Hi Khul Sat,
Hope you are doing well. Thank you for using Wazuh.
Currently we do not have a direct integration with Gsuite or rules and decoders for these logs.
A workaround can be, you could route the audit logs for Google Workspace to Google Cloud following the following guide:
https://cloud.google.com/logging/docs/audit/configure-gsuite-audit-logs
and then use Wazuh to monitor GCP services: https://documentation.wazuh.com/current/gcp/index.html
Once you have everything configured, you would have to create your own rules and decoders. You have a guide on how to do it in our documentation: https://documentation.wazuh.com/current/user-manual/ruleset/custom.html
As you can see, this process is time consuming, so it has been decided to add Google Suite integration to Wazuh out of the box. Also, here's an issue in our repository where you can track the progress of this new feature and some implementations that different users have made.
I hope you find this information helpful.
Regards
Md. Nazmur Sakib
Hi Khul Sat,
Sorry for the late response.
We do not have a direct integration with GSuite or rules and decoders for these logs. We have an issue in our roadmap to incorporate it: https://github.com/wazuh/wazuh/issues/10776
In this issue, you can track the progress of this new feature.
I hope you find this information helpful.
Regards
Md. Nazmur Sakib
joining this question - any news regarding this question?