Skip to main content
Solved

Retrieving alerts from chronicle SIEM

  • September 5, 2024
  • 2 replies
  • 57 views

Forum|alt.badge.img+6

I would like to retrieve generated alerts in google secops SIEM on daily basis. For that I identified the following API endpoint to get the required data: listAlerts_deprecated

It seems that this endpoint will be soon deprecated. Is there an alternative endpoint that provides information about generated alerts ?

Best answer by bsalvatore

Hi,

I think you can use the Chronicle v1alpha API: Method: legacy.legacySearchAlerts  |  Google Security Operations  |  Google Cloud

2 replies

bsalvatore
Forum|alt.badge.img+6
  • Bronze 1
  • Answer
  • September 5, 2024

David-French
Staff
Forum|alt.badge.img+9

I'd also recommend checking out the legacySearchRulesAlerts API method if you're interested in searching for alerts generated by rules in SecOps' detection engine.