Google Cloud Logging
| Typically Used By | Google Cloud users; Organizations standardized on GCP |
| Description | An integration with Google Cloud Logging that collects logs from Google Cloud Platform services and resources with native GCP authentication. |
| Official Vendor Documentation | https://docs.cloud.google.com/logging/docs/ |
| Setup Difficulty | 3 (Moderate) |
| Useful for | SecOps , SecOps |
| Primary Use Case | Track admin and data access activity in GCP |
| Scenarios not Recommended | Non-GCP environments; Organizations with strict data locality requirements |
| Data Volume Handling | High |
| Authentication Method | Service account |
| Fault Tolerance | High |
| Additional Tools Required | GCP subscription |
Google Cloud Logging (formerly Stackdriver Logging) is a fully managed service that allows you to store, search, analyze, monitor, and alert on log data and events from Google Cloud Platform (GCP) and Amazon Web Services (AWS). Cloud Logging automatically collects logs from GCP services, applications running on Google Kubernetes Engine (GKE), Compute Engine VMs, and custom applications using the Cloud Logging API. By integrating Cloud Logging with Falcon LogScale Collector, organizations can centralize their GCP logs alongside other data sources for unified security monitoring, compliance reporting, and operational analytics. Cloud Logging's log routing capabilities enable real-time streaming of logs to LogScale through Pub/Sub topics, providing a scalable, serverless ingestion pipeline.
Google Cloud Logging ingest flowThe following diagram shows how Google Cloud Logging data flows through Log Collector's ingestion pipeline, highlighting specific parser types applied to the log data before data is compressed, stored in the repository, and indexed for searching: