Skip to main content
Solved

Chronicle Audit Logs

  • December 27, 2024
  • 3 replies
  • 98 views

Forum|alt.badge.img+8

Hello , 
I want to know if there is any possibility to view internal audit logs of chronicle ( login , modifications on parsers , rules modifications etc ... ) 
Thank you in advance

Best answer by mikewilusz

SecOps/Chronicle stores its audit logs in Cloud Logging. Details available here: https://cloud.google.com/chronicle/docs/administration/audit-logging

-mike

3 replies

mikewilusz
Staff
Forum|alt.badge.img+10
  • Staff
  • Answer
  • December 27, 2024

SecOps/Chronicle stores its audit logs in Cloud Logging. Details available here: https://cloud.google.com/chronicle/docs/administration/audit-logging

-mike


Forum|alt.badge.img+8
  • Author
  • Silver 2
  • December 31, 2024

SecOps/Chronicle stores its audit logs in Cloud Logging. Details available here: https://cloud.google.com/chronicle/docs/administration/audit-logging

-mike


Thanks for your reply 
How i can forward them to chronicle ? i want to make rules based on audit logs
Thanks


cmmartin_google
Staff
Forum|alt.badge.img+11

Thanks for your reply 
How i can forward them to chronicle ? i want to make rules based on audit logs
Thanks


If you use the native GCP log collection you'll get Chronicle API Admin audit logs automatically, e.g., rule creation, deletion. 

To collect data access logs, e.g., users running a Search for X, you'll need an additional filter:

OR (log_id("cloudaudit.googleapis.com/data_access") AND protoPayload.serviceName = "chronicle.googleapis.com")

 We have an example Blog series on this topic available here:

https://www.googlecloudcommunity.com/gc/Community-Blog/Monitoring-for-Unexpected-Rule-Changes-in-Google-Security/ba-p/810901