Chronicle has the ability to pull logs from GCP GCS.
Creating a GCP GCS Bucket
- GCP has great information online about how to create new GCS Buckets. Feel free to follow this GCP Guide.
- CYDERES will provision a service account and provide you with the service accounts email. This service account will be used to access the bucket.
- Feel free to follow this GCP Guide on how to add a service account to your GCS bucket. The permissions that are required are
Storage Legacy Bucket Reader (roles/storage.legacyBucketReader)and
Storage Object Viewer (roles/storage.objectViewer)
Send the following to CYDERES when completed
- GCP Bucket Name
- GCP Bucket File Path
- GCS Project Service Account
- Log Types