QuestionQ13

Platform operations

You are examining the results of a UDM search in Google Security Operations (SecOps). The UDM fields displayed in the default view are not pertinent to your search. You want to quickly see the data that is relevant to your analysis. What should you do?

  • A Download the search results as a CSV file, and manipulate the data to display relevant data in a spreadsheet.
  • B Create a Google SecOps SIEM dashboard based on the search you have run, and visualize the data in an appropriate table or graphical format.
  • C Select the events of interest, and choose the relevant UDM fields from the event view using the checkboxes. Copy, extract, and analyze the UDM fields, and refine the search query.
  • D Use the columns feature to select or remove columns that are relevant to your analysis.
Explanation

Google SecOps lets analysts use the Columns feature (Column Manager) in UDM Search to add or remove columns in the Events table, creating a view containing the UDM fields relevant to the analysis. Understand search — Google Security Operations

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!