Skip to main content

Hi everyone,

can someone please help me write rule for below scenario?

if any logsource which is placed in on prem  is not streaming to chronicle SIEM in last 24 hours, it should trigger an alert.

I read somewhere to use cloud monitoring for that but how does that work, as in if my device is on prem or on azure and i have used forwarder  how will cloud monitoring identify the not reporting part. Can someone help me with this? 

 

Hi @rahul7514,


Are you using the Google SecOps forwarder? Have you seen this documentation that explains how to create a Google Cloud Monitoring policy to detect silent Google SecOps forwarders? https://cloud.google.com/chronicle/docs/ingestion/ingestion-notifications-for-health-metrics#forwardermetricandfilters


You may also find the following blog posts helpful when thinking about monitoring your logging/data pipeline for issues:


https://www.googlecloudcommunity.com/gc/Community-Blog/Practical-Techniques-for-Monitoring-Your-Security-Data-Pipeline/ba-p/809060


https://medium.com/@thatsiemguy/chronicle-forwarder-telemetry-via-google-cloud-monitoring-39ccb32b3853


 


Reply