<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I stream Google Workspace Vault logs into Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-stream-Google-Workspace-Vault-logs-into-Splunk/m-p/756917#M120069</link>
    <description>&lt;P&gt;The line &lt;STRONG&gt;application = vault&lt;/STRONG&gt; is the issue. It's not supported as a stanza in the TA. The link below has the supported values.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://splunk.github.io/splunk-add-on-for-google-workspace/Configureinputs2/" target="_blank" rel="noopener"&gt;Configure the Splunk Add-on for Google Workspace - Splunk Add-on for Google Workspace&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;That being said, what you could do is write a short script that uses the Google API to pull the Vault audit event into a custom input&lt;BR /&gt;&lt;A href="https://developers.google.com/workspace/admin/reports/v1/appendix/activity/vault?utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;Vault Audit Activity Events &amp;nbsp;|&amp;nbsp; Admin console &amp;nbsp;|&amp;nbsp; Google for Developers&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jan 2026 19:35:48 GMT</pubDate>
    <dc:creator>Wander</dc:creator>
    <dc:date>2026-01-02T19:35:48Z</dc:date>
    <item>
      <title>How can I stream Google Workspace Vault logs into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-stream-Google-Workspace-Vault-logs-into-Splunk/m-p/756913#M120068</link>
      <description>&lt;P&gt;I want to add vault logs to my inputs.conf for the Google Workspace TA. I added the following stanza&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[activity_report://VaultReport]
account = &amp;lt;company&amp;gt;
application = vault
index = gsuite
interval = 300
lookbackOffset = 14400
disabled = 0&lt;/LI-CODE&gt;&lt;P data-unlink="true"&gt;But I see the following error coming from the&amp;nbsp;/app/splunk/var/log/splunk/splunk_ta_google_workspace_VaultReport.log&amp;nbsp;&amp;nbsp; -&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Parameter "applicationName" value "" does not match the pattern "(access_transparency)|(admin)|(calendar)|(chat)|(chrome)|(context_aware_access)|(data_studio)|(drive)|(gcp)|(gplus)|(groups)|(groups_enterprise)|(jamboard)|(keep)|(login)|(meet)|(mobile)|(rules)|(saml)|(token)|(user_accounts)"&lt;/LI-CODE&gt;&lt;P&gt;How can I add vault logs to Splunk?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 18:21:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-stream-Google-Workspace-Vault-logs-into-Splunk/m-p/756913#M120068</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2026-01-02T18:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: How can I stream Google Workspace Vault logs into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-stream-Google-Workspace-Vault-logs-into-Splunk/m-p/756917#M120069</link>
      <description>&lt;P&gt;The line &lt;STRONG&gt;application = vault&lt;/STRONG&gt; is the issue. It's not supported as a stanza in the TA. The link below has the supported values.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://splunk.github.io/splunk-add-on-for-google-workspace/Configureinputs2/" target="_blank" rel="noopener"&gt;Configure the Splunk Add-on for Google Workspace - Splunk Add-on for Google Workspace&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;That being said, what you could do is write a short script that uses the Google API to pull the Vault audit event into a custom input&lt;BR /&gt;&lt;A href="https://developers.google.com/workspace/admin/reports/v1/appendix/activity/vault?utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;Vault Audit Activity Events &amp;nbsp;|&amp;nbsp; Admin console &amp;nbsp;|&amp;nbsp; Google for Developers&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 19:35:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-stream-Google-Workspace-Vault-logs-into-Splunk/m-p/756917#M120069</guid>
      <dc:creator>Wander</dc:creator>
      <dc:date>2026-01-02T19:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: How can I stream Google Workspace Vault logs into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-stream-Google-Workspace-Vault-logs-into-Splunk/m-p/756988#M120074</link>
      <description>&lt;P&gt;While the app that you tagged does not support Vault ingest, checkout&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/5498" target="_blank"&gt;https://splunkbase.splunk.com/app/5498&lt;/A&gt;&amp;nbsp;that does have an input for Vault, among others. Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2026 15:17:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-stream-Google-Workspace-Vault-logs-into-Splunk/m-p/756988#M120074</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2026-01-05T15:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: How can I stream Google Workspace Vault logs into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-stream-Google-Workspace-Vault-logs-into-Splunk/m-p/757190#M120112</link>
      <description>&lt;P&gt;Thank you so much&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/3514"&gt;@alacercogitatus&lt;/a&gt;, I installed it, and Vault data is being streamed in. One thing I don't understand is how do they relate to each other? Should I switch all sourcetypes to &lt;A href="https://splunkbase.splunk.com/app/5498" target="_blank"&gt;https://splunkbase.splunk.com/app/5498&lt;/A&gt;&amp;nbsp;or keep only Vault on this one?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 17:19:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-stream-Google-Workspace-Vault-logs-into-Splunk/m-p/757190#M120112</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2026-01-12T17:19:56Z</dc:date>
    </item>
  </channel>
</rss>

