Skip to main content
Question

Google admin console ingestion to SecOps platform

  • May 23, 2026
  • 3 replies
  • 37 views

Mii_star
Forum|alt.badge.img

Hello I am new to the sscops world and my mentor tasked me with integrating the successful and unsuccessful login attempts from the admin console to SecOps platform.

 

I know that we can export the login logs as a csv file, is there any automated way where we can like send these logs to the cloud console for the eecops directly or at least the logs explorer

 

Thank you!

3 replies

GromeroSec
Forum|alt.badge.img+1
  • Bronze 1
  • May 23, 2026

Hello !! You have two supported ways to ingest Google Cloud audit logs into Google SecOps:

  1. Direct ingestion
    Best when you want near real-time forwarding for supported Google Cloud log types, including Cloud Audit Logs. This is the simplest option if you just want Google Cloud service logs sent directly to SecOps from the moment the filter is configured.

  2. Cloud Storage
    Best when you want more control before ingestion, especially filtering or reducing volume before logs reach SecOps. Cloud Logging routes logs to GCS, and Google SecOps ingests them from there on a schedule.

For Cloud Audit Logs, I’d usually start with direct ingestion unless you specifically need pre-filtering or volume control.

Google’s doc here covers both methods and when to use each:
https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/ingest-gcp-logs


Mii_star
Forum|alt.badge.img
  • Author
  • New Member
  • May 24, 2026

Hello !! You have two supported ways to ingest Google Cloud audit logs into Google SecOps:

  1. Direct ingestion
    Best when you want near real-time forwarding for supported Google Cloud log types, including Cloud Audit Logs. This is the simplest option if you just want Google Cloud service logs sent directly to SecOps from the moment the filter is configured.

  2. Cloud Storage
    Best when you want more control before ingestion, especially filtering or reducing volume before logs reach SecOps. Cloud Logging routes logs to GCS, and Google SecOps ingests them from there on a schedule.

For Cloud Audit Logs, I’d usually start with direct ingestion unless you specifically need pre-filtering or volume control.

Google’s doc here covers both methods and when to use each:
https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/ingest-gcp-logs

is there any way where i can ingest the login logs directly from the admin console https://admin.google.com/, i know we can export the login logs as a csv but this is not practical?


cmorris
Staff
Forum|alt.badge.img+13
  • Staff
  • May 24, 2026

That admin console is for Google Workspace, is that what you are trying to ingest? If so, you can configure via these docs - https://docs.cloud.google.com/chronicle/docs/ingestion/default-parsers/workspace-activity