Skip to main content
Solved

Multi Tenancy & Forwarder Labels

  • October 15, 2024
  • 2 replies
  • 20 views

Forum|alt.badge.img

Greetings--

Piggybacking on this post:
https://www.googlecloudcommunity.com/gc/SOAR-Forum/Using-Environments-for-Multi-Tenancy/m-p/687636#M1977

Are there any guides or syntax about how to link or associate
Forwarder Labels and Ingestion Labels and/or NameSpaces
to their respective Environments to support a multi-tenancy deployment?

e.g. I see in yaml:
env: dev

Any advice is helpful.
Thank you!!

Best answer by dlove40

If you're wanting to have a SOAR case created in a defined SOAR environment based on the ingestion label, you can define the environment details in the advanced section of the Google Chronicle SOAR connector. 

 

 

 

2 replies

cmmartin_google
Staff
Forum|alt.badge.img+11

I wrote up a series on apply Data RBAC in Chronicle SIEM and Chronicle in these two posts:

This provides examples of how to plan for using either Namespaces or Ingestion Labels and aligning the configuration across SIEM and SOAR components.

 


dlove40
Forum|alt.badge.img+4
  • Bronze 2
  • Answer
  • October 31, 2024

If you're wanting to have a SOAR case created in a defined SOAR environment based on the ingestion label, you can define the environment details in the advanced section of the Google Chronicle SOAR connector.