Hello,
I’m trying to figure out if it's possible to send all Google Workspace audit logs to Google Cloud Platform (GCP)
I want to combine all logs (GCP + all Workspace services) into a single Pub/Sub connection so we can send them to the SIEM.
We need more information.
Are you saying to want to send data collected by Splunk to GCP? Is that all data or just some of it?
Can you be more specific about the destination? Saying "GCP" is like saying "AWS". Both offer a large number of services with different requirements and capabilities.
What is your SIEM?
It may be necessary to write code that uses the API to fetch data and then ship it to GCP.