Replies: 2 comments
-
We are working on an integration with Google Chronicle but we don't have any additional details to share at this time. |
Beta Was this translation helpful? Give feedback.
0 replies
-
For those who are interested on how to send Suricata events to Google Chronicle, please go through the following workaround. Pre requisites
Security Onion Configuration
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello there,
Anyone has some guidence on how can I forward the Suricata and Zeek logs to Google Chronicle?
I tried this https://docs.securityonion.net/en/latest/logstash.html#original-event-forwarding and this https://docs.securityonion.net/en/latest/logstash.html#modified-event-forwarding but I have not been lucky.
Specifically I need to send the raw logs such http.log, dns.log, connection.log and others.
Also, I would like to ingest the alerts generated in Security Onion and see the message of Suricata into Chronicle.
Thank you in advance.
Beta Was this translation helpful? Give feedback.
All reactions