Skip to main content
Question

Is there a way to create detection for SIEM parsing error?

  • November 4, 2025
  • 5 replies
  • 37 views

Forum|alt.badge.img+1

We see occasionally parsing errors for some log types in the Data Ingestion dashboard. However as dashboard is not regularly monitored and doesn’t show out custom parsers, I would like to check if there is is way to create some detection for the parsing error so that we can act immediately. 

5 replies

_K_O
Forum|alt.badge.img+12
  • Bronze 5
  • November 4, 2025

What type of errors are you seeing? Do you have logs for them, etc.? My guess is that it would be possible via a detection and / or a scheduled task since you can see it on a dashboard.


Forum|alt.badge.img+1
  • Author
  • New Member
  • November 5, 2025

So these are the ingestion errors I see in the default “Data Ingestion and Health” dashboard. However I don’t see related events in the chronicle audit logs. As it is default dashboard I’m unable to view the filter or logic of it. 


_K_O
Forum|alt.badge.img+12
  • Bronze 5
  • November 5, 2025

For the default dashboards, you can click on “View Details” which will show you the logic for the graphs / tables:

 

 

Is this what you’re looking for?

 


_K_O
Forum|alt.badge.img+12
  • Bronze 5
  • November 5, 2025

There was also this thread from earlier this year which may help: 

 


Forum|alt.badge.img+1
  • Author
  • New Member
  • November 5, 2025

Nice, thank you. I was looking at legacy dashboard. The new one does have the ability to view the query as you showed. However I’m unable to run that query in UDM or Yaral
What I’m looking for is to create a detection to alert on parsing error.
Looks like there api for list.errors is no longer there in https://cloud.google.com/chronicle/docs/administration/cli-user-guide