Skip to content

[google-secops-siem-incidents] Creation of the connector (#5406)#6322

Open
Kakudou wants to merge 38 commits intomasterfrom
feat/create-google-secops
Open

[google-secops-siem-incidents] Creation of the connector (#5406)#6322
Kakudou wants to merge 38 commits intomasterfrom
feat/create-google-secops

Conversation

@Kakudou
Copy link
Copy Markdown
Member

@Kakudou Kakudou commented Apr 30, 2026

Proposed changes

Add new google-secops-siem-incidents external-import connector that fetches Chronicle SIEM rule alerts via the Legacy Search API, converts them to STIX2.1 (incidents, observables, relationships), and sends bundles to OpenCTI with backward-sliding-window pagination and checkpoint-based state persistence.

Catalog/Composer:
Screenshot from 2026-04-30 09-35-06
Screenshot from 2026-04-30 09-59-27
Screenshot from 2026-04-30 09-59-10
Screenshot from 2026-04-30 09-59-19

Log of the connector:
Screenshot from 2026-04-29 17-00-21

Tests:
Screenshot from 2026-04-29 17-00-41

Linter:
Screenshot from 2026-04-29 18-28-47

Manifest:
Screenshot from 2026-04-29 18-29-44

Related issues

#5406

Checklist

  • I consider the submitted work as finished
  • I have signed my commits using GPG key.
  • I tested the code for its functionality using different use cases
  • I added/update the relevant documentation (either on github or on notion)
  • Where necessary I refactored code to improve the overall quality

Further comments

@Kakudou Kakudou self-assigned this Apr 30, 2026
@Kakudou Kakudou added filigran team use to identify PR from the Filigran team connector: google-secops-incidents labels Apr 30, 2026
@Kakudou Kakudou changed the title Feat/create google secops [google-secops-siem-incidents] Creation of the connector (#5406) Apr 30, 2026
@codecov
Copy link
Copy Markdown

codecov Bot commented Apr 30, 2026

⚠️ JUnit XML file not found

The CLI was unable to find any JUnit XML files to upload.
For more help, visit our troubleshooting guide.

@Kakudou Kakudou force-pushed the feat/create-google-secops branch 10 times, most recently from 260b366 to cf72754 Compare April 30, 2026 11:29
@Kakudou Kakudou added the do not merge Do not merge this PR until this tag will be removed label May 4, 2026
Kakudou and others added 24 commits May 4, 2026 17:55
@Kakudou Kakudou force-pushed the feat/create-google-secops branch from d5533a0 to 5511a5c Compare May 4, 2026 15:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

connector: google-secops-incidents do not merge Do not merge this PR until this tag will be removed filigran team use to identify PR from the Filigran team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[google-secops-siem-incidents] New connector for Google SecOps SIEM to collect Incidents, discovered IOCs

3 participants