tenzir-google-udm

Installation
SKILL.md

Google UDM

Google UDM (Unified Data Model) is the Google SecOps data model for normalized security telemetry. It represents events and entities as common records so logs from different products can describe actors, assets, resources, network activity, security outcomes, and product context with consistent field names and enum values.

Use this skill for two primary workflows: mapping logs into UDM event or entity objects for Google SecOps UDM API ingestion, and referencing UDM fields in YARA-L, Detect Engine, CBN, or other dotted field-path contexts. It also answers which event or entity type to choose, which fields to populate, and how Google expects values to be formatted.

Nomenclature

Installs
13
Repository
tenzir/skills
GitHub Stars
3
First Seen
Jun 5, 2026
tenzir-google-udm — tenzir/skills