Getting Data In

Get logs for G Suite

splunkcol
Builder

 

Hello,

My client requests to ingest G Suite logs, when searching I see several APPs which do not have Splunk support.

Question 1:
What should I understand when an APP does not have Splunk support?

Question 2:
What is the best way to ingest the GSuite logs?

 

https://splunkbase.splunk.com/app/3793/ or https://splunkbase.splunk.com/app/4560/ or https://splunkbase.splunk.com/apps/#/search/G%20Suite/

 

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @splunkcol 

I guess you should be looking for Google Workspace as Gsuite has been renamed. It depends what you want to ingest to Splunk and add-on supporting those logs to be ingested - Splunk Add-on For Google Workspace | Splunkbase this is a splunk supported add-on which i see doc link is broken you have to reachout splunk support for correct link and do a search to find out.

Non Splunk supported add-ons are mostly being developed by Individual developers they usually support it if you contact them in case of any issues with add-on and licensing terms vary free vs paid etc etc you have to read it.

Splunk supported add-ons you can reach out to Splunk support that's the difference in terms of support. Most of the add-ons are free unless there are premium you can find in splunkbase.

---

An upvote would be appreciated and Accept solution if this reply helps!

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...