All Apps and Add-ons

Google G Suite Audit logs collection

ali_alnajjar_ve
Explorer

Hello Splunkers,

We're going to collect Google G Suite Audit logs into our on-primes Splunk deployment.

I can see in the Splunk Add-on for Google Cloud Platform documentation (https://docs.splunk.com/Documentation/AddOns/released/GoogleCloud/Configureinputsv6topics) that it's doable through Splunk HEC, and in this case it requires a Splunk instance that faces the Internet with static public IP Address. but we don't recommend this approach because its complexity.

My question is, can we pull the G Suite Audit logs by other means, I mean can the Audit logs be forwarded to Google Pub/Sub subscription and we pull them from the TA input Cloud Pub/Sub 

Regards,

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Alpha Launch: AI-Assisted Auto-Schematization for CIM

Streamlining Data Onboarding: Announcing the Alpha Release of AI-Assisted Auto-Schematization For many Splunk ...

Enterprise Security(ES) Essentials or Premier? Let's discuss Splunk ES Editions on ...

  Hi everyone, Last year at .conf25, we shared something exciting: Splunk Enterprise Security is evolving ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 5

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...