Skip to content

Google Security Operations integration

Send rule alerts from Have I Been Squatted to Google Security Operations (Google SecOps) as Unified Data Model (UDM) events. Each rule controls which alerts are sent. Connecting Google SecOps alone does not export alerts.

  1. Identify the Google Cloud project ID or number, Google SecOps region, and instance ID. Confirm that the Chronicle API is enabled for that project.
  2. Use a Google account with chronicle.events.import permission on the intended instance. The account must also meet the organization’s Google access policies.
  3. In the app, open Connectors > Google Security Operations.
  4. Enter the project, region, and instance ID, then select Save.
  5. Select Connect with Google and authorize the account that has import access to the instance.
  6. Select Test connection. This sends a labeled test event to Google SecOps and enables export if Google accepts it.
  7. Open each intended rule in the rule editor. In the Response tab, select Add action > Notify Google SecOps and choose the configured destination. Save the rule and ensure it is enabled.

Saving the configuration and authorizing Google access do not send a test event or enable export. Test connection is a separate step. If a test fails, the configuration stays saved and export remains inactive.

Save configuration changes before testing. Saving pauses export until another connection test succeeds. Changing the project, region, or instance also requires reconnecting with Google.

Delivery uses the authorized Google account’s permissions and can continue after the browser closes. If that account loses access or its authorization expires or is revoked, delivery can stop. Select Reconnect with Google, approve access, then select Test connection.

Each alert includes its timestamp, severity, title, rule details, and available domain names from the alert’s cited evidence:

  • Domain findings contribute the matched domain names.
  • Email findings contribute sender and URL domains.
  • Canary findings contribute observed hostnames.

These domain names reflect the evidence retained in the alert. Each event also includes the alert ID as its product log ID, so it can be correlated with the original alert.

The connector page shows the result of the last connection test.

Result Meaning
API accepted Google accepted the event submission.
Schema rejected Google rejected the event format.
Authentication failed The Google authorization is no longer valid. Reconnect and test again.
Authorization failed The Google account lacks permission to import into the selected instance.
Authentication network failure Google authorization could not be completed. The event was not submitted.
Throttled Google returned a rate-limit response.
API acceptance unknown No conclusive response was received. Google may have accepted the event.

API accepted does not confirm ingestion or search visibility. Those remain unverified in the connector. To verify an exported alert, locate the event in Google SecOps and match its product log ID to the original alert ID.

Failed or uncertain submissions are not automatically resent, and historical alerts are not backfilled. Each connection test sends a new test event.