Hi @leezanelatto, do you see anything in a raw log search in SecOps (e.g. raw = “noname”), or is the feed totally silent? It’s a little difficult to find out much about how to enable things on the NoName side as they were acquired by Akamai, so their documentation is closed to me. Maybe you would have more luck: https://techdocs.akamai.com/api-security/docs/welcome-to-api-security
For reference, in case you didn’t find it already, we published exactly what our parser is looking for here, but of course that depends on the feed sending any data at all: https://cloud.google.com/chronicle/docs/ingestion/parser-list/noname-api-security-changelog
If none of the above gets you any further forward, a support ticket filed on our side would allow you to conclusively prove whether the feed is totally silent or not, and if it is, I think involving Akamai/NoName support would be essential, to figure out how to turn the feed on at the other end.
Hi @leezanelatto , You could try using Postman to send an empty POST request with the webhook endpoint and custom headers (secret=… , key=...) or custom query parameters ; ( ?secret=...&key=….) , and verify that the return code in Postman is 200.
If you get any different HTTP code then you are not using the correct parameters ; (401 mostly means you are using wrong URL/parameters/headers, 403 authorization issue meaning the key is missing IAM permission to Chronicle API, ..etc)