Skip to main content
Solved

YARA-L Rule Severity based on the value of an UDM field

  • October 6, 2025
  • 1 reply
  • 45 views

ar3diu
Forum|alt.badge.img+8

How can I set YARA-L rule severity using a UDM field from the matched events, such as security_result.severity?

Best answer by cmmartin_google

No, not at present.  You would need to set Severity as a custom Outcome variable; however, I checked with our Product team and this is scheduled for the mid term, and as an indicative estimate could be available by end of Q1 next year. 

1 reply

cmmartin_google
Staff
Forum|alt.badge.img+11

No, not at present.  You would need to set Severity as a custom Outcome variable; however, I checked with our Product team and this is scheduled for the mid term, and as an indicative estimate could be available by end of Q1 next year.