Skip to main content

Hi Community, I have two questions/doubts.


1. is there any way to pull the search ID for every user search on chronicle(Google Secops) siem?


If yes, how do we pull the search ID for the udm and raw_log searches?


2. can we get MD5/Hash() function details for user search(data access logs(gcp cloudaudit))


Please assist me with this.


@rafaelramirez  @cmorris 


Best regards,


Emmie


 


 

Information around audit logging, to include search, can be found here - https://cloud.google.com/chronicle/docs/administration/audit-logging


Reply