Hi everyone,
We're ingesting Google Workspace logs into Google SecOps using feed-based ingestion (Method 2, Third Party API). Most Workspace feeds work, but we have two issues:
1. WORKSPACE_ALERTS only brings in a small subset of the alerts shown in the Workspace Alert Center.
2. WORKSPACE_CHROMEOS shows "Completed" but no data is ingested at all.
Environment
- Google SecOps (SIEM + SOAR), region: asia-southeast1
- Google Workspace editions: Enterprise Starter, Business Starter, Frontline Starter (no Enterprise Standard/Plus)
- Other subscriptions: Chrome Enterprise Core, Chrome Enterprise Premium, Google Meet hardware, Cloud Identity Free
- Auth: GCP service account + domain-wide delegation, impersonating a dedicated Workspace admin user
What's configured
- APIs enabled in the GCP project: Admin SDK API, Alert Center API
- Domain-wide delegation for the service account with all 7 documented scopes, including:
- https://www.googleapis.com/auth/apps.alerts
- https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly
- Impersonation user (JWT subject) has: [Super Admin / custom role with Alert Center > Full access > View access and Chrome Management > Settings]
- Customer ID: WITHOUT the leading "C" for WORKSPACE_ALERTS, WITH the "C" for all other feeds
- All feeds use the same credentials (JWT issuer, subject, private key)
What works
- WORKSPACE_ACTIVITY: 30,000+ events/day, normalized and searchable in UDM
- WORKSPACE_USERS, WORKSPACE_GROUPS, WORKSPACE_PRIVILEGES: ingesting as entity context data
- Ingestion dashboard shows 0 parsing, validation and indexing errors for all Workspace log types
Issue 1: WORKSPACE_ALERTS (partial data)
- Feed status is "Completed" and some alerts arrive, but only ActivityRule alerts and user password change alerts, about [6] per day
- In the same period, the Workspace Alert Center shows [X] alerts, including these types that never reach SecOps: [e.g., Suspicious login, Leaked password, Device compromised, ...]
- We excluded GMAIL_BLOCK_MESSAGE, which we know is not exported by the Alert Center API
- Each ingested alert also appears as two UDM events a few milliseconds apart, split across two namespaces. Only one WORKSPACE_ALERTS feed is active [confirm this].
Issue 2: WORKSPACE_CHROMEOS (no data)
- Feed status is "Completed" with a recent "Last succeeded on" time
- WORKSPACE_CHROMEOS does not appear at all in the Data Ingestion and Health dashboard, and returns nothing in entity (graph) search
- In the Admin console, Devices > Chrome > Devices shows [N] enrolled
- ChromeOS devices [including Meet hardware devices, if any]
Questions
1. Does the WORKSPACE_ALERTS feed ingest all Alert Center alert types, or only a subset? Are there other unsupported alert types besides GMAIL_BLOCK_MESSAGE?
2. Does the impersonation user need Super Admin to see all alert types and ChromeOS devices through the APIs, or are the documented custom role privileges enough?
3. Does the WORKSPACE_ALERTS feed backfill existing alerts, or only alerts created after the feed is set up?
4. Is it expected for one Workspace alert to produce two UDM events, or does that point to a duplicate feed or parser behavior?
5. For WORKSPACE_CHROMEOS, is the feed expected to return data when the only enrolled ChromeOS devices are [Meet hardware / N devices]? Is there a known way to confirm what the feed is receiving when it shows "Completed" but nothing is ingested?
Any guidance or similar experiences would be appreciated. Thank you!

