The Add-on typically imports and enriches data from Google SCC SDK, creating a rich data set ready for direct analysis or use in an App. The GoogleSCC Add-on for Splunk will provide the below functionalities:
- Collect sources data, findings data, assets data and audit logs from Google SCC SDK and store in Splunk indexes.
- Categorize the data in different sourcetypes.
- Parse the data and extract important fields