Apps
Google SecOps
Interpres Application - Google SecOps
- Type: SIEM/Data Lake
- Vendor: Google
This app integrates with Google SecOps to get Detections, Alerts and Telemetry.
- A Google SecOps Enterprise Plus Tier subscription is required
- Add Roles to Service Account
- roles/chronicle.viewer (or add permissions to list alerts and rules)
- roles/bigquery.jobUser
- roles/bigquery.dataViewer
- Credentials: The entire contents of the Google Cloud OAuth2 credential.json file
Check there is connectivity (green light) in the integration created.
- Get Detections: Gets latest version of rules.
- Get Alerts: Gets the latest asset-based and user-based alerts.
- Get Available Telemetry: Queries BigQuery ingestion_metrics and returns a list of telemetry identifiers with their current status.