Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Filebeat][google_workspace] Support additional applications from reports API #33891

Open
ynirk opened this issue Nov 30, 2022 · 4 comments
Open
Labels
enhancement Team:Security-Service Integrations Security Service Integrations Team

Comments

@ynirk
Copy link

ynirk commented Nov 30, 2022

Describe the enhancement:

Filebeat google_workspace module only supports a subset of applications from Google Reports API.
In order to gain visibility and have more detection capabilities, it would be nice to have the other applications available for ingestion:

Elastic Agent has a similar enhancement issue in elastic/integrations#4722

Describe a specific use case for the enhancement or feature:

As a security analyst we like to have a full visibility on logs in case we need them for investigation. Also we can create new detection based on these new sources.

@elasticmachine
Copy link
Collaborator

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@ghost
Copy link

ghost commented Mar 31, 2023

I would like that highlight that token is closely tied to the existing google_workspace audit sources and has security use cases on par with login type events.

@jamiehynds
Copy link

jamiehynds commented Apr 11, 2023

@sf-sharris we recently added some additional sources to our Workspace integration (via Elastic Agent). Additional sources included Access Transparency, Groups Enterprise, Mobile/Device, Oauth/Token and Context Aware Access.

elastic/integrations#4722

@elasticmachine
Copy link
Collaborator

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement Team:Security-Service Integrations Security Service Integrations Team
Projects
None yet
Development

No branches or pull requests

5 participants