-
Notifications
You must be signed in to change notification settings - Fork 514
Open
Labels
Integration:google_workspaceGoogle WorkspaceGoogle WorkspaceTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]
Description
Google has made recent changes to its admin log event schema, as described here.
These changes include modifications to some event names, event types, and log event frequency for the following Admin console settings:
Account & security
App access control
Google Drive settings with inherited values
Drive
Gmail
New Gmail parameters
New Gmail events
We should review the changes in case any modifications are needed to ECS mappings.
terrancedejesus
Metadata
Metadata
Assignees
Labels
Integration:google_workspaceGoogle WorkspaceGoogle WorkspaceTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]