Google Security Operations | Dropzone AI Documentation

Google SecOps Integration Guide

Google SecOps is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. They are optional, but enabling more integrations enhances Dropzone analysis.

Dropzone integrates with Google Security Operations to investigate different security alerts across many of Google's security products.

Integration Overview

To enable these integrations you will perform the following actions:

Identify your service account email address

To obtain the email address of your Dropzone service account, do the following:

Grant IAM Access to Dropzone AI

Obtain Account Details

To obtain your Instance Name, do the following:

To obtain your Project ID, do the following:

SOAR Details

If you want Dropzone to be able to investigate cases, you will need to generate a SOAR API Key and locate your SOAR Instance Hostname.

To generate your SOAR API Key, do the following:

To obtain your SOAR Instance Hostname, do the following:

Enable Google SecOps

To enable the Alert Source integration, you will need the following information:

The SOAR API Key and SOAR Instance Hostname are only necessary if you wish to enable Dropzone to investigate cases.

To enable the Alert Source integration, do the following:

Click "Test & Save" to finish.

If you have any errors, engage your Dropzone AI support representative.