Google Chronicle UDM Parsing
Budget: $2 – $8 USD
I need to turn a variety of security logs into properly structured Google Chronicle UDM events so they flow cleanly through SecOps investigations and detection rules. The raw feeds are already landing in Cloud Storage; what I’m missing is the parser logic and mapping that converts each record into UDM with correct field attribution, normalised timestamps and enrichment ready for detection engineering.
You’ll work directly in my Chronicle tenant (access will be provided) to build, test and deploy the parsers, then validate that sample log batches are ingested without errors and appear in the Chronicle Browser exactly as expected. I’ll provide representative log files for each source and clarification on any custom fields; you bring the YARA-L parsing expertise and a solid grasp of Google’s Unified Data Model conventions.
Deliverables:
• Production-ready parser rules (YARA-L) for the supplied security log samples
• A brief README explaining field mappings, assumptions and any enrichment logic
• Proof of successful ingestion: screenshot or short clip showing parsed events visible in Chronicle with expected field population
Acceptance criteria: no parsing errors, core UDM fields populated, and at least 95 % of tested records mapped exactly to the schema.
If you’ve previously built UDM parsers or have hands-on Chronicle deployment experience, let’s talk and get this moving quickly.
You’ll work directly in my Chronicle tenant (access will be provided) to build, test and deploy the parsers, then validate that sample log batches are ingested without errors and appear in the Chronicle Browser exactly as expected. I’ll provide representative log files for each source and clarification on any custom fields; you bring the YARA-L parsing expertise and a solid grasp of Google’s Unified Data Model conventions.
Deliverables:
• Production-ready parser rules (YARA-L) for the supplied security log samples
• A brief README explaining field mappings, assumptions and any enrichment logic
• Proof of successful ingestion: screenshot or short clip showing parsed events visible in Chronicle with expected field population
Acceptance criteria: no parsing errors, core UDM fields populated, and at least 95 % of tested records mapped exactly to the schema.
If you’ve previously built UDM parsers or have hands-on Chronicle deployment experience, let’s talk and get this moving quickly.