Ingest events into Google SecOps (Chronicle) in UDM format

domain: docs.cloud.google.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Create a Google Cloud service account with the Chronicle API Writer role and download a JSON key, or use Workload Identity Federation for keyless auth.
  2. Obtain an OAuth2 access token scoped to https://www.googleapis.com/auth/chronicle-backstory using the service account credentials.
  3. Format each event as a UDM JSON object adhering to the Google SecOps Unified Data Model schema (metadata.event_timestamp, metadata.event_type, principal, target, network, etc.).
  4. Use the recommended current-generation API: POST to https://{region}-chronicle.googleapis.com/v1alpha/projects/{project}/locations/{location}/instances/{instance}/events:import with a JSON body containing a udmEvents array.
  5. Monitor ingestion health in the Google SecOps ingestion status dashboard and check for schema validation errors returned in the API response.

Known gotchas

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans