Skip to main content

How to forward logs from the source to the forwarder and then from the forwarder to the SIEM?

  • September 19, 2023
  • 8 replies
  • 17 views

Forum|alt.badge.img+3

Hi All,
I'm currently in the process of integrating the forwarder with the SIEM system.
I've successfully installed the forwarder on my Ubuntu machine, and I also have administrative access to the SIEM platform. Could someone please provide guidance on how to forward logs from the source to the forwarder and then from the forwarder to the SIEM? If there's any documentation or a guide available, I would greatly appreciate it. Thank you in advance.

View files in slack

8 replies

Forum|alt.badge.img+3
  • New Member
  • September 19, 2023

You will need to use the Chronicle CLI to create a forwarder configuration.
https://cloud.google.com/chronicle/docs/administration/cli-user-guide


Forum|alt.badge.img+3
  • Author
  • New Member
  • September 19, 2023

@Daniel_Love thank you for sharing the doc. Is there any doc we can refer for doing this is GUI?


Forum|alt.badge.img+3
  • New Member
  • September 19, 2023

Forum|alt.badge.img+3
  • Author
  • New Member
  • September 19, 2023

Thank you. Yeah I found this and used to integrate few logs via Syslog.


Forum|alt.badge.img+3
  • Author
  • New Member
  • September 19, 2023

Trying to do more like a "log file"


Forum|alt.badge.img+3
  • New Member
  • September 19, 2023

I havent used the forwarder file setting for log ingestion yet. We use NXlog to monitor log files and have it send the logs to the Chronicle forwarder.
Their documentation explains how to use NXlog.
https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-windows-ad


Forum|alt.badge.img+3
  • Author
  • New Member
  • September 19, 2023

Thank you @Daniel_Love for the update


JaredBloomberg
Forum|alt.badge.img+4

It looks like you are trying to pull in Windows logs based on your screenshots, I would review the docs

https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-windows-events