Google Security Operations (SecOps) is Google Cloud’s security operations platform for detecting, investigating, and responding to threats across large volumes of security telemetry. To make that telemetry useful across sources, Google SecOps uses the Unified Data Model (UDM), a common event schema that provides a consistent structure for security logs. But logs from firewalls, endpoints, identity providers, and other sources all describe and format security events differently. Before teams can analyze those logs in Google SecOps, they need to map the data from each source to UDM. As organizations add new technologies, the effort required to maintain those mappings can become significant and difficult to scale.
Observability Pipelines addresses this challenge with Google SecOps packs. Each of these packs consists of preconfigured mappings that normalize logs from a particular source to the UDM format in your pipeline before they reach Google SecOps. With Google SecOps packs, your logs can land with the right structure already in place, ready for detections, dashboards, and investigations.
In this post, we’ll explore how Google SecOps packs make it easy to:
Normalize and optimize security data before it reaches Google SecOpsInvestigate security activity across every sourceControl Google SecOps ingest costs without losing visibility








