Skip to main content

Looking for some insight on the log source monitoring in Chronicle SIEM?

  • August 27, 2023
  • 11 replies
  • 42 views

Forum|alt.badge.img

Hopefully this is the right place - looking for some insight on what you all are doing for log source monitoring in Chronicle SIEM?

11 replies

Forum|alt.badge.img+3
  • New Member
  • August 27, 2023

We use silent log alerting from Chronicle. You will get an email if a log type stops sending data to Chronicle.


JaredBloomberg
Forum|alt.badge.img+4

How do you enable log alerting within Chronicle?


Forum|alt.badge.img+3
  • New Member
  • August 27, 2023

Chronicle support has to do it


JaredBloomberg
Forum|alt.badge.img+4

Thanks!


Forum|alt.badge.img+3
  • New Member
  • August 27, 2023

I was trying to find the details about it and came across the new way to do it.
https://cloud.google.com/chronicle/docs/ingestion/ingestion-notifications-for-health-metrics


Forum|alt.badge.img+3
  • New Member
  • August 27, 2023

For the current way, IIRC, the data type has to be silent for several hours before you’re notified.


cmmartin_google
Staff
Forum|alt.badge.img+11

cmmartin_google
Staff
Forum|alt.badge.img+11

if you have integrated your Chronicle SIEM instance with GCP you can use GCP Metrics for Forwarder, and Feed Management notifications, e.g., silent log source, or else abnormal deviation from baseline


cmmartin_google
Staff
Forum|alt.badge.img+11

Forum|alt.badge.img+1
  • New Member
  • September 11, 2023

I also have some questions about this: log type is nice for single sources on a log source type, but what with sysmon for example? Losing sight of one host may warrant an alert (domain controllers), but will never trigger on logtype alone. Any way to do that?


maxjunker
Forum|alt.badge.img+4
  • Bronze 4
  • February 19, 2024

Is there any other way to detect log source / log source type outages without BigQuery?
We don´t have GCP integration within our Chronicle tentans, but we need to detect if a log source stops sending events. 
I get that because of sliding windows a detection rule with YARAL is not sufficient (https://medium.com/@thatsiemguy/silent-asset-detection-47ad34fdab55)