This website uses Cookies. Click Accept to agree to our website's cookie use as described in our Privacy Policy. Click Preferences to customize your cookie settings.
I need to collect and ingest FortiEDR logs. I have access to the API,
and have been provided a read-only api key, but I do not see a built in
feed type.Has anyone collected and ingested FortiEDR logs from the API?
The doc linked here
https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-windows-dnsshows
Bindplane collecting DNS from the Windows Event channel
Microsoft-Windows-DNSServer/Audit. I enabled "Analytical and Debug Logs"
and see qu...
I have tested a date filter that imports the metadata.event_timestamp
correctly when used in a custom parser. I set the timezone in the date
filter and the tz offset is applied to the time so that the
metadata.event_timestamp is correct in Z time.Whe...
Unfortunately, this client cannot get access to the syslog feed, and the
existing MSSP is unable to write only this one customer's logs to a
bucket. The API is the only access provided to the logs. I'll see what I
can achieve.