QuestionQ25
Data managementYou use Google Security Operations (SecOps) curated detections and YARA-L rules to identify suspicious activity on Windows endpoints. Your source telemetry consists of EDR and Windows Event logs, and your rules match the principal.user.userid UDM field. You need to ingest an additional log source so this field can match all possible log entries from your EDR and Windows Event logs. What should you do?
- A Ingest logs from Windows Sysmon.
- B Ingest logs from Microsoft Entra ID.
- C Ingest logs from Windows PowerShell.
- D Ingest logs from Windows Procmon.
Community Discussion