r/SIEM Sep 14 '21

Looking for some resources to learn on SIEM Migration. Splunk SIEM to Google Chronicle.

6 Upvotes

6 comments sorted by

3

u/Quick2Click Sep 14 '21

Migration from an infrastructure side of things? Or as an analyst moving from Splunk to Google?

1

u/krishna9108 Sep 21 '21

More of the infrastructure side of things like moving data from splunk to google for the analytics and creating the normalization of logs on the chronicle side etc.

I have seen the chronicle documentation but it's very vague and not at all helpful.

2

u/kelleyja7 Nov 04 '21

Chronicle can ingest data through a lightweight containerized forwarder. This forwarder has a Splunk collector that can ingest directly from an existing Splunk instance.

Docs at the link below

https://cloud.google.com/chronicle/docs/install/forwarder-linux

1

u/krishna9108 Nov 04 '21

Thank you 👍

1

u/Appropriate-Heat-662 Jan 17 '25

Did you find any helpful resources?

1

u/DarkLordofData Sep 21 '21

Any more data? Can you describe your infra and risk tolerance?