Hi Everyone,
I am just starting with Google SecOps/Chronicle and find creating custom/new parsers interesting. I was wondering if there is a course or clear documentation on how to get started with writing parsers and how to create an efficient one.
Hi Everyone,
I am just starting with Google SecOps/Chronicle and find creating custom/new parsers interesting. I was wondering if there is a course or clear documentation on how to get started with writing parsers and how to create an efficient one.
Best answer by dnehoda
Hi Silas.
Here’s some content related to syntax
https://cloud.google.com/chronicle/docs/reference/parser-syntax
There’s also a great piece here by Chris from our org.
https://medium.com/@thatsiemguy/understanding-chronicle-parsers-with-visualization-4ff79f674323
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.