Google Workspace Alerts

Step 1: Create a New Source

In the Scanner UI, go to the Collect tab.

  • Click Create New Source.

  • Click Select a Source Type.

  • Choose Google Workspace.

  • Choose Google Workspace: Alerts

You’ll be prompted to choose an Ingest Method:

  • Select API Pull.

  • Then, choose a Destination: Select Scanner.

Click Next.

Step 2: Configure the Source

Set a Display Name, such as my-google-workspace-alerts-logs.

Click Next.

Step 3: Authenticate with Google Workspace

  • If you’ve previously created an Google Workspace connection, select it from the list.

  • Otherwise, select New Google Workspace Connection and fill in the required fields:

    • Connection Name: Give the connection a recognizable name.

    • Service Account Subject Email: e.g. [email protected]

    • Service Account Key JSON

To create the service account and the service account key JSON:

  • Domain-wide delegation must be enabled for the service account

  • The Alert Center API must be enabled on the Google Cloud project

  • The service account subject email is the email of the user who created the service account. It is NOT the service account email ending in @my-project.iam.gserviceaccount.com. The service account impersonates this user when polling from the API.

  • The service account must have the authorization scope https://www.googleapis.com/auth/apps.alerts

Click Next.

Step 4: Configure the Destination

  • Choose the S3 Bucket where the raw Google Workspace logs should be stored.

  • (Optional) Enter a Key Prefix to organize the data path in your bucket.

  • Choose the Scanner Index where logs will be made searchable.

  • Leave the Source Label as google_workspace:alerts.

Click Next.

Step 5: Transform and Enrich

  • (Optional) Add additional transformation or enrichment steps if needed.

Click Next.

Step 6: Timestamp Extraction

Leave the default setting: Extract timestamp from field createTime.

This field is included in every Google Workspace alerts log and reflects when the event occurred.

Click Next.

Step 7: Review and Create

  • Review all configuration settings.

  • Click Create Source.

What Happens Next

Once created:

  • Scanner will poll the Google Workspace Alert Center API every 5 minutes.

  • New events will be written to your S3 bucket, under the specified key prefix.

  • Logs will then be indexed for search and detections using your selected Scanner index.

Last updated

Was this helpful?