Skip to main content
Question

Google workspace connection

  • July 28, 2025
  • 6 replies
  • 75 views

yasinmnk
Forum|alt.badge.img+7

Hi,

One of our customers has two different tenants in their workspace. They would like to send logs to Google SecOps, but only from one of the tenants.
Is there a solution to filter the logs or any alternative approach to achieve this?

6 replies

Eoved
Forum|alt.badge.img+8
  • Bronze 1
  • July 29, 2025

You can set up a feed connection to the specific tenant you want and label it for advanced filtering:
https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-workspace-logs


yasinmnk
Forum|alt.badge.img+7
  • Author
  • Bronze 3
  • August 1, 2025

@Eoved 
Thanks for your answer. I know this solution but i need to set filter before i send the logs to secops, there are two tenants in our workspace and we dont want to ingest all them!


Florian11_2
Forum|alt.badge.img+1
  • Bronze 1
  • November 18, 2025

@yasinmnk Hi,

I see multiple customers having this issue, have you been able to resolve it, I say posts from you ingesting via BigQuery, did that resolve your topic?

 

Thank you


yasinmnk
Forum|alt.badge.img+7
  • Author
  • Bronze 3
  • November 18, 2025

Hi ​@Florian11_2  Unfortunately there is no solution if you want to ingest via feed i have tried to filter logs in bigquery but it was unsuccesfull , you can either seperate the tenants or use Bindplane to use regex filters, where you can set filter to send only the logs that you want.


cmmartin_google
Staff
Forum|alt.badge.img+11

There is a private preview feature - https://docs.cloud.google.com/chronicle/docs/ingestion/data-processing-pipeline - which enables you to filter logs (prior to ingestion and charging) so as long as there is an org or OU id in the workspace logs (which I’m pretty sure there is) you can filter


stefancoook1
Forum|alt.badge.img+2
  • Bronze 3
  • November 18, 2025

@cmmartin_google is there any tutorial or walkthrough you can point to for how to filter specifically workspace logs using this method? This is a question that’s come up a lot