Apps
Chronicle

Interpres Application - Chronicle

  • Type: SIEM/Data Lake
  • Vendor: Google

This app integrates with Google Chronicle to get Detections and Alerts.

In order to get Google Chronicle Telemetry please create an integration with Google BigQuery.

Vendor setup

  1. Contact Google to generate a Service Account
  2. Add Roles to Service Account
    • roles/chronicle.viewer (or add permissions to list alerts and rules)

App Configuration

App Parameters:

App Validation

Check there is connectivity (green light) in the integration created.

Implemented Actions

  • Get Detections: Gets Chronicle latest version of rules.
  • Get Alerts: Gets the latest asset-based and user-based alerts.