You're viewing version 2.13 of the OpenSearch documentation. This version is no longer maintained. For the latest version, see the current documentation. For information about OpenSearch version maintenance, see Release Schedule and Maintenance Policy.
Google Workspace
The gworkspace
log type monitors Google Workspace log entries, such as the following:
- Admin actions
- Group and group membership actions
- Events related to logins
The following code snippet contains all the raw_field
and ecs
mappings for this log type:
"mappings": [
{
"raw_field":"eventSource",
"ecs":"google_workspace.admin.service.name"
},
{
"raw_field":"eventName",
"ecs":"google_workspace.event.name"
},
{
"raw_field":"new_value",
"ecs":"google_workspace.admin.new_value"
}
]