vectordotdev / vectordotdev/vector

Support for new Chronicle ingestion api

Open
#26,102 0 comments 6 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
22.6k
Forks
2.3k
Avg merge
1d 7h
Merged PRs (30d)
146

Description

A note for the community
  • Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment
Use Cases

The end goal is for security events from Kubernetes containers to end up in the SIEM

Attempted Solutions

We're looking at https://vector.dev/docs/reference/configuration/sinks/gcp_chronicle_unstructured/, but there's a big notice saying the API will be removed by July 20, 2027

Proposal

Add a new sink for the new chronicle api

References

No response

Version

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the referenced Vector GCP Chronicle unstructured sink documentation and the Chronicle ingestion-methods documentation for the new API. The work is done when Vector has a new Chronicle API sink that can send security events from Kubernetes containers to the SIEM.

Written by the indexing model from the issue text.

Assessment

Tech stack
google-cloud, kubernetes, rust
Domain
cloud, observability, stream-processing
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.