Google Cloud Platform - Learn more about the Google Cloud Platform standard data source and content pack integrations in Cortex XDR. - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-04
Category
Administrator Guide
Abstract

Learn more about the Google Cloud Platform standard data source and content pack integrations in Cortex XDR.

You can configure collecting Google Cloud Platform (GCP) logs using a standard data source, Cloud Service Provider (CSP) onboarding data source, or with a content pack integration:

Google Cloud Platform vendor

Description

Standard data source overview

If you use the Pub/Sub messaging service from Google Cloud Platform (GCP), forward logs and data to Cortex XDR from your GCP instance using the Google Cloud Platform data source.

Link to standard data source instructions

The following types of logs can be ingested from Google Cloud Platform:

  • Audit logs, including Google Kubernetes Engine (GKE) audit logs.

  • Generic logs

  • Google Cloud DNS logs

  • Network flow logs

For more information, see Ingest logs and data from a GCP Pub/Sub.

Link to full configuration Cloud Service Provider (CSP) onboarding data source instructions

Onboard Google Cloud PlatformOnboard Google Cloud Platform

Link to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XDR NG SIEM, Cortex XDR Enterprise license, and Cortex XDR Enterprise+ licenses.

Onboard Google Cloud Platform with basic configurationOnboard Google Cloud Platform with basic configuration

Links to content pack/ integration details

The Google Cloud Pub / Sub content pack integrates with the Google Cloud Pub / Sub messaging service to enable you to send and receive messages between independent applications. It contains the following integration:

  • Google Cloud Pub/Sub: Use this integration to enable automated security operations and issue response through a series of dedicated commands that manage messaging topics, subscriptions, and message flow. For example, there are commands for listing, creating, updating, and deleting topics and subscriptions, publishing messages, and manually pulling or seeking messages for processing.

This integration requires specific elevated permissions such as Project-Owner or Pub/Sub Admin,