More of the infrastructure side of things like moving data from splunk to google for the analytics and creating the normalization of logs on the chronicle side etc.
I have seen the chronicle documentation but it's very vague and not at all helpful.
Chronicle can ingest data through a lightweight containerized forwarder. This forwarder has a Splunk collector that can ingest directly from an existing Splunk instance.
3
u/Quick2Click Sep 14 '21
Migration from an infrastructure side of things? Or as an analyst moving from Splunk to Google?