Using Splunk to Secure Your Productivity and Team Collaboration Environment

Security Alexey Bokov
Productivity and collaboration tools are key components for any business today – we use mail, docs, spreadsheets, shared whiteboards and many other cool tools daily. In this post, we will talk about how Splunk helps teams work and collaborate securely while using Google Chrome and Google Workspace.

Google Workspace and modern browsers like Google Chrome support effective collaboration within an organization – from mail, docs, spreadsheets up to calls, meetings, and scheduling. Google Workspace provides comprehensive logging, monitoring, and audit telemetry. Google Chrome provides many security and data protection features,from protecting end user from malware and dangerous sites and up to advanced technologies such as site isolation, sandboxing, and predictive phishing protection. Splunk’s integration with Chrome and Workspace allows companies to provide a secure working environment for their employees.

Let’s start with Chrome browser. Earlier this year, Chrome introduced the Chrome Enterprise Connectors Framework, enabling plug-and-play integration with partner solutions, and Splunk was one of the inaugural Reporting Connector partners. You can now easily have data from your Chrome browser fleet within your organization sent directly to Splunk for further forensic analysis.

The chrome browser is the ultimate endpoint where most end-user interactions happen and most data flows cross. This makes web browsers one of the top origins for many kinds of cyberattacks – from malware transfer and security vulnerabilities, up to high-risk and unsafe end-user behavior, like visiting malicious web resources. Splunk provides a complete set of capabilities to monitor and mitigate all these attacks – please refer to "Get Extended Security Insights from Chrome Browser with Splunk" for more details.

In order to provide security for Chrome users, organizations will use the Splunk HEC and Chrome Reporting Connector. They provide Google Workspace administrators the means to connect with Splunk and configure which Chrome events to send. Today, the available security events include password reuse, password change, unsafe site visit, malware transfer, login event, password breach, and potentially unsafe content transfer. These events cover most core scenarios for malware and intrusion detection through web resources and online browsing. For more details on setup and configuration check out our demo video and our blog on how to get extended security insights from Chrome browser with Splunk.

For businesses using Google Workspace, Splunk’s Google Workspace add-on provides comprehensive integration capabilities. This add-on enables advanced security monitoring by easily sending Google Workspace events into Splunk and utilizing out of the box and custom rulesets to analyze the data for potential security threats. Our engineering team frequently updates this add-on to keep up with new or modified event types, logs sources and metrics. Today, the add-on covers a wide range of use cases, such as:

To get started today monitoring your Google productivity tools with Splunk, you can visit our Splunkbase page for the Chrome Add-on for Splunk or the Splunk Add-on for Google Workspace. Gain some peace of mind that your Google users are getting business done in a safe and secure way. Stay tuned for updates on Splunk and Google!

Related Articles

Enhancing SOC Efficiency with OCSF & Splunk Enterprise Security
Security
3 Minute Read

Enhancing SOC Efficiency with OCSF & Splunk Enterprise Security

As threat volumes grow and environments become more complex, standardized, high-fidelity telemetry is no longer a luxury–it’s a necessity.
Dark Crystal RAT Agent Deep Dive
Security
9 Minute Read

Dark Crystal RAT Agent Deep Dive

The Splunk Threat Research Team (STRT) analyzed and developed Splunk analytics for this RAT to help defenders identify signs of compromise within their networks.
Splunk for OT Security V2: SOAR and More
Security
3 Minute Read

Splunk for OT Security V2: SOAR and More

OT attacks are on the rise, as we've seen from the Oldsmar water facility attack. the Splunk IoT, Manufacturing and Energy team has been hard at work improving Splunk for OT Security to help secure your environment.