Skip to main content
Solved

Microsoft Managed AD, VPC and Firewall logs not showing in SecOps

  • March 14, 2025
  • 1 reply
  • 7 views

Casim
Forum|alt.badge.img

I have a separate project for network and all managed AD logs, VPC logs and firewall logs getting stored in default/ required buckets of the project. I dont think with direct ingestion these logs are getting ingested into SecOps. Can someone please guide how i can get those logs ingested to SecOps?

Best answer by cmorris

Direct ingestion will cover a subset of logs - https://cloud.google.com/chronicle/docs/ingestion/cloud/ingest-gcp-logs#option_1_direct_ingestion. For log types out of scope for direct ingestion, you can configure GCS feeds, if you already have the logs there - https://cloud.google.com/chronicle/docs/reference/feed-management-api#gc-storage

1 reply

cmorris
Staff
Forum|alt.badge.img+10
  • Staff
  • Answer
  • March 15, 2025

Direct ingestion will cover a subset of logs - https://cloud.google.com/chronicle/docs/ingestion/cloud/ingest-gcp-logs#option_1_direct_ingestion. For log types out of scope for direct ingestion, you can configure GCS feeds, if you already have the logs there - https://cloud.google.com/chronicle/docs/reference/feed-management-api#gc-storage