Skip to main content

Alert for not reporting

  • October 16, 2024
  • 1 reply
  • 16 views

rahul7514
Forum|alt.badge.img+10

Hi everyone,

can someone please help me write rule for below scenario?

if any logsource which is placed in on prem  is not streaming to chronicle SIEM in last 24 hours, it should trigger an alert.

I read somewhere to use cloud monitoring for that but how does that work, as in if my device is on prem or on azure and i have used forwarder  how will cloud monitoring identify the not reporting part. Can someone help me with this? 

 

1 reply

David-French
Staff
Forum|alt.badge.img+9

Hi @rahul7514,

Are you using the Google SecOps forwarder? Have you seen this documentation that explains how to create a Google Cloud Monitoring policy to detect silent Google SecOps forwarders? https://cloud.google.com/chronicle/docs/ingestion/ingestion-notifications-for-health-metrics#forwardermetricandfilters

You may also find the following blog posts helpful when thinking about monitoring your logging/data pipeline for issues:

https://www.googlecloudcommunity.com/gc/Community-Blog/Practical-Techniques-for-Monitoring-Your-Security-Data-Pipeline/ba-p/809060

https://medium.com/@thatsiemguy/chronicle-forwarder-telemetry-via-google-cloud-monitoring-39ccb32b3853