Cloud platforms
PlannedGoogle Cloud audit logs
By Google
Admin activity and data access audit logs from Google Cloud projects.
What you can connect
Capabilities and availability
Each capability has its own setup and status. Review the details before enabling it for your organisation.
Log collection
PlannedSetup is not available yet
Polling Google Cloud audit logs directly is not available. Export the logs with a Cloud Logging sink to a Pub/Sub push subscription pointed at the HTTP Event Collector source; events are stored as generic JSON.
What to know before connecting
Polling Google Cloud audit logs directly is not available. Export the logs with a Cloud Logging sink to a Pub/Sub push subscription pointed at the HTTP Event Collector source; events are stored as generic JSON.
- A poller for Google Cloud audit logs with a parser that names the actor, action and resource fields.
Roadmap timing: No release date is committed. AWS CloudTrail, Microsoft 365 and Google Workspace audit collection are available.
More in Cloud platforms
Cloud platforms
AWS CloudTrail
Console sign-ins, IAM changes and every API call recorded by CloudTrail, pulled from the S3 bucket the trail writes to and parsed into named fields.
Cloud platforms
AWS IAM Identity Center
SAML 2.0 sign-in through AWS IAM Identity Center (formerly AWS SSO). SCIM user provisioning from Qorionix is not available.
Cloud platforms
Amazon GuardDuty
Imports GuardDuty findings — unauthorized API calls, compromised credentials, anomalous network behaviour — from a tenant's own AWS account into the Qorionix SIEM incident queue. Read-only: does not archive, suppress or resolve findings in AWS.