In the following document:
https://cloud.google.com/chronicle/docs/investigation/investigate-alert
> To maximize graph capabilities, specify the important indicators in the outcome section. Here are the indicators supported by Chronicle: hostname, asset_id, etc.
But the list of indicators are basically Nouns in UDM. So why are they referred to as indicators?
Also, when it says "specify the important indicators" in the outcome section. Does it mean in the outcome section of the YARA-L rule? If yes, why is it required to specify these indicators in the outcome section. Also, in the YARA-L rule that follows in the documentation, the indicators are not specified in the YARA-L rule.
Can you please break it down.
Thank you.