Welcome to the Google Cloud Security Forums! Your ultimate security conversation spot. Collaborate with peers and experts to solve challenges, together.
Recently active
Hello, everyone! I’m configuring my CSV connection, and I’ve changed the title of my CSV file multiple times, but Ontology still giving me the initial version of my CSV file, as seen in the first image below, even though I’ve previously changed it.
Hi, Hello, I’m attempting to run a basic local case to test my playbook, but I’m having trouble setting up my local csv connector. Can someone assist me with this error? thanks a lot. [13:48:29,000 INFO] Csv Folder Path: /root/conantest.csv [13:48:29,000 INFO] CSV Limit: 10 [13:48:29,000 INFO] DeviceProductField: device_product [13:48:29,000 INFO] Time Field Name: timestamp [13:48:29,000 INFO] Time Field Timezone: UTC [13:48:29,000 INFO] Environment Field Name: conantest [13:48:29,000 INFO] Environment Regex Pattern: .* [13:48:29,000 INFO] Rule Generator Field Name: conantest [13:48:29,000 INFO] CSV Has Header: true [13:48:29,000 INFO] File Encoding Types: utf-8, latin-1, iso-8859-1 [13:48:29,000 INFO] Alert Field Name: conantest [13:48:29,000 INFO] Severity Field Name: 10 [13:48:29,000 ERROR] Unable to create folder: [Errno 13] Permission denied: '/root/conantest.csv' LOGGER: loadCon
Hello, Please I have a question on the entity selection, is there a way to display or use those entities selected in the playbook step individually?
Hello, please can someone direct me on how the query joiner works? These are the screenshot below of what i tried and error i was getting. Just trying to explore the action to see if it can accomplish my aim
Hey community, I am new to siemplify, I just installed Community OVA in VirtualBox, chose Bridged Adapter, en0: Wi-fi. But when ssh to the vm to ip addresses show, I don't see an IP address from enp0s3 interface, as explained in step 14 as below https://www.manula.com/manuals/siemplify/quick-start-guide/5.6.x/en/topic/deploy-community-ova-in-virtualbox My VirtualBox is running on a MacBook Pro host, using wifi. Any suggestions?
Ok last question (for now). What is UDM (Unified Data Model)?
Hi,When projects in GCP are in shut-down state, will Security Command Center remove all project-related vulnerabilities (vulnerabilities for all resources within the project)?As far as I see, non of them is removed, vulnerabilities still remain.Should we wait for 30-day period for the projects to be deleted, after which vulnerabilities will be automatically removed? Or will we have to mark them one-by-one with security marks?Thanks in advance for an answer.Best Regards,SBG
Is there any documentation on how to get started with Chronicle?
I have a new team member, how do I get them access to Chronicle?
One more question - how can I contact Chronicle Support?
Does anybody have an AbuseCH Malware Bazaar integration up and running yet? I am working on one and wondering if there would be interest from others to integrate into their environment.
I know the grouping based on the entities and the time frame. to be more precise which time will it consider for the grouping? Is the base event (start time/ end time) or the alert ingestion time into Siemplify like (Triage time) . Kindly confirm?
How or witch tool should I use to monitore por example seven endpoints at my local network
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.