Google Security Operations (Chronicle)
Integrating Keeper SIEM push to Google Security Operations (formerly Chronicle)
Last updated
Was this helpful?
Integrating Keeper SIEM push to Google Security Operations (formerly Chronicle)
Keeper supports event streaming into Google Security Operations, formerly known as Google Chronicle. External logging is real-time, and new events will appear within a few minutes. Setup instructions are below.
Go to the Google Cloud console and select the project associated with your Google Security Operations (Chronicle) environment.
Select APIs & Services > Credentials and create a new credential > API Key.
After creating the API key, edit the key and apply restrictions.
Ensure that the API key is restricted to "Chronicle API" capabilities only.
Save this API key for step 3 below.

From your Google Security Operations tenant:
Go to Settings > Feeds > Add Feed.
Select Source Type of "Webhook" and then select Log Type of "Keeper Enterprise Security"
Select Next and then Submit.
When prompted, generate the Secret Key and save it for step 3.
Also, copy the Feed Endpoint and save this for step 3.




When audit events are sent from Keeper to Google, the data will begin to populate within a few minutes.
Last updated
Was this helpful?
Was this helpful?

