Chronicle API
The Chronicle API provides programmatic access to Chronicle's security analytics platform. Developers can use the API to ingest security telemetry, search across normalized security data using UDM (Unified Data Model), manage detection rules, investigate alerts, and retrieve threat intelligence. The API supports creating and managing detection rules, running retrohunts, and accessing curated threat detections.
Documentation
Documentation
https://cloud.google.com/chronicle/docs/reference/rest
Authentication
https://cloud.google.com/chronicle/docs/reference/rest#authentication
Specifications
Schemas & Data
OpenAPI
#Detection Rules
#Security Events
#Threat Intelligence
#UDM Search