[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-02。"],[[["\u003cp\u003eWatchlists are curated lists of entities within Google SecOps Risk Analytics that allow for manual monitoring based on internal risk considerations.\u003c/p\u003e\n"],["\u003cp\u003eThey enhance risk scoring by incorporating human expertise, allowing analysts to ensure specific entities receive attention through modifying risk scores using a multiplying factor.\u003c/p\u003e\n"],["\u003cp\u003eUsers can create up to 200 watchlists and apply a multiplying factor between 0-100 to adjust the risk score of all entities within a specific watchlist.\u003c/p\u003e\n"],["\u003cp\u003eEntities such as IP addresses, emails, employee IDs, hostnames, and usernames can be added to a watchlist, allowing for versatile monitoring.\u003c/p\u003e\n"],["\u003cp\u003eWatchlists are useful for monitoring specific cases like employees leaving a company, tracking unusual activities, and managing internal red team alerts, all within the Risk Analytics dashboard.\u003c/p\u003e\n"]]],[],null,["# Watchlists FAQ\n==============\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nWhat are Watchlists?\n--------------------\n\nWatchlists let you manually curate lists of entities to monitor (in Risk\nAnalytics only) based on internal risk considerations.\n\nWhere are Watchlists located?\n-----------------------------\n\nOn the **Risk Analytics** dashboard, click the **Watchlists** tab to access\nwatchlists.\n\nWhy use Watchlists?\n-------------------\n\nWatchlists allow you to monitor specific entities, boosting or suppressing your\nrisk scores in the system. They are useful for tracking entities that may not\nhave high risk scores, but are important to monitor based on internal risk\nconsiderations.\n\nHow do Watchlists enhance risk scoring?\n---------------------------------------\n\nWatchlists incorporate human expertise and context into the risk assessment\nprocess. Analysts can ensure that high-value assets, sensitive data locations,\nor specific you receive appropriate attention. An example of this is the use of\nmultiplying factors (see below).\n\nHow many Watchlists can I create?\n---------------------------------\n\nYou can configure up to 200 watchlists.\n\nWhat is a Multiplying factor in Watchlists?\n-------------------------------------------\n\nA Multiplying factor, with values ranging from 0-100, can be applied to each\nwatchlist to modify the risk score of all entities in that watchlist.\nThe default value is 1.\n\nHow do I add a Watchlist?\n-------------------------\n\nTo add a watchlist, do the following:\n1. Click **Create watchlist** .\n1. Enter a **Watchlist name** , an optional **Description** , and an optional\n**Multiplying factor**.\n1. Add the entities to the watchlist.\n\nWhat type of entities can be added to a Watchlists?\n---------------------------------------------------\n\nYou can add entities to a Watchlists based on the following types:\n- `ASSET_IP_ADDRESS`\n- `EMAIL`\n- `EMPLOYEE_ID`\n- `HOSTNAME`\n- `MAC`\n- `PRODUCT_OBJECT_ID`\n- `PRODUCT_SPECIFIC_ID`\n- `USERNAME`\n- `WINDOWS_SID`\n\nWhat actions can I perform on Watchlists?\n-----------------------------------------\n\nYou can create, edit, pin, unpin, and delete watchlists, and add or\nremove entities from them.\n\nWhat are some use cases for Watchlists?\n---------------------------------------\n\nWatchlists can be used to monitor employees about to leave a company, track\nunusual activity, or manage the alerts triggered by an\ninternal red team.\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]