QUESTION

What's the difference between p_udm and event.udm in Panther?

ANSWER

Both of these refer to unified data models. They may not necessarily refer to one single model that unifies all data everywhere, because it's possible to define your own data models in Panther.

For more information about Core Fields and Data Models for detections, see our documentation here.