Google Chronicle (SecOps)
SIEM
Maps Isochronic events to Chronicle's Unified Data Model. Same forwarding semantics; coming in the next destination wave.
Forwarding rules
- All policy_outcome events
- All data_access events where data_class ∈ {PII, HR, financial}
Surfaces this would light up
- Chronicle search (Isochronic UDM events)