elastic / beats

:tropical_fish: Beats - Lightweight shippers for Elasticsearch & Logstash
https://www.elastic.co/products/beats
Other
12.07k stars 4.89k forks source link

[Filebeat][google_workspace] Support additional applications from reports API #33891

Open ynirk opened 1 year ago

ynirk commented 1 year ago

Describe the enhancement:

Filebeat google_workspace module only supports a subset of applications from Google Reports API. In order to gain visibility and have more detection capabilities, it would be nice to have the other applications available for ingestion:

Elastic Agent has a similar enhancement issue in https://github.com/elastic/integrations/issues/4722

Describe a specific use case for the enhancement or feature:

As a security analyst we like to have a full visibility on logs in case we need them for investigation. Also we can create new detection based on these new sources.

elasticmachine commented 1 year ago

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

sf-sharris commented 1 year ago

I would like that highlight that token is closely tied to the existing google_workspace audit sources and has security use cases on par with login type events.

jamiehynds commented 1 year ago

@sf-sharris we recently added some additional sources to our Workspace integration (via Elastic Agent). Additional sources included Access Transparency, Groups Enterprise, Mobile/Device, Oauth/Token and Context Aware Access.

https://github.com/elastic/integrations/issues/4722

elasticmachine commented 5 months ago

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)