Rule chaining

https://cloud.google.com/chronicle/docs/detection/rule-chaining?hl=en#single_event_detection_rules

Has anyone worked with this function? I did open a ticket, when I create the consumer rule I am seeing this error

parsing: error with token: "detection"
detection source is not supported

 

Solved Solved
1 10 467
1 ACCEPTED SOLUTION

Rule chaining (now named as Composite Detections) is only available in private preview, it will soon be available in public preview next month.

View solution in original post

10 REPLIES 10

Rule chaining (now named as Composite Detections) is only available in private preview, it will soon be available in public preview next month.

thank you! 

Hi @suzhuang ,

Is 'rule chaining' available now?

Or is there a specific release date planned?

Cause I faced the same error too.

Thanks!

I am also interested in rule chaining and expected date for GA. Thanks all! 

Hi everyone, Composite Detections public preview (formally known as rule chaining) will be available in a few days, I will post an update here once the public preview is ready in the next few days. I would love to hear from everyone on what your use cases are to see if we can better assist you.

One use case that we have has to do with discovery. We have host discovery and AD discovery rules. Alone, they are noisy. 

Any update on this?

Composite Detections has just been released for Public Preview

https://cloud.google.com/chronicle/docs/detection/composite-detections

It will be a few days before you see it populating within tenants, so please be patient. More content will be posted on how to leverage it further.

Can't wait! ๐ŸŒŸ