Google Chronicle Siem
Google Chronicle SIEM is a cloud-native security platform that provides scalable threat detection and response capabilities.
Google Chronicle SIEM is a cloud-native security information and event management (SIEM) platform that provides advanced threat detection and response capabilities. This connector allows Swimlane Turbine users to seamlessly integrate with Google Chronicle SIEM, enabling automated log entry creation, alert retrieval, and event forwarding. By leveraging this integration, users can enhance their security operations with real-time insights, streamline threat detection processes, and improve incident response times.
Limitations
None to date.
Supported Versions
This Google Chronicle SIEM Connector uses the latest version API.
Configuration
Prerequisites
Before you can use the Google Chronicle SIEM connector for Turbine, you'll need access to the Google Chronicle API. This requires the following:
- OAuth2.0 authentication using the following parameters:
- Service Account Info: JSON key file for service account authentication.
- URL: Endpoint URL for accessing Google Chronicle services.
- Scopes: Permissions required for accessing specific Google Chronicle resources.
Authentication Methods
OAuth 2.0 Client Credentials Authentication:
To effectively utilize the Google Chronicle SIEM connector within Swimlane Turbine, ensure you have the following prerequisites:
- OAuth2.0 authentication for Google Chronicle SIEM with these parameters:
- Service Account Info: A JSON file containing your service account credentials.
- URL: The endpoint URL for the Google Chronicle SIEM API.
GCP Project Creation:
- Log in to GCP Console here: https://console.cloud.google.com/
- Navigate to this link to create a new project: https://console.cloud.google.com/projectcreate
- Name your project and click Create. We recommend specific and recognizable project names.
- Navigate to your projects, and select your new project.
- Enable the Google Chronicle API:
- Go to the API & Services Dashboard in the Cloud Console.
- Click on the "Enable APIs and Services" button.
Asset Configuration:
Configuring a Service Account:
Google Chronicle SIEM connector requires a Google service account to authenticate.
- Select the appropriate project.
- Click + CREATE NEW SERVICE ACCOUNT.
- Assign a name for the service account and add a description, click CREATE AND CONTINUE
- Click the Select a Role dropdown and type βOwnerβ in the filter. Choose Owner , Chronicle API Admin and click Continue.
- For the menu specifying Grant users access to this service account (optional) you may select Users or Skip and click Done. This is not required for the connector.
- Click on the newly created service account email.
- Navigate to the KEYS menu.
- Click ADD KEY, select CREATE NEW KEY, select JSON format, and click CREATE. Make sure you download the .json file presented.
- Json needs to be passed in the asset input Service Account Info as a Base64 encoded string. This file will be needed when configuring the asset in Swimlane.
Setting API Scopes:
After creating a service account, the necessary API scopes required to be authorized must be set.
- From https://admin.google.com, navigate to Security > API Controls and then click Manage Domain Wide Delegation at the bottom of the window.
- Click Add new
- In the Client ID field, enter the Unique ID from the service account Details menu
- Enter the following CSV value into the OAuth Scopes (comma-delimited) input: https://www.googleapis.com/auth/chronicle-backstory
- Click Authorize
Capabilities
This Google Chronicle SIEM Connector provides the following capabilities:
- Create Entities
- Fetch Alerts
- Log Types
- UDM Events
- Unstructured Log Entries
- Update Alert
- Update Reference List
Create Entities
- Creates entities here
Fetch Alerts
- Legacy streaming endpoint for getting alerts (and in some cases, non-alerting detections) along with aggregated fields that match the query Here .
Log Types
- Retrieve a list of supported log types here
UDM Events
- Forwards UDM events to Google SecOps in batches here
Unstructured Log Entries
- Forwards unstructured log entries to Google SecOps one batch at a time here
Update Alert
- Legacy endpoint for updating an alert Here.
Update Reference List
- Updates an existing list here
Regional Endpoints
Chronicle provides regional endpoints for each API.
Region | Endpoint |
|---|---|
European Multi-Region | |
Tel Aviv | |
London | |
Singapore | |
Sydney | |
United States Multi-Region |
Additional Documentation
Configurations
Google Chronicle SIEM Authentication
OAuth2.0 authentication for Google Chronicle SIEM.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
b64_service_info | Base64-encoded credentials JSON authentication file contents. | string | Required |
url | Server API Address. | string | Required |
scopes | Scope to be used for authentication. | array | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Create Entries
Create new log entries in Google Chronicle SIEM using specified customer ID, log type, and entity details. Requires parent path parameter and JSON body with log_type and entities.
Endpoint
- URL: /v1/{{parent}}/entities:import
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.parent | string | Required | The name of the parent resource, which is the customer ID. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
log_type | string | Optional | Any log_type value returned by the logtypes endpoint. |
entities | array | Optional | Array of Entities. |
entities.metadata | object | Optional | Response data |
entities.metadata.collected_timestamp | string | Optional | Response data |
entities.metadata.entity_type | string | Optional | Response data |
entities.metadata.vendor_name | string | Optional | Response data |
entities.metadata.product_name | string | Optional | Response data |
entities.entity | object | Optional | Parameter for Create Entries |
entities.entity.user | object | Optional | Parameter for Create Entries |
entities.entity.user.userid | string | Optional | Unique identifier |
entities.entity.user.product_object_id | string | Optional | Unique identifier |
Input Example
{"json_body":{"customer_id":"c8c65bfa-5f2c-42d4-9189-64bb7b939f2c","log_type":"AZURE_AD_CONTEXT","entities":[{"metadata":{"collected_timestamp":"2021-11-14T15:30:18.142265Z","entity_type":"USER","vendor_name":"vendor","product_name":"product"},"entity":{"user":{"userid":"johndoe","product_object_id":"doejohn"}}},{"metadata":{"collected_timestamp":"2021-11-14T16:30:18.142265Z","entity_type":"USER","vendor_name":"vendor","product_name":"product"},"entity":{"user":{"userid":"janedoe","product_object_id":"doejane"}}}]},"path_parameters":{"parent":"customers/c8c65bfa-5f2c-42d4-9189-64bb7b939f2c"}}
Fetch Alerts
Retrieve alerts and detections from Google Chronicle SIEM using specific queries and a defined time range. Requires instance, baselineQuery, snapshotQuery, start_time, and end_time.
Endpoint
- URL: v1alpha/{{instance}}/legacy:legacyFetchAlertsView
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.baselineQuery | string | Required | The baseline query to search for. The baseline query is used for this request and its results are cached for subseqent requests, so that supplying additional filters in the snapshotQuery will not require re-running the baseline query. |
parameters.snapshotQuery | string | Required | The snapshot query to search for. This uses a syntax similar to UDM search, with support for all fields within 7 levels of nesting within the collection proto. For composite detections, the filters prefixed with "collectionElements.references.event" or "collectionElements.references.entity" are also checked against one-level of producer detections. |
parameters.timeRange.startTime | string | Optional | The start of the time range of alerts to search for. |
parameters.timeRange.endTime | string | Optional | The end of the time range of alerts to search for. |
parameters.alertListOptions.maxReturnedAlerts | number | Optional | The maximum number of alerts to return. |
parameters.alertListOptions.entityIndicator.indicatorNamespace | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.hostname | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.assetIpAddress | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.mac | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.productId | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.userName | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.email | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.employeeId | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.windowsSid | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.rawPid | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.processId | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.fullCommandLine | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.parentProcessId | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.hashMd5 | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.hashSha1 | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.hashSha256 | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.filePath | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.destinationIpAddress | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.domainName | string | Optional | Parameters for the Fetch Alerts action |
parameters.alertListOptions.entityIndicator.resourceName | string | Optional | Parameters for the Fetch Alerts action |
Input Example
{"parameters":{"baselineQuery":"severity='HIGH' OR severity='CRITICAL'","snapshotQuery":"severity='HIGH' OR severity='CRITICAL'","timeRange.startTime":"2023-10-01T00:00:00Z","timeRange.endTime":"2023-10-31T23:59:59Z","alertListOptions.maxReturnedAlerts":50,"alertListOptions.entityIndicator.indicatorNamespace":"MISP","alertListOptions.entityIndicator.hostname":"example-host","alertListOptions.entityIndicator.assetIpAddress":"192.168.1.1","alertListOptions.entityIndicator.mac":"00:1A:2B:3C:4D:5E","alertListOptions.entityIndicator.productId":"prod-12345","alertListOptions.entityIndicator.userName":"jdoe","alertListOptions.entityIndicator.email":"[email protected]","alertListOptions.entityIndicator.employeeId":"E123456","alertListOptions.entityIndicator.windowsSid":"S-1-5-21-3623811015-3361044348-30300820-1013","alertListOptions.entityIndicator.productObjectId":"prod-obj-001","alertListOptions.entityIndicator.rawPid":"4567","alertListOptions.entityIndicator.processId":"1234","alertListOptions.entityIndicator.fullCommandLine":"python script.py","alertListOptions.entityIndicator.parentProcessId":"4321","alertListOptions.entityIndicator.hashMd5":"098f6bcd4621d373cade4e832627b4f6","alertListOptions.entityIndicator.hashSha1":"a94a8fe5ccb19ba61c4c0873d391e987982fbbd3","alertListOptions.entityIndicator.hashSha256":"9e107d9d372bb6826bd81d3542a419d6","alertListOptions.entityIndicator.filePath":"/usr/bin/example","alertListOptions.entityIndicator.destinationIpAddress":"10.0.0.2","alertListOptions.entityIndicator.domainName":"example.com","alertListOptions.entityIndicator.resourceProjectObjectId":"res-proj-001","alertListOptions.entityIndicator.resourceName":"resource-1","fieldAggregationOptions.maxValuesPerField":5,"enableCache":"ALERTS_FEATURE_PREFERENCE_UNSPECIFIED","includeNonAlertingDetections":"ALERTS_FEATURE_PREFERENCE_UNSPECIFIED"},"path_parameters":{"instance":"testing 1"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Log Types
Retrieve a list of supported log types from Google Chronicle SIEM for integration and analysis. Requires instance path as a path parameter.
Endpoint
- URL: /v1/{{instance_path}}/logTypes
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.instance_path | string | Required | Required. The parent, which owns this collection of log types. Format: projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ |
parameters.pageSize | number | Optional | The maximum number of log types to return. The service may return fewer than this value. |
parameters.pageToken | string | Optional | A page token, received from a previous logTypes.list call. Provide this to retrieve the subsequent page. |
parameters.filter | string | Optional | Parameters for the Log Types action |
parameters.orderBy | string | Optional | Parameters for the Log Types action |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
Input Example
{"parameters":{"pageSize":100,"pageToken":"test page token","filter":"test filter","orderBy":"test order by"},"path_parameters":{"instance_path":"testing"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
logtypes | array | Type of the resource |
logtypes.log_type | string | Type of the resource |
logtypes.description | string | Type of the resource |
Output Example
{"status_code":200,"reason":"OK","json_body":{"logtypes":[{"log_type":"BIND_DNS","description":"BIND DNS Server"},{"log_type":"WINDOWS_DNS","description":"Windows DNS"},{"log_type":"WINDOWS_DHCP","description":"Windows DHCP"}]}}
UDM Events
Forward User-Defined Management events to Google Chronicle SIEM using specified instance paths and time range queries.
Endpoint
- URL: /v1/{{instance_path}}:udmSearch
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.instance_path | string | Required | Required. Chronicle instance this request is sent to. Format: projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ |
parameters.query | string | Required | The boolean query to search for. Example - 'ip=/172.*/ AND metadata.event_type!="NETWORK_CONNECTION" AND ( target.ip = "3.225.179.73" OR target.ip = "23.47.48.70")' |
parameters.time_range.start_time | string | Required | The start of the time range of events to search for. |
parameters.time_range.end_time | string | Required | The end of the time range of events to search for. |
parameters.limit | number | Optional | Maximum number of results to be returned for the query. Anything over 10000 will be coerced to 10000. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
Input Example
{"parameters":{"query":"metadata.event_type!='NETWORK_CONNECTION'"},"path_parameters":{"instance_path":"testing"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Unstructured Log Entries
Forward batches of unstructured log entries to Google Chronicle SIEM using customer_id, log_type, namespace, and entries.
Endpoint
- URL: /v1/{{parent}}/logs:import
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.parent | string | Required | The name of the parent resource, which is the customer ID. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
hint | string | Optional | Opaque hint to help parsing the log. |
inlineSource | object | Optional | Logs to be imported are specified inline. |
inlineSource.logs | array | Optional | The logs to be imported. |
inlineSource.forwarder | string | Optional | The forwarder sending the import request. This value determines the SecOps CollectorID. |
inlineSource.sourceFilename | string | Optional | Populated for certain types of files processed by the outofband processor which may have metadata encoded in it for use by the parser. |
Input Example
{"json_body":{"hint":"test hint","inlineSource":{"logs":[{}],"forwarder":"test forwarder","sourceFilename":"test source filename"}},"path_parameters":{"parent":"customers/c8c65bfa-5f2c-42d4-9189-64bb7b939f2c"}}
Update Alert
Update an existing alert in Google Chronicle SIEM with user-provided feedback using the specified instance and alert ID.
Endpoint
- URL: v1alpha/{{instance}}/legacy:legacyUpdateAlert
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.instance | string | Required | Chronicle instance this request is sent to. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
alertId | string | Optional | The unique identifier for the alert to be updated. |
feedback | object | Optional | Parameter for Update Alert |
feedback.verdict | string | Optional | A verdict on whether the finding reflects a security inc. |
feedback.reputation | string | Optional | A categorization of the finding as useful or not useful. |
feedback.confidenceScore | number | Optional | Confidence score (0-100) of the finding. |
feedback.riskScore | number | Optional | Risk score (0-100) of the finding. |
feedback.disregarded | boolean | Optional | Analyst disregard (or un-disregard) the event. |
feedback.severity | number | Optional | Severity score (1-100) of the finding. |
feedback.comment | string | Optional | Analyst comment. |
feedback.status | string | Optional | The status of the alert. |
feedback.priority | string | Optional | The priority of the alert. |
feedback.rootCause | string | Optional | The root cause of the alert. |
feedback.reason | string | Optional | The reason for the alert. |
feedback.severityDisplay | string | Optional | Severity display name for UI and filtering. |
feedback.triageAgentInvestigationId | string | Optional | Output only. Investigation Id of the latest investigation performed by the Triage Agent on the alert. The Triage Agent is designed to autonomously investigate alerts and determine whether an alert needs to be escalated to a human while providing transparency about the actions it took as part of its investigation. |
feedback.userType | string | Optional | Output only. Type of user that submitted or updated the feedback. This field is used to distinguish between the feedback submitted by a human analyst and an AI agent. By default, the user is assumed to be a human analyst. |
caseName | string | Optional | The case name that the alert is associated with. |
responsePlatformInfo | object | Optional | The response platform info of the alert. |
responsePlatformInfo.alertId | string | Optional | Id of the alert in SOAR product. |
responsePlatformInfo.responsePlatformType | string | Optional | Type of SOAR product. |
Input Example
{"json_body":{"alertId":"alert 1","feedback":{"verdict":"MALICIOUS","reputation":"HIGH","confidenceScore":85,"riskScore":70,"disregarded":false,"severity":4,"comment":"Suspicious activity detected.","status":"OPEN","priority":"HIGH","rootCause":"Phishing email","reason":"SUSPICIOUS_BEHAVIOR","severityDisplay":"Critical","triageAgentInvestigationId":"invest-67890","userType":"EMPLOYEE"},"caseName":"case name 1","responsePlatformInfo":{"alertId":"alert 1","responsePlatformType":"RESPONSE_PLATFORM_TYPE_UNSPECIFIED"}},"path_parameters":{"instance":"testing 1"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Update Reference List
Update a reference list in Google Chronicle SIEM with new entries, using 'update_mask' for specific changes. Requires path parameters: project, location, instance, and referenceList.
Endpoint
- URL: /v1/projects/{{project}}/locations/{{location}}/instances/{{instance}}/referenceLists/{{referenceList}}
- Method: PATCH
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.project | string | Required | The project of the reference list. |
path_parameters.location | string | Required | The location of the reference list. |
path_parameters.instance | string | Required | The instance of the reference list. |
path_parameters.referenceList | string | Required | The reference list of the reference list. |
parameters.update_mask | array | Optional | The fields to update. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
name | string | Optional | The name of the reference list. |
displayName | string | Optional | The display name of the reference list. |
revisionCreateTime | string | Optional | The creation time of the reference list. |
description | string | Optional | The description of the reference list. |
entries | array | Optional | The entries of the reference list. |
entries.value | string | Optional | Value for the parameter |
rules | array | Optional | The rules of the reference list. |
syntaxType | string | Optional | The syntax type of the reference list. |
ruleAssociationsCount | number | Optional | The number of rule associations of the reference list. |
scopeInfo | object | Optional | The scope info of the reference list. |
scopeInfo.scope | string | Optional | The scope of the reference list. |
Input Example
{"parameters":{"update_mask":["list.lines"]},"json_body":{"name":"projects/{project}/locations/{location}/instances/{instance}/referenceLists/{referenceList}","displayName":"Reference List Name","revisionCreateTime":"2026-08-04T12:00:00Z","description":"Reference List Description","entries":[{"value":"1.2.3.4/24"}],"rules":["rules"],"syntaxType":"REFERENCE_LIST_SYNTAX_TYPE_UNSPECIFIED","ruleAssociationsCount":1,"scopeInfo":{"scope":"SCOPE_TYPE_UNSPECIFIED"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
name | string | Name of the resource |
description | string | Output field: description |
lines | array | Output field: lines |
create_time | string | Time value |
content_type | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"name":"list_name","description":"description of the list","lines":["1.2.3.4/24","5.6.7.8/24"],"create_time":"2020-11-20T17:18:20.409247Z","content_type":"CIDR"}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |