Skip to main content

Cisco NDR with chronicle

  • October 28, 2024
  • 1 reply
  • 16 views

rahul7514
Forum|alt.badge.img+10

Hi

Can someone suggest how i can integrate cisco NDR with chronicle? 

 

1 reply

brodsky
Staff
Forum|alt.badge.img+2
  • Staff
  • October 28, 2024

Hi - if you are referring to Cisco Stealthwatch, there is a supported Google SecOps parser, recently updated. See: https://cloud.google.com/chronicle/docs/ingestion/parser-list/cisco-stealthwatch-changelog. Suggest you configure a regular Syslog feed into SecOps, use the CEF format, and ensure you are setting the ingestion label to CISCO_STEALTHWATCH and see how you do. If you're talking about the SOAR side of SecOps, there's also support for that: https://cloud.google.com/chronicle/docs/soar/marketplace-integrations/stealthwatch