Skip to main content

How to Use Regex for Variable detected Google Chronicle

  • January 16, 2025
  • 2 replies
  • 34 views

agar_s
Forum|alt.badge.img+2

Hello,

I’m trying to create a save search in Google Chronicle where a field matches a regex pattern instead of performing an exact match.

Specifically, my query looks like this:

metadata.log_type = "MCAFEE_WEBPROXY"

target.url = ${URL} nocase

 

However, I want target.url to match a regex pattern rather than being equal to a specific value.

How can I achieve a regex-based search on the save searches with using Variable detected  in Google secops? 

Thanks for your help!

2 replies

jstoner
Staff
Forum|alt.badge.img+22
  • Staff
  • January 16, 2025

I tried a few different things and was not able to arrive at a solution. I did open a ticket asking for some additional support in this regard. If this is something that you would like to see improved in the product, I would encourage opening a ticket as well to raise more attention to it.


agar_s
Forum|alt.badge.img+2
  • Author
  • New Member
  • January 16, 2025

Thank you very much for the help and the tests.
I would appreciate it if you could update that this is necessary in the product as well, we are trying to optimize processes with our analysts in the organization.

Thank you very much  😀