Google Security Operations memberi Anda kemampuan untuk menelusuri data perusahaan yang disimpan di akun Anda hingga satu tahun. Alat ini juga mencakup sejumlah alat yang memungkinkan Anda menjalankan beberapa kueri penelusuran UDM, lalu mengambil dan membagikan hasil kueri tersebut.
Menggunakan UDM untuk menelusuri data hingga satu tahun
Anda dapat melakukan penelusuran UDM pada data UDM Anda hingga satu tahun. Untuk menyesuaikan jangka waktu penelusuran UDM, selesaikan langkah-langkah berikut:
Buka Investigasi > Penelusuran SIEM.
Klik kolom pemilih waktu untuk membuka dialog pemilih waktu.
Dari tab Rentang (tab default), sesuaikan rentang waktu dengan memilih salah satu opsi dari 5 menit terakhir hingga Tahun lalu.
Gunakan kolom Mulai dan Akhir untuk memilih rentang tanggal yang lebih spesifik (misalnya, dua minggu pertama bulan November).
Sesuaikan waktu dengan memilih nilai mulai dan akhir tertentu, misalnya,
03.00 dan 08.30.
Klik Terapkan, lalu klik Jalankan Penelusuran.
Menjalankan penelusuran bersamaan dan mengelola kueri penelusuran
Penelusuran serentak dan hasil yang disimpan memerlukan fitur histori penelusuran agar aktif. Untuk memastikan histori penelusuran aktif, selesaikan langkah-langkah berikut:
Buka Investigasi > Penelusuran SIEM.
Klik Histori. Jika pesan Histori Penelusuran Dinonaktifkan ditampilkan, lanjutkan ke langkah berikutnya. Jika Anda tidak melihat pesan ini, berarti
Histori Penelusuran sudah diaktifkan untuk akun Anda.
Klik
more_vert
, lalu pilih Aktifkan histori penelusuran.
Mengelola kueri penelusuran
Anda dapat menjalankan beberapa penelusuran UDM, mengambil hasil penelusuran kueri sebelumnya, dan membagikan hasil kueri Anda kepada anggota tim lainnya:
Menjalankan beberapa penelusuran UDM: Saat kueri penelusuran sedang berlangsung, Anda dapat menjalankan penelusuran tambahan di editor kueri. Google SecOps terus menjalankan penelusuran Anda sebelumnya dan menjalankan penelusuran baru secara paralel.
Melihat hasil kueri: Scroll histori kueri dan pilih hasil penelusuran dalam waktu 24 jam setelah menjalankan kueri. Klik Histori, lalu pilih salah satu kueri Anda dari daftar.
Kueri yang sedang berlangsung ditampilkan dengan ikon status melingkar. Kueri yang selesai ditampilkan dengan ikon tanda centang hijau, beserta penghitung yang menunjukkan jumlah peristiwa yang ditampilkan oleh kueri. Klik kueri yang selesai
untuk menampilkan hasilnya. Hasil ini di-cache dan hanya menyertakan
data yang tersedia pada waktu kueri dijalankan. Namun, Anda dapat mengklik
dalam cache
Jalankan ulang untuk menjalankan kueri terhadap data terbaru. Run baru ini ditambahkan ke histori penelusuran dan hasilnya tersedia saat kueri selesai.
Bagikan hasil kueri: Salin URL hasil kueri untuk membagikannya kepada pengguna lain.
Saat hasil penelusuran disimpan, cakupan RBAC pengguna yang menjalankan penelusuran disimpan bersama hasil penelusuran tersebut. Saat hasil ini dilihat oleh pengguna lain, cakupan RBAC pelihat dibandingkan dengan cakupan yang disimpan. Jika cakupan penonton
lebih ketat, error akan ditampilkan dan mereka tidak akan dapat
melihat hasilnya.
Hasil penelusuran yang disimpan akan berakhir 24 jam setelah kueri dijalankan. Namun, kueri penelusuran Anda masih tersedia di panel Histori. Anda dapat menjalankan ulang penelusuran dan hasilnya akan tersedia hingga 24 jam setelah waktu eksekusi kueri.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-21 UTC."],[[["\u003cp\u003eGoogle Security Operations allows searching up to one year of enterprise data using UDM.\u003c/p\u003e\n"],["\u003cp\u003eUsers can adjust the time range for UDM searches, from "Last 5 minutes" up to "Last year," and select a specific date and time range.\u003c/p\u003e\n"],["\u003cp\u003eThe platform supports running multiple UDM searches concurrently, with each query being processed in parallel.\u003c/p\u003e\n"],["\u003cp\u003eQuery results are stored and can be retrieved from the history within 24 hours of running them, with the option to rerun queries against the latest data.\u003c/p\u003e\n"],["\u003cp\u003eUsers can share query results by copying the URL, though access is subject to RBAC scope restrictions, ensuring data security.\u003c/p\u003e\n"]]],[],null,["# Use UDM Search time range and manage queries\n============================================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n| **Note:** This feature is covered by [Pre-GA Offerings Terms](https://chronicle.security/legal/service-terms/) of the Google Security Operations Service Specific Terms. Pre-GA features might have limited support, and changes to pre-GA features might not be compatible with other pre-GA versions. For more information, see the [Google SecOps Technical Support Service guidelines](https://chronicle.security/legal/technical-support-services-guidelines/) and the [Google SecOps Service Specific Terms](https://chronicle.security/legal/service-terms/).\n\n\u003cbr /\u003e\n\n| **Note:** This feature is not available to all customers in all regions.\n\n\u003cbr /\u003e\n\nGoogle Security Operations gives you the ability to search through up to a year of the\nenterprise data stored in your account. It also includes a number of tools that\nlet you run multiple UDM search queries and later retrieve and share the results\nof those queries.\n\nUse UDM to search up to a year of data\n--------------------------------------\n\nYou can conduct a UDM search on up to one year of your UDM data. To adjust the\ntime period for your UDM search, complete the following steps:\n\n1. Go to **Investigation \\\u003e SIEM Search**.\n2. Click the time selector field to open the time selector dialog.\n3. From the **Range** tab (the default tab), adjust the time range by selecting any of the options from **Last 5 minutes** to **Last year**.\n4. Use the **Start** and **End** fields to choose a more specific date range (for example, the first two weeks in November).\n5. Adjust the times by selecting specific start and end values, for example, 03:00 and 08:30.\n6. Click **Apply** and then click **Run Search**.\n\nRun concurrent searches and manage search queries\n-------------------------------------------------\n\nConcurrent searches and stored results require the search history feature to be\nactive. To ensure that search history is on, complete the following steps:\n\n1. Go to **Investigation \\\u003e SIEM Search**.\n\n2. Click **History** . If the **Search History Is Disabled** message is\n displayed, proceed to the next step. If you don't see this message, then\n **Search History** is already enabled for your account.\n\n3. Click more_vert and select **Opt into search history**.\n\n### Manage search queries\n\nYou can run multiple UDM searches, retrieve previous query search results, and\nshare your query results with other members of your team:\n\n- **Run multiple UDM searches**: While a search query is in progress, you can\n run additional searches in the query editor. Google SecOps continues\n running your previous searches and runs the new searches in parallel.\n\n- **View query results** : Scroll through the query history and select search\n results within 24 hours of running a query. Click **History** and select one\n of your queries from the list.\n\n In-progress queries are displayed with a circular status icon. Completed\n queries are displayed with a green check mark icon, along with a counter\n indicating the number of events returned by the query. Click a completed\n query to display the results. These results are cached and only include the\n data available at query run time. However, you can click cached **Rerun** to run the query against the latest data. This new run is\n added to the search history and the results are made available when the\n query completes.\n- **Share query results**: Copy the URL of the query results to share them\n with other users.\n\n When search results are stored, the RBAC scopes of the user who ran the\n search are stored with them. When these results are viewed by another user,\n the viewer's RBAC scope is compared to the stored scopes. If the viewer's\n scopes are more restrictive, an error is displayed and they won't be able to\n view the results.\n\n Stored search results expire 24 hours after a query is run. However, your\n search query is still available in the **History** pane. You can rerun your\n searches and the results are made available for up to 24 hours after the\n query run time.\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]