I'm building an automation that integrates Google SecOps with our ITSM platform, and I need to retrieve the raw log from within a playbook so I can send it to the ITSM.
I found the event._raw field, but it is always empty in my playbook.
Is there another way to access the original raw log within a Google SecOps playbook? If so, what is the recommended approach?








