Google SecOps Detection Posture Report
Delivers a weekly report on Google SecOps ingestion gaps by log type and feed, rules that are erroring, disabled, or blind, and anything in the instance that needs an admin, from parser failures to silent forwarders.
What this agent does
This read-only agent checks the health of a Google SecOps instance every week. It finds log types, feeds, and forwarders that stopped sending, and parsers that are failing to normalize events. It finds rules that are disabled, erroring, reading log types with no data, using empty reference lists, or hitting the daily detection limit. It lists curated rule sets with alerting off. It summarizes the detections and alerts raised and closed since last week. It flags anything that needs an admin.
The challenge
A rule fires only when its log type arrives and parses. A feed's credential expires and a whole log source goes dark. A vendor changes its log format and the parser drops every event into the unparsed bucket. A rule's live run fails, and the error sits in the rule's error list. Detection volume falls, and the drop gets no review.
The solution
The agent checks ingestion, parser health, rule health, and detection activity in one pass each week and compares them with the previous week. It names the data that stopped, the rules that cannot fire, and the fix for each. Provides a weekly briefing a detection engineer can read in a few minutes.
Workflow
- 01
Check ingestion
Compare event volume per log type, feed, and forwarder with the previous week, and check feed status and forwarder check-ins.
- 02
Check parsers
Read parsing success and failure counts per log type and flag parsers whose failure rate rose.
- 03
Check rule health
Read each rule's enabled and live state, its execution errors, its detection limit hits, and the log types and reference lists it depends on.
- 04
Check activity
Summarize detections and alerts raised and closed since last week, by rule.
- 05
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# Google SecOps Detection Posture Report
## Measurable outcomes
Every week, the detection engineer knows which data stopped arriving or parsing, which rules cannot fire, and what needs action before a detection is missed. Track the silent log types, the unhealthy rules, and the open action items on every run.
## Procedure
Once a week, read the ingested event volume per log type, per feed, and per forwarder for the last 7 days and compare with the previous 7 days. Flag each one that fell to zero or dropped by more than half, unless I mark it as expected. Read each feed's status and flag feeds in a failed or disabled state. Flag forwarders with no check-in in the window. Read the parsing success and failure counts per log type. Flag log types whose failure rate is 10 points above last week, unless I set another threshold, or whose events land unparsed. For each rule, read whether it is enabled and running live, its execution errors in the window, and the log types and reference lists its logic depends on. Flag a rule as blind when a log type it depends on is silent or failing to parse. Flag a reference list a rule uses that is empty. Flag rules with execution errors, and quote the error. Flag rules that hit the daily detection limit. List rules that were disabled or changed since last week, with who changed them. List curated rule sets that are enabled with alerting off, and rule sets Google changed since last week. Summarize the detections and alerts raised and closed since the last report, by rule. Flag rules that raised nothing in the last 30 days and at least one in the 90 days before. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only Google SecOps API access to ingestion statistics, feeds, forwarders, parser status, rules and their execution results, curated rule sets, reference lists, detections, and alerts, and nothing more. It never changes rules, rule sets, feeds, parsers, reference lists, or alerts. Related templates
-
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools -
Bitbucket Public Repository Posture Audit
Reports the public repositories in a Bitbucket workspace that fail its security policy, with each failing check.
Reporting and Compliance 1 tools