Understand BigQuery data schema
The BigQuery data schema defines how Google Security Operations exports normalized and contextualized security data into BigQuery. Each linked dataset corresponds to a different data type, such as UDM events, rule detections, IoC matches, entity relationships, and ingestion metrics. These datasets provide a structural view of your exported data, letting you query, join, and analyze security information.
The following topics describe the available schemas, their field definitions, and how they map to data exported by Google SecOps:
- Ingestion metrics schema
- UDM events schema
- Google SecOps events schema
- View alerts and IoCs
- Enrich event and entity data with Google SecOps
- Ingestion metrics reference for Looker and BigQuery
Need more help? Get answers from Community members and Google SecOps professionals.