Hi,
We have ingested our customer’s Google Workspace (GWS) logs via BigQuery into Google SecOps, and they are currently being processed using the BigQuery context. My question is: should we switch to the workspace activity parser to properly interpret these logs for udm and generate alerts, or is the current BigQuery context parser sufficient for this purpose?
Workspace Parser
Login to the community
Login with SSO
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.

