Skip to main content

Help with wise mapping and relevant documentation

  • June 13, 2023
  • 6 replies
  • 19 views

Forum|alt.badge.img+2

Hi
I'm trying to understand what are the default parsers actually doing mapping wise and looking for relevant documentation
So far I found this
https://cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers
which lists the supported products
but its not as detailed as this https://cloud.google.com/chronicle/docs/preview/default-parsers
which explains in detail whats going on in the mapping
Any idea where to find a full listing like in the second link for all the supported products?
Thanks

6 replies

Forum|alt.badge.img+6
  • Bronze 2
  • June 13, 2023

This is probably your best bet for the parsers that aren’t comprehensively documented. I haven’t played around with it myself though:
https://medium.com/@thatsiemguy/understanding-chronicle-parsers-with-visualization-4ff79f674323


Forum|alt.badge.img+2
  • Author
  • New Member
  • June 13, 2023

Much appreciated Ion


Forum|alt.badge.img+2
  • Author
  • New Member
  • June 13, 2023

@ion_ So when looking at the settings tab in your instance you see a tab for parsers right?


Forum|alt.badge.img+6
  • Bronze 2
  • June 13, 2023

I don’t, i’ve requested access but haven’t heard back Its a preview feature currently


Forum|alt.badge.img+3
  • Staff
  • June 13, 2023

I can enable your tenant for the Parser Management preview as long as it's not partner managed. Can you drop me an email with your tenant name? licata@google.com


Forum|alt.badge.img+6
  • Bronze 2
  • June 13, 2023

This has been enabled for our tenant, thank you