Splunk® Supported Add-ons

Splunk Add-on for Google Workspace

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

REST API reference

Admin SDK REST API reference

Collect Google Workspace Admin SDK information from the following APIs.

Resources Description API endpoint
Reports:login Lists information on account user login activities, based on application name.
GET https://www.googleapis.com/admin/reports/v1/activity/users/all/applications/login?endTime=end date&startTime=start date&maxResults=maximum number of events returned on a response page
Reports:token Lists token event information about third party websites and applications, based on application name.
GET https://www.googleapis.com/admin/reports/v1/activity/users/all/applications/token?endTime=end date&startTime=start date&maxResults=maximum number of events returned on a response page
Reports:user activity Lists Google Workspace service user activities event information, based on application name.
GET https://www.googleapis.com/admin/reports/v1/usage/users/all/dates/yyyy-mm-dd date?parameters=application: user usage parameter,...&filters=application: user usage parameter relational operator usage parameter's value,...&maxResults=number of events listed on each page of the report
Reports:admin Lists admin event information on the Admin console activities of all of your account's administrators, based on application name.
GET https://www.googleapis.com/admin/reports/v1/activity/users/all/applications/admin?endTime=a date&startTime=a date&maxResults=number of events listed on each page of the report

/admin/reports/v1/activity/users/all/applications/login

GET https://www.googleapis.com/admin/reports/v1/activity/users/all/applications/login?endTime=end date&startTime=start date&maxResults=maximum number of events returned on a response page.


GET

Lists information on account user login activities, based on application name.

Request parameters
None

Returned values

Gets a report on all of your account's user login events for the past 180 days.



admin/reports/v1/activity/users/all/applications/token

GET https://www.googleapis.com/admin/reports/v1/activity/users/all/applications/token?endTime=end date&startTime=start date&maxResults=maximum number of events returned on a response page


GET

Lists token event information about third party websites and applications, based on application name.

Request parameters
None

Returned values
Gets a report on all of your account's third party websites and application authorization events for the past 180 days.


admin/reports/v1/usage/users

https://www.googleapis.com/admin/reports/v1/usage/users/all/dates/yyyy-mm-dd date?parameters=application: user usage parameter,...&filters=application: user usage parameter relational operator usage parameter's value,...&maxResults=number of events listed on each page of the report


GET

Lists Google Workspace service user activities event information, based on application name.

Request parameters
None

Returned values
Gets a report on all Google Workspace service user activities for the account.


admin/reports/v1/activity/users/all/applications/admin

https://www.googleapis.com/admin/reports/v1/activity/users/all/applications/admin?endTime=a date&startTime=a date&maxResults=number of events listed on each page of the report


GET

Lists admin event information on the Admin console activities of all of your account's administrators, based on application name.

Request parameters
None

Returned values
Gets a report on all of your account's Admin console activities activities for the past 180 days which is the maximum time period for a report.



Last modified on 10 May, 2023
PREVIOUS
Troubleshoot the Splunk Add-on for Google Workspace
 

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters