[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-04-02。"],[[["Raw log searches in Google Security Operations allow users to examine raw logs and their correlation with UDM events and entities, aiding in understanding log normalization and identifying gaps."],["Users can perform raw log searches by adding the prefix `raw =` to their search terms in the SIEM Search, or the UDM Search page, enclosed within quotation marks."],["To optimize performance, users can limit the scope of raw log searches by adjusting the time range, selecting specific log sources, or using regular expressions."],["The results of a raw log search display UDM events, entities, and the raw logs, which can be explored further to view related data or the complete log line and its source."],["The number of events and entities extracted from each log line is limited to a maximum of 10."]]],[]]