Destination

Google Cloud Chronicle API

Enrich and route high-volume workloads into Google Security Operations (SecOps) via Chronicle API destination.

Benefits of the Integration  

  • Add precise context at the event level: Use expression-driven values to add event-level labels for SecOps-bound data, enabling faster pivoting, clearer attribution, and deeper analytics without expanding your parser or rule complexity.

  • Handle mixed data types with confidence: Apply per-event log type overrides using the __logType field, so you can route multiple source types through a single destination while ensuring the right parser is applied every time.

  • Accelerate throughput at scale: Send larger batches—up to 4 MB per batch—for high-volume data streams to reduce ingestion overhead and speed up processing.

  • Enhance visibility: Enrich events in-flight before they reach Google SecOps to maintain consistent visibility across mixed data sources without rewriting parsers or restructuring pipelines.


Read the integration blog post: https://cribl.io/blog/context-is-king-how-cribl-stream-supercharges-google-secops-with-faster-and-smarter-ingestion/ 

How to Get Data Flowing 

This is a built-in integration between Cribl Stream and Google Cloud Security Operations

  • Configure Stream to send data to Google SecOps via Destinations > Google Cloud Chronicle API 

  • Specify the output ID, select default log type, and add your Google instance information.

  • Add event-level context with Custom Labels. 

  • Stream will start sending data as it becomes available

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s suite of products to collect, process, route, and analyze all IT and security data, delivering the flexibility, choice, and control required to adapt to their ever-changing needs.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on-Sandboxes for those interested in how companies globally leverage our products for their data challenges.