Google Cloud Platform (GCP)
You can integrate Google Cloud Platform (GCP) with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
GCP product overview
Google Cloud Platform (GCP) is Google's suite of cloud computing services — including compute, Google Kubernetes Engine (GKE), storage, networking, and security — running on Google's global infrastructure.
What we ingest
Sophos XDR collects Google Cloud Platform logs via the Google Cloud Pub/Sub messaging service: you create a log sink in GCP that routes the selected logs to a Pub/Sub topic, which Sophos XDR ingests. The following log categories are collected:
- Cloud audit activity: Google Cloud Audit Logs (Admin Activity).
- Security findings: Google Security Command Center findings.
- Network flows1: VPC Flow Logs and GKE Dataplane V2 network flows.
Event and data types
We ingest the following event and data types from GCP:
- Cloud audit activity: Google Cloud Audit Logs (Admin Activity) — administrative and configuration operations across GCP services, including the caller identity, resource, and action. Normalized to cloud audit telemetry.
- Security findings: Google Security Command Center (SCC) findings, including the finding category, severity, and affected resource. Normalized to third-party security alert telemetry.
- Network flows1: VPC Flow Logs and GKE Dataplane V2 network flow records, including source and destination addresses and ports. Normalized to netflow telemetry.
Data provided by this integration
Data provided by GCP gets normalized to the following schemas:
cloudauditnetflow1thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.
Vendor documentation
- What is Pub/Sub?
- Cloud Audit Logs
- Security Command Center Findings
- Collate and route organization- and folder-level logs to supported destinations
- About resource hierarchy
- Overview of activating Security Command Center
- Activate Security Command Center for a project
-
Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview. ↩↩↩