SIEM Forum - Google Cloud Community
Hello everyone, I would like to ask if it is possible to search for alerts and their details using the udm search.
Accidental Discovery in SIEM UDM Search
Hi folks, I just accidentally found that I can comment out a line in SIEM UDM search by pressing ctrl-/ and I can be any...
Integration Issue with SAP and SM20 Log
Dear Community Members, I have the following issue. A customer is using SAP and we want to include the SM20 log...
Firebase Push Notifications JSON File Creation
Hello, Google support team. I'm trying to create or download a JSON file for Firebase push notifications...
Solving Conundrum in CBN with JSON Object Parsing
Hey, wondering if anyone has any decent ideas to solve this conundrum in CBN given the below JSON object to p...
Official Fix for a Pending Issue
Dear all, This is not really a question, but rather a memento, waiting for an official fix to be rolled out...
Validation Issue with Sample Log
Why are we getting the output in the below format when we validate the sample log with parser using cbn-tool/c...
Enhancing SIEM Rule Descriptions
I want to add longer descriptions in the meta of some SIEM rules so the info shows up in the related SOAR case...
Palo Alto Integration with Chronicle
Hello Everyone, While integrating Palo Alto with Chronicle, I found a document from Palo Alto which states that...
Ingestion Filter Review Discovery
Hello everyone, While reviewing the ingestion filter for our organization, we discovered that we are unable to...
Monitoring Successful Windows Logons
I want to be able to find successful Windows logons, specifically remote logons, and capture data from fields...
Creating Dashboard for SIEM Alerts
I Want to create a dashboard for the alerts that are triggered in SIEM and need to know the case has been...
Mapping Entities in the Parser
Has anyone tried to map entities in the parser? (Ex. entity.user.user_id, entity.url, entity.hostname, etc......
Throttling Rule Triggers in a Period of Time
Hi #community, Is there any option to throttle or prevent a rule with the same criteria triggers for x period of...