Statistics and aggregations in UDM search using YARA-L 2.0 | Google Security Operations | Google Cloud
This product or feature is subject to the "Pre-GA Offerings Terms" in the General Service Terms section of the Service Specific Terms. Pre-GA products and features are available "as is" and might have limited support. For more information, see the launch stage descriptions. This page describes how to run statistical queries on UDM events and group the results for analysis using YARA-L 2.0. When dealing with a large volume of UDM events generated within your environment, it's important to understand the trends in your UDM search data. You can use statistics and aggregate functions to gain actionable insights from your UDM logs. UDM search supports all the aggregate functions in YARA-L 2.0. You can use statistical queries for the following use cases: Track critical metrics: You can measure the distribution and frequency of UDM events and the assets involved, such as hosts communicating with known malicious IP addresses. Detect anomalous behaviour: You can detect unusual patterns or spike
This product or feature is subject to the "Pre-GA Offerings Terms" in the General Service Terms section of the Service Specific Terms. Pre-GA products and features are available "as is" and might have limited support. For more information, see the launch stage descriptions. This page describes how to run statistical queries on UDM events and group the results for analysis using YARA-L 2.0. When dealing with a large volume of UDM events generated within your environment, it's important to understand the trends in your UDM search data. You can use statistics and aggregate functions to gain actio
Explore this link on the map →