Dokumen ini menjelaskan cara Anda dapat menggunakan Gemini untuk membuat kueri penelusuran dari panel Gemini atau saat menggunakan penelusuran Google Security Operations.
Untuk mendapatkan hasil terbaik, sebaiknya gunakan panel Gemini untuk membuat kueri penelusuran.
Membuat kueri penelusuran menggunakan panel Gemini
Login ke Google SecOps.
Klik logo Gemini untuk membuka panel Gemini.
Masukkan perintah natural language, lalu tekan Enter. Perintah bahasa alami harus dalam bahasa Inggris.
Gambar 1. Buka panel Gemini dan masukkan perintah.
Tinjau kueri penelusuran yang dibuat. Kueri penelusuran menggunakan sintaksis YARA-L 2.0.
Jika kueri penelusuran yang dibuat memenuhi persyaratan Anda, klik Jalankan penelusuran.
Gemini akan menghasilkan ringkasan hasil beserta tindakan yang disarankan.
Contoh perintah penelusuran dan pertanyaan lanjutan
Show me all failed logins for the last 3 days
Generate a rule to help detect that behavior in the future
Show me events associated with the principle user izumi.n
Who is this user?
Search for all of the events associated with the IP 198.51.100.121 in the
last 3 hours
List all of the domains in the results set
What types of events were returned?
Show me events from my firewall in the last 24 hours
What were the 16 unique hostnames in the results set?
What were the 9 unique IPs associated with the results set?
Membuat kueri penelusuran menggunakan bahasa alami
Dengan fitur penelusuran Google SecOps, Anda dapat memasukkan kueri bahasa alami tentang data Anda, dan Gemini dapat menerjemahkannya menjadi kueri penelusuran untuk dijalankan terhadap peristiwa UDM.
Untuk menggunakan penelusuran bahasa alami guna membuat kueri penelusuran, selesaikan langkah-langkah berikut:
Login ke Google SecOps.
Buka Investigasi > Penelusuran SIEM.
Masukkan pernyataan penelusuran di kolom kueri bahasa alami, lalu klik
Buat Kueri. Anda harus menggunakan bahasa Inggris untuk penelusuran.
Gambar 2. Masukkan penelusuran bahasa alami, lalu klik Buat Kueri.
Pernyataan berikut adalah contoh yang dapat menghasilkan penelusuran yang berguna:
network connections from 10.5.4.3 to google.com
failed user logins over the last 3 days
emails with file attachments sent to john@example.com or jane@example.com
all Cloud service accounts created yesterday
outbound network traffic from 10.16.16.16 or 10.17.17.17
all network connections to facebook.com or tiktok.com
service accounts created in Google Cloud yesterday
Windows executables modified between 8 AM and 1 PM on May 1, 2023
all activity from winword.exe on lab-pc
scheduled tasks created or modified on exchange01 during the last week
email messages that contain PDF attachments
emails sent by or sent from admin@acme.com on September 1
any files with the hash 44d88612fea8a8f36de82e1278abb02f
all activity associated with user "sam@acme.com"
Jika pernyataan penelusuran menyertakan istilah berbasis waktu, pemilih waktu akan otomatis disesuaikan agar cocok. Misalnya, hal ini akan berlaku untuk penelusuran berikut:
yesterday
within the last 5 days
on Jan 1, 2023
Jika pernyataan penelusuran tidak dapat diinterpretasikan, Anda akan melihat pesan berikut: "Maaf, tidak ada kueri yang valid yang dapat dibuat. Coba tanyakan dengan cara lain."
Tinjau kueri penelusuran yang dibuat. Sintaksisnya adalah YARA-L
2.0.
Opsional: Sesuaikan rentang waktu penelusuran.
Klik Run Search.
Tinjau hasil penelusuran untuk menentukan apakah acara tersebut ada atau tidak. Jika perlu,
gunakan filter penelusuran untuk mempersempit daftar hasil.
Berikan masukan tentang kueri menggunakan ikon masukan Kueri yang Dihasilkan. Pilih salah satu opsi berikut:
Jika kueri menampilkan hasil yang diharapkan, klik thumb_upSuka.
Jika kueri tidak menampilkan hasil yang diharapkan, klik thumb_downTidak Suka.
Opsional: Sertakan detail tambahan di kolom Masukan.
Untuk mengirimkan kueri penelusuran yang direvisi yang membantu meningkatkan kualitas hasil:
Edit kueri penelusuran yang dibuat.
Klik Kirim.
Jika Anda tidak menulis ulang kueri, Anda akan diminta untuk mengedit kueri.
Jika Anda menulis ulang kueri, kueri penelusuran yang direvisi akan dibersihkan dari data sensitif dan digunakan untuk meningkatkan kualitas hasil.
Menghapus sesi chat
Anda dapat menghapus sesi percakapan chat atau menghapus semua sesi chat.
Gemini menjaga kerahasiaan semua histori percakapan pengguna dan mematuhi praktik AI yang bertanggung jawab dari Google Cloud. Histori pengguna tidak pernah digunakan untuk melatih model.
Di panel Gemini, pilih Hapus percakapan dari menu di kanan atas.
Klik Hapus percakapan di kanan bawah untuk menghapus sesi percakapan saat ini.
Opsional: Untuk menghapus semua sesi chat, pilih Hapus semua sesi chat
lalu klik Hapus semua percakapan.
Berikan masukan
Anda dapat memberikan masukan untuk respons yang dihasilkan oleh bantuan penyelidikan AI Gemini. Masukan Anda membantu Google meningkatkan kualitas fitur dan output yang dihasilkan oleh Gemini.
Di panel Gemini, klik thumb_upSuka atau thumb_downTidak Suka.
Opsional: Klik thumb_downTidak Suka dan berikan masukan.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-21 UTC."],[[["\u003cp\u003eGemini can be used within Google SecOps to generate search queries, either through the dedicated Gemini pane or by using the natural language search bar.\u003c/p\u003e\n"],["\u003cp\u003eUsing the Gemini pane is the recommended method for generating search queries, where you input a natural language prompt and Gemini will convert it to a YARA-L 2.0 search query.\u003c/p\u003e\n"],["\u003cp\u003eYou can also input natural language search terms directly into the Google SecOps search bar, and Gemini will translate this into a search query.\u003c/p\u003e\n"],["\u003cp\u003eAfter generating a query, you can run the search, refine it, and provide feedback to help improve Gemini's query generation capabilities.\u003c/p\u003e\n"],["\u003cp\u003eChat sessions with Gemini can be deleted individually or in their entirety, while also ensuring Google's responsible AI practices for user privacy and data management.\u003c/p\u003e\n"]]],[],null,["# Generate search queries with Gemini\n===================================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nThis document explains how you can use Gemini to generate search queries from the Gemini\npane or when using Google Security Operations search.\n\nFor best results, we recommend using the Gemini pane to generate search\nqueries.\n\n- [Generate a search query using the Gemini pane](#udm-query-gemini)\n\n- [Generate a search query using natural language](#nl-to-udm)\n\nGenerate a search query using the Gemini pane\n---------------------------------------------\n\n1. Sign in to Google SecOps.\n2. Click the Gemini logo to open the Gemini pane.\n3. Enter a natural language prompt and press **Enter**. The natural language\n prompt must be in English.\n\n **Figure 1.** Open Gemini pane and enter prompt.\n4. Review the generated search query. The search query uses YARA-L 2.0 syntax.\n If the generated search query meets your requirements, click **Run search**.\n Gemini produces a results summary along with suggested actions.\n\n### Example search prompts and follow-up questions\n\n- `Show me all failed logins for the last 3 days`\n - `Generate a rule to help detect that behavior in the future`\n- `Show me events associated with the principle user izumi.n`\n - `Who is this user?`\n- `Search for all of the events associated with the IP 198.51.100.121 in the\n last 3 hours`\n - `List all of the domains in the results set`\n - `What types of events were returned?`\n- `Show me events from my firewall in the last 24 hours`\n - `What were the 16 unique hostnames in the results set?`\n - `What were the 9 unique IPs associated with the results set?`\n\nGenerate a search query using natural language\n----------------------------------------------\n\nUsing the Google SecOps search feature, you can enter a natural\nlanguage query about your data, and Gemini can translate this into a\nsearch query to run against UDM events.\n\nFor better results, we recommend using the [Gemini pane to generate\nsearch queries](#udm-query-gemini).\n\nTo use a natural language search to create a search query, complete the\nfollowing steps:\n\n1. Sign in to Google SecOps.\n2. Go to **Investigation \\\u003e SIEM Search**.\n3. Enter a search statement in the natural language query bar and click\n **Generate Query**. You must use English for the search.\n\n **Figure 2.** Enter a natural language search and click **Generate Query**.\n\n The following statements are examples that might generate a useful search: \n \u003cbr /\u003e\n\n - *network connections from 10.5.4.3 to google.com*\n - *failed user logins over the last 3 days*\n - *emails with file attachments sent to john@example.com or jane@example.com*\n - *all Cloud service accounts created yesterday*\n - *outbound network traffic from 10.16.16.16 or 10.17.17.17*\n - *all network connections to facebook.com or tiktok.com*\n - *service accounts created in Google Cloud yesterday*\n - *Windows executables modified between 8 AM and 1 PM on May 1, 2023*\n - *all activity from winword.exe on lab-pc*\n - *scheduled tasks created or modified on exchange01 during the last week*\n - *email messages that contain PDF attachments*\n - *emails sent by or sent from admin@acme.com on September 1*\n - *any files with the hash 44d88612fea8a8f36de82e1278abb02f*\n - *all activity associated with user \"sam@acme.com\"*\n4. If the search statement includes a time-based term, the time picker is automatically adjusted to match. For example, this would apply to the following searches: \n- *yesterday*\n- *within the last 5 days*\n- *on Jan 1, 2023*\n5. If the search statement can't be interpreted, you see the following message: \n \"Sorry, no valid query could be generated. Try asking a different way.\"\n6. Review the generated search query. The syntax is [YARA-L\n 2.0](/chronicle/docs/detection/yara-l-2-0-syntax).\n\n7. Optional: Adjust the search time range.\n\n8. Click **Run Search**.\n\n9. Review the search results to determine if the event is present. If needed,\n use search filters to narrow the list of results.\n\n10. Provide feedback about the query using the **Generated Query** feedback\n icons. Select one of the following:\n\n - If the query returns the expected results, click thumb_up **Thumbs Up**.\n - If the query does not return the expected results, click thumb_down **Thumbs Down**.\n - Optional: Include additional detail in the **Feedback** field.\n11. To submit a revised search query that helps improve results:\n\n 1. Edit the search query that was generated.\n 2. Click **Submit** .\n - If you didn't rewrite the query, you're prompted to edit the query.\n - If you did rewrite the query, the revised search query is sanitized for sensitive data and used to improve results.\n\n### Delete a chat session\n\nYou can delete your chat conversation session or delete all chat sessions.\nGemini maintains all user conversation histories privately and adheres\nto Google Cloud's [responsible AI\npractices](/duet-ai/docs/discover/responsible-ai). User history is never used to train models.\n\n1. In the Gemini pane, select **Delete chat** from the menu at the top right.\n2. Click **Delete chat** at the bottom right to delete the current chat session.\n3. Optional: To delete all chat sessions, select **Delete all chat sessions** and then click **Delete all chats**.\n\n### Provide feedback\n\nYou can provide feedback to responses generated by the Gemini AI\ninvestigation assistance. Your feedback helps Google improve the feature and the\noutput generated by Gemini.\n\n1. In the Gemini pane, click thumb_up **Thumb Up** or thumb_down **Thumb Down**.\n2. Optional: Click thumb_down **Thumb Down** and provide feedback.\n3. Click **Send feedback**.\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]