Hi All,
I recently tried to do a PoC of chronicle SIEM and after setting up a forwarder to send logs collected by a fluentd aggregator to chronicle, i can't find the logs on Chronicle. I used the steps described here: https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-fluentd#configure-fluentd
Here's the log output from the forwarder which shows the logs being uploaded. What could i be doing wrong?
Solved! Go to Solution.
Hi zunni27,
Where in Chronicle are you looking for the logs? Is the data type for selection available in raw log search and have you tried searching there with "." as regex?
Hi zunni27,
Where in Chronicle are you looking for the logs? Is the data type for selection available in raw log search and have you tried searching there with "." as regex?