
Chronicle parser for CORELIGHT and related information.
This document describes how you can collect Corelight Sensor logs by configuring the Corelight Sensor and a Chronicle forwarder. This document also lists the supported log types and supported Corelight versions.
For more information, see Data ingestion to Chronicle.
The following deployment architecture diagram illustrates how a Corelight Sensor is set up to send logs to Google Security Operations using two different ingestion architectures. It's important to note that each customer deployment may vary from this representation and could be more complex.
An ingestion label identifies the parser which normalizes raw log data to structured UDM format. The information in this document applies to the parser with the CORELIGHT ingestion label.

The architecture diagram shows the following components:
Corelight Sensor: The system running the Corelight Sensor .
Corelight Sensor exporters: The Corelight Sensor exporter collects log data from the Sensor, and forwards it to Google Security Operations.
Google Security Operations: Google Security Operations retains and analyzes the logs from Corelight Sensor.
Use the Sensor or Fleet Manager web interface to configure the Google SecOps exporter. This configuration uses the API credentials from your Google SecOps instance to establish the secure connection.
Log in to the Fleet Manager or Sensor web interface of Corelight Sensor as an administrator.
Navigate to the exporter configuration area:
In the Create Exporter section, click Google SecOps.




The architecture diagram shows the following components:
Corelight Sensor: The system running the Corelight Sensor .
Corelight Sensor exporter: The Corelight Sensor exporter collects log data from the Sensor, and forwards it to the Google Security Operations forwarder.
Google Security Operations forwarder: The Google Security Operations forwarder is a lightweight software component, deployed in the customer's network, that supports syslog. The Google Security Operations forwarder forwards the logs to Google Security Operations.
Google Security Operations: Google Security Operations retains and analyzes the logs from Corelight Sensor.
To configure the Google Security Operations forwarder, do the following:
Set up a Google Security Operations forwarder. See Install and configure the forwarder on Linux.
Configure the Google Security Operations forwarder to send logs to Google Security Operations.
collectors:
- syslog:
common:
enabled: true
data_type: CORELIGHT
data_hint:
batch_n_seconds: 10
batch_n_bytes: 1048576
tcp_address: <Chronicle forwarder listening IP:Port>
tcp_buffer_size: 524288
udp_address: <Chronicle forwarder listening IP:Port>
connection_timeout_sec: 60

The Corelight parser supports the following log types: