Is there a documented procedure for ingesting enrichment data (Assets, Identities) in the SIEM when the source is not listed in Supported log types and default parsers? Let’s say I have sources such as a CMDB, a less common identity provider, or even an EDR with context data.
Is the answer to construct my own process via this?https://docs.cloud.google.com/chronicle/docs/reference/ingestion-methods#importentities


