In this section, you will learn how to configure Portnox™ Cloud to send alert data to the Google SecOps feed using the
Google Cloud API key.
-
In the Cloud portal top menu, click on the Settings option.
-
In the Cloud portal left-hand menu, click on the option.
-
Create a new SIEM integration with Google SecOps.
-
In the SIEM integration service section, click on the Add a new SIEM
integration link.
The New SIEM integration section opens.
-
In the Integration type field, select the Google SecOps
option.
-
In the Name field, enter the name for the new integration.
In this example, we used the name Google SecOps but you can use any name you
like.
-
In the Status field, select the Enabled option.
-
In the HTTPS endpoint field, paste the HTTPS endpoint that you copied from the
Google SecOps feed configuration and saved in a temporary text file.
-
In the API Key field, paste the API key that you copied from the Google Cloud API
key configuration and saved in a temporary text file.
-
In the Access Secret field, paste the secret key that you copied from the Google
SecOps configuration and saved in a temporary text file.
- Optional:
Modify or turn off the health check frequency.
We recommend keeping the default values.
- Optional:
If you want to send each alert separately instead of merging related alerts together, activate the
Unmerge alerts checkbox.
-
Click on the Save button to add the integration.
- Optional:
Test the configuration by clicking on the Test button.
- Optional:
To configure the types of alerts sent to your SIEM solution, see the following topic: Portnox Cloud alerts.
You can also send all of the Portnox Cloud activity log (activities performed by administrators in Portnox Cloud) to
your SIEM solution. To do this, go to , activate the Activity log switch, and click on the
Save button.

Result: Google SecOps is receiving alerts from Portnox Cloud.
You can confirm the integration, for example, by running the following query in :
metadata.vendor_name = "PORTNOX_CEF"
