Skip to main content
Solved

Integrate CloudTrail, CloudWatch, and Guardduty with Google secops SIEM - Queries

  • January 19, 2026
  • 1 reply
  • 26 views

JFlorest
Forum|alt.badge.img

Good afternoon, I'm trying to integrate AWS CloudTrail, CloudWatch, and GuardDuty alerts with Google SIEM Secops. My question is, what are the differences between sending these logs to Amazon S3 or Firehose and then to Google SIEM? Is it possible to send the logs from these cloud resources directly via API without any intermediary? Why? What do you recommend?

Best answer by Eoved

Hello,

There are differences between these integration methods (from a cost perspective, log latency, and more). You should follow the best practices recommended by the vendor to ensure your integration is up to date and that the logs are properly adjusted to the system (parse and ingest methods).

Please review the following guides:

Collect AWS CloudTrail logs

Collect AWS CloudWatch logs

Collect AWS GuardDuty logs

1 reply

Eoved
Forum|alt.badge.img+8
  • Bronze 2
  • Answer
  • January 20, 2026

Hello,

There are differences between these integration methods (from a cost perspective, log latency, and more). You should follow the best practices recommended by the vendor to ensure your integration is up to date and that the logs are properly adjusted to the system (parse and ingest methods).

Please review the following guides:

Collect AWS CloudTrail logs

Collect AWS CloudWatch logs

Collect AWS GuardDuty logs