- Predefined log collection jobs perform scheduled API queries for G Suite logs and USM Anywhere produces events from this data.
- The out-of-the-box correlation rules for G Suite events enable USM Anywhere to automatically create alarms, notifying you about suspicious activity in your environment.
- The BlueApp for G Suite includes predefined dashboards that give an overview of G Suite Audit and G Suite Drive to streamline your investigation and incident response processes.
Important: All G Suite environments include access to the Google Drive Activity API, which provides the basic G Suite audit log data. However, only G Suite Enterprise or G Suite Business include access to the Reports API, which provides to the advanced G Suite log data. If you are a G Suite Basic customer, you cannot collect log data for Google Drive.See their Google Support site for more information about the differences between the G Suite editions.
Warning: If the BlueApp fails and you receive a message informing you that it has not been loaded, please contact LevelBlue Technical Support to solve the problem.
Related Video Content