Google Workspace Alerts
Last updated
Was this helpful?
In the Scanner UI, go to the Collect tab.
From the Overview page click the '+' icon in the upper right corner
Select create new Collect Rule
Choose Google Workspace.
Choose Google Workspace: Alerts
Click Continue.
Set a Display Name, such as my-google-workspace-alerts-logs.
Click Next.
If you’ve previously created an Google Workspace connection, select it from the list.
Otherwise, select New Google Workspace Connection and fill in the required fields:
Connection Name: Give the connection a recognizable name.
Service Account Subject Email: e.g. johndoe@yourcompany.com
Service Account Key JSON
To create the service account and the service account key JSON:
Domain-wide delegation must be enabled for the service account
The Alert Center API must be enabled on the Google Cloud project
The service account subject email is the email of the user who created the service account. It is NOT the service account email ending in @my-project.iam.gserviceaccount.com. The service account impersonates this user when polling from the API.
The service account must have the authorization scope https://www.googleapis.com/auth/apps.alerts
Click Next.
Choose the S3 Bucket where the raw Google Workspace logs should be stored.
(Optional) Enter a Key Prefix to organize the data path in your bucket.
Choose the Scanner Index where logs will be made searchable.
Leave the Source Label as google_workspace:alerts.
Click Next.
(Optional) Add additional transformation or enrichment steps if needed.
Click Next.
Leave the default setting: Extract timestamp from field createTime.
This field is included in every Google Workspace alerts log and reflects when the event occurred.
Click Next.
Review all configuration settings.
Click Create Source.
Once created:
Scanner will poll the Google Workspace Alert Center API every 5 minutes.
New events will be written to your S3 bucket, under the specified key prefix.
Logs will then be indexed for search and detections using your selected Scanner index.
Last updated
Was this helpful?
Was this helpful?