Skip to content

Google Cloud Platform (GCP)

You can integrate Google Cloud Platform (GCP) with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

GCP product overview

Google Cloud Platform (GCP) is Google's suite of cloud computing services — including compute, Google Kubernetes Engine (GKE), storage, networking, and security — running on Google's global infrastructure.

What we ingest

Sophos XDR collects Google Cloud Platform logs via the Google Cloud Pub/Sub messaging service: you create a log sink in GCP that routes the selected logs to a Pub/Sub topic, which Sophos XDR ingests. The following log categories are collected:

  • Cloud audit activity: Google Cloud Audit Logs (Admin Activity).
  • Security findings: Google Security Command Center findings.
  • Network flows1: VPC Flow Logs and GKE Dataplane V2 network flows.

Event and data types

We ingest the following event and data types from GCP:

  • Cloud audit activity: Google Cloud Audit Logs (Admin Activity) — administrative and configuration operations across GCP services, including the caller identity, resource, and action. Normalized to cloud audit telemetry.
  • Security findings: Google Security Command Center (SCC) findings, including the finding category, severity, and affected resource. Normalized to third-party security alert telemetry.
  • Network flows1: VPC Flow Logs and GKE Dataplane V2 network flow records, including source and destination addresses and ports. Normalized to netflow telemetry.

Data provided by this integration

Data provided by GCP gets normalized to the following schemas:

  • cloudaudit
  • netflow 1
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview