I would like to have an example of a rule on Sentinel that uses log sources from GCP Audit Log.

Koonnamchok Klongkaew 140 Reputation points
2023-10-02T11:00:02.53+00:00

I would like to have an example of a rule on Sentinel that uses log sources from GCP Audit Log.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,261 questions
0 comments No comments
{count} votes

Accepted answer
  1. Clive Watson 7,481 Reputation points MVP
    2023-10-02T12:27:29.1633333+00:00

    You could take a look at the Sigma examples here https://github.com/SigmaHQ/sigma/tree/master/rules/cloud/gcp and use a tool like uncoder.ai to translate into a Microsoft Sentinel rule.

    I hope this helps, please accept if it does?

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.