Benefits of the Integration
Add precise context at the event level: Use expression-driven values to add event-level labels for SecOps-bound data, enabling faster pivoting, clearer attribution, and deeper analytics without expanding your parser or rule complexity.
Handle mixed data types with confidence: Apply per-event log type overrides using the __logType field, so you can route multiple source types through a single destination while ensuring the right parser is applied every time.
Accelerate throughput at scale: Send larger batches—up to 4 MB per batch—for high-volume data streams to reduce ingestion overhead and speed up processing.
Enhance visibility: Enrich events in-flight before they reach Google SecOps to maintain consistent visibility across mixed data sources without rewriting parsers or restructuring pipelines.
Read the integration blog post: https://cribl.io/blog/context-is-king-how-cribl-stream-supercharges-google-secops-with-faster-and-smarter-ingestion/
How to Get Data Flowing
This is a built-in integration between Cribl Stream and Google Cloud Security Operations
Configure Stream to send data to Google SecOps via Destinations > Google Cloud Chronicle API
Specify the output ID, select default log type, and add your Google instance information.
Add event-level context with Custom Labels.
Stream will start sending data as it becomes available