Apps
Chronicle
Interpres Application - Chronicle
- Type: SIEM/Data Lake
- Vendor: Google
This app integrates with Google Chronicle to get Detections and Alerts.
In order to get Google Chronicle Telemetry please create an integration with Google BigQuery.
- Add Roles to Service Account
- roles/chronicle.viewer (or add permissions to list alerts and rules)
- Credentials: The entire contents of the Google Cloud OAuth2 credential.json file
Check there is connectivity (green light) in the integration created.
- Get Detections: Gets Chronicle latest version of rules.
- Get Alerts: Gets the latest asset-based and user-based alerts.