Skip to main content

Unable to find spam classification from logs sent to Google Secops SIEM from Google workspace

  • June 5, 2025
  • 3 replies
  • 27 views

devashishsingh
Forum|alt.badge.img+3

Hey,

I am unable to find spam classification from Google workspace activity logs ingested to our Google Secops SIEM. Is there're any related field that I need to look into or any additional configuration required to fetch it?

Delivered to Gmail mailbox
Spam classification details:
The message was considered suspicious.
The message contains suspicious content.

It's retrieved from admin.google.com > reporting > Email log search

3 replies

Eoved
Forum|alt.badge.img+8
  • Bronze 1
  • June 10, 2025

Hi ,
How do you perform log collection from Google Workspace? Are you using direct ingestion as described in the following link?
 https://cloud.google.com/chronicle/docs/ingestion/cloud/workspace-to-chronicle
Or are you collecting Google Workspace logs by setting up a SecOps feed, as shown here?
https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-workspace-logs
From my experience, direct ingestion provides more data than the feed (for example :feed methods cannot ingest gmail application logs) — this is also what’s recommended in the documentation:




devashishsingh
Forum|alt.badge.img+3

Hi ,
How do you perform log collection from Google Workspace? Are you using direct ingestion as described in the following link?
 https://cloud.google.com/chronicle/docs/ingestion/cloud/workspace-to-chronicle
Or are you collecting Google Workspace logs by setting up a SecOps feed, as shown here?
https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-workspace-logs
From my experience, direct ingestion provides more data than the feed (for example :feed methods cannot ingest gmail application logs) — this is also what’s recommended in the documentation:




We use direct ingestion, yet I do not have much of it. Anyway, I have a support ticket opened for this case. If I hear back anything from them, will update here.


Forum|alt.badge.img+4
  • Bronze 3
  • June 17, 2025

can you give a try for the UDM field: 

https://cloud.google.com/chronicle/docs/reference/udm-field-list#securityresultsecuritycategory
SecurityResult.SecurityCategory = "MAIL_SPAM"

maybe something like this:

metadata.vendor_name = "Google Workspace"
security_result.category = "MAIL_SPAM"