Skip to main content

How to build an alert when chronicle siem ingestion?

  • April 16, 2023
  • 1 reply
  • 6 views

Forum|alt.badge.img+1

Hi all, we are trying to build an alert when chronicle siem ingestion would drop by 20% for a certain type of logs within an hour, does anyone have experience with something like this?

1 reply

Forum|alt.badge.img+12
  • Staff
  • April 16, 2023

Hi Pete, if you migrated to Bring Your Own Project preview then you can use GCP Cloud Monitoring, which can create percentage based deviation alerting - see the blog written by one of our team members - https://medium.com/@thatsiemguy/chronicle-forwarder-telemetry-via-google-cloud-monitoring-39ccb32b3853