Google Security Operations 用户视图使客户能够更好地了解企业用户如何受到安全性事件的影响。通过关注个人用户的行为,安全管理员可以搜索表示账号泄露或其他安全问题的活动。确保从您网络(例如 EDR、防火墙、Web 代理、用户上下文和身份验证)的设备中提取和规范化数据。
搜索用户
如需在 Google SecOps 中打开用户视图,请在“搜索”字段中输入企业内用户的用户名或电子邮件地址。如果该用户存在于您的 Google SecOps 账号中,则该用户会作为结果显示。点击用户名以切换到用户视图。
“用户”视图别名
用户视图包含用户别名功能,可确保与单个用户关联的事件不会重复,并且可在 Google SecOps 账号中更轻松地搜索。例如,如果您有一个名叫 Dennis 的员工,其用户标识符为 dennis,电子邮件地址为 dennis@altostrat.com,而您在 Google SecOps 中搜索 dennis,则系统会返回 dennis 和 dennis@altostrat.com 的事件。
“用户”视图功能
用户视图包含许多功能和界面控件,可让您更仔细地检查企业中的用户数据。其中一些功能是用户视图所独有的,还有一些则与其他 Google SecOps 事件视图(“网域”视图、“IP 地址”视图等)共用。
Google SecOps 用户视图功能
1 用户信息
显示在企业 IT 系统(例如 Active Directory、Workday、Okta 等)中存储的用户信息。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-02。"],[[["\u003cp\u003eGoogle Security Operations User view helps security administrators understand how users are impacted by security events, enabling them to detect potential account compromises or other security concerns.\u003c/p\u003e\n"],["\u003cp\u003eSearching for a user in Google Security Operations is done by entering their username or email, and the User view displays information and events related to that user.\u003c/p\u003e\n"],["\u003cp\u003eUser aliasing ensures that events from different identifiers associated with the same user (like username and email) are aggregated, preventing duplication and simplifying searches.\u003c/p\u003e\n"],["\u003cp\u003eThe Gradient Heat Map in User view provides a visual representation of user activity over time, helping identify unusual patterns or atypical behavior, such as late-night or weekend activity.\u003c/p\u003e\n"],["\u003cp\u003eUser view allows filtering of user information based on various characteristics, like Principal Location, which can help identify unusual login locations or other potential security anomalies.\u003c/p\u003e\n"]]],[],null,["# Investigate a user\n==================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nGoogle Security Operations **User** view enables customers to better understand how users\nwithin an enterprise are impacted by security events. By focusing on the\nbehavior of individual users, security administrators can search for activity\nindicating an account compromise or other security concerns. Make sure you are\ningesting and normalizing data from devices on your network, such as EDR,\nfirewall, web proxy, user context, and authentication, etc.\n\nSearch for a user\n-----------------\n\nTo open **User** view in Google SecOps, enter the username or email address of\na user within your enterprise in the Search field. If the user is present within\nyour Google SecOps account, that user is displayed as a result. Click the\nusername to pivot to **User** view.\n| **Note:** [UDM search](/chronicle/docs/investigation/udm-search) provides enhanced capabilities that let you conduct more thorough investigations of the events and alerts within your Google SecOps instance than is possible using **User** view alone. For more information, see [UDM search](/chronicle/docs/investigation/udm-search).\n\nUser view aliasing\n------------------\n\n**User** view includes a user aliasing feature to ensure events associated with a\nsingle user are not duplicated and are easier to search within your\nGoogle SecOps account. For example, if you have an employee named Dennis\nwhose user identifier is `dennis` and whose email is `dennis@altostrat.com` and\nyou search for `dennis` in Google SecOps, events for both `dennis` and\n`dennis@altostrat.com` are returned.\n\nUser view features\n------------------\n\n**User** view includes many features and user interface controls to enable you to\nmore closely examine the user data within your enterprise. Some of these\nfeatures are unique to **User** view and some are shared with the other\nGoogle SecOps event views (Domain View, IP Address View, etc.).\n\n\n**Google SecOps User view features**\n\n#### 1 User information\n\nDisplays information about the user stored within your enterprise IT systems\n(for example, Active Directory, Workday, Okta, etc.).\n\n#### 2 Date selection\n\nUse the left and right arrows to examine the events associated with the user\nover a one calendar week interval (Saturday through Sunday). If no data is\navailable in the displayed time period, you are given First Seen and\nLast Seen options to shift the view quickly to a relevant time period.\n\n#### 3 X-axis time shift\n\nBy default, **User** view centers the Gradient Heat Map at 12:00 UTC (noon). Using\nthe X-Axis Time Shift control, you can center the Heat Map up to 12 hours before\nor after 12:00. This lets you focus on atypical time periods for the user.\nFor example, you could time shift the display to 0:00 UTC (midnight) to focus on\nuser activity in the late evening and early morning hours as shown in these\nfigures.\n\n\n**Setting X-Axis time shift to +12**\n\n#### 4 Gradient heat map\n\n**User** view Gradient Heat Map displays an aggregate view of user activity across\nthe time period you are investigating. Each square indicates an hour of the day\n(UTC) for a logged user activity across the time period. This chart lets you\nto locate unusual or atypical user activity.\n\nClicking on a square shows the activity date and clicking on that date from the\ngreen popover takes you to that hour of events in the Timeline.\n\nThe color of each square varies from black through shades of gray to white:\n\n- Black squares indicate no user activity.\n\n- White squares indicate frequent user activity.\n\n- Dark gray to light gray squares indicate increasing levels of activity with\n dark shades of gray representing less activity and light shades of gray\n representing more.\n\nFor example, a user is routinely active during normal work hours and never\nactive late at night or on weekends. However, this user has recently become\nactive every day at 3AM. The Gradient Heat Map lets you to quickly locate\nthis type of atypical activity.\n\n#### 5 User alerts\n\nUser security alerts are captured by Google SecOps and displayed here. You\ncan click the associated links to further investigate the alert.\n\n#### 7 Columns\n\nCustomize the columns displayed in the **Timeline** tab.\n\n#### 6 Timeline and assets\n\nThe **Timeline and Assets** tabs are also available within **User** view. As with\nother Google SecOps views, the **Timeline** tab lists events\nchronologically and the **Assets** tab lists the assets associated with the user\nalphabetically or numerically. The assets displayed correspond to this specific\nuser's activity within your enterprise and is limited by the time period\nspecified.\n\nUse these tabs as follows:\n\n- **Timeline** tab: Selecting an event in the Timeline tab also highlights\n the corresponding event in the Gradient Heat Map in green. Alerts are\n indicated by a red triangle and red text.\n\n- **Asset** tab: Selecting an asset highlights it in green in the Asset tab\n and all activity involving that asset is also highlighted in green in the\n Gradient Heat Map. You can pivot to Asset view by clicking on the first\n accessed or last accessed in the Assets tab.\n\n#### 8 Procedural filtering\n\nYou can open the **Procedural Filtering** menu by clicking the Procedural\nFiltering icon in **User** view and filter the user information based on a variety\nof characteristics. For example, you could filter on Principal Location to\nexamine the geographic location of the user's login attempts. It might indicate\nthat a user is logging in from unusual locations.\n\n**Procedural filtering on principal location**\n\nConsiderations\n--------------\n\nUser view has the following limitations:\n\n- Only 80k events can be displayed in this view.\n- You can only filter events that are displayed in this view.\n- Only User, Email, and DNS event types are populated in this view. The first seen and last seen information populated in this view is also limited to these event types.\n- Generic events don't appear in any of the curated views. They appear only in raw log and UDM searches.\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]