Skip to main content

Responses are generated using AI and may contain mistakes.

CollectorsCloud Collectors Administration Guide

Table of Contents

Prerequisites to Configure the Google Security Operations Cloud Collector

Before you configure the Google Security Operations Cloud Collector, complete the following prerequisites.

Obtain Project Number, GCP Project Region, GCP Project ID, and Customer ID

Use the following steps to obtain the project number, GCP project region, GCP project IS and the customer ID.

  1. On the Google Security Operations (SecOps) console, navigate to Settings > SIEM Settings > Profile.

  2. Record the Customer ID, GCP Project Number, and GCP Project ID from the Profile page. Use this information while configuring the Google Security Operations Cloud Collector.

Create a Service Account and Obtain a Project ID

Use the following steps to create a service account and obtain a project ID.

  1. To create a service account in the project in which the Pub/Sub subscription has been created, in the Google Cloud console, navigate to IAM & Admin > Service Accounts > CREATE SERVICE ACCOUNT page.

  2. Select a Cloud project if you already created a project. If not, create a Cloud project.

  3. Enter the project name and edit the automatically generated project ID. Note the Project ID that you set while creating the Google service account. You require to use the project ID while configuring the Cloud Collector.

  4. For more information and relevant steps, see Creating and managing service accounts in the Google documentation.

Supported Regions

Refer to the following table that lists regions supported for deployment of Google Security Operations Cloud Collector.

Google SecOps Location

Description

Exabeam Deployment Region

United States (Multi-region)

US Multi-region

us-east1 or us-west1

northamerica-northeast2 (Canada - Toronto)

Canada

northamerica-northeast1

europe-west3 (Frankfurt)

Germany

europe-west3

europe-west6 (Zurich)

Switzerland

europe-west6

europe-west2 (London)

United Kingdom

europe-west2

asia-northeast1(Tokyo)

Japan

asia-northeast1

asia-southeast1(Singapore)

Singapore

asia-southeast1

australia-southeast1 (Sydney)

Australia

australia-southeast1

me-central2 (Dammam)

Saudi Arabia

me-central2

me-central1 (Doha)

Qatar

me-central2

asia-southeast2 (Jakarta)

Indonesia

asia-southeast1

Recommendations for Log Type Configuration

Refer to the following recommendations before configuring the Google Security Operations Cloud Collector.

  1. Select the log types for data ingestion.

  2. Generate a Data Ingestion and Health report in your Google SecOps instance to check the available log types and the amount of data generated by each of the log type. For more information see Configure scheduled reports in Google Security Operations documentation.

  3. Review your options to determine which Log Types to ingest based on your data volume limits, license restrictions, and specific security use cases. For assistance, consult your Exabeam Account team.

  4. Record the selected Log Types and enter them in the LOG TYPES field while configuring the Google Security Operations Cloud Collector.