FLUENTD Logs Uploaded by forwarder not showing on Chronicle

Hi All,

I recently tried to do a PoC of chronicle SIEM and after setting up a forwarder to send logs collected by a fluentd aggregator to chronicle, i can't find the logs on Chronicle. I used the steps described here: https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-fluentd#configure-fluentd
 
Here's the log output from the forwarder which shows the logs being uploaded. What could i be doing wrong?

zunni27_0-1700348684747.png

 

 

Solved Solved
0 1 248
1 ACCEPTED SOLUTION

Hi zunni27,

Where in Chronicle are you looking for the logs? Is the data type for selection available in raw log search and have you tried searching there with "." as regex?

View solution in original post

1 REPLY 1

Hi zunni27,

Where in Chronicle are you looking for the logs? Is the data type for selection available in raw log search and have you tried searching there with "." as regex?