Skip to main content

Looking for an API to monitor EPS events ingested, parsed in UDM etc

  • June 13, 2023
  • 6 replies
  • 18 views

Forum|alt.badge.img+2

Hi i'm searching for an API to monitor EPS for number of events ingested, parsed in UDM etc,
Is there anything like this? not finding in documentation
Im seeing this in dashboards but that seems to use looker which doesnt seem to have documented APIs for chronicle
Thanks

6 replies

Forum|alt.badge.img+6
  • Bronze 2
  • June 13, 2023

Your best bet might be checking this out and then pulling from bigquery directly. What are you trying to achieve?

https://medium.com/@thatsiemguy/chronicle-ingestion-stats-metrics-4fa14386b9fc


Forum|alt.badge.img+2
  • Author
  • New Member
  • June 13, 2023

Thanks Ion
basically trying to view the ingestions metrics via API
to detect the ingestion, trends, failures etc


Forum|alt.badge.img+2
  • Author
  • New Member
  • June 13, 2023

So this means I have to register for a big query subscription right


Forum|alt.badge.img+6
  • Bronze 2
  • June 13, 2023

This is where someone from Chronicle needs to come in, you can get them to enable this for you.

We don’t automate interactions with BQ so i’m not sure what the options are, but you might be limited to using only read_access related interactions (?)


Forum|alt.badge.img+3
  • Staff
  • June 13, 2023

@David-B Cloud Monitoring integration can help with alerts and trends. It requires binding to a google cloud project. It’s currently in preview, but should GA within a month. https://cloud.google.com/chronicle/docs/preview/cloud-integration/ingestion-notifications-for-health-metrics

The other alternative is getting access to the Bigquery table that has that data.


Forum|alt.badge.img+2
  • Author
  • New Member
  • June 13, 2023

Thanks Adam
As recommended by @ion_ and yourself we are already looking into the relevant stats tables