Curated queries overview

Supported in:

Google SecOps offers curated dashboards—predefined dashboards designed for visibility across various security use cases. While you cannot edit or delete curated dashboards, you can create a copy and customize it to fit your needs. For more information on how to create dashboards, see Manage dashboards.

Out-of-the-box dashboards catalog

The out-of-the-box dashboards catalog lists predefined dashboards available in Google SecOps, organized by data source. Each catalog document details the individual charts within a dashboard, including chart descriptions and underlying search queries.

You can inspect the query syntax for each chart to identify the Unified Data Model (UDM) fields, event types, or metrics visualized by the dashboard. You can also use these queries in the query editor or as a baseline to create custom widgets and reports. To locate specific dashboards or charts, use the search and filter controls on each catalog page.

For operational guidance and use cases for common curated dashboards, see Common curated dashboards overview.

Explore the out-of-the-box dashboards by data source:

Dashboard category Description
Entities Analyzes assets and entities that communicate with indicators of compromise (IoCs).
IoC matches Provides visibility into the IoC matching events within the enterprise.
Ingestion metrics Monitors data flow, error counts, and log distributions.
Rules and detections Evaluates rule performance and highlights threat patterns from detections.
Security orchestration, automation, and response cases Provides metrics on security orchestration, automation, and response (SOAR) cases.
SOAR case history Reviews historical activity and performance across SOAR cases.
SOAR playbooks Displays automation metrics and playbook execution results.
Unified Data Model Visualizes UDM security telemetry.
UDM and datatable Visualizes UDM metrics and structured datatable telemetry.

Need more help? Get answers from Community members and Google SecOps professionals.