Google Workspace Profiles (Beta)
Fetch and store Google Workspace user data to use in detections and search
Last updated
Was this helpful?
Fetch and store Google Workspace user data to use in detections and search
Last updated
Was this helpful?
You can configure your Google Workspace log source integration in Panther to pull user profiles into Panther-managed Lookup Tables. This means you can use profile data in detection logic and search queries.
You can customize user profiles in Google Workspaces by following . You might consider adding custom attributes that would be useful in detection logic, such as the level of permissions expected for that user.
To view the data stored in your Google Workspace profile tables, follow .
You can configure Google Workspace user profiles while you are initially setting up your Google Workspace log source integration in Panther, or later, by editing the source.
During either flow, you'll toggle the Google Workspace profile pulling setting on, then set the cadence at which you'd like profile data to be refreshed.
In order to pull Google Workspace user profiles into Panther, the following configurations must be set:
Your Google Workspace Cloud App must have the https://www.googleapis.com/auth/admin.directory.user.readonly
scope.
The user who created the Google Cloud App must have read users privileges.
Follow , paying close attention to the Enable user profiles field.
To set up Google Workspace profiles after you've already created an Google Workspace log source in Panther:
In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.
Locate the Google Workspace log source for which you'd like to set up user profiles, and click its name.
On the Configure page for your Google Workspace log source, click the Enable user profiles and/or Enable device profiles checkboxes.
In the upper-right corner, click Save.
Panther supports pulling user profiles from Google Workspace.
In the upper right corner of the log source page, click Configuration, then Edit.
For each profile you enable, set the Refresh period (min) value. This represents the cadence at which Panther will update profile data with what is stored in Google Workspace.