You’re a SOC analyst who understands that as employees spend more time working in browsers, the chances of risky browser behavior impacting enterprise resiliency increases. You are concerned about the following risky browser behavior and more:
- Installing an extension that was impersonating a legitimate one and is now acting maliciously
- Accessing content that is considered dangerous, malicious, banned, or unwanted
- Opening, clicking, or visiting a URL that is considered deceptive or malicious
- Updating an extension to the latest version that contains malicious code due to a recent acquisition by a malicious entity
The Google Chrome Add on for Splunk and Google Chrome App for Splunk are able to help address these risks by:
- Bringing Chrome Threat and Data Protection events into Splunk and mapping them to the Splunk Common Information Model (CIM) to allow for easy correlation with other data sources and maximum efficiency at search time.
- Providing prebuilt dashboards and analytics to help investigate the most critical incidents of extension installs, malware transfer, and unsafe site visits.
- Alerting on the events that are the most important and automatically responding to these events with the following actions:
- Block extensions that are risky
- Change policies on a user or device that is exhibiting suspicious behavior
- Send an email to users who need to remove something from their device or receive training on safe browsing
- Create a ticket in ServiceNow or Jira to document work and pass on to a responsible team
Step 1: Prepare the Splunk platform
- In your Splunk instance, navigate to Settings > Data Inputs > HTTP Event Collector.
- Click New Token to issue a new token.
- Enter a name for the token, and leave the other fields as their default values. You do not need to select Enable indexer acknowledgement.
- On the next page, leave the Source type set to Automatic, and either create a new or select an existing index for testing Chrome event ingestion. We recommend you create a new index for testing.
- Click Review, then Submit if the information is correct.
- Copy the HEC token value for use in the next step.
Step 2: Set up the Splunk integration in Chrome Browser Cloud Management (CBCM)
Using the newly created Splunk HEC token, set up the Splunk reporting connector in the CBCM console. For instructions, see Getting started with the Splunk integration in Chrome Browser Cloud Management.
It is also recommended that you update the browser reporting frequency from the default of 24 hours to the minimum of 3 hours so that extension data is reported more frequently. For more information, see Turn on Chrome browser reporting in the Google documentation.
Step 3: Install and configure the service account and external lookup inputs
- Install the Google Chrome Add on for Splunk from Splunkbase. For instructions, see Install apps on your Splunk Cloud Platform deployment.
- Navigate to the Configuration panel in the Google Chrome Add-on for Splunk.
- Click Add to create a new service account configuration.
- Input the required credentials shown in the following screenshot. You can obtain these from the CBCM console.
- Navigate to the Inputs panel in the Google Chrome Add-on for Splunk.
- Click Create New Input and create the Extensions Lookup Query input. Use the Service Account that you saved in the Configuration panel. Then do the same to create the Organization Units Lookup Query input.
Step 4: Verify the configuration
- If you have already set up the Splunk Reporting Connector in the Google Chrome Admin console, then there may already be events in the Splunk instance. Run a search for events using the test index with
- If there are no events, you can simulate chrome browser events using the website (Safe) Safe Browsing Testing Links.
- If there are still no events, then review and repeat the setup steps to ensure everything is configured correctly.
Set up the Google Chrome App for Splunk
- In your Splunk instance, navigate to Apps > Find More Apps.
- Search “Google Chrome App for Splunk” and install. For instructions, see Install apps on your Splunk Cloud Platform deployment.
- Configure the chrome search macro to use the same index that the HEC token is configured for.
- Navigate to Settings > Advanced Search > Search Macros, and click chrome.
- If necessary, edit the search to change the value for the index field.
- Verify that data has been ingested correctly by viewing one of the dashboards in the app and ensuring the visualizations are populated.
Q: What products do I need for this?
A: Splunk Core (version 8.1.x and above) and Chrome Browser Cloud Management.
Q: Do I need to have Splunk Enterprise Security?
A: Splunk Enterprise Security is not required. All events are CIM tagged so any Splunk Enterprise Security content built on the data models that an event is tagged to will populate with the tagged event.
Q: Is this a joint developed product with Google?
A: Yes, we jointly developed this product with Google Chrome.
Q: What types of events are ingested? Does this include ChromeOS events?
A: See all the different types of events here. ChromeOS events are ingested, but not CIM tagged. There are plans to CIM tag ChromeOS events and provide prebuilt analytics and alerts in the future.
Q: What use cases does this app address?
A: The app focuses on malware downloads, unsafe site visits, and browser extensions. All Chrome security log events are ingested and CIM tagged, allowing for ease of use for developing additional analytics and event population in content that references data models. We plan to address additional use cases in the future.
Q: Which browsers will this app work for?
A: Chrome 110+ is required for extension events. Chrome 104+ is required for malicious download events.
Q: Where can I find this app? Will it be Splunk supported?
A: In Splunkbase. It will be Splunkworks supported.
Now that you have the app running configured, the next best step is to configure alert actions, which you can learn how to do here.
Still need help? Check out some of the resources below or email our team directly at email@example.com.