Skip to main content

Filter Workspace Logs

  • June 30, 2025
  • 2 replies
  • 26 views

kaushalpatel
Forum|alt.badge.img+5

Is there a way to filter the workspace logs and reduce it before sending it to secops ?
It is consuming too much storage of the tenant storage limit.

2 replies

hzmndt
Staff
Forum|alt.badge.img+9
  • Staff
  • July 1, 2025

@kaushalpatel 

If using direct ingestion, today no filtering option but you can use feed to ingest, see below: 

https://cloud.google.com/chronicle/docs/ingestion/cloud/workspace-to-chronicle

Note: Direct ingestion collects a wider range of workspace data compared to other feed methods. For example, other feed methods cannot ingest gmail application logs.
However, you can still use these other feed methods to ingest subsets of Google Workspace data, for example, to ingest WORKSPACE_USERS and WORKSPACE_GROUPS into your Google SecOps instance. For more information, see Configure a feed in Google SecOps to ingest Google Workspace logs.


kaushalpatel
Forum|alt.badge.img+5
  • Author
  • New Member
  • July 2, 2025

@kaushalpatel 

If using direct ingestion, today no filtering option but you can use feed to ingest, see below: 

https://cloud.google.com/chronicle/docs/ingestion/cloud/workspace-to-chronicle

Note: Direct ingestion collects a wider range of workspace data compared to other feed methods. For example, other feed methods cannot ingest gmail application logs.
However, you can still use these other feed methods to ingest subsets of Google Workspace data, for example, to ingest WORKSPACE_USERS and WORKSPACE_GROUPS into your Google SecOps instance. For more information, see Configure a feed in Google SecOps to ingest Google Workspace logs.


@hzmndt 
I am looking to filter logs for WORKSPACE_ACTIVITY
I am currently using feed but it does not have option to remove any workspace log evetns.

Is there a option like removing specific log events before sending it to secops , like we do in GCP Log Export filter ?