Skip to main content

Hi All,

Could someone please assist me with Autonomous Parsers? I read a blog on Medium (https://medium.com/@thatsiemguy/automagic-json-parsing-e838ecda08c2) that explains how log sources without a parser can generate a GENERIC_EVENT UDM event.

If the log source is in JSON format, all the fields are automatically extracted.

I have ingested a log in JSON format and checked it, but it did not work. I would like to know how to properly work with Autonomous Parsers. Are there specific steps that need to be followed to ensure proper functioning of Autonomous Parsers?

 

Thanks,

Manoj 

Hi ,

This is something I would suggest speaking to your Account Team. This is a preview feature known as 'Dynamic Fields' (extracted fields) as mentioned here and is not on by default -https://www.googlecloudcommunity.com/gc/Community-Blog/Detecting-Impossible-Travel-with-Google-SecOps-Part-1/bc-p/790653/highlight/true#M145

Kind Regards,

Ayman


Reply