Skip to main content

Tired of SOAR integration bugs disrupting your flow? It's time to change the frequency! Join Sandy Borneman-Wenzel, Principal Architect Cloud Security, in this webinar to enhance your proficiency in troubleshooting SecOps SOAR Python integrations directly within the Integrated Development Environment (IDE). This session is designed to equip security engineers and developers with advanced techniques and best practices for effectively diagnosing and resolving integration issues, minimizing downtime and improving operational efficiency.

 

We will explore essential debugging methodologies, including:

  • Python Traceback Analysis: Learn to methodically dissect Python tracebacks to pinpoint the root causes of errors within integration scripts.
  • Strategic Debug Logging: Master the use of debugging and function calls to gain visibility into code execution flow and variable states.
  • Leveraging Large Language Models (LLMs): Discover how LLMs can assist in interpreting complex errors, generating potential code fixes, and accelerating the debugging process.
  • Support-Driven Best Practices: Benefit from field-tested strategies derived from the SecOps SOAR support team for safely modifying, testing, and deploying fixes for various integration components.

 

This webinar will provide practical guidance, best practices, and actionable insights to streamline your debugging workflow, enabling faster identification and resolution of errors in your SecOps SOAR integrations.

 

Watching this video for the first time? Didn't get your questions answered during the live stream event? Post your questions below and the Community will help get them answered!

 

Enjoy and happy learning!

 

 

@Mason_Masoff. Wanted to follow up with you on your question you added right as we were ending the webinar. 

 

“We have been using the GitSync plugin for a while, and I have noticed that there isnt any functionality for Parsers and Parser extensions that we have custom written. Do you see a future for this on the roadmap? Not sure if GitSync is something managed by Google”

 

The GitSync integration is designed to synchronize Google SecOps SOAR components with a Git repository. This includes assets such as:

  • Playbooks and playbook blocks
  • Integrations (both commercial and custom)
  • Connectors
  • Ontology settings like visual families and mappings
  • Custom lists

Custom parsers and parser extensions are considered SIEM components, and the GitSync tool was not built to manage them.

 

These resources might also help you find the answers you’re looking for. 

GitHub: https://github.com/google/secops-wrapper/tree/main/examples

Community Post: Managing content via Google SecOps' API

Product Docs: https://cloud.google.com/chronicle/docs/soar/marketplace/power-ups/gitsync