The Google Security Operations data benefit program allows customers to ingest eligible data sources up to the amounts indicated below. Ingestion of these data sources will not count toward eligible customer’s existing Google Security Operations data cap.
Data Source | Benefit Details | Notes & limitations |
|---|---|---|
GCP Cloud audit logs | Free (up to 10GB/day) | Includes Admin Activity and System Event logs. Data access logs may incur separate charges in Cloud Observability. |
GCP CNAPP alerts | Free | Available for Google Security Command Center (SCC) alerts |
Chrome Enterprise logs and alerts | Free | Available for Chrome Enterprise Core or Premium logs and alerts |
Google Workspace Logs | Free (up to 10GB/day) | Includes standard Workspace log types |
GCP context data | Free | Includes entity and asset context from Cloud Asset Inventory |
Approved third-party EDR alerts | Free | Applicable to alerts from Google approved third-party EDR vendors. Excludes raw logs. |
To qualify for this benefit, a customer must meet all of the following criteria:
Program terms