The Unified Data Model provides a means to organize the data in logs into common fields so that data can but compared, enriched, and filtered more reliably. What are the two primary data models contained within UDM?
- Event, Case
- Event, IOC
- Event, Entity
- Entity, Alert