googlesecops data.md

For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.

Google Security Operations

Google Security Operations is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. They are optional, but enabling more integrations enhances Dropzone analysis.

Dropzone integrates with Google Security Operations to investigate different security alerts across many of Google's security products.

Integration Overview

To enable these integrations you will perform the following actions:

Identify your service account email address

To obtain the email address of your Dropzone service account, do the following:

Integrations Dropdown

Click Available

The Google SecOps Tile

Copy the service account email

Grant IAM Access to Dropzone AI

Open the navigation menu

Navigate to IAM

Click "Grant Access"

Input the email address from the Dropzone UI Service Account Email

Click "Select a role"

Assign the Chronicle API Viewer role

Click "Save"

Obtain Account Details

To obtain your Instance Name, do the following:

Open the navigation menu

Navigate to Google SecOps

Reveal the Instance Details

Copy the Instance Name

To obtain your Project ID, do the following:

Click the project icon

Copy the Project ID

SOAR Details

If you want Dropzone to be able to investigate cases, you will need to generate a SOAR API Key and locate your SOAR Instance Hostname

To generate your SOAR API Key, do the following:

Navigate to SOAR Settings

Navigate to API Keys

Add API Key

Select Managed User

Copy the API Key

Copy the API Key

To obtain your SOAR Instance Hostname, do the following:

Navigate to Webhook

Add new Webhook

Click Save

Copy the SOAR Instance Hostname

Enable Google SecOps

To enable the Data Source integration, you will need the following information:

Dropzone Field Source
Instance Name The "Customer ID" value you copied earlier
Project ID The "Project ID" value you copied earlier

To enable the Data Source integration, do the following:

Integrations Dropdown

Click Available

The Google SecOps Tile

The Google SecOps Data Source Configuration

If you have any errors engage your Dropzone AI support representative.