Hi all, we are trying to build an alert when chronicle siem ingestion would drop by 20% for a certain type of logs within an hour, does anyone have experience with something like this?
Hi Pete, if you migrated to Bring Your Own Project preview then you can use GCP Cloud Monitoring, which can create percentage based deviation alerting - see the blog written by one of our team members - https://medium.com/@thatsiemguy/chronicle-forwarder-telemetry-via-google-cloud-monitoring-39ccb32b38...