Multi Tenancy & Forwarder Labels

Greetings--

Piggybacking on this post:
https://www.googlecloudcommunity.com/gc/SOAR-Forum/Using-Environments-for-Multi-Tenancy/m-p/687636#M...

Are there any guides or syntax about how to link or associate
Forwarder Labels and Ingestion Labels and/or NameSpaces
to their respective Environments to support a multi-tenancy deployment?

e.g. I see in yaml:
env: dev

Any advice is helpful.
Thank you!!

Solved Solved
0 2 442
1 ACCEPTED SOLUTION

If you're wanting to have a SOAR case created in a defined SOAR environment based on the ingestion label, you can define the environment details in the advanced section of the Google Chronicle SOAR connector. 

dlove40_0-1730403197460.png

dlove40_1-1730403272401.png

 

 

 

View solution in original post

2 REPLIES 2

I wrote up a series on apply Data RBAC in Chronicle SIEM and Chronicle in these two posts:

This provides examples of how to plan for using either Namespaces or Ingestion Labels and aligning the configuration across SIEM and SOAR components.

 

If you're wanting to have a SOAR case created in a defined SOAR environment based on the ingestion label, you can define the environment details in the advanced section of the Google Chronicle SOAR connector. 

dlove40_0-1730403197460.png

dlove40_1-1730403272401.png