> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Google Workspace Audit Logs source plugin

> Use the Google Workspace Audit Logs source plugin.

export const entity_0 = "Google Workspace Audit Logs source plugin"

export const plugin_0 = "Google Workspace Audit Logs source plugin"

<Info>
  This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone
  product separate from Palo Alto Networks Cortex XCOR.
</Info>

The Google Workspace Audit Logs [source plugin](/ingest/pipeline/plugins/source-plugins)
(name: `gsuite-reporter`) lets you retrieve data from Google Workspace and
ingest it into a telemetry pipeline.

This is a
[pull-based](/ingest/pipeline/plugins/source-plugins#push-based-and-pull-based-source-plugins)
source plugin.

<Note>
  This plugin doesn't support the use of a
  [descriptive metadata name](/ingest/pipeline/plugins#descriptive-names) in the
  Pipeline Builder interface.
</Note>

<Note>
  This plugin doesn't support duplicates of itself within the same pipeline.
</Note>

## Supported telemetry types

The {plugin_0} for Palo Alto Networks Telemetry Pipeline supports these telemetry types:

| Logs | Metrics | Traces |
| :-: | :-: | :-: |
| <Icon icon="circle-check" color="green" /> | <Icon icon="ban" color="red" /> | <Icon icon="ban" color="red" /> |

## Configuration parameters

Use the parameters in this section to configure the {entity_0}. The
Palo Alto Networks Telemetry Pipeline web interface uses the items in the **Name** column to
describe these parameters. [Pipeline configuration files](/ingest/pipeline/v2/configure/config-files)
use the items in the **Key** column as YAML keys.

### API Key

| Name | Key | Description | Default |
| - | - | - | - |
| **API Key** | `access_token` | Either an API key or a service account file for authentication. | *none* |

### Options

| Name | Key | Description | Default |
| - | - | - | - |
| **Enable Telemetry** | `telemetry` | If `true`, enables telemetry through the Google API. Accepted values: `true`, `false`. | `false` |
| **Pull Interval** | `pull_interval` | The time between calls to the Google API. Minimum of `1s`. | `30s` |
| **Data Directory** | `data_dir` | The storage path to allow resuming data collection. | `/data/storage/gsuite-reporter` |
| **Application Name** | `application_name` | The application name you want to get reports from. See [ApplicationName](https://developers.google.com/admin-sdk/reports/reference/rest/v1/activities/list#ApplicationName). | `admin` |
| **User Key** | `user_key` | The user you want to get reports from. | `all` |
| **Memory Buffer Limit** | `mem_buf_limit` | Sets a limit for how much buffered data the plugin can write to memory, which affects backpressure. This value must follow Fluent Bit's rules for [unit sizes](https://docs.fluentbit.io/manual/administration/configuring-fluent-bit#unit-sizes). If unspecified, no limit is enforced. <p />For v2 pipelines, this parameter affects only pipelines with the Deployment or DaemonSet [workload](/ingest/pipeline/v2/configure/kubernetes/workloads) type. To learn more, see the v2 [backpressure](/ingest/pipeline/v2/configure/backpressure) guide. <p />For v3 pipelines, this parameter is independent from the [OpenTelemetry `memory_limiter` and `batch` processors](/ingest/pipeline/v3#route-data-from-fluent-bit-to-opentelemetry). | *none* |


## Related topics

- [Ingest telemetry data with source plugins](/ingest/pipeline/plugins/source-plugins.md)
- [Microsoft Intune - Audit event source plugin](/ingest/pipeline/plugins/source-plugins/intune.md)
- [Azure Monitor Logs destination plugin](/ingest/pipeline/plugins/destination-plugins/azure-monitor.md)
- [Audit logs](/administer/audit-logs.md)
- [Google Chronicle destination plugin](/ingest/pipeline/plugins/destination-plugins/google-chronicle.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.