Hi Team, I have a question regarding one of the requirements we are working on.
We have integrated Chronicle with our GCP (Via web hook) to get the cloud armor logs. We leveraged pub-sub with Cloud Armor to push the logs to Chronicle.
Once integration is successful, we started getting messages in Chronicle but the data was encoded with base63 encoding. Does it has to be this way for data transmission?
Second questions is how to we decode it on chronicle (any parser) so that we can read it and trigger some alerts/further actions ?
Any help would be greatly appreciated. Thanks in advance!
View files in slack
We have integrated Chronicle with our GCP got data in base63, how we decode it .
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
