Skip to main content

How to query SIEM Logs via SOAR action

  • December 11, 2024
  • 1 reply
  • 55 views

shubham8agar
Forum|alt.badge.img+5

I am trying to create a custom action in google secops SOAR in which I am fetching some data and it needs to be matched with corresponding logs in chronicle SIEM. 

How I cam achieve this ? Is there any corresponding module or API way or both ?

1 reply

mikewilusz
Staff
Forum|alt.badge.img+10
  • Staff
  • December 11, 2024

The Google Chronicle integration has a UDM Query action that will allow you to query the SIEM and display the results in the SOAR. Details available here: https://cloud.google.com/chronicle/docs/soar/marketplace-integrations/google-chronicle#execute_udm_query

-mike