Skip to main content

Hello All,

I have this query regarding Asset_Namesapce, while ingesting a new log source we will give a Asset_Namespace but i don't know how it is getting parsed into UDM as there is no parsing condition mentioned in the prebuilt as well as custom parser.

So anyone can help me on finding how does it works in the backend.

Thanks.

AFAIK, all ingestion parameters defined as tags or namespace are automatically added to events coming from that source as metadata in the events.


AFAIK, all ingestion parameters defined as tags or namespace are automatically added to events coming from that source as metadata in the events.


Hi @ankitsynx ,

I also thought the same, but i was not sure.

if you have any white paper regarding this please share it.

Thankyou.


Hi @ankitsynx ,

I also thought the same, but i was not sure.

if you have any white paper regarding this please share it.

Thankyou.


Hi @sudeep_singh , you may refer the detailed documentation on Namespace here https://cloud.google.com/chronicle/docs/investigation/asset-namespaces#:~:text=Google%20SecOps%20SIEM.%20When%20you%20search%20for%20an%20asset%20in


Hi @ankitsynx ,

Thanks for providing the information.


Reply