googlesecops alert.md

For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.

Google Security Operations

Google SecOps is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. They are optional, but enabling more integrations enhances Dropzone analysis.

Dropzone integrates with Google Security Operations to investigate different security alerts across many of Google's security products.

Integration Overview

To enable these integrations you will perform the following actions:

Identify your service account email address

To obtain the email address of your Dropzone service account, do the following:

Grant IAM Access to Dropzone AI

Obtain Account Details

To obtain your Instance Name, do the following:

To obtain your Project ID, do the following:

SOAR Details

If you want Dropzone to be able to investigate cases, you will need to generate a SOAR API Key and locate your SOAR Instance Hostname.

To generate your SOAR API Key, do the following:

To obtain your SOAR Instance Hostname, do the following:

Enable Google SecOps

To enable the Alert Source integration, you will need the following information:

Dropzone Field Source
Instance Name The "Customer ID" value you copied earlier
Project ID The "Project ID" value you copied earlier
SOAR API Key The "SOAR API Key" value you copied earlier
SOAR Instance Hostname The "SOAR Instance Hostname" value you copied earlier

To enable the Alert Source integration, do the following:

If you have any errors, engage your Dropzone AI support representative.