Maintained with ☕️ by
IcePanel logo

Chronicle - January 16th, 2024 [Feature]

Share

Services

## Feature [UDM Search for entity investigation](https://cloud.google.com/chronicle/docs/investigation/udm-search-investigate-entity) UDM Search now includes a feature that lets you investigate entities (for example, an IP address, user, or asset) in addition to the events and alerts that match the search query terms. UDM Search query conditions can include both UDM fields (for example, `principal.hostname="alice"`) and grouped fields (for example, `hostname="alice"`). When a search query includes a condition that identifies a specific entity, the search results include details about that entity in addition to UDM events that match the entire search query.