When I run a UDM search directly in Google SecOps, it returns exactly the data I need, including aggregated statistics. However, when I use the 'Execute UDM Query' playbook action, it only returns raw UDM events without any aggregation or statistical summaries. Is there a way to configure the playbook action so that it returns the same aggregated results as a standard SIEM search?
Question
UDM SEARCH
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.