Skip to main content

Google Cloud Logging

Download With Dependencies

Google Cloud Logging is a managed logging solution provided by Google Cloud Platform (GCP) that allows users to collect, store, search, analyze, and monitor logs generated by GCP services, third-party applications, and custom applications running on GCP.

What does this pack do

The Google Cloud Logging Cortex XSOAR pack helps users to centralize all their GCP logs in a single location, making it easier to troubleshoot issues and gain insights from their data.

Google Cloud Logging Integration

The Google Cloud Logging Integration enables you to retrieve selected log entries that originated from a project/folder/organization/billing account. See the Google Cloud Logging integration documentation for additional details.

What does this pack do

The Google Cloud Logging Cortex XSIAM pack helps users to centralize all their GCP logs in a single location, making it easier to troubleshoot issues and gain insights from their data.

Google Cloud Logging Integration

The Google Cloud Logging Integration enables you to retrieve selected log entries that originated from a project/folder/organization/billing account. See the Google Cloud Logging integration documentation for additional details.

Google Cloud Logging SIEM Content

The SIEM content includes Cortex Data Modeling (XDM) Rules and Parsing Rules which are applied on Google Cloud Audit Logs and Google Cloud DNS Query Logs that are ingested into the google_cloud_logging_raw and google_dns_raw datasets (respectively) via the Google Cloud Platform Pub/Sub data source on Cortex XSIAM. See Ingest Logs and Data from a GCP Pub/Sub for additional details.

Remarks

  • When configuring a sink to route Google Cloud logs to the Pub/Sub service as described here, you may wish to create an inclusion filter to include only a subset of the logs. See filter examples here and samples below:
     logName:"cloudaudit.googleapis.com"
    log_id("dns.googleapis.com/dns_queries") 

PUBLISHER

PLATFORMS

Cortex XSOARCortex XSIAM

INFO

CertificationRead more
Supported ByCortex
CreatedMay 16, 2023
Last ReleaseNovember 18, 2024
WORKS WITH THE FOLLOWING INTEGRATIONS:

DISCLAIMER
Content packs are licensed by the Publisher identified above and subject to the Publisher’s own licensing terms. Palo Alto Networks is not liable for and does not warrant or support any content pack produced by a third-party Publisher, whether or not such packs are designated as “Palo Alto Networks-certified” or otherwise. For more information, see the Marketplace documentation.