Welcome to the

Google Cloud Community

Meet industry peers, ask questions, collaborate to find answers, and connect with Googlers who are making the products you use every day.

cancel
Showing results for 
Search instead for 
Did you mean: 
Bronze 4
Since ‎09-15-2023
‎12-27-2023

My Stats

  • 15 Posts
  • 1 Solutions
  • 7 Likes given
  • 5 Likes received

HokutoMunemura's Bio

Badges NastyaS Earned

View all badges

Recent Activity

Hello everyone,I'm building the rule that will detects malicious domains, by matching them against VirusTotal.However, there is a big issue about it.I ingested 26 logs to Chronicle in order to test the rule.25 logs contain malicious domains and just ...
Hello everyone!I am creating a custom parser for json logs and I need to convert domains_list into principal.user.attribute.labels udm event. "activity_metadata": { "settings_new_value": { "block_type": "whitelist", "domains_list": [ "test.com", "att...
Hello everyone!I am having a doubt regarding the deprecated label; i.e., $ioc.graph.entity.labels.key, which has to be populated as $ioc.graph.entity.user.attribute.labels.key nowadays.I am using this new label in the rule, however, all logs contain ...
Hello everyone!Im currently struggling with the regex usage in the rule.I need to create a regex in order to detect the logs with an Admin privilege from "PermissionGroup": "Admins" or "SocRole": "Administrator"security_result.detection_fields.value ...
Hello everyone!I recently started using Fluent Bit to send DNS logs from Windows Server to Google Chronicle Forwarder which then forwards them to Google Chronicle SIEM.But I have a doubt.Im able to send dns logs in JSON raw format, using the followin...