All Apps and Add-ons

Is there a G Suite Splunk integration guide? (DESK-148)

summitsplunk
Communicator

Hello,

My IT Director has tasked me figuring out how to send our G Suite log data to Splunk. Is there any guides on how to do this?

1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

Yes, the app you linked to provides that. http://apps.splunk.com/app/2714 . The bigger question is, what logs are you looking for? The App includes instructions, and I'm working on the next version (targeting 2-4 weeks to release).

We can have more in-depth discussion on slack (http://splk.it/slack) and find me! OR email, or IrC. any works for me.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

Yes, the app you linked to provides that. http://apps.splunk.com/app/2714 . The bigger question is, what logs are you looking for? The App includes instructions, and I'm working on the next version (targeting 2-4 weeks to release).

We can have more in-depth discussion on slack (http://splk.it/slack) and find me! OR email, or IrC. any works for me.

rafaelkrealo
New Member

WARNING: This App could produce a fatal error into Splunk. This is what happen me.
"Unable to initialize modular input "ga_ss" Define in GsuiteForSplunk

0 Karma

rafaelkrealo
New Member

you are right, I have Splunk 8

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Are you using Splunk 8? It is not supported yet.

0 Karma

nieyf
New Member

@alacercogitatus,

Hi there, can I use this APP to retrieve the G Suite email audit logs and email header, like so on? so that we could use the logs to conduct the investigation for phishing, business email compromise...

Thanks.

0 Karma

nieyf
New Member

@alacercogitatus , can I use this app to retrieve the g suite email audit log into Splunk? seems it doesn't require gmail API...

thanks.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...