Using Splunk to Secure Your Productivity and Team Collaboration Environment

Productivity and collaboration tools are key components for any business today – we use mail, docs, spreadsheets, shared whiteboards and many other cool tools daily. In this post, we will talk about how Splunk helps teams work and collaborate securely while using Google Chrome and Google Workspace.

Google Workspace and modern browsers like Google Chrome support effective collaboration within an organization – from mail, docs, spreadsheets up to calls, meetings, and scheduling. Google Workspace provides comprehensive logging, monitoring, and audit telemetry. Google Chrome provides many security and data protection features,from protecting end user from malware and dangerous sites and up to advanced technologies such as site isolation, sandboxing, and predictive phishing protection. Splunk’s integration with Chrome and Workspace allows companies to provide a secure working environment for their employees.

Let’s start with Chrome browser. Earlier this year, Chrome introduced the Chrome Enterprise Connectors Framework, enabling plug-and-play integration with partner solutions, and Splunk was one of the inaugural Reporting Connector partners. You can now easily have data from your Chrome browser fleet within your organization sent directly to Splunk for further forensic analysis.

The chrome browser is the ultimate endpoint where most end-user interactions happen and most data flows cross. This makes web browsers one of the top origins for many kinds of cyberattacks – from malware transfer and security vulnerabilities, up to high-risk and unsafe end-user behavior, like visiting malicious web resources. Splunk provides a complete set of capabilities to monitor and mitigate all these attacks – please refer to "Get Extended Security Insights from Chrome Browser with Splunk" for more details.

In order to provide security for Chrome users, organizations will use the Splunk HEC and Chrome Reporting Connector. They provide Google Workspace administrators the means to connect with Splunk and configure which Chrome events to send. Today, the available security events include password reuse, password change, unsafe site visit, malware transfer, login event, password breach, and potentially unsafe content transfer. These events cover most core scenarios for malware and intrusion detection through web resources and online browsing. For more details on setup and configuration check out our demo video and our blog on how to get extended security insights from Chrome browser with Splunk.

For businesses using Google Workspace, Splunk’s Google Workspace add-on provides comprehensive integration capabilities. This add-on enables advanced security monitoring by easily sending Google Workspace events into Splunk and utilizing out of the box and custom rulesets to analyze the data for potential security threats. Our engineering team frequently updates this add-on to keep up with new or modified event types, logs sources and metrics. Today, the add-on covers a wide range of use cases, such as:

To get started today monitoring your Google productivity tools with Splunk, you can visit our Splunkbase page for the Chrome Add-on for Splunk or the Splunk Add-on for Google Workspace. Gain some peace of mind that your Google users are getting business done in a safe and secure way. Stay tuned for updates on Splunk and Google!

Related Articles

NotDoor Insights: A Closer Look at Outlook Macros and More
Security
10 Minute Read

NotDoor Insights: A Closer Look at Outlook Macros and More

The Splunk Threat Research Team breaks down the NotDoor Outlook-macro backdoor linked to APT28 and shows how to detect these stealthy techniques to strengthen security coverage.
Refined User Experience, New Executive Visibility, and Enhanced Cloud Monitoring with Splunk Enterprise Security 7.0
Security
3 Minute Read

Refined User Experience, New Executive Visibility, and Enhanced Cloud Monitoring with Splunk Enterprise Security 7.0

Check out the latest Security Analytics enhancements to Splunk Enterprise Security with our latest 7.0 release.
Splunk SOAR 6.2 Introduces New Automation Features, Workload Migration, and Firewall Integrations
Security
3 Minute Read

Splunk SOAR 6.2 Introduces New Automation Features, Workload Migration, and Firewall Integrations

Announcing the release of Splunk SOAR 6.2 with features like logic loops for playbooks, integrations with CyberArk, two new firewall apps, and a new conversion option for classic playbooks.