Skip to main content


I will like to know, if this type of SIEM needs agents to be installed on the client host?

Hi @Eddy_Guzman - Chronicle SIEM typically uses a data forwarding service to ingest security logs from a client's host (non-Cloud storage). Here is a link to an Overview of data ingestion from our Chronicle SIEM documentation site: https://cloud.google.com/chronicle/docs/data-ingestion-flow?hl=en


Reply