How to build an alert when chronicle siem ingestion?

Hi all, we are trying to build an alert when chronicle siem ingestion would drop by 20% for a certain type of logs within an hour, does anyone have experience with something like this?

0 1 435
1 REPLY 1

Hi Pete, if you migrated to Bring Your Own Project preview then you can use GCP Cloud Monitoring, which can create percentage based deviation alerting - see the blog written by one of our team members - https://medium.com/@thatsiemguy/chronicle-forwarder-telemetry-via-google-cloud-monitoring-39ccb32b38...