Skip to main content

Is there any other solution to configure chronicle as a code instead of clickops?

  • March 23, 2023
  • 3 replies
  • 16 views

Forum|alt.badge.img+1

hi, maybe someone know if exist some tool / terraform provider / other solution which allow configure whole chronicle as a code instead of clickops?

3 replies

Forum|alt.badge.img+3
  • New Member
  • March 23, 2023

If you are talking about SIEM, We are experimenting with Detection as Code. We are using the https://cloud.google.com/chronicle/docs/reference/detection-engine-api in github action to go through end-to-end deployment of a rule lifecycle. We will work harder over the next quarter on this and hopefully open source with the detections.


Louis_Mesmin
Forum|alt.badge.img+5

Hello !
Maybe the GitSync integration for Chronicle SOAR ?


Forum|alt.badge.img+1
  • New Member
  • February 13, 2024

You may wish to check out this Terraform provider which has just been open sourced by Form3tech

https://github.com/form3tech-oss/terraform-provider-chronicle