Skip to main content

Which resources for UDM parsing are apart from the official reference documentation?

  • August 15, 2023
  • 4 replies
  • 0 views

JaredBloomberg
Forum|alt.badge.img+4

Does anyone here know of any resources for UDM parsing apart from the official reference documentation? The docs are fine for what they are, showing you how , but Google doesn't seem to have very good training on teaching you why . I'm just trying to find any kind of tutorial (blog, YouTube video, webinar, etc.) that starts with the fundamentals elements of a parser/extension at a high level and walks you through it start to finish.

4 replies

cmmartin_google
Staff
Forum|alt.badge.img+11

cmmartin_google
Staff
Forum|alt.badge.img+11

else my blog on the topic of parsing available here - https://medium.com/@thatsiemguy/parsing-101-best-practices-tips-c2e8b7ce9db8


cmmartin_google
Staff
Forum|alt.badge.img+11

the training has a 20~ minute video on parsing too under SIEM - https://learn.chronicle.security/


JaredBloomberg
Forum|alt.badge.img+4
  • Author
  • New Member
  • August 15, 2023

Thank you sir, much appreciated