Google Chronicle Audit Log Forwarding
Google Chronicle Audit Log Forwarding
What’s New
Britive audit events can now be forwarded to Google Chronicle, part of Google SecOps, using Britive’s webhook notification medium pointed at a Chronicle HTTPS webhook feed.
Chronicle ingests events over a plain HTTPS webhook, and Britive can push its audit log to any HTTPS URL. Connecting the two needs nothing installed and no compute running on either side.
How It Fits Together
- Create an HTTPS webhook feed in Google SecOps, with its authentication credentials.
- Configure a webhook notification medium in Britive pointed at that feed.
- Attach the notification medium to Britive’s audit log so matching events forward automatically.
There is no published Chronicle parser for Britive’s audit log format. Events arrive as raw Britive audit JSON under a generic log type. Mapping those fields into Chronicle’s Unified Data Model requires a custom parser you write yourself — the guide covers what the fields are, not the parser.
Learn More
Last updated on