Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Question: google admin activity log #584

Closed
weichea opened this issue Oct 16, 2019 · 10 comments
Closed

Question: google admin activity log #584

weichea opened this issue Oct 16, 2019 · 10 comments
Labels
mapping Mappings from various sources to ECS

Comments

@weichea
Copy link

weichea commented Oct 16, 2019

Hello

Has anyone mapped out the google admin activity log to ecs schema? If yes, could you share it?

@webmat webmat added the mapping Mappings from various sources to ECS label Oct 22, 2019
@jamiehynds
Copy link
Contributor

@weichea The GSuite admin activity log is something we'd like to support in Elastic SIEM. Did you ever get around to mapping the events to ECS?

@weichea
Copy link
Author

weichea commented May 5, 2020

@jamiehynds Yea, we have mapped out some of the gadmin fields. Whats the best way for us share this?

@jamiehynds
Copy link
Contributor

jamiehynds commented May 5, 2020

If you could drop me an email it'd be great. Worth noting that we're not currently working on GSuite support, but would love to see the mappings you've done to date. Thanks!

@webmat
Copy link
Contributor

webmat commented May 5, 2020

A good way to capture these mappings could be via an online spreadsheet that you share publicly here (if you'r comfortable with that).

The column names could be like the ones supported by this experimental tool ecs-mapper. So "source_field", "destination_field", and a few more if needed (see the CSV Format heading).

@weichea
Copy link
Author

weichea commented May 9, 2020

@webmat let me check on the ecs-mapper.

Just a quick update, I'm getting approval internally before I can share the mapping. Shouldn't have any issue, hopefully I can get back next week.

@ebeahan
Copy link
Member

ebeahan commented Jul 13, 2020

Hi @weichea. It's been a bit, but wondering if you were able to obtain necessary approval to share your mappings?

@jamiehynds
Copy link
Contributor

@weichea kindly provided Gsuite mappings to me via email. We are currently working on a new Beats module for GSuite, tracking here elastic/beats#19769

@weichea
Copy link
Author

weichea commented Jul 14, 2020

@jamiehynds I have already sent it to you back in May... Do you want me to resend it?

@jamiehynds
Copy link
Contributor

All good @weichea - I still have it. Thanks again :)

@ebeahan
Copy link
Member

ebeahan commented Jul 14, 2020

Excellent - thanks both for following up @jamiehynds @weichea !

@ebeahan ebeahan closed this as completed Jul 14, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
mapping Mappings from various sources to ECS
Projects
None yet
Development

No branches or pull requests

4 participants