https://cloud.google.com/chronicle/docs/detection/rule-chaining?hl=en#single_event_detection_rules
Has anyone worked with this function? I did open a ticket, when I create the consumer rule I am seeing this error
parsing: error with token: "detection" detection source is not supported
Solved! Go to Solution.
Rule chaining (now named as Composite Detections) is only available in private preview, it will soon be available in public preview next month.
Rule chaining (now named as Composite Detections) is only available in private preview, it will soon be available in public preview next month.
thank you!
Hi @suzhuang ,
Is 'rule chaining' available now?
Or is there a specific release date planned?
Cause I faced the same error too.
Thanks!
I am also interested in rule chaining and expected date for GA. Thanks all!
Hi everyone, Composite Detections public preview (formally known as rule chaining) will be available in a few days, I will post an update here once the public preview is ready in the next few days. I would love to hear from everyone on what your use cases are to see if we can better assist you.
One use case that we have has to do with discovery. We have host discovery and AD discovery rules. Alone, they are noisy.
Any update on this?
Composite Detections has just been released for Public Preview
https://cloud.google.com/chronicle/docs/detection/composite-detections
It will be a few days before you see it populating within tenants, so please be patient. More content will be posted on how to leverage it further.
Can't wait! ๐