartner(map) -> bool

例🔗

investigationCreatedByPartner(inputs)
investigationCreatedByPartner(inputs)

出力: false

investigationFieldChanged🔗

調査レコードを解析し、指定されたフィールドが変更された場合は true を返します。

入力と出力🔗

investigationFieldChanged(map, string) -> bool

例🔗

investigationFieldChanged(inputs, 'priority')
investigationFieldChanged(inputs, 'priority')

出力: true

investigationFieldChanged(inputs, 'nonexistent_field')
investigationFieldChanged(inputs, 'nonexistent_field')

出力: false

investigationId🔗

調査レコードを解析し、ID を返します。

入力と出力🔗

investigationId(map) -> string

例🔗

investigationId(inputs)
investigationId(inputs)

出力: "a251201f-9a26-4cd5-81f6-20509999933d"

investigationKeyFindings🔗

調査レコードを解析し、主な発見事項を返します。

入力と出力🔗

investigationKeyFindings(map) -> string

例🔗

investigationKeyFindings(inputs)
investigationKeyFindings(inputs)

出力: "Sample Investigation Key Findings"

investigationPriority🔗

調査レコードを解析し、優先度を単語 (Low、Medium、High、または Critical) として返します。

省略可能な 2 番目の引数に true を指定すると、優先度を整数 (1-4) として返します。

入力と出力🔗

investigationPriority(map) -> string
investigationPriority(map, bool) -> int

例🔗

investigationPriority(inputs)
investigationPriority(inputs)

出力: "High"

investigationPriority(inputs, true)
investigationPriority(inputs, true)

出力: 3

investigationProcessingStatus🔗

調査レコードを解析し、処理ステータスマップを返します。

入力と出力🔗

investigationProcessingStatus(map) -> map

例🔗

investigationProcessingStatus(inputs)
investigationProcessingStatus(inputs)

出力: {"alerts": "SUCCESS", "assets": "SUCCESS", "events": "SUCCESS"}

investigationRuleId🔗

調査レコードを解析し、それを作成した自動調査ルール ID を返します。

入力と出力🔗

investigationRuleId(map) -> string

例🔗

investigationRuleId(inputs)
investigationRuleId(inputs)

出力: "12345"

investigationStatus🔗

調査レコードを解析し、ステータスを返します。

入力と出力🔗

investigationStatus(map) -> string
investigationStatus(map, string) -> string

例🔗

investigationStatus(inputs)
investigationStatus(inputs)

出力: "OPEN"

investigationStatus(inputs, "v1")
investigationStatus(inputs, "v1")

出力: "Open"

investigationTenantId🔗

調査レコードを解析し、テナントの ID を返します。

入力と出力🔗

investigationTenantId(map) -> string

例🔗

investigationTenantId(inputs)
investigationTenantId(inputs)

出力: "12345"

investigationThirdPartyId🔗

調査レコードを解析し、それに関連付けられたサードパーティレコードの ID を返します。

入力と出力🔗

investigationThirdPartyId(map) -> string

例🔗

investigationThirdPartyId(inputs)
investigationThirdPartyId(inputs)

出力: "bdf9f35a8383121055c9e330ceaad3b8"

investigationThirdPartyType🔗

調査レコードを解析し、それに関連付けられたサードパーティレコードのタイプを返します。

入力と出力🔗

investigationThirdPartyType(map) -> string

例🔗

investigationThirdPartyType(inputs)
investigationThirdPartyType(inputs)

出力: "SNOW"

investigationTitle🔗

調査レコードを解析し、タイトルを返します。

入力と出力🔗

investigationTitle(map) -> string

例🔗

investigationTitle(inputs)
investigationTitle(inputs)

出力: "Taegis Watchlist Investigation"

investigationType🔗

調査レコードを解析し、タイプを返します。

省略可能な 2 番目の引数 'v1' または 'v2' はタイプを変換します。デフォルトは 'v2' です。

入力と出力🔗

investigationType(map) -> string
investigationType(map, string) -> string

例🔗

investigationType(inputs)
investigationType(inputs)

出力: "SECURITY_INVESTIGATION"

investigationType(inputs, 'v1')
investigationType(inputs, 'v1')

出力: "Security Investigation"

investigationUpdatedAt🔗

調査レコードを解析し、最後に更新された日時を返します。

入力と出力🔗

investigationUpdatedAt(map) -> string

例🔗

investigationUpdatedAt(inputs)
investigationUpdatedAt(inputs)

出力: "2024-06-20T17:57:46.700164Z"

investigationUpdatedById🔗

調査レコードを解析し、最後に更新したユーザーの ID を返します。

入力と出力🔗

investigationUpdatedById(map) -> string

例🔗

investigationUpdatedById(inputs)
investigationUpdatedById(inputs)

出力: "dac1ed31-111-4809-9cc9-9f99b6e"

ipInNetwork🔗

最初の引数の IP アドレスが、2 番目の引数の 1 つ以上の IP ネットワーク範囲内にある場合は true を返します。

2 番目の引数は、CIDR 表記のネットワークのリストとして表されます。

入力と出力🔗

ipInNetwork(string, list) -> bool

例🔗

ipInNetwork("10.1.1.1", ["10.0.0.0/8"])
ipInNetwork("10.1.1.1", ["10.0.0.0/8"])

出力: true

ipInNetwork("192.168.1.1", ["10.0.0.0/8"])
ipInNetwork("192.168.1.1", ["10.0.0.0/8"])

出力: false

ipsv4🔗

アラートまたはエンティティを解析し、見つかった場合は IPv4 アドレスのリストを返します。

入力と出力🔗

ipsv4(map) -> list

例🔗

ipsv4(inputs)
ipsv4(inputs)

出力: ["127.0.0.111", "4.3.2.1", "1.2.3.4", "9.8.7.6", "6.7.8.9"]

isCaseClosed🔗

ケースレコードを解析し、ケースがクローズされているかどうかを返します。

入力と出力🔗

isCaseClosed(map) -> bool

例🔗

isCaseClosed(inputs)
isCaseClosed(inputs)

出力: false

isCaseVisibleToCustomers🔗

ケースレコードを解析し、ケースがお客様に表示されるかどうかを返します。

入力と出力🔗

isCaseVisibleToCustomers(map) -> bool

例🔗

isCaseVisibleToCustomers(inputs)
isCaseVisibleToCustomers(inputs)

出力: true

isDomain🔗

指定された文字列引数が有効なドメインを表す場合は true を返します。

入力と出力🔗

isDomain(string) -> bool

例🔗

isDomain("example.com")
isDomain("example.com")

出力: true

isDomain("not_a_domain")
isDomain("not_a_domain")

出力: false

isEmail🔗

指定された文字列引数が有効なメールアドレスを表す場合は true を返します。

入力と出力🔗

isEmail(string) -> bool

例🔗

isEmail("sara@example.com")
isEmail("sara@example.com")

出力: true

isEmail("not_an_email")
isEmail("not_an_email")

出力: false

isIP🔗

指定された文字列引数が有効な IPv4 アドレスを表す場合は true を返します。

入力と出力🔗

isIP(string) -> bool

例🔗

isIP("127.0.0.1")
isIP("127.0.0.1")

出力: true

isIP("not_an_ip")
isIP("not_an_ip")

出力: false

isPrivateIP🔗

指定された文字列引数が、プライベート (RFC-1918)、リンクローカル、またはループバック IPv4 アドレスを表す場合は true を返します。

入力と出力🔗

isPrivateIP(string) -> bool

例🔗

isPrivateIP("192.168.1.1")
isPrivateIP("192.168.1.1")

出力: true

isPrivateIP("8.8.8.8")
isPrivateIP("8.8.8.8")

出力: false

isURL🔗

指定された文字列引数が有効な Uniform Resource Locator (URL) を表す場合は true を返します。

入力と出力🔗

isURL(string) -> bool
isURL(list) -> bool

例🔗

isURL("https://example.com")
isURL("https://example.com")

出力: true

isURL("not_a_url")
isURL("not_a_url")

出力: false

isUUID🔗

指定された文字列引数が有効な Universally Unique Identifier (UUID) を表す場合は true を返します。

入力と出力🔗

isUUID(string) -> bool

例🔗

isUUID("ce53ce61-0745-4b9b-ad16-568a022b6002")
isUUID("ce53ce61-0745-4b9b-ad16-568a022b6002")

出力: true

isUUID("not_a_uuid")
isUUID("not_a_uuid")

出力: false

join🔗

リストの要素を、指定された区切り文字を使用して文字列に結合します。

デフォルトの区切り文字はカンマ文字です。

入力と出力🔗

join(list) -> string
join(list, string) -> string

例🔗

join(["a", 1, true])
join(["a", 1, true])

出力: "a,1,true"

join(["a", 1, true], ".")
join(["a", 1, true], ".")

出力: "a.1.true"

keys🔗

マップからトップレベルキーのリストを返します。

入力と出力🔗

keys(map) -> list

例🔗

keys({"foo": "bar", "a": "b"})
keys({"foo": "bar", "a": "b"})

出力: ["foo", "a"]

last (list elements)🔗

リストの最後の N 個の要素を返します。

入力と出力🔗

last(list, int) -> list

例🔗

last(["a", "c", "b"], 2)
last(["a", "c", "b"], 2)

出力: ["c", "b"]

last (optional element)🔗

リストの最後の要素を含む optional を返します。リストが空の場合は optional.none() を返します。

入力と出力🔗

list.last() -> optional(T)

リストの最後の要素を含む optional を返します。

リストが空の場合は optional.none() を返します。

ユースケース🔗

末尾への安全なアクセス。
[1, 2, 3].last().orValue(0)

最後の要素を取得するか、デフォルト値を返します。

最新の項目。
events.last().optMap(e, e.timestamp)

最新イベントのタイムスタンプを取得します。

空かどうかを確認する。
items.last().hasValue()

リストに要素があるかどうかを確認します。

最新の値。
history.last().orValue('No history')

最新の値、またはデフォルトメッセージを取得します。

シーケンスの末尾。
sequence.last().orValue(-1) > threshold

最後の値をしきい値と比較します。

検証。
results.last().hasValue() ? 'Complete' : 'Empty'

リストの状態を確認します。

注意事項🔗

  • T が要素型である optional(T) を返します。
  • 空のリストに対しては安全に optional.none() を返します。
  • list[?list.size()-1] よりも表現力があります。
  • デフォルトを指定するには .orValue() を使用します。
  • 元のリストは変更しません。

例🔗

[1, 2, 3].last().orValue(0)
[1, 2, 3].last().orValue(0)

出力: 3

最後の要素を取得します。

[].last().hasValue()
[].last().hasValue()

出力: false

空のリストを確認します。

[].last().orValue(99)
[].last().orValue(99)

出力: 99

空のリストに対してデフォルト値を使用します。

['a', 'b', 'c'].last().value()
['a', 'b', 'c'].last().value()

出力: 'c'

最後の文字列を抽出します。

lastIndexOf🔗

部分文字列が最後に出現するインデックスを返します。

入力と出力🔗

string.lastIndexOf(string) -> int
string.lastIndexOf(string, int) -> int

部分文字列が最後に出現する位置の 0 ベースのインデックスを返します。

部分文字列が見つからない場合は -1 を返します。

省略可能な 2 番目の引数は、検索の終了位置を指定します。

例🔗

'hello world'.lastIndexOf('o')
'hello world'.lastIndexOf('o')

出力: 7

'hello world'.lastIndexOf('l')
'hello world'.lastIndexOf('l')

出力: 9

'hello world'.lastIndexOf('o', 6)
'hello world'.lastIndexOf('o', 6)

出力: 4

'hello world'.lastIndexOf('xyz')
'hello world'.lastIndexOf('xyz')

出力: -1

list🔗

入力をリストに変換します。

入力と出力🔗

list(any) -> list

例🔗

list([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
list([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))

出力: [1, 3]

lists.range🔗

0 から n-1 までの連続した整数のリストを生成します。

入力と出力🔗

lists.range(int) -> list

0 (含む) から n (含まない) までの整数のリストを生成します。

[0, 1, 2, ..., n-1] を返します。

0 以下の値に対しては空のリストを返します。

ユースケース🔗

インデックスリストを生成する。
lists.range(items.size())

リストのインデックスを取得します。

N 回繰り返す。
lists.range(5).map(i, processItem(i))

インデックス付きで関数を 5 回実行します。

テストデータを作成する。
lists.range(100)

100 個の連続した数値を生成します。

バッチ処理。
lists.range(totalItems / batchSize).map(i, processBatch(i))

項目をバッチで処理します。

ページネーション。
lists.range(totalPages)

ページ番号を生成します。

配列を埋める。
lists.range(10).map(i, 'item-' + string(i))

出力: ['item-0', 'item-1', ..., 'item-9']

文字列のリストを作成します。

lowerAscii🔗

文字列内のすべての ASCII 文字を小文字に変換します。

入力と出力🔗

string.lowerAscii() -> string

すべての ASCII 大文字 (A-Z) を小文字 (a-z) に変換します。

ASCII 以外の文字は変更されません。

例🔗

'HELLO World'.lowerAscii()
'HELLO World'.lowerAscii()

出力: "hello world"

'ABC123XYZ'.lowerAscii()
'ABC123XYZ'.lowerAscii()

出力: "abc123xyz"

'Café'.lowerAscii()
'Café'.lowerAscii()

出力: "café"

map🔗

入力をマップに変換します。

入力と出力🔗

map(list) -> map

例🔗

map([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
map([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))

出力: {"1": {"a": 1, "b": 2}, "3": {"a": 3, "b": 4}}

matchGroup🔗

指定された regex キャプチャグループから 1 つ以上の文字列のリストを返します。

入力と出力🔗

matchGroup(string, string) -> list

例🔗

"https://www.example.com".matchGroup("([^:]+:\\/\\/)?([\\w]+[\\.\\w+]+)")
"https://www.example.com".matchGroup("([^:]+:\\/\\/)?([\\w]+[\\.\\w+]+)")

出力: ["https://www.example.com", "https://", "www.example.com"]

math.abs🔗

数値の絶対値を返します。

入力と出力🔗

math.abs(double) -> double
math.abs(int) -> int
math.abs(uint) -> uint

入力された数値の絶対値 (非負の値) を返します。

int、uint、および double 型で動作します。

例🔗

math.abs(-5)
math.abs(-5)

出力: 5

math.abs(5)
math.abs(5)

出力: 5

math.abs(-3.14)
math.abs(-3.14)

出力: 3.14

math.abs(0)
math.abs(0)

出力: 0

math.bitAnd🔗

2 つの整数に対してビット単位の AND 演算を実行します。

入力と出力🔗

math.bitAnd(int, int) -> int
math.bitAnd(uint, uint) -> uint

2 つの整数のビット単位 AND を返します。

結果の各ビットは、オペランドの対応する両方のビットが 1 の場合にのみ 1 になります。

例🔗

math.bitAnd(5, 3)
math.bitAnd(5, 3)

出力: 1 (0101 & 0011 = 0001)

math.bitAnd(12, 10)
math.bitAnd(12, 10)

出力: 8 (1100 & 1010 = 1000)

math.bitAnd(15, 15)
math.bitAnd(15, 15)

出力: 15

math.bitAnd(7, 0)
math.bitAnd(7, 0)

出力: 0

math.bitNot🔗

整数に対してビット単位の NOT (補数) 演算を実行します。

入力と出力🔗

math.bitNot(int) -> int
math.bitNot(uint) -> uint

整数のビット補数を返します。

各ビットは反転されます。0 は 1 に、1 は 0 になります。

例🔗

math.bitNot(0)
math.bitNot(0)

出力: -1

math.bitNot(-1)
math.bitNot(-1)

出力: 0

math.bitNot(5)
math.bitNot(5)

出力: -6

math.bitNot(10)
math.bitNot(10)

出力: -11

math.bitOr🔗

2 つの整数に対してビット単位の OR 演算を実行します。

入力と出力🔗

math.bitOr(int, int) -> int
math.bitOr(uint, uint) -> uint

2 つの整数のビット単位 OR を返します。

結果の各ビットは、オペランドの対応するいずれかのビットが 1 の場合に 1 になります。

例🔗

math.bitOr(5, 3)
math.bitOr(5, 3)

出力: 7 (0101 0011 = 0111)

math.bitOr(8, 4)
math.bitOr(8, 4)

出力: 12 (1000 0100 = 1100)

math.bitOr(0, 15)
math.bitOr(0, 15)

出力: 15

math.bitOr(7, 0)
math.bitOr(7, 0)

出力: 7

math.bitShiftLeft🔗

整数のビットを指定された位置数だけ左にシフトします。

入力と出力🔗

math.bitShiftLeft(int, int) -> int
math.bitShiftLeft(uint, uint) -> uint

すべてのビットを指定された位置数だけ左にシフトします。

右側から 0 がシフトインされます。これは 2^n を掛けることと同等です。

例🔗

math.bitShiftLeft(5, 1)
math.bitShiftLeft(5, 1)

出力: 10 (0101 << 1 = 1010)

math.bitShiftLeft(5, 2)
math.bitShiftLeft(5, 2)

出力: 20 (0101 << 2 = 10100)

math.bitShiftLeft(1, 3)
math.bitShiftLeft(1, 3)

出力: 8

math.bitShiftLeft(3, 4)
math.bitShiftLeft(3, 4)

出力: 48

math.bitShiftRight🔗

整数のビットを指定された位置数だけ右にシフトします。

入力と出力🔗

math.bitShiftRight(int, int) -> int
math.bitShiftRight(uint, uint) -> uint

すべてのビットを指定された位置数だけ右にシフトします。

符号なし整数では、左側から 0 がシフトインされます。

符号付き整数では、符号ビットが保持されます。これは 2^n で割ることと同等です。

例🔗

math.bitShiftRight(10, 1)
math.bitShiftRight(10, 1)

出力: 5 (1010 >> 1 = 0101)

math.bitShiftRight(20, 2)
math.bitShiftRight(20, 2)

出力: 5 (10100 >> 2 = 0101)

math.bitShiftRight(8, 3)
math.bitShiftRight(8, 3)

出力: 1

math.bitShiftRight(48, 4)
math.bitShiftRight(48, 4)

出力: 3

math.bitXor🔗

2 つの整数に対してビット単位の XOR (排他的 OR) 演算を実行します。

入力と出力🔗

math.bitXor(int, int) -> int
math.bitXor(uint, uint) -> uint

2 つの整数のビット単位 XOR を返します。

結果の各ビットは、オペランドの対応するビットが異なる場合に 1 になります。

例🔗

math.bitXor(5, 3)
math.bitXor(5, 3)

出力: 6 (0101 ^ 0011 = 0110)

math.bitXor(12, 10)
math.bitXor(12, 10)

出力: 6 (1100 ^ 1010 = 0110)

math.bitXor(15, 15)
math.bitXor(15, 15)

出力: 0

math.bitXor(7, 0)
math.bitXor(7, 0)

出力: 7

math.ceil🔗

数値を最も近い整数に切り上げます (正の無限大方向)。

入力と出力🔗

math.ceil(double) -> double

入力以上の最小の整数値を返します。

負の数であっても常に切り上げます。

例🔗

math.ceil(1.2)
math.ceil(1.2)

出力: 2.0

math.ceil(1.9)
math.ceil(1.9)

出力: 2.0

math.ceil(-1.2)
math.ceil(-1.2)

出力: -1.0

math.ceil(5.0)
math.ceil(5.0)

出力: 5.0

math.floor🔗

数値を最も近い整数に切り下げます (負の無限大方向)。

入力と出力🔗

math.floor(double) -> double

入力以下の最大の整数値を返します。

負の数であっても常に切り下げます。

例🔗

math.floor(1.2)
math.floor(1.2)

出力: 1.0

math.floor(1.9)
math.floor(1.9)

出力: 1.0

math.floor(-1.2)
math.floor(-1.2)

出力: -2.0

math.floor(5.0)
math.floor(5.0)

出力: 5.0

math.greatest🔗

指定された引数の中から最大値を返します。

入力と出力🔗

math.greatest(...) -> number

指定されたすべての引数の中で最大の値を返します。

可変個の引数 (int、uint、または double) を受け付けます。

すべての引数は比較可能な数値型である必要があります。

例🔗

math.greatest(1, 5, 3, 9, 2)
math.greatest(1, 5, 3, 9, 2)

出力: 9

math.greatest(-10, -5, -20)
math.greatest(-10, -5, -20)

出力: -5

math.greatest(1.5, 2.3, 0.9)
math.greatest(1.5, 2.3, 0.9)

出力: 2.3

math.greatest(42)
math.greatest(42)

出力: 42

math.isFinite🔗

値が有限数かどうかを確認します (NaN または無限大ではない)。

入力と出力🔗

math.isFinite(double) -> bool

値が有限数 (NaN または無限大ではない) の場合は true を返します。

NaN、正の無限大、または負の無限大に対しては false を返します。

例🔗

math.isFinite(3.14)
math.isFinite(3.14)

出力: true

math.isFinite(1.0 / 0.0)
math.isFinite(1.0 / 0.0)

出力: false

math.isFinite(0.0 / 0.0)
math.isFinite(0.0 / 0.0)

出力: false

math.isFinite(-100.5)
math.isFinite(-100.5)

出力: true

math.isInf🔗

値が正または負の無限大かどうかを確認します。

入力と出力🔗

math.isInf(double) -> bool

値が無限大の場合は true を返します。

例🔗

math.isInf(1.0 / 0.0)
math.isInf(1.0 / 0.0)

出力: true

math.isInf(-1.0 / 0.0)
math.isInf(-1.0 / 0.0)

出力: true

math.isInf(1.0 / 0.0)
math.isInf(1.0 / 0.0)

出力: true

math.isInf(3.14)
math.isInf(3.14)

出力: false

math.isNaN🔗

値が NaN (Not a Number) かどうかを確認します。

入力と出力🔗

math.isNaN(double) -> bool

値が NaN の場合は true を返します。そうでない場合は false を返します。

浮動小数点値にのみ適用されます。

例🔗

math.isNaN(0.0 / 0.0)
math.isNaN(0.0 / 0.0)

出力: true

math.isNaN(1.0)
math.isNaN(1.0)

出力: false

math.isNaN(math.sqrt(-1.0))
math.isNaN(math.sqrt(-1.0))

出力: true

math.isNaN(3.14)
math.isNaN(3.14)

出力: false

math.least🔗

指定された引数の中から最小値を返します。

入力と出力🔗

math.least(...) -> number

指定されたすべての引数の中で最小の値を返します。

可変個の引数 (int、uint、または double) を受け付けます。

すべての引数は比較可能な数値型である必要があります。

例🔗

math.least(1, 5, 3, 9, 2)
math.least(1, 5, 3, 9, 2)

出力: 1

math.least(-10, -5, -20)
math.least(-10, -5, -20)

出力: -20

math.least(1.5, 2.3, 0.9)
math.least(1.5, 2.3, 0.9)

出力: 0.9

math.least(42)
math.least(42)

出力: 42

math.round🔗

数値を最も近い整数に丸めます (0 から離れる方向に 0.5 を丸める)。

入力と出力🔗

math.round(double) -> double

最も近い整数値を返し、0.5 の値は 0 から離れる方向に丸めます。

正の数では 0.5 は切り上げられます。負の数では -0.5 は切り下げられます。

例🔗

math.round(1.4)
math.round(1.4)

出力: 1.0

math.round(1.5)
math.round(1.5)

出力: 2.0

math.round(-1.5)
math.round(-1.5)

出力: -2.0

math.round(5.0)
math.round(5.0)

出力: 5.0

math.sign🔗

数値の符号を返します。負の場合は -1、ゼロの場合は 0、正の場合は 1 です。

入力と出力🔗

math.sign(double) -> double
math.sign(int) -> int

返される値:

  • 数値が負の場合は -1
  • 数値がゼロの場合は 0
  • 数値が正の場合は 1

例🔗

math.sign(-5)
math.sign(-5)

出力: -1

math.sign(0)
math.sign(0)

出力: 0

math.sign(5)
math.sign(5)

出力: 1

math.sign(-3.14)
math.sign(-3.14)

出力: -1.0

math.sqrt🔗

数値の平方根を返します。

入力と出力🔗

math.sqrt(int) -> double
math.sqrt(double) -> double

入力された数値の平方根を返します。

負の入力に対しては NaN を返します。

例🔗

math.sqrt(9.0)
math.sqrt(9.0)

出力: 3.0

math.sqrt(16)
math.sqrt(16)

出力: 4.0

math.sqrt(2.0)
math.sqrt(2.0)

出力: 1.414...

math.sqrt(0.0)
math.sqrt(0.0)

出力: 0.0

math.trunc🔗

数値を整数部分に切り詰めます (0 方向)。

入力と出力🔗

math.trunc(double) -> double

小数部分を取り除いて数値の整数部分を返します。

正の数と負の数の両方で 0 方向に丸めます。

例🔗

math.trunc(1.9)
math.trunc(1.9)

出力: 1.0

math.trunc(-1.9)
math.trunc(-1.9)

出力: -1.0

math.trunc(5.0)
math.trunc(5.0)

出力: 5.0

math.trunc(3.14159)
math.trunc(3.14159)

出力: 3.0

md5sum🔗

指定された文字列に対して計算された MD5 ダイジェストを返します。

入力と出力🔗

md5sum(string) -> bytes

例🔗

md5sum("Hello").toHex()
md5sum("Hello").toHex()

出力: "8b1a9953c4611296a827abf8c47804d7"

merge🔗

既存のマップに要素を追加します。

入力と出力🔗

merge(map, map) -> map

例🔗

merge({"key1": "val1"}, {"key2": "val2"})
merge({"key1": "val1"}, {"key2": "val2"})

出力: {"key1": "val1", "key2": "val2"}

now🔗

現在のローカル時刻をタイムスタンプとして返します。

入力と出力🔗

now() -> timestamp

例🔗

now()
now()

出力: "2025-04-29T12:34:56.789Z"

nowUnixMilli🔗

現在時刻を、エポックからのミリ秒数として返します。

入力と出力🔗

nowUnixMilli() -> int

例🔗

nowUnixMilli()
nowUnixMilli()

出力: 1742395914211

optFlatMap🔗

optional の値を、optional を返す関数で変換し、結果をフラット化します。

入力と出力🔗

optional(T).optFlatMap(var, expr) -> optional(R)

optional を返す変換を適用します。

optMap とは異なり、optional がネストされません。元の optional が空であるか、変換が optional.none() を返す場合、結果は optional.none() になります。

ユースケース🔗

連鎖した optional アクセス。
optional.of([1, 2, 3]).optFlatMap(l, l[?0])

最初の要素を optional として取得します。

条件付き変換。
optional.of(value).optFlatMap(v, v > 0 ? optional.of(v * 2) : optional.none())

条件が満たされた場合にのみ変換します。

安全なネストアクセス。
optional.of(user).optFlatMap(u, u.?email)

ネストされた optional 値に安全にアクセスします。

ゼロ値のフィルタリング。
optional.of(input).optFlatMap(i, optional.ofNonZeroValue(i.trim()))

trim 後に空文字列を除外します。

複数の optional ソース。
optional.of(config).optFlatMap(c, c[?'setting'])

optional オブジェクト内で optional のマップ参照を実行します。

注意事項🔗

  • 変数バインディング構文: optFlatMap(var, optional を返す式)。
  • optional(optional(T)) のような optional のネストを防ぎます。
  • 変換自体が optional を返す場合に便利です。
  • 空の optional は変更されずに optional.none() としてそのまま渡されます。
  • 変換は optional に値が含まれている場合にのみ実行されます。

例🔗

optional.of([1, 2, 3]).optFlatMap(l, l[?0]).orValue(0)
optional.of([1, 2, 3]).optFlatMap(l, l[?0]).orValue(0)

出力: 1

optional.of([]).optFlatMap(l, l[?0]).orValue(0)
optional.of([]).optFlatMap(l, l[?0]).orValue(0)

出力: 0

optional.none().optFlatMap(l, l[?0]).orValue(0)
optional.none().optFlatMap(l, l[?0]).orValue(0)

出力: 0

optMap🔗

optional に値が存在する場合にその値を変換し、変換後の値を含む新しい optional を返します。

入力と出力🔗

optional(T).optMap(var, expr) -> optional(R)

optional に値が存在する場合、その値に変換を適用します。

変換は新しい値を返し、その値は optional にラップされます。

optional が空の場合は optional.none() を返します。

ユースケース🔗

値を変換する。
optional.of(5).optMap(x, x * 2)

出力: optional(10)

値を 2 倍にします。

文字列操作。
optional.of('hello').optMap(s, s.upperAscii())

出力: optional('HELLO')

大文字に変換します。

プロパティアクセス。
optional.of(user).optMap(u, u.email)

ラップされたオブジェクトからプロパティを抽出します。

複雑な計算。
optional.of([1, 2, 3]).optMap(l, l.size())

出力: optional(3)

リストのサイズを取得します。

連鎖した変換。
optional.of(10).optMap(x, x * 2).optMap(x, x + 1).orValue(0)

出力: 21

複数の変換を連鎖させます。

map によるフィルタリング。
optional.of([1, 2, 3, 4, 5]).optMap(l, l.filter(x, x > 2))

データを変換してフィルタリングします。

安全なナビゲーション。
data.?user.optMap(u, u.name).orValue('Anonymous')

変換を伴う安全なネストアクセスです。

注意事項🔗

  • 変数バインディング構文: optMap(var, var を使用する式)。
  • R が結果型である optional(R) を返します。
  • 空の optional は変更されずにそのまま渡されます。
  • 最終結果を取り出すには .orValue() を使用します。
  • 変換が optional を返す場合は .optFlatMap() と比較してください。

例🔗

optional.of(5).optMap(x, x * 2).orValue(0)
optional.of(5).optMap(x, x * 2).orValue(0)

出力: 10

optional.none().optMap(x, x * 2).orValue(0)
optional.none().optMap(x, x * 2).orValue(0)

出力: 0

optional.of('hello').optMap(s, s.upperAscii()).orValue('NONE')
optional.of('hello').optMap(s, s.upperAscii()).orValue('NONE')

出力: 'HELLO'

optional.of([1, 2, 3]).optMap(l, l.size()).orValue(0)
optional.of([1, 2, 3]).optMap(l, l.size()).orValue(0)

出力: 3

optional.none🔗

内容を持たない空の optional 値を作成します。

入力と出力🔗

optional.none() -> optional

値を含まない空の optional 値を作成します。

ユースケース🔗

欠損値を表す。
optional.none()

値が存在しないことを明示します。

条件式のデフォルトとして使用する。
hasError ? optional.none() : optional.of(result)

エラーが発生した場合に空の optional を返します。

.or() と連鎖させる。
optional.none().or(optional.of(5))

別の optional にフォールバックします。

空であることを確認する。
optional.none().hasValue()

出力: false

optional が空かどうかを確認します。

デフォルトを指定する。
optional.none().orValue('default')

フォールバック付きで値を取り出します。

注意事項🔗

  • 値が存在しないことを表します (null に類似)。
  • optional.none() に対して .hasValue() は false を返します。
  • optional.none() に対して .value() を呼び出すとエラーになります。
  • デフォルト値を指定するには .orValue() を使用します。
  • 他の optional と連鎖させるには .or() を使用します。

例🔗

optional.none().hasValue()
optional.none().hasValue()

出力: false

optional.none().orValue(42)
optional.none().orValue(42)

出力: 42

optional.none().or(optional.of(5)).orValue(0)
optional.none().or(optional.of(5)).orValue(0)

出力: 5

optional.of🔗

指定された値を含む optional 値を作成します。

入力と出力🔗

optional.of(T) -> optional(T)

指定された値を含む optional 値を作成します。

ゼロ値を含め、任意の値が有効と見なされます。

ユースケース🔗

既知の値をラップする。
optional.of(42)

42 を含む optional を作成します。

ゼロ値または空の値をラップする。
optional.of(0)

0 を含む optional を作成します。

空文字列をラップする。
optional.of('')

空文字列を含む optional を作成します。

変換を連鎖させる。
optional.of(5).optMap(x, x * 2)

ラップされた値を変換します。

条件付きラップ。
hasValue ? optional.of(value) : optional.none()

条件付きで値をラップします。

デフォルト値パターン。
optional.of(userInput).orValue('default')

フォールバック付きで入力をラップします。

注意事項🔗

  • 0、''、[]、または {} などのゼロ値を含む任意の値を受け付けます。
  • T が値の型である optional(T) を返します。
  • ゼロ値を拒否する optional.ofNonZeroValue() と比較してください。
  • 値が存在するかどうかを確認するには .hasValue() を使用します。
  • フォールバック付きで値を取り出すには .orValue() を使用します。

例🔗

optional.of(42)
optional.of(42)

出力: optional(42)

optional.of('hello')
optional.of('hello')

出力: optional('hello')

optional.of([1, 2, 3])
optional.of([1, 2, 3])

出力: optional([1, 2, 3])

optional.of(0).hasValue()
optional.of(0).hasValue()

出力: true

optional.ofNonZeroValue🔗

値がゼロでない場合にのみ、その値を含む optional を作成します。そうでない場合は optional.none() を返します。

入力と出力🔗

optional.ofNonZeroValue(T) -> optional(T)

指定された値がゼロ値または空の値でない場合にのみ、その値を含む optional を作成します。

0、''、[]、{}、および null などのゼロ値は optional.none() になります。

ユースケース🔗

ゼロ値をフィルタリングする。
optional.ofNonZeroValue(userInput)

空でない入力のみをラップします。

空でない値を検証する。
optional.ofNonZeroValue('').hasValue()

出力: false

文字列が空でないかどうかを確認します。

空のリストをスキップする。
optional.ofNonZeroValue([]).orValue([1, 2, 3])

空のリストに対してデフォルト値を使用します。

条件付き処理。
optional.ofNonZeroValue(score).optMap(s, s * 100)

ゼロでないスコアのみを処理します。

null 安全性。
optional.ofNonZeroValue(null).orValue('N/A')

null 値を安全に処理します。

注意事項🔗

型ごとのゼロ値:

  • 数値: 0, 0.0
  • 文字列: ''
  • リスト: []
  • マップ: {}
  • ブール値: false
  • バイト列: b''
  • Null: null

追加の注意事項:

  • ゼロ値に対しては optional.none() を返します。
  • 空またはゼロの値を欠損として扱いたい場合に使用します。
  • すべての値を受け付ける optional.of() と比較してください。
  • 検証やフィルタリングに便利です。

例🔗

optional.ofNonZeroValue(42).hasValue()
optional.ofNonZeroValue(42).hasValue()

出力: true

ゼロでない数値です。

optional.ofNonZeroValue(0).hasValue()
optional.ofNonZeroValue(0).hasValue()

出力: false

ゼロは拒否されます。

optional.ofNonZeroValue('').hasValue()
optional.ofNonZeroValue('').hasValue()

出力: false

空文字列は拒否されます。

optional.ofNonZeroValue('hello').hasValue()
optional.ofNonZeroValue('hello').hasValue()

出力: true

空でない文字列は受け入れられます。

or🔗

最初の optional に値がある場合はそれを返します。そうでない場合は 2 番目の optional を返します。

入力と出力🔗

optional(T).or(optional(T)) -> optional(T)

optional 値を連鎖させます。

左側の optional に値がある場合はそれが返されます。そうでない場合は右側の optional が返されます。

評価は短絡されます。

ユースケース🔗

フォールバックチェーン。
optional.none().or(optional.of(5))

代替の optional 値を使用します。

複数のソース。
cache[?key].or(database[?key]).or(optional.of(default))

キャッシュ、次にデータベース、最後にデフォルト値を試します。

Coalesce パターン。
primary.or(secondary).or(tertiary).orValue(fallback)

複数の optional ソースを連鎖させます。

安全なナビゲーションチェーン。
obj.?field1.or(obj.?field2).orValue('none')

優先順位に従って複数のフィールドを試します。

優先度ベースの選択。
premium.?feature.or(basic.?feature)

プレミアム機能を優先し、基本機能にフォールバックします。

注意事項🔗

  • T ではなく optional(T) を返します。
  • 最後に .orValue() を使用して最終値を取り出します。
  • 最初の optional に値がある場合、評価は短絡されます。
  • 複数の optional ソースを連鎖させるのに便利です。
  • 具体的な値を返す .orValue() と比較してください。

例🔗

optional.none().or(optional.of(5)).orValue(0)
optional.none().or(optional.of(5)).orValue(0)

出力: 5

optional.of(3).or(optional.of(5)).orValue(0)
optional.of(3).or(optional.of(5)).orValue(0)

出力: 3

optional.none().or(optional.none()).orValue(10)
optional.none().or(optional.none()).orValue(10)

出力: 10

orValue🔗

optional に値が存在する場合はその値を返します。そうでない場合は指定されたデフォルト値を返します。

入力と出力🔗

optional(T).orValue(T) -> T

optional に値が存在する場合はその値を取り出し、そうでない場合は指定されたデフォルト値を返します。

ユースケース🔗

デフォルトを指定する。
optional.none().orValue(42)

出力: 42

optional が空の場合にデフォルトを使用します。

安全なフィールドアクセス。
obj.?field.orValue('N/A')

フィールド値を取得するか、デフォルトを返します。

安全なマップアクセス。
config[?'timeout'].orValue(30)

フォールバック付きで設定値を取得します。

安全なリストアクセス。
items[?0].orValue('empty')

最初の項目を取得するか、デフォルトを返します。

操作を連鎖させる。
optional.of(5).orValue(0) * 2

出力: 10

取り出した値を計算で直接使用します。

ネストアクセス。
data.?user.?name.orValue('Anonymous')

ネストされたフィールドに安全にアクセスします。

Coalesce パターン。
primary.orValue(secondary.orValue(tertiary))

複数のフォールバック値を連鎖させます。

注意事項🔗

  • デフォルト値は optional の型と一致している必要があります。
  • 常に具体的な値を返します。
  • 通常の値が期待される場所ならどこでも安全に使用できます。
  • 条件式よりも簡潔です。
  • 空の optional に対してエラーをスローする .value() と比較してください。

例🔗

optional.of(42).orValue(0)
optional.of(42).orValue(0)

出力: 42

optional.none().orValue(0)
optional.none().orValue(0)

出力: 0

optional.of('hello').orValue('default')
optional.of('hello').orValue('default')

出力: 'hello'

{'a': 1}[?'b'].orValue(0)
{'a': 1}[?'b'].orValue(0)

出力: 0

parseURL🔗

指定された URL 文字列を URL マップ構造として返します。

入力と出力🔗

parseURL(string) -> map

例🔗

parseURL("https://www.example.com")
parseURL("https://www.example.com")

出力: {"Scheme": "https", "Host": "www.example.com", "Path": "", "RawQuery": "", "Fragment": ""}

queryJSON🔗

最初の引数から、2 番目の引数で指定された JMESPath クエリを使用してデータを返します。

入力と出力🔗

queryJSON(map, string) -> any

例🔗

queryJSON(inputs.alert2, "metadata.confidence")
queryJSON(inputs.alert2, "metadata.confidence")

出力: 0.5

random🔗

0 から .99 までのランダムな値 (両端を含む) を返します。

入力と出力🔗

random() -> double

例🔗

random()
random()

出力: 0.42

regex.extract🔗

文字列から正規表現パターンの最初の一致を抽出し、optional 値として返します。

入力と出力🔗

regex.extract(string, pattern) -> string

文字列に正規表現パターンを適用し、最初の一致を optional にラップして返します。

パターンにキャプチャグループが含まれている場合は、キャプチャされた値が返されます。

パターンにキャプチャグループが含まれていない場合は、一致全体が返されます。

一致が見つからない場合は optional.none() を返します。

注意事項🔗

パターン構文:

  • RE2 正規表現構文を使用します。
  • キャプチャグループには丸括弧 () を使用します。
  • バックスラッシュは CEL 文字列内でエスケープする必要があります。
  • 一般的なパターンには \d、\w、\s があります。

追加の注意事項:

  • optional 値を返します。.orValue() または .hasValue() を使用してください。
  • パターン一致は左から右に進み、最初の一致のみを返します。
  • すべての一致を取得するには extractAll() を使用します。
  • 空文字列および空パターンは適切に処理されます。
  • 無効な regex パターンはコンパイルエラーを引き起こします。

regex.extractAll🔗

文字列から正規表現パターンのすべての一致をリストとして抽出します。

入力と出力🔗

regex.extractAll(string, pattern) -> list

文字列に正規表現パターンを適用し、すべての一致を文字列のリストとして返します。

一致が見つからない場合は空のリストを返します。

extract() とは異なり、この関数は最初の一致だけでなく、すべての一致を返します。

ユースケース🔗

すべての数値を抽出する。
regex.extractAll('test123foo456bar', '\\d+')

出力: ["123", "456"]

すべての数値シーケンスを見つけます。

すべての単語を抽出する。
regex.extractAll('hello world test', '\\w+')

出力: ["hello", "world", "test"]

テキストを単語に分割します。

複数の値を解析する。
regex.extractAll('192.168.1.1', '\\d+')

出力: ["192", "168", "1", "1"]

IP アドレスからすべての数値を抽出します。

すべてのメールアドレスを見つける。
regex.extractAll(text, '\\w+@\\w+\\.\\w+')

文字列からすべてのメールアドレスを抽出します。

一致数を数える。
regex.extractAll('test123foo456bar', '\\d+').size()

出力: 2

数値シーケンスの数を数えます。

一致があるか確認する。
regex.extractAll('no-numbers-here', '\\d+').size() == 0

出力: true

パターンが何かに一致するかどうかを確認します。

抽出して処理する。
regex.extractAll('1,2,3,4,5', '\\d+').map(x, int(x))

出力: [1, 2, 3, 4, 5]

数値を抽出して整数に変換します。

結果をフィルタリングする。
regex.extractAll('a1 b2 c3', '\\w+').filter(x, x.size() > 1)

出力: ["a1", "b2", "c3"]

トークンを抽出し、長さでフィルタリングします。

注意事項🔗

  • optional 値ではなくリストを返します。
  • 一致が見つからない場合は空のリストを返します。
  • キャプチャグループは無視されます。完全一致のみが返されます。
  • 文字列から複数の値を抽出するのに便利です。
  • extract() を複数回呼び出すより効率的です。
  • 左から右への一致順序を保持します。

例🔗

regex.extractAll('test123foo456bar', '\\d+')
regex.extractAll('test123foo456bar', '\\d+')

出力: ["123", "456"]

regex.extractAll('hello world test', '\\w+')
regex.extractAll('hello world test', '\\w+')

出力: ["hello", "world", "test"]

regex.extractAll('192.168.1.1', '\\d+')
regex.extractAll('192.168.1.1', '\\d+')

出力: ["192", "168", "1", "1"]

regex.extractAll('no-numbers-here', '\\d+')
regex.extractAll('no-numbers-here', '\\d+')

出力: []

regex.replace🔗

文字列内の正規表現パターンの出現箇所を置換文字列で置き換えます。

入力と出力🔗

regex.replace(string, pattern, replacement) -> string
regex.replace(string, pattern, replacement, count) -> string

regex パターンに一致する重複しない部分文字列を置き換えます。

必要に応じて count 引数を使用して置換回数を制限できます。

count が省略された場合または負の場合は、すべての出現箇所が置換されます。

ユースケース🔗

単純なテキスト置換。
regex.replace('hello world hello', 'hello', 'hi')

出力: "hi world hi"

hello のすべての出現箇所を置換します。

すべての数字を削除する。
regex.replace('test123test456', '\\d+', '')

出力: "testtest"

すべての数値シーケンスを削除します。

機密データをマスクする。
regex.replace('ID: 12345', '\\d+', 'XXXXX')

出力: "ID: XXXXX"

数字をプレースホルダーに置き換えます。

置換回数を制限する。
regex.replace('banana', 'a', 'x', 1)

出力: "bxnana"

最初の出現箇所のみを置換します。

負の count ですべて置換する。
regex.replace('banana', 'a', 'x', -1)

出力: "bxnxnx"

負の count はすべての出現箇所を置換することを意味します。

空白を正規化する。
regex.replace('hello    world  test', '\\s+', ' ')

出力: "hello world test"

複数のスペースを 1 つのスペースに置き換えます。

特殊文字を除去する。
regex.replace('hello@world#test', '[^a-zA-Z0-9]', '')

出力: "helloworldtest"

英数字以外の文字を削除します。

電話番号を整形する。
regex.replace('1234567890', '(\\d{3})(\\d{3})(\\d{4})', '($1) $2-$3')

キャプチャグループを使用して電話番号を整形します。

注意事項🔗

  • パターンは有効な正規表現である必要があります。
  • 置換文字列は、キャプチャグループ参照を除き、文字どおりに扱われます。
  • count が 0 の場合、元の文字列が変更されずに返されます。
  • count が負の場合、すべての一致が置換されます。
  • 一致しないパターンでは元の文字列が変更されずに返されます。
  • 空のパターンは文字間に一致します。

キャプチャグループ参照:

  • \1、\2、\3 などを使用します。
  • 数値のキャプチャグループのみがサポートされます。
  • 名前付きキャプチャグループは置換文字列ではサポートされません。
  • 無効なキャプチャグループ参照は実行時エラーを引き起こします。

例🔗

regex.replace('hello world hello', 'hello', 'hi')
regex.replace('hello world hello', 'hello', 'hi')

出力: "hi world hi"

regex.replace('banana', 'a', 'x')
regex.replace('banana', 'a', 'x')

出力: "bxnxnx"

regex.replace('test123test456', '\\d+', 'NUM')
regex.replace('test123test456', '\\d+', 'NUM')

出力: "testNUMtestNUM"

regex.replace('banana', 'a', 'x', 1)
regex.replace('banana', 'a', 'x', 1)

出力: "bxnana"

regex.replace('foo bar', 'foo', 'hello')
regex.replace('foo bar', 'hello')

出力: "hello bar"

replace🔗

部分文字列のすべての出現箇所を別の文字列に置き換えます。

入力と出力🔗

string.replace(string, string) -> string
string.replace(string, string, int) -> string

最初の部分文字列の出現箇所を 2 番目の部分文字列に置き換えます。

省略可能な 3 番目の引数は置換回数を制限します。すべての出現箇所を置換するには -1 を使用します。

例🔗

'hello world'.replace('o', 'a')
'hello world'.replace('o', 'a')

出力: "hella warld"

'hello world'.replace('l', 'L')
'hello world'.replace('l', 'L')

出力: "heLLo worLd"

'hello world'.replace('l', 'L', 1)
'hello world'.replace('l', 'L', 1)

出力: "heLlo world"

'hello world'.replace('world', 'universe')
'hello world'.replace('world', 'universe')

出力: "hello universe"

resolvePartnerName🔗

Taegis テナント ID を解決し、パートナー名を返します。

入力と出力🔗

resolvePartnerName(string) -> string

例🔗

resolvePartnerName('12345')
resolvePartnerName('12345')

出力: "Partner Name"

resolveSubjectName🔗

Taegis ユーザー ID またはクライアント ID を解決し、名前文字列を返します。

入力と出力🔗

resolveSubjectName(string) -> string

例🔗

resolveSubjectName('auth0asdf')
resolveSubjectName('auth0asdf')

出力: "GivenName FamilyName"

resolveSubjectName('ff0197b0@clients')
resolveSubjectName('ff0197b0@clients')

出力: "ClientName"

resolveTenantName🔗

Taegis テナント ID を解決し、テナント名を返します。

入力と出力🔗

resolveTenantName(string) -> string

例🔗

resolveTenantName('12345')
resolveTenantName('12345')

出力: "Tenant Name"

resolveUser🔗

ID、Auth0 ID、またはメールアドレスによって Taegis ユーザーを解決し、Taegis ユーザー ID を返します。

入力と出力🔗

resolveUser(string) -> string

例🔗

resolveUser('auth0asdf')
resolveUser('auth0asdf')

出力: "dac1ed31-111-4809-9cc9-9f99b6e"

resolveUserName🔗

Taegis ユーザー ID を解決し、ユーザー名文字列を返します。

入力と出力🔗

resolveUserName(string) -> string

例🔗

resolveUserName('auth0asdf')
resolveUserName('auth0asdf')

出力: "GivenName FamilyName"

reverse🔗

リスト内の要素の順序を逆にします。

入力と出力🔗

list.reverse() -> list

要素が逆順になった新しいリストを返します。

最初の要素は最後になり、その逆も同様です。

元のリストは変更しません。

ユースケース🔗

逆時系列順。
events.reverse()

最新のイベントを最初に表示します。

逆順で処理する。
steps.reverse().map(s, s.execute())

手順を逆順で実行します。

回文チェック。
list == list.reverse()

リストが回文かどうかを確認します。

最後から最初への処理。
queue.reverse()

項目を LIFO 順で処理します。

逆順にしてフィルタリングする。
items.reverse().filter(i, i.priority > 5)

リストを逆順にしてからフィルタリングします。

2 回逆順にする。
list.reverse().reverse() == list

出力: true

2 回逆順にすると元のリストに戻ります。

注意事項🔗

  • 新しいリストを返します。
  • 任意のリスト型で動作します。
  • 空のリストおよび単一要素のリストは変更されません。
  • 2 回逆順にすると元の順序に戻ります。

例🔗

[1, 2, 3, 4].reverse()
[1, 2, 3, 4].reverse()

出力: [4, 3, 2, 1]

['a', 'b', 'c'].reverse()
['a', 'b', 'c'].reverse()

出力: ['c', 'b', 'a']

[1].reverse()
[1].reverse()

出力: [1]

[].reverse()
[].reverse()

出力: []

[5, 3, 1, 2].reverse()
[5, 3, 1, 2].reverse()

出力: [2, 1, 3, 5]

sets.contains🔗

最初のリストに、2 番目のリストのすべての要素が含まれているかどうかを確認します (部分集合チェック)。

入力と出力🔗

sets.contains(list, list) -> bool

最初のリストに 2 番目のリストのすべての要素が含まれている場合は true を返します。

最初のリストは 2 番目のリストの上位集合と見なされます。

順序は関係ありません。

いずれのリスト内の重複も無視されます。

ユースケース🔗

権限チェック。
sets.contains(user.roles, ['admin'])

ユーザーが必要なロールを持っているかどうかを確認します。

必須タグの検証。
sets.contains(resource.tags, ['production', 'critical'])

リソースに必要なタグがすべて含まれていることを検証します。

機能の可用性。
sets.contains(subscription.features, ['api_access', 'export'])

サブスクリプションに必要な機能がすべて含まれているかどうかを確認します。

空のリストの処理。
sets.contains([1, 2, 3], [])

出力: true

空のリストは任意のリストの部分集合です。

重複の処理。
sets.contains([1, 1, 2, 2, 3], [1, 2])

出力: true

重複は無視されます。

例🔗

sets.contains([1, 2, 3, 4], [2, 3])
sets.contains([1, 2, 3, 4], [2, 3])

出力: true

sets.contains([1, 2, 3], [3, 2, 1])
sets.contains([1, 2, 3], [3, 2, 1])

出力: true

sets.contains([1, 2, 3], [1, 2, 4])
sets.contains([1, 2, 3], [1, 2, 4])

出力: false

sets.contains(['admin', 'user', 'guest'], ['admin'])
sets.contains(['admin', 'user', 'guest'], ['admin'])

出力: true

sets.equivalent🔗

2 つのリストに同じ要素が含まれているかどうかを確認します。順序と重複は無視されます (集合の等価性)。

入力と出力🔗

sets.equivalent(list, list) -> bool

両方のリストにまったく同じ要素が含まれている場合は true を返します。

順序は関係ありません。

重複は無視されます。

ユースケース🔗

ユーザー権限を比較する。
sets.equivalent(user1.permissions, user2.permissions)

2 人のユーザーが同一の権限を持っているかどうかを確認します。

タグ比較。
sets.equivalent(resource1.tags, resource2.tags)

リソースタグを比較します。

設定を検証する。
sets.equivalent(actual_settings, expected_settings)

設定値が一致していることを確認します。

空のリスト。
sets.equivalent([], [])

出力: true

空のリストは等価です。

文字列比較。
sets.equivalent(['a', 'b', 'c'], ['c', 'a', 'b'])

出力: true

任意の比較可能な型で動作します。

対称演算。
sets.equivalent(list1, list2) == sets.equivalent(list2, list1)

出力: true

引数の順序は関係ありません。

例🔗

sets.equivalent([1, 2, 3], [3, 2, 1])
sets.equivalent([1, 2, 3], [3, 2, 1])

出力: true

sets.equivalent([1, 2, 3], [1, 2, 3])
sets.equivalent([1, 2, 3], [1, 2, 3])

出力: true

sets.equivalent([1, 1, 2, 3], [1, 2, 3, 3])
sets.equivalent([1, 1, 2, 3], [1, 2, 3, 3])

出力: true

sets.equivalent([1, 2, 3], [1, 2, 4])
sets.equivalent([1, 2, 3], [1, 2, 4])

出力: false

sets.intersects🔗

2 つのリストに共通要素があるかどうかを確認します (空でない積集合)。

入力と出力🔗

sets.intersects(list, list) -> bool

2 つのリストが少なくとも 1 つの共通要素を共有している場合は true を返します。

順序は関係ありません。

重複は無視されます。

ユースケース🔗

ロールベースのアクセス制御。
sets.intersects(user.roles, ['admin', 'owner', 'moderator'])

ユーザーが少なくとも 1 つの特権ロールを持っているかどうかを確認します。

タグフィルタリング。
sets.intersects(resource.tags, ['production', 'staging'])

リソースが対象環境に属しているかどうかを確認します。

機能フラグ。
sets.intersects(user.features, ['beta', 'preview'])

ユーザーがベータ機能にアクセスできるかどうかを確認します。

カテゴリ一致。
sets.intersects(product.categories, filter.categories)

製品が選択されたカテゴリのいずれかに属しているかどうかを確認します。

権限の検証。
sets.intersects(user.permissions, required_permissions)

ユーザーが少なくとも 1 つの必要な権限を持っているかどうかを確認します。

複数値の確認。
sets.intersects([user.status], ['active', 'pending', 'trial'])

複数の値に対して OR 形式の一致を適用します。

例🔗

sets.intersects([1, 2, 3], [3, 4, 5])
sets.intersects([1, 2, 3], [3, 4, 5])

出力: true

sets.intersects([1, 2, 3], [4, 5, 6])
sets.intersects([1, 2, 3], [4, 5, 6])

出力: false

sets.intersects(['admin', 'user'], ['admin', 'owner'])
sets.intersects(['admin', 'user'], ['admin', 'owner'])

出力: true

sets.intersects([1, 2, 3], [1, 2, 3])
sets.intersects([1, 2, 3], [1, 2, 3])

出力: true

sha1sum🔗

指定された文字列に対して計算された SHA-1 ダイジェストを返します。

入力と出力🔗

sha1sum(string) -> bytes

例🔗

sha1sum("Hello").toHex()
sha1sum("Hello").toHex()

出力: "f7ff9e8b7bb2e09b70935a5d785e0cc5d9d0abf0"

sha256sum🔗

指定された文字列に対して計算された SHA-256 ダイジェストを返します。

入力と出力🔗

sha256sum(string) -> bytes

例🔗

sha256sum("Hello").toHex()
sha256sum("Hello").toHex()

出力: "185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969"

sha512sum🔗

指定された文字列に対して計算された SHA-512 ダイジェストを返します。

入力と出力🔗

sha512sum(string) -> bytes

例🔗

sha512sum("Hello").toHex()
sha512sum("Hello").toHex()

出力: "3615f80c9d293ed7402687f94b22d58e529b8cc7916f8fac7fddf7fbd5af4cf777d3d795a7a00a16bf7e7f3fb9561ee9baae480da9fe7a18769e71886b03f315"

slice🔗

2 つのインデックスの間にあるリストの一部を抽出します。

入力と出力🔗

list.slice(int, int) -> list

開始インデックス (含む) から終了インデックス (含まない) までのサブリストを抽出します。

インデックスは 0 ベースです。

ユースケース🔗

ページネーション。
results.slice(page * pageSize, (page + 1) * pageSize)

結果の 1 ページ分を抽出します。

最初の N 個の要素を取得する。
list.slice(0, 5)

最初の 5 個の要素を取得します。

最初の N 個の要素をスキップする。
list.slice(3, list.size())

最初の 3 個の要素をスキップします。

中央部分を取得する。
list.slice(2, 8)

リストの中央部分を抽出します。

最後の N 個の要素を取得する。
list.slice(list.size() - 3, list.size())

最後の 3 個の要素を取得します。

sort🔗

指定されたリストを昇順に並べ替えたコピーを返します。

2 番目の引数に "desc" を指定すると、並べ替え順を降順に反転できます。

入力と出力🔗

sort(list) -> list
sort(list, string) -> list

例🔗

sort(["a", "c", "b"])
sort(["a", "c", "b"])

出力: ["a", "b", "c"]

sort([3, 2, 1], "desc")
sort([3, 2, 1], "desc")

出力: [3, 2, 1]

sortBy🔗

計算されたキー式によってリストを並べ替え、カスタムの並べ替え条件を指定できます。

入力と出力🔗

list.sortBy(var, key_expression) -> list

各要素に対してキー式で計算された値に基づいてリストを並べ替えます。

変数名はキー計算中に各要素にバインドされます。

要素は計算されたキーに基づいて昇順に並べ替えられます。

ユースケース🔗

オブジェクトのプロパティで並べ替える。
users.sortBy(u, u.name)

ユーザーを名前でアルファベット順に並べ替えます。

年齢で並べ替える。
users.sortBy(u, u.age)

ユーザーを年齢順に並べ替えます。

降順ソート。
scores.sortBy(s, -s.value)

スコアを降順に並べ替えます。

計算値で並べ替える。
products.sortBy(p, p.price * (1 - p.discount))

最終的な割引後価格で並べ替えます。

文字列長で並べ替える。
words.sortBy(w, w.size())

単語を長さで並べ替えます。

複数条件で並べ替える。
items.sortBy(i, string(i.priority) + i.name)

優先度で並べ替え、その後に名前で並べ替えます。

距離で並べ替える。
locations.sortBy(loc, math.abs(loc.lat - target.lat) + math.abs(loc.lon - target.lon))

マンハッタン距離で場所を並べ替えます。

ブール値で並べ替える。
items.sortBy(i, i.active)

false の値を先に、true の値を後に並べ替えます。

大文字小文字を区別しない並べ替え。
names.sortBy(n, n.lowerAscii())

大文字小文字を区別せずに文字列を並べ替えます。

ネストされたプロパティで並べ替える。
orders.sortBy(o, o.customer.tier)

ネストされたプロパティで並べ替えます。

複雑な計算。
tasks.sortBy(t, t.priority * 10 + (t.dueDate - now).getHours())

重み付けされた優先度と時間の計算を使用して並べ替えます。

注意事項🔗

  • 新しく並べ替えられたリストを返します。
  • 元のリストは変更されません。
  • キー式は各要素に対して評価されます。
  • 並べ替えは安定しており、キーが等しい要素は相対順序を保持します。
  • キーは比較可能である必要があります。
  • 数値を負にすると降順ソートを実行できます。

例🔗

[3, 1, 4, 1, 5, 9].sortBy(x, x)
[3, 1, 4, 1, 5, 9].sortBy(x, x)

出力: [1, 1, 3, 4, 5, 9]

値自体をキーとして使用して並べ替えます。

[3, 1, 4, 1, 5, 9].sortBy(x, -x)
[3, 1, 4, 1, 5, 9].sortBy(x, -x)

出力: [9, 5, 4, 3, 1, 1]

降順に並べ替えます。

split🔗

指定された区切り文字を使用して文字列をリストに分割します。

入力と出力🔗

string.split(string) -> list
string.split(string, int) -> list

区切り文字を使用して文字列を部分文字列のリストに分割します。

省略可能な 2 番目の引数は分割回数を制限します。すべて分割するには -1 を使用します。

例🔗

'hello world'.split(' ')
'hello world'.split(' ')

出力: ["hello", "world"]

'a,b,c,d'.split(',')
'a,b,c,d'.split(',')

出力: ["a", "b", "c", "d"]

'a,b,c,d'.split(',', 2)
'a,b,c,d'.split(',', 2)

出力: ["a", "b,c,d"]

'one'.split('')
'one'.split('')

出力: ["o", "n", "e"]

substring🔗

2 つのインデックスの間にある文字列の一部を抽出します。

入力と出力🔗

string.substring(int) -> string
string.substring(int, int) -> string

最初のインデックスから始まる部分文字列を抽出します。

2 番目の引数が指定されている場合、そのインデックスの直前で抽出を停止します。

引数が 1 つだけ指定されている場合、抽出は文字列の末尾まで続きます。

例🔗

'hello world'.substring(0, 5)
'hello world'.substring(0, 5)

出力: "hello"

'hello world'.substring(6)
'hello world'.substring(6)

出力: "world"

'hello world'.substring(6, 11)
'hello world'.substring(6, 11)

出力: "world"

'hello'.substring(1, 4)
'hello'.substring(1, 4)

出力: "ell"

take🔗

リストの最初の x 個の要素、または開始位置と終了位置の間の要素を返します。

入力と出力🔗

take(list, int) -> list
take(list, int, int) -> list

例🔗

take(["a", "c", "b"], 1)
take(["a", "c", "b"], 1)

出力: ["a"]

take(["a", "c", "b"], 0, 2)
take(["a", "c", "b"], 0, 2)

出力: ["a", "c"]

tenantAllowResponseActions🔗

テナントに対してレスポンスアクションが許可されているかどうかを確認します。

入力と出力🔗

tenantAllowResponseActions(map) -> bool

例🔗

tenantAllowResponseActions(tenant)
tenantAllowResponseActions(tenant)

出力: true

tenantCentralAccountOrigin🔗

centralTenant マップから accountOrigin の値を返します。

入力と出力🔗

tenantCentralAccountOrigin(map) -> string

例🔗

tenantCentralAccountOrigin(tenant)
tenantCentralAccountOrigin(tenant)

出力: "taegis"

tenantCentralAccountType🔗

centralTenant マップから accountType の値を返します。

入力と出力🔗

tenantCentralAccountType(map) -> string

例🔗

tenantCentralAccountType(tenant)
tenantCentralAccountType(tenant)

出力: "tenant"

tenantCentralDataRegion🔗

centralTenant マップから dataRegion の値を返します。

入力と出力🔗

tenantCentralDataRegion(map) -> string

例🔗

tenantCentralDataRegion(tenant)
tenantCentralDataRegion(tenant)

出力: "us03"

tenantCentralId🔗

centralTenant マップから中央テナント ID を返します。

入力と出力🔗

tenantCentralId(map) -> string

例🔗

tenantCentralId(tenant)
tenantCentralId(tenant)

出力: "7f8f1dee-98da-4b1b-bb70-1f788254687e"

tenantCentralLastRefresh🔗

centralTenant マップから lastRefresh の値を返します。

入力と出力🔗

tenantCentralLastRefresh(map) -> string

例🔗

tenantCentralLastRefresh(tenant)
tenantCentralLastRefresh(tenant)

出力: "2025-09-23T17:28:01.113261229Z"

tenantCentralRegion🔗

centralTenant マップから region の値を返します。

入力と出力🔗

tenantCentralRegion(map) -> string

例🔗

tenantCentralRegion(tenant)
tenantCentralRegion(tenant)

出力: "us-east-2"

tenantCentralXdrOwnership🔗

centralTenant マップから xdrOwnership の値を返します。

入力と出力🔗

tenantCentralXdrOwnership(map) -> string

例🔗

tenantCentralXdrOwnership(tenant)
tenantCentralXdrOwnership(tenant)

出力: "securityOperations"

tenantDataRetentionMonths🔗

テナントマップから、月単位のデータ保持期間を抽出します。

入力と出力🔗

tenantDataRetentionMonths(map) -> int

例🔗

tenantDataRetentionMonths(tenant)
tenantDataRetentionMonths(tenant)

出力: 60

tenantDescription🔗

テナントマップからテナントの説明を抽出します。

入力と出力🔗

tenantDescription(map) -> string

例🔗

tenantDescription(tenant)
tenantDescription(tenant)

出力: "CTPx Playground"

tenantEnabled🔗

テナントが有効かどうかを確認します。

入力と出力🔗

tenantEnabled(map) -> bool

例🔗

tenantEnabled(tenant)
tenantEnabled(tenant)

出力: true

tenantEnvironments🔗

テナントの環境名のリストを返します。

入力と出力🔗

tenantEnvironments(map) -> list

例🔗

tenantEnvironments(tenant)
tenantEnvironments(tenant)

出力: ["pilot", "pilot_1", "pilot_2"]

tenantHasService🔗

テナントが名前で指定された特定のサービスを持っているかどうかを確認します (大文字小文字を区別しません)。

入力と出力🔗

tenantHasService(map, string) -> bool

例🔗

tenantHasService(tenant, "MDR")
tenantHasService(tenant, "MDR")

出力: true

tenantId🔗

テナントマップからテナント ID を抽出します。

入力と出力🔗

tenantId(map) -> string

例🔗

tenantId(tenant)
tenantId(tenant)

出力: "11772"

tenantIsOrganization🔗

テナントが組織かどうかを確認します。

入力と出力🔗

tenantIsOrganization(map) -> bool

例🔗

tenantIsOrganization(tenant)
tenantIsOrganization(tenant)

出力: false

tenantIsPartner🔗

テナントがパートナーかどうかを確認します。

入力と出力🔗

tenantIsPartner(map) -> bool

例🔗

tenantIsPartner(tenant)
tenantIsPartner(tenant)

出力: false

tenantIsSophosMDR🔗

テナントの licenseLevel が正確に "MDR" の場合に true を返します。

このマクロは次と同等です:

tenant.licenseLevel == 'MDR'

入力と出力🔗

tenantIsSophosMDR(map) -> bool

例🔗

tenantIsSophosMDR(tenant)
tenantIsSophosMDR(tenant)

出力: true

tenantIsSophosXDR🔗

テナントが XDR のお客様である場合に true を返します。

次と同等です:

tenantCentralXdrOwnership(tenant) != 'taegis' &&
tenantCentralXdrOwnership(tenant) != '' &&
tenant.licenseLevel != 'MDR'

入力と出力🔗

tenantIsSophosXDR(map) -> bool

例🔗

tenantIsSophosXDR(tenant)
tenantIsSophosXDR(tenant)

出力: true

tenantLabelValue🔗

テナントの特定のラベルの値を返します。

入力と出力🔗

tenantLabelValue(map, string) -> string

例🔗

tenantLabelValue(tenant, "testing")
tenantLabelValue(tenant, "testing")

出力: "true"

tenantLabels🔗

テナントのラベル名から値へのマップを返します。

入力と出力🔗

tenantLabels(map) -> map

例🔗

tenantLabels(tenant)
tenantLabels(tenant)

出力: {"testing": "true", "Endpoints Licensed": "2000"}

tenantName🔗

テナントマップからテナント名を抽出します。

入力と出力🔗

tenantName(map) -> string

例🔗

tenantName(tenant)
tenantName(tenant)

出力: "CTPx Playground"

tenantOrganization🔗

テナントマップから組織を抽出します。

入力と出力🔗

tenantOrganization(map) -> string

例🔗

tenantOrganization(tenant)
tenantOrganization(tenant)

出力: ""

tenantParent🔗

テナントマップから親テナント ID を抽出します。

入力と出力🔗

tenantParent(map) -> string

例🔗

tenantParent(tenant)
tenantParent(tenant)

出力: "5000"

tenantParentId🔗

テナントマップから親テナント ID を抽出します。

入力と出力🔗

tenantParentId(map) -> string

例🔗

tenantParentId(tenant)
tenantParentId(tenant)

出力: "5000"

tenantPartner🔗

テナントマップからパートナーテナント ID を抽出します。

入力と出力🔗

tenantPartner(map) -> string

例🔗

tenantPartner(tenant)
tenantPartner(tenant)

出力: "5000"

tenantPartnerId🔗

テナントマップからパートナーテナント ID を抽出します。

入力と出力🔗

tenantPartnerId(map) -> string

例🔗

tenantPartnerId(tenant)
tenantPartnerId(tenant)

出力: "5000"

tenantServices🔗

テナントのサービス名のリストを返します。

入力と出力🔗

tenantServices(map) -> list

例🔗

tenantServices(tenant)
tenantServices(tenant)

出力: ["Access Point", "Ask an Expert", "Data Retention: 60 mo"]

tenantSupportEnabled🔗

テナントでサポートが有効かどうかを確認します。

入力と出力🔗

tenantSupportEnabled(map) -> bool

例🔗

tenantSupportEnabled(tenant)
tenantSupportEnabled(tenant)

出力: false

toHTML🔗

指定された文字列を HTML として返します。

入力と出力🔗

toHTML(string) -> string

例🔗

'**bold**'.toHTML()
'**bold**'.toHTML()

出力: "bold"

toHex🔗

バイトリストの 16 進文字列表現を返します。

入力と出力🔗

toHex(bytes) -> string

例🔗

md5sum("Hello").toHex()
md5sum("Hello").toHex()

出力: "8b1a9953c4611296a827abf8c47804d7"

toLower🔗

すべての文字を小文字に変換した文字列のコピーを返します。

入力と出力🔗

toLower(string) -> string

例🔗

"TEST".toLower()
"TEST".toLower()

出力: "test"

toPreferredTimestamp🔗

指定されたタイムスタンプ、タイムゾーン、および言語に基づいて、ユーザーが希望するタイムスタンプ形式を返します。

入力と出力🔗

toPreferredTimestamp(string, string, string) -> string

例🔗

toPreferredTimestamp('2025-01-02T15:04:05Z', 'UTC', 'en')
toPreferredTimestamp('2025-01-02T15:04:05Z', 'UTC', 'en')

出力: "Jan 2 2025 15:04 UTC"

toString🔗

任意のデータ型の指定された値を文字列として返します。

入力と出力🔗

toString(any) -> string

例🔗

toString(100)
toString(100)

出力: "100"

toTable🔗

指定されたデータの文字列表現を、テキストまたは Markdown テーブルとして返します。

入力と出力🔗

toTable(list, list, list, bool) -> string

例🔗

toTable([["row1_column1", "row1_column2"], ["row2_column1", "row2_column2"]], ["header1", "header2"], [], false)
toTable([["row1_column1", "row1_column2"], ["row2_column1", "row2_column2"]], ["header1", "header2"], [], false)

出力: "+------+------+\\n HEADER1 HEADER2 \\n+------+------+\\n row1_column1 row1_column2 \\n row2_column1 row2_column2 \\n+------+------+"

toTimestamp🔗

日付と時刻の文字列からタイムスタンプを返します。

入力と出力🔗

toTimestamp(string) -> timestamp

例🔗

'1/1/2012'.toTimestamp()
'1/1/2012'.toTimestamp()

出力: "2012-01-01T00:00:00Z"

toTitle🔗

各単語の最初の文字を大文字に変換した文字列のコピーを返します。

入力と出力🔗

toTitle(string) -> string

例🔗

'hello world'.toTitle()
'hello world'.toTitle()

出力: "Hello World"

toURLQuery🔗

URL の特殊文字をエスケープシーケンスに変換した文字列のコピーを返します。

入力と出力🔗

toURLQuery(string) -> string

例🔗

'hello world'.toURLQuery()
'hello world'.toURLQuery()

出力: "hello+world"

toUpper🔗

すべての文字を大文字に変換した文字列のコピーを返します。

入力と出力🔗

toUpper(string) -> string

例🔗

"hello".toUpper()
"hello".toUpper()

出力: "HELLO"

transformList🔗

インデックス/キーと値を使用してリストまたはマップを反復処理し、各要素を新しいリストに変換します。

入力と出力🔗

list.transformList(index, value, expression) -> list
list.transformList(index, value, condition, expression) -> list
map.transformList(key, value, expression) -> list
map.transformList(key, value, condition, expression) -> list

変換式ではインデックス/キーと値の両方にアクセスできます。

必要に応じてフィルター条件もサポートします。

例🔗

[1, 2, 3].transformList(i, v, i * v)
[1, 2, 3].transformList(i, v, i * v)

出力: [0, 2, 6]

[10, 20, 30].transformList(i, v, v + i)
[10, 20, 30].transformList(i, v, v + i)

出力: [10, 21, 32]

[1, 2, 3, 4].transformList(i, v, i % 2 == 0, i * v)
[1, 2, 3, 4].transformList(i, v, i % 2 == 0, i * v)

出力: [0, 6]

transformMap🔗

インデックス/キーと値を使用してリストまたはマップを反復処理し、キーを保持したまま値を変換します。

入力と出力🔗

list.transformMap(index, value, expression) -> map
list.transformMap(index, value, condition, expression) -> map
map.transformMap(key, value, expression) -> map
map.transformMap(key, value, condition, expression) -> map

変換式ではインデックス/キーと値の両方にアクセスできます。

必要に応じてフィルター条件もサポートします。

例🔗

[10, 20, 30].transformMap(i, v, v * 2)
[10, 20, 30].transformMap(i, v, v * 2)

出力: {"0": 20, "1": 40, "2": 60}

[1, 2, 3].transformMap(i, v, i * v)
[1, 2, 3].transformMap(i, v, i * v)

出力: {"0": 0, "1": 2, "2": 6}

[1, 2, 3, 4].transformMap(i, v, i % 2 == 0, i * v)
[1, 2, 3, 4].transformMap(i, v, i % 2 == 0, i * v)

出力: {"0": 0, "2": 6}

{'a': 1, 'b': 2}.transformMap(k, v, v * 10)
{'a': 1, 'b': 2}.transformMap(k, v, v * 10)

出力: {"a": 10, "b": 20}

transformMapEntry🔗

インデックス/キーと値を使用してリストまたはマップを反復処理し、新しいマップ内にカスタムのキーと値のペアを作成します。

入力と出力🔗

list.transformMapEntry(index, value, expression) -> map
list.transformMapEntry(index, value, condition, expression) -> map
map.transformMapEntry(key, value, expression) -> map
map.transformMapEntry(key, value, condition, expression) -> map

変換式は、単一のエントリを含むマップリテラルを生成する必要があります。

例🔗

[1, 2, 3].transformMapEntry(i, v, {string(v): i})
[1, 2, 3].transformMapEntry(i, v, {string(v): i})

出力: {"1": 0, "2": 1, "3": 2}

['a', 'b', 'c'].transformMapEntry(i, v, {v: i})
['a', 'b', 'c'].transformMapEntry(i, v, {v: i})

出力: {"a": 0, "b": 1, "c": 2}

[1, 2, 3, 4].transformMapEntry(i, v, i % 2 == 0, {string(v): i})
[1, 2, 3, 4].transformMapEntry(i, v, i % 2 == 0, {string(v): i})

出力: {"1": 0, "3": 2}

{'a': 1, 'b': 2}.transformMapEntry(k, v, {string(v): k})
{'a': 1, 'b': 2}.transformMapEntry(k, v, {string(v): k})

出力: {"1": "a", "2": "b"}

trim (string or list)🔗

先頭と末尾の空白を削除します。

入力と出力🔗

trim(string) -> string
trim(list) -> list

例🔗

" 1 ".trim()
" 1 ".trim()

出力: "1"

trim([" 1 ", " 2 ", " 3 "])
trim([" 1 ", " 2 ", " 3 "])

出力: ["1", "2", "3"]

trim (string)🔗

文字列の先頭と末尾の空白を削除します。

入力と出力🔗

string.trim() -> string

文字列の先頭と末尾からスペース、タブ、および改行文字を削除します。

文字列の途中にある空白は削除しません。

例🔗

' hello '.trim()
'  hello  '.trim()

出力: "hello"

'hello world'.trim()
'hello world'.trim()

出力: "hello world"

'\\n\\t test \\n'.trim()
'\\n\\t  test  \\n'.trim()

出力: "test"

' hello world '.trim()
'  hello  world  '.trim()

出力: "hello world"

unique🔗

重複要素を削除したリストのコピーを返します。

完全に同一の要素のみが削除されます (大文字小文字を区別します)。

入力と出力🔗

unique(list) -> list

例🔗

unique(["a", "b", "a"])
unique(["a", "b", "a"])

出力: ["a", "b"]

unwrapOpt🔗

値を持つ optional 要素の値のみを含むリストを返し、optional.none() を除外します。

入力と出力🔗

list(optional(T)).unwrapOpt() -> list(T)

optional 値のリストを受け取り、値を含む optional の値のみを含む新しいリストを返します。

すべての optional.none() エントリを除外します。

ユースケース🔗

存在する値をフィルタリングする。
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()

出力: [1, 3]

空の optional を削除します。

安全なマップアクセス。
keys.map(k, data[?k]).unwrapOpt()

存在するキーの値のみを取得します。

結果をクリーンアップする。
items.map(i, i.?value).unwrapOpt()

存在する値のみを抽出します。

条件付き収集。
data.map(x, x > 0 ? optional.of(x) : optional.none()).unwrapOpt()

条件を満たす値を収集します。

コンパクト操作。
optionalList.unwrapOpt()

すべての optional.none() 値を削除します。

安全な変換。
inputs.map(i, parseValue(i)).unwrapOpt()

正常に解析された値のみを保持します。

注意事項🔗

  • 入力: list(optional(T))
  • 出力: list(T)
  • .hasValue() が true を返す optional のみを含みます。
  • 空でない値の順序を保持します。
  • すべての optional が空の場合は空のリストを返します。
  • optional.unwrap(list) としても利用できます。

例🔗

[optional.of(1), optional.of(2), optional.of(3)].unwrapOpt()
[optional.of(1), optional.of(2), optional.of(3)].unwrapOpt()

出力: [1, 2, 3]

すべての値が存在します。

[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()

出力: [1, 3]

空の optional を除外します。

[optional.none(), optional.none()].unwrapOpt()
[optional.none(), optional.none()].unwrapOpt()

出力: []

すべての値が空です。

[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()[0]
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()[0]

出力: 1

最初に存在する値にアクセスします。

upperAscii🔗

文字列内のすべての ASCII 文字を大文字に変換します。

入力と出力🔗

string.upperAscii() -> string

すべての ASCII 小文字 (a-z) を大文字 (A-Z) に変換します。

ASCII 以外の文字は変更されません。

例🔗

'hello World'.upperAscii()
'hello World'.upperAscii()

出力: "HELLO WORLD"

'abc123xyz'.upperAscii()
'abc123xyz'.upperAscii()

出力: "ABC123XYZ"

'café'.upperAscii()
'café'.upperAscii()

出力: "CAFé"

userIds🔗

アラートまたはエンティティを解析し、ユーザー ID のリストを返します。

入力と出力🔗

userIds(map) -> list

例🔗

userIds(inputs)
userIds(inputs)

出力: ["1234", "dac1ed31-111-4809-9cc9-9f99b6e", "5678"]

userInDomain🔗

指定されたユーザー名が、指定された 1 つ以上のドメインに属している場合は true を返します。

入力と出力🔗

userInDomain(string, list) -> bool

例🔗

userInDomain("asdf@example.com", ["example.com"])
userInDomain("asdf@example.com", ["example.com"])

出力: true

userNames🔗

アラートまたはエンティティを解析し、ユーザー名のリストを返します。

入力と出力🔗

userNames(map) -> list

例🔗

userNames(inputs)
userNames(inputs)

出力: ["sample_user", "another_sample_user"]

users🔗

アラートまたはエンティティを解析し、ユーザー名とユーザー ID のリストを返します。

入力と出力🔗

users(map) -> list

例🔗

users(inputs)
users(inputs)

出力: ["sample_user", "another_sample_user", "1234", "dac1ed31-111-4809-9cc9-9f99b6e", "5678"]

value🔗

optional から値を返します。optional が空の場合はエラーを発生させます。

入力と出力🔗

optional(T).value() -> T

optional から値を取り出します。

optional が空 (optional.none()) の場合、実行時エラーが発生します。

ユースケース🔗

既知の値を取り出す。
optional.of(42).value()

出力: 42

値を直接取得します。

検証後に取り出す。
opt.hasValue() ? opt.value() : 'default'

取り出す前に確認します。

即時失敗。
requiredField.value()

フィールドが存在しない場合にエラーを発生させます。

結果をアンラップする。
computation().value()

結果を取得するか失敗します。

注意事項🔗

  • optional.none() に対して .value() を呼び出すとエラーになります。
  • 必ず最初に .hasValue() で確認するか、代わりに .orValue() を使用してください。
  • optional に値が含まれていることが確実な場合にのみ使用してください。
  • 値が存在しないことをエラーとして扱うべき場合に便利です。
  • optional の連鎖には .orValue() を使用してください。
  • 即時失敗のシナリオでよく使用されます。

例🔗

optional.of(42).value()
optional.of(42).value()

出力: 42

整数値を取り出します。

optional.of('text').value()
optional.of('text').value()

出力: 'text'

文字列値を取り出します。

[1, 2, 3].first().value()
[1, 2, 3].first().value()

出力: 1

リストから最初の要素を取り出します。