Skip to main content

How can I set YARA-L rule severity using a UDM field from the matched events, such as security_result.severity?

No, not at present.  You would need to set Severity as a custom Outcome variable; however, I checked with our Product team and this is scheduled for the mid term, and as an indicative estimate could be available by end of Q1 next year.