Configure Google Workspace cloud for Arctic Wolf monitoring
You can configure Google Workspace® to send the necessary logs to Arctic Wolf® for security monitoring.
Note:
Google Workspace endpoints can have a reporting latency of up to 4 hours between when an event is created on a monitored system and when the logs are available for Arctic Wolf to analyze. See Data retention and lag times for more information.
These resources are required:
Super administrator permissions in the workspace that you want Arctic Wolf to monitor.
Note:
Arctic Wolf requires an administrator username, but not the associated password, because the service account created for Arctic Wolf monitoring impersonates this administrator when interacting with the Google Admin SDK Reports API to retrieve Google Workspace events. See Perform Google Workspace Domain-Wide Delegation of Authority for more information.
In the Open project picker menu, , select the organization that you want Arctic Wolf to monitor, and then click New project.
On the New Project page, configure these settings:
Project name — Enter a short, descriptive name. For example, Arctic Wolf Monitoring.
Project ID — (Optional) To edit the Project ID, in the Project name field, select the Edit option, and then replace the automatically generated value with a unique identifier.
Organization — Make sure that the selected option is the organization you want Arctic Wolf to monitor.
Location — (Optional) Select Browse, and then select a location.
Tip:
You can select a parent organization or folder that is different from the organization that you want to monitor.
Copy the Project ID, and then save it in a safe, encrypted location. You will provide it to Arctic Wolf later.
In the Open project picker menu, , verify that these items are selected:
The organization that you want Arctic Wolf to monitor.
The project that you created previously. For example, Arctic Wolf Monitoring.
In the navigation menu, click IAM & Admin > Service Accounts.
Click + Create service account.
In the Create service account section, configure these settings:
Service account name — Enter a short, descriptive name. For example, arctic-wolf-service-account.
Service account ID — (Optional) Enter a unique ID for the service account. For example, arcticwolfmonitoring.
Tip:
A unique value is automatically generated when you specify a service account name.
Service account description — (Optional) Enter a description for the service account. For example, Used for Arctic Wolf monitoring.
Click Create and continue.
In the Grant this service account access to project (optional) section, keep the role field empty.
Click Continue.
In the Grant users access to this service account (optional) section, keep the Service account users role and Service account admins role fields empty.
Click Done.
The service account is now listed on the Service accounts page.
On the Service Accounts page, for the service account that you created, complete these steps:
Click Actions > Manage keys.
In the Add key list, select Create new key.
In the dialog, select the JSON option.
Click Create.
The JSON file containing the service account credentials automatically downloads to your computer.
Copy the JSON filename and path to a safe, encrypted location to provide to Arctic Wolf later.
Enable domain-wide delegation
On the Service Accounts page, complete these steps for the service account that you created:
Click Actions > Manage details.
Click Advanced settings, and then scroll to the Domain-wide Delegation section.
Note:
A Google Workspace Marketplace OAuth Client is not required.
Copy the Client ID value to a safe, encrypted location. You will use it in a later step.
Wait 5-10 minutes after adding OAuth scopes before proceeding to the next step.
Provide Google Workspace credentials to Arctic Wolf
Note:
Time-based events are polled with a delay to make sure that data is available. For new deployments, Arctic Wolf begins polling and reviewing activity from approximately one hour prior to configuration success. If API credentials fail, for example due to expired credentials, Arctic Wolf notifies you and requests a new set of credentials. After receiving refreshed credentials, Arctic Wolf can only retrieve data from the previous 12 hours. Provide refreshed credentials within 12 hours of expiry to enable complete data polling and coverage.
In the navigation menu, click Data Collection > Cloud Sensors.
Click Add Account +.
On the Add Account page, clickGoogle Workspace.
Configure these settings:
Account Name — Enter a unique and descriptive name for the account.
Admin username — Enter the username of the super administrator account, in the form of an email address. To find this username, click your user icon in the top-right corner of the Google Admin Console.
JSON credential file section — Click Choose File, and then upload the JSON file that you downloaded as part of Create a service account.
Credential Expiry — (Optional) Enter the credential expiration date, if applicable.
Click Test and submit credentials.
Cloud Detection and Response (CDR)Integrations and Log ForwardingGoogle CloudManaged Detection and Response (MDR)Installation or ConfigurationPublic