Skip to main content

Integrate CloudTrail, CloudWatch, and Guardduty with Google secops SIEM - Queries

  • January 19, 2026
  • 0 replies
  • 23 views

JFlorest
Forum|alt.badge.img

Good afternoon, I'm trying to integrate AWS CloudTrail, CloudWatch, and GuardDuty alerts with Google SIEM Secops. My question is, what are the differences between sending these logs to Amazon S3 or Firehose and then to Google SIEM? Is it possible to send the logs from these cloud resources directly via API without any intermediary? Why? What do you recommend?