Skip to main content
Solved

Log source stopped sending logs-Alert

  • February 14, 2025
  • 2 replies
  • 18 views

Forum|alt.badge.img+8

Hello, I want to perform an alerting notification in chronicle (not GCP), maybe a rule or dashboard visualisation about log source or a forwarder stopped sending logs, i want to do this on the siem directly without doing it on GCP 
For info i have GCP audit logs ingested in chronicle
Thanks

Best answer by AymanC

Hi @Rached1996,

The following will likely be of use, modify this to look for metadata.log_type, as opposed to principal.hostname- Re: How to Configure Log Stoppage Alert for Indivi... - Google Cloud Community

Kind Regards,

Ayman

2 replies

AymanC
Forum|alt.badge.img+13
  • Bronze 5
  • Answer
  • February 14, 2025

Hi @Rached1996,

The following will likely be of use, modify this to look for metadata.log_type, as opposed to principal.hostname- Re: How to Configure Log Stoppage Alert for Indivi... - Google Cloud Community

Kind Regards,

Ayman


Forum|alt.badge.img+8
  • Author
  • Silver 2
  • February 14, 2025

Thanks aymen