Skip to main content

We are having an application which is exposing it's findings in it's own API, we have been provided with their endpoint URL and API token.

I'm unable to see any integration options available in SIEM/SOAR where we can pull such data from the 3rd party API except those already defined like Microsoft Graph/Crowdstrike etc.,

What should be our approach here? 

 

Please see these sample programs to create your own cloud function that will pull logs from the source and ingest into Chronicle.


https://github.com/chronicle/ingestion-scripts/tree/main


 


Reply