Overview
The Google Security Operations data benefit program allows customers to ingest eligible data sources up to the amounts indicated below. Ingestion of these data sources will not count toward eligible customer’s existing Google Security Operations data cap.
Eligible Data Sources
Data Source | Benefit Details | Notes & limitations |
|---|---|---|
GCP Cloud Audit Logs | Up to 10GB/day | Includes Admin Activity & System Event logs. Data access logs may incur separate charges in Cloud Observability. |
GCP CNAPP Alerts | Unlimited | Available for Google Security Command Center (SCC) alerts |
Chrome Enterprise Logs & Alerts | Unlimited | Available for Chrome Enterprise Core or Premium logs and alerts |
Google Workspace Logs | Up to 10GB/day | Includes standard Workspace log types |
GCP Context Data | Unlimited | Includes entity and asset context from Cloud Asset Inventory |
Approved Third-Party EDR Alerts | Unlimited | Applicable to alerts from Google approved third-party EDR vendors. Excludes raw logs. |
Wiz Data Sources | Source-specific volume exemptions | Available to qualifying joint Wiz Defend customers. See the Wiz Data Benefits page for details and eligibility. |
Eligibility Criteria
To qualify for this benefit, a customer must meet all of the following criteria:
Program Terms