Hi everyone,
I am currently setting up a test environment to collect logs from a Linux host using BindPlane, following the official quick start guide: Google SecOps with BindPlane Quick Start
My configurations on BindPlane appear to match the recommended setup, and the agent status looks consistent. However, I am stuck on the verification step:
-
Data Visibility: I cannot see the ingested data in Google SecOps (Chronicle).
-
Verification Process: To be precise, I’m not sure how or where to properly verify if the logs are actually reaching Google SecOps, or if they are getting stuck somewhere in the pipeline (e.g., BindPlane collector, Google SecOps ingestion API, or UDM mapping).
Are there recommended troubleshooting steps, CLI tools, or specific queries in Google SecOps to verify that data is flowing correctly? Any guidance on how to inspect and validate this setup would be greatly appreciated!
Thanks in advance!


