Google SecOps

Google SecOps is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. They are optional, but enabling more integrations enhances Dropzone analysis.

Dropzone integrates with Google SecOps to investigate different security alerts across many of Google's security products.

Integration Overview

To enable these integrations you will perform the following actions:

  • Identify your service account address

  • Grant IAM access to the Dropzone service account

  • Obtain your Google Account Details

  • Enable the Alert and Data sources

Identify your service account email address

To obtain the email address of your Dropzone service account, do the following:

  • Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app

  • In the bottom left hand corner, navigate to Settings > Integrations

Integrations Dropdown
  • Click "Available"

Click Available
  • In the Search bar, search Google SecOps, then click "Configure"

The Google SecOps Tile
  • Copy the "SERVICE ACCOUNT EMAIL" field for use in the Google Console interface

Copy the service account email

Grant IAM Access to Dropzone AI

  • Navigate to the Google Console page of the project your SecOps instance is in

  • In the upper left hand corner, open the navigation menu

Open the navigation menu
  • Navigate to IAM & Admin > IAM

Navigate to IAM
  • Under "View by principals," click "Grant Access"

To be able to complete this step, you will need the resourcemanager.projects.setIamPolicy permission.

Click "Grant Access"
  • Under "New principals," input the email address you copied earlier from the Dropzone UI "SERVICE ACCOUNT EMAIL"

Input the email address from the Dropzone UI Service Account Email
  • Click "Select a role"

Click "Select a role"
  • Search the "Chronicle API Viewer" role, then click it

Assign the Chronicle API Viewer role
  • Click "Save"

Click "Save"

Obtain Account Details

To obtain your Instance Name, do the following:

  • Return to the Google Console page of the project your SecOps instance is in

  • In the upper left hand corner, open the navigation menu

Open the navigation menu
  • Navigate to Security > Detection and Controls > Google SecOps

Navigate to Google SecOps
  • In the Google SecOps page, click the carrot next to "Instance Details"

Reveal the Instance Details
  • Copy the Customer ID shown for use later in the Dropzone UI where it is called "Instance Name"

Copy the Instance Name

To obtain your Project ID, do the following:

  • In the upper left, click on the project icon

Click the project icon
  • Using the search bar, locate the project your SecOps instance is in

  • Under "ID," copy the ID value shown for use later in the Dropzone UI where it is called "Project ID"

Copy the Project ID

Enable Google SecOps

To enable the Data Source integration, you will need the following information:

Dropzone Field
Source

Instance Name

The "Customer ID" value you copied earlier

Project ID

The "Project ID" value you copied earlier

To enable the Data Source integration, do the following:

  • Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app

  • In the bottom left hand corner, navigate to Settings > Integrations

Integrations Dropdown
  • Click "Available"

Click Available
  • In the Search bar, search Google SecOps, then click "Configure"

The Google SecOps Tile
  • Input the Instance Name and Project ID

The Google SecOps Data Source Configuration
  • Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.

Last updated

Was this helpful?