SIEM integration

Automate Google Security Operations (Chronicle) SIEM with plain language

Read Chronicle detections, IoC matches and asset activity, and ingest VernacSecure SuperBot™ events as unstructured logs.

What you can do

Google SecOps / Chronicle — Backstory REST API v2

  • List rule detections
  • Read IoC matches for assets
  • Ingest unstructured log entries

Connection: bearer authentication against https://backstory.googleapis.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.

Example

Ask in plain English

Prompt: “Show the last 24 hours of high severity alerts in Google Security Operations (Chronicle)”

Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.

Get started free

Read actions
  • Fetch detections — Lists rule detections.
  • Fetch IoC matches — Lists IoC matches seen in the environment.
Write actions
  • Ingest log entry — Ingests a VernacSecure SuperBot™ log line.