Skip to main content

Silent forwarder rule

  • January 14, 2025
  • 3 replies
  • 4 views

Forum|alt.badge.img+8

Hello , 

it's possible to create a rule to detect silent forwarders in chronicle ? i don't want to create a policy in gcp monitoring .
Which UDM should i use ? can you help please ?
Thanks

3 replies

rajukg11
Staff
Forum|alt.badge.img+6
  • Staff
  • January 14, 2025

Assuming you are looking for silent forwarders, not silent devices, I can imagine how this can be accomplished.  You may send the metrics to Chronicle via pub/sub from GCP console (essentially you are feeding these forwarder metrics to Chronicle) and then write a parser for them.  We need to check if there is a log type we can use to ingest these.  Once there you can then write a rule to look for silent forwarder.


manoj610
Forum|alt.badge.img+4
  • New Member
  • January 15, 2025

Is it possible to achieve this in GCP by creating a policy that triggers an alert when a Forwarder is down?
If so, could you please guide me on how to set this up?

Thanks


Forum|alt.badge.img+8
  • Author
  • Silver 2
  • January 15, 2025

Is it possible to achieve this in GCP by creating a policy that triggers an alert when a Forwarder is down?
If so, could you please guide me on how to set this up?

Thanks


Hello 
https://cloud.google.com/chronicle/docs/ingestion/ingestion-notifications-for-health-metrics#forwardermetricandfilters