Google Cloud Platform Integration
Cloud audit and threat signals across your entire GCP organisation.
What this integration does
Google Cloud Platform meets agentic SOC
Google Cloud Platform audit logs — Cloud Audit Logs, Security Command Center findings, and VPC Flow Logs — provide deep visibility into your GCP estate. ManySignal ingests these via Pub/Sub subscriptions and Cloud Storage exports, normalises events to OCSF, and correlates GCP signals with Workspace, Kubernetes, and identity data.
Cloud Audit Log ingestion (Admin Activity, Data Access, System Events)
Security Command Center finding ingestion
VPC Flow Log analysis for network threat detection
Data collected
- Cloud Audit Logs (all log types)
- Security Command Center findings
- VPC Flow Logs
- GKE audit logs
- Cloud Identity and IAM changes
Actions supported
- Disable service account
- Revoke service account key
- Add IAM deny policy
- Quarantine VM instance (remove from network)
- Create Security Command Center custom finding
Getting started
Set up in minutes
- 1
Create a GCP service account for ManySignal
- 2
Configure Pub/Sub log export
- 3
Enable Security Command Center
- 4
Connect in ManySignal
Google Cloud Platform Integration: frequently asked questions
Do I need the Security Command Center Premium tier?
Standard tier findings (misconfigurations) are included in GCP. Premium tier is required for Event Threat Detection and Container Threat Detection findings, which provide the highest-value security signals.
How does ManySignal handle multi-project GCP organisations?
Organisation-level log sinks and SCC aggregate signals from all projects automatically. No per-project configuration is required.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.