SIEM integration
Automate Google Security Operations (Chronicle) SIEM with plain language
Read Chronicle detections, IoC matches and asset activity, and ingest VernacSecure SuperBot™ events as unstructured logs.
What you can do
Google SecOps / Chronicle — Backstory REST API v2
- List rule detections
- Read IoC matches for assets
- Ingest unstructured log entries
Connection: bearer authentication against https://backstory.googleapis.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Show the last 24 hours of high severity alerts in Google Security Operations (Chronicle)”
Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.
Read actions
- Fetch detections — Lists rule detections.
- Fetch IoC matches — Lists IoC matches seen in the environment.
Write actions
- Ingest log entry — Ingests a VernacSecure SuperBot™ log line.
Related siem automation pages
Armor Point · Datadog Cloud SIEM · Devo Platform · Elastic Security · Exabeam Security Operations · Fortinet FortiSIEM