Google SecOps SIEM: UDM fields show enrichment status
Google SecOps SIEM now visually indicates whether User Data Model (UDM) fields are enriched or unenriched using new 'E' or 'U' icons. This feature helps users understand the origin of data and the additional context provided by Google SecOps. It applies to all UDM fields within the SIEM. More details are available in the "Viewing events" documentation.
Features (1) ›
- Google SecOps SIEM UDM fields now show whether data is enriched or not
UDM fields now show whether data is enriched or not The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to indicate its data source: U for unenriched fields and E for enriched fields. Enriched fields contain values that Google SecOps generates to provide additional context about artifacts in your environment. For more information, see: Viewing events .
https://docs.cloud.google.com/release-notes#June_09_2026
