Google Workspace Alerts
Step 1: Create a New Source
In the Scanner UI, go to the Collect tab.
Click Create New Source.
Click Select a Source Type.
Choose Google Workspace.
Choose Google Workspace: Alerts
You’ll be prompted to choose an Ingest Method:
Select API Pull.
Then, choose a Destination: Select Scanner.
Click Next.
Step 2: Configure the Source
Set a Display Name, such as my-google-workspace-alerts-logs.
Click Next.
Step 3: Authenticate with Google Workspace
If you’ve previously created an Google Workspace connection, select it from the list.
Otherwise, select New Google Workspace Connection and fill in the required fields:
Connection Name: Give the connection a recognizable name.
Service Account Subject Email: e.g.
[email protected]Service Account Key JSON
To create the service account and the service account key JSON:
Domain-wide delegation must be enabled for the service account
The Alert Center API must be enabled on the Google Cloud project
The service account subject email is the email of the user who created the service account. It is NOT the service account email ending in
@my-project.iam.gserviceaccount.com. The service account impersonates this user when polling from the API.The service account must have the authorization scope
https://www.googleapis.com/auth/apps.alerts
Click Next.
Step 4: Configure the Destination
Choose the S3 Bucket where the raw Google Workspace logs should be stored.
(Optional) Enter a Key Prefix to organize the data path in your bucket.
Choose the Scanner Index where logs will be made searchable.
Leave the Source Label as
google_workspace:alerts.
Click Next.
Step 5: Transform and Enrich
(Optional) Add additional transformation or enrichment steps if needed.
Click Next.
Step 6: Timestamp Extraction
Leave the default setting: Extract timestamp from field createTime.
This field is included in every Google Workspace alerts log and reflects when the event occurred.
Click Next.
Step 7: Review and Create
Review all configuration settings.
Click Create Source.
What Happens Next
Once created:
Scanner will poll the Google Workspace Alert Center API every 5 minutes.
New events will be written to your S3 bucket, under the specified key prefix.
Logs will then be indexed for search and detections using your selected Scanner index.
Last updated
Was this helpful?