Forwarding to Google Chronicle
Event Forwarding to Chronicle is authenticated with a Service Account. The legacy authentication method, involving an API Key, continues to be supported. However, we recommend that you use Service Accounts for authentication. See Service Accounts.
Prerequisites
Event forwards originate from region-specific IPs. For the full list of outbound IPs by region, see SaaS Regions and IP Ranges. Update your firewall and allow inbound requests from these IP addresses to enable Sysdig to handle event forwarding.
Google Chronicle v2 now uses JSON format, which Sysdig does currently support. Contact Google Chronicle customer support to request a v1 API key.
Configure Event Forwarding
To set up Event Forwarding to Chronicle with a Service Account:
Log in to Sysdig Secure as Admin.
Open Settings > Event Forwarding. Alternatively, Integrations > Event Forwarding.
From the top right corner, select Add Integration and Google Chronicle.
Specify the following:
Integration Name: A unique name to help you identify the Chronicle integration.
Customer ID: The Google Customer ID associated with your GCP account. In the Google Chronicle UI, find this in Settings > Profile > IDP USER ID.
Namespace: User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality.
JSON Credentials: Upload your Google Chronicle JSON credentials. See Getting API Authentication Credentials.
Region: Select your region, such as US, Europe, or Asia.
Data to Send: From the drop-down, select which data to forward, such as activity audit, Sysdig platform audit, and runtime policy events. The available list depends on the Sysdig features and products you have enabled.
Test the integration, then toggle Enabled to activate it.
Click Save to finish.
Configure Agent Local Forwarding
Review the configuration steps and use the following parameters for this integration.
Type | Attribute | Required? | Type | Allowed values | Default | Description |
---|---|---|---|---|---|---|
CHRONICLE | credentialsOAuth2 | yes | string | The Goolge Chronicle JSON credentials | ||
CHRONICLE | region | no | string | us, europe, asia-southeast1 | us | The target region |
CHRONICLE | chronicleCustomerId | yes | string | The Google Chronicle Customer ID | ||
CHRONICLE | namespace | yes | string | The namespace to identify the data domain |
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.