Google Security Operations Silent Host Monitoring lets you create alerts for ingestion rate changes using Google Cloud Monitoring. It generates alerts per collector and notifies you when the ingestion rate falls below your defined threshold, signaling potential collector stoppages. This feature works with the gRPC API.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-09-04 UTC."],[],[],null,["# Configure Bindplane for Silent Host Monitoring\n==============================================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n| **Note:** This feature is covered by [Pre-GA Offerings Terms](https://chronicle.security/legal/service-terms/) of the Google Security Operations Service Specific Terms. Pre-GA features might have limited support, and changes to pre-GA features might not be compatible with other pre-GA versions. For more information, see the [Google SecOps Technical Support Service guidelines](https://chronicle.security/legal/technical-support-services-guidelines/) and the [Google SecOps Service Specific Terms](https://chronicle.security/legal/service-terms/).\n\nGoogle Security Operations Silent Host Monitoring lets you create alerts for ingestion rate changes using Google Cloud Monitoring. It generates alerts per collector and notifies you when the ingestion rate falls below your defined threshold, signaling potential collector stoppages. This feature works with the gRPC API.\n\nPrerequisites\n-------------\n\nThis guide assumes you already use a [Google SecOps Standardization processor](https://bindplane.com/docs/resources/processors/google-secops-standardization).\n\nConfigure Bindplane for Silent Host Monitoring\n----------------------------------------------\n\nTo enable Bindplane for Silent Host Monitoring, send the collector server's hostname as an attribute within the log entry.\n\n1. On the **Log** tab, select **Processors** \\\u003e **Add Processors** \\\u003e **Copy Field**.\n2. Configure the **Copy Field** processor:\n - Enter a short description for the resource.\n - Choose the `Logs` telemetry type.\n - Set the `Copy From` field to `Resources`.\n - Set the `Resource field` field to `host.name`.\n - Set the `Copy To field` field to `Attributes`.\n - Set the `Attributes Field` field to `chronicle_ingestion_label[\"ingestion_source\"]`.\n\nGoogle Cloud Monitoring threshold\n---------------------------------\n\nSet the threshold according to your needs:\n\n- A very low threshold alerts you when the collector might be down.\n- A very high threshold indicates potential source collection issues.\n\nWe recommend that you monitor the **Chronicle Collector** \\\u003e **Ingestion** \\\u003e **Total Ingestion Log Count** metric.\n\nFor detailed setup instructions, see [Set up a sample policy to detect silent Google SecOps forwarders](/chronicle/docs/ingestion/ingestion-notifications-for-health-metrics#create-policy-forwarders).\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]