Chronicle context parsers

This document lists the Chronicle context parsers that normalize context logs into Chronicle Unified Data Model (UDM) fields.

Context logs contain information about Google Cloud asset metadata of the resources that Chronicle supports. For more information about resource types, see Cloud Asset Inventory supported resource types. Examples of Resource Manager context log fields: assetType, resource.data.name, and resource.version.

Configure ingestion of context logs

To ingest the context logs to Chronicle, follow the instructions in Ingest Google Cloud data to Chronicle.

If you encounter issues when you ingest the context logs, contact Chronicle support.

Field mapping reference and supported resource types

The following table lists the context parsers that Chronicle supports, the corresponding ingestion label, and the supported resource types.

To view the mapping reference documentation of the context parser, click the corresponding context parser name from the table.

Service name Ingestion label Supported resource types
Resource Manager GCP_RESOURCE_MANAGER_CONTEXT
Cloud SQL GCP_SQL_CONTEXT
Cloud Functions GCP_CLOUD_FUNCTIONS_CONTEXT
Identity and Access Management GCP_IAM_CONTEXT
Network Connectivity Center GCP_NETWORK_CONNECTIVITY_CONTEXT
Google Kubernetes Engine GCP_KUBERNETES_CONTEXT
Compute Engine GCP_COMPUTE_CONTEXT