Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

N/A

Log Type

 Ingestion label

Preferred Logging Protocol - Format

Log Collection Method

Data Source

Security Command Center Threat

GCP_SECURITYCENTER_THREAT

API Prop Vendor API - JSONC2C

Direct Ingestion

https://cloud.google.com/chronicle/docs/ingestion/cloud/ingest-gcp-logs#exporting_findings_to

Device Configuration

Before you can ingest your Google Cloud data into your Chronicle instance, you must complete the following steps:

  • Contact your Chronicle representative Adaptive MxDR on-boarding engineer and obtain the one-time access code you need to ingest your GCP telemetry.

  • Grant the following IAM roles required for you to access the Chronicle section:

    • Chronicle Service Admin (roles/chroniclesm.admin): IAM role for performing all activities.

    • Chronicle Service Viewer (roles/chroniclesm.viewer): IAM role to only view the state of ingestion.

    • Security Center Admin Editor (roles/securitycenter.adminEditor): Required to enable the ingestion of Cloud Asset Metadata.

...

  1. Navigate to the Chronicle page for the Google Cloud console.
    Go to the Chronicle page

  2. Enter your one-time access code in the 1-time Chronicle access code.

  3. Select I consent to the terms and conditions of Chronicle's usage of my Google Cloud data.

  4. Click Connect Chronicle. Your Google Cloud data is now going to be sent to Chronicle.

...

...

Once Google cloud connected to Chronicle, you need to enable Google Cloud Logging, see below screenshot.

...

  1. click Save.

...

Your Google Cloud data is now going to be sent to Chronicle.

To Enable GCP logs

  1. Under Security Tab, navigate to Detections and Controls > Google SecOps

...

  1. Select the project which Security Command Center logs you want to monitor.

...

  1. Enable Security Command Center Premium Findings

Image Added

Integration Parameters

The integration feed details are not required as service is sending data directly to the chronicle. Please refer device configuration.