Elastic medium stable kql

Google SecOps External Alerts

Generates a detection alert for each Google SecOps alert written to the configured indices. Enabling this rule allows you to immediately begin investigating Google SecOps alerts in the app.

View Source

Detection Logic

event.kind: alert and data_stream.dataset: google_secops.alert

Field Validations

Loading…

Comments (0)

Loading comments...