There's an official Chronicle Looker block available on the Marketplace, and it mentions that the 'BigQuery Export feature needs to be enabled for your Chronicle tenant.' Can someone please explain what this feature is and how I can set it up?
Block on Marketplace
I understand that this feature involves the Chronicle sending parsed events to BigQuery, which can then be used to connect with Looker. I'm currently facing delays in seeing these events in BigQuery. Is there anyone who can assist me with this issue?
Hi Abhi,
Your understanding that we send parsed events to BigQuery is correct. More information on this feature is available here.
Regarding delays and whether that is within guidelines or not, I recommend opening a support ticket to investigate further.