Google Cloud Audit Integration via API

Overview

To view Google Cloud Audit (Cloud Logging) logs through the Logsign Unified SecOps Platform, you will need to create a Google Cloud service account and use its credentials to add the source in Logsign.

Prerequisites

  • Logsign Unified SecOps Platform 6.4.21+ versions support this integration.
  • An authorized user who can access the Google Cloud Console management panel and take actions (create a service account, enable an API).

Configure On Google Cloud Audit

  1. Access the Google Cloud Console with a user that has Administrator authorization.
  2. Create a project, or select an existing project, for which you want to pull Google Cloud Audit Logs. Write down the project ID — you will need it in Logsign.
  3. Go to APIs & Services > Library, search for the Cloud Logging API, and enable it. This is the API used to access Audit Logs.
  4. Go to IAM & Admin > Service Accounts and create a new service account.
    • Name: any descriptive name you want (for example, auditapi).
    • Role: grant the Logs Viewer role, or Logs Admin if more extensive access is required. This is what allows the service account to read audit logs.
  5. Select Manage Keys from the Actions menu next to the service account you created, then create a new key and download it in JSON format. This file is used for authentication when calling the API.

Add Device in Logsign USO

Log into Logsign Unified SecOps Platform, click Settings in the top menu, then Data Collection on the left to view the sources already added. Click + Device to begin adding a source, and fill in the fields below using the values from the JSON key file you downloaded.

FieldRequiredDescription
Client EmailYesThe client_email value from the downloaded JSON key file.
Private KeyYes (on creation)The private_key value from the JSON key file. When editing an existing source, this can be left blank to keep the currently stored key.
Project IDYesThe Google Cloud project ID you noted in Step 2 above.
Verify SSLNoUnchecked by default. When left unchecked, the poller does not validate Google's TLS certificate when calling the Cloud Logging API. Enable it if your environment requires strict certificate validation; leaving it unchecked does not affect data collection under normal conditions.

Click Check Connection to verify the credentials before saving. Once the source is added, you can observe audit logs in Logsign USO and build reports and searches based on the incoming events.

Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.