Integration Use Cases
Get Evidence
Retrieves the evidence for an investigation.
Get Investigation
Retrieves an investigation by ID.
Patch Investigation
Updates an investigation by ID.
Post Events
Writes a batch of `Event` objects to the SIEM configured with the token used for authentication.
Query Alerts
Queries alerts from the SIEM configured with the token used for authentication.
Query Events
Queries events from the SIEM configured with the token used for authentication.
Query Investigations
Queries investigations
Query Log Providers
Queries available log providers in the source SIEM
Integration Resources
Configuration Guide
Google Security Operations (Chronicle Compatibility) Configuration Guide