Ingest logs and data from Google Workspace - Ingest logs and data from Google Workspace for use in Cortex XDR. - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Ingest logs and data from Google Workspace for use in Cortex XDR.

Notice

Requires the ITDR Module add-on and Data Collection add-on.

Cortex XDR can ingest various types of data from Google Workspace. Most data is collected as audit events from various Google reports using the Google Workspace data collector.

To receive logs from Google Workspace for any of the data types except emails, you must first enable the Google Workspace Admin SDK API with a user with access to the Admin SDK Reports API. For emails, you must set up a compliance email account as explained in the prerequisite steps below and then enable the Google Workspace Gmail API.

Once implemented, you can then configure the Data Sources & Integrations settings in Cortex XDR. After you set up data collection, Cortex XDR begins receiving new logs and data from the source.