Skip to main content

SIEM > UDM search > "Add to Events Table" - column views

  • September 11, 2024
  • 3 replies
  • 38 views

Chris_B
Forum|alt.badge.img+8

Every so often I'm unable to add as a column a key or value type column I can see in the aggregations pane (image)
That is, "Add to Events Table" does not show up as an option.

I do tend to use a lot of columns, but I don't think it's a column limit.

thanks

3 replies

BrianK
Staff
Forum|alt.badge.img+5
  • Staff
  • September 11, 2024

are the fields you are trying to add UDM fields or additional/extracted fields?


Chris_B
Forum|alt.badge.img+8
  • Author
  • Silver 2
  • September 12, 2024

@BrianK Thanks for your reply

 

I don't think so - here's an image of the UDM lookup for the field - it doesn't say "enum" per se but it does come up as a result for UDM lookup on values "enum" (image)

 

 

Here's an example of a UDM line for a value also in the the same UDM field(s)

...and it does exist in the raw log, although there does seem to be some enrichment - it's put in the form of a sentence

thanks again

 

 


Adrian So
Forum|alt.badge.img+1
  • Bronze 1
  • September 15, 2025

Did you find the solution?

i have this question too.

I can see the UDM contain the information i want but unable to add in the event table!