Google Workspace Activity
Last updated
Was this helpful?
If you’ve previously created an Google Workspace connection, select it from the list.
Otherwise, select New Google Workspace Connection and fill in the required fields:
Connection Name: Give the connection a recognizable name.
Service Account Subject Email: e.g. johndoe@yourcompany.com
Service Account Key JSON
To create the service account and the service account key JSON:
Domain-wide delegation must be enabled for the service account
The Admin SDK API must be enabled on the Google Cloud project
The service account subject email is the email of the user who created the service account. It is NOT the service account email ending in @my-project.iam.gserviceaccount.com. The service account impersonates this user when polling from the API.
The service account must have the following authorization scopes:
https://www.googleapis.com/auth/admin.reports.audit.readonly
https://www.googleapis.com/auth/admin.reports.usage.readonly
With the Collect Rule created, Scanner will poll the Google Workspace Admin SDK API every 5 minutes, writing new events to your S3 bucket. Create an Index Rule to make them searchable.
When you create the Index Rule from the Collect Rule, the following defaults are pre-populated:
Transformations: Add Metadata, Parse JSON Columns, Unroll Array, ECS Normalization: Google Workspace
Timestamp Field: .id.time
Last updated
Was this helpful?
Was this helpful?