Skip to main content

SOAR connectors not ingesting data.

  • May 3, 2024
  • 2 replies
  • 17 views

Forum|alt.badge.img+1

Can someone help with this?

We have removed the old connector as its been deprecated, but the new
connector isnt ingesting IOC detections into the SOAR instance.

Do we need to explicitly mention in Dynamic List while integrating the connector.

2 replies

gsec
Forum|alt.badge.img+4
  • Bronze 3
  • May 3, 2024

Hey,

I think you need this because the old function in the old Connector isn't avaible anymore. 

https://cloud.google.com/chronicle/docs/detection/ati-curated-detections?hl=en

Regards,


Dmitry_Sarakeev
Staff
Forum|alt.badge.img+9

hi, i think you are referring to Chronicle integration and IOC connector in particular - yes, IOC connector was deprecated, you should use Chronicle Alerts Connector with this integration, and as for IOCs - i also suggest checking on how to get IOCs through SIEM rules ( i dont have details on that)