This guide describes how to export Cloud Security Command Center (Cloud SCC) data, including assets, findings, and security marks. Cloud SCC enables you to export data using the Cloud SCC API, or by using the Google Cloud Platform Console.
Before you begin
To export Cloud SCC data, you need the following:
- A Cloud Identity and Access Management (Cloud IAM) role that includes the permissions of the Security Center Admin Viewer role.
- A GCP project in which you can create a Cloud Storage bucket and write the export data.
Export data using the GCP Console
This section describes how to export Cloud SCC data to a JSON file using the GCP Console. When you click Export in the Cloud SCC dashboard, Cloud SCC gets credentials or permissions to write to the Cloud Storage bucket automatically.
To export a JSON file to a Cloud Storage bucket, follow the steps below. If you don't already have a Cloud Storage bucket you want to use, you can create one during the export process.
Finding and Asset data are exported in separate operations. If you want to filter the exported data, select the filters you want to use on the Assets or Findings tab before you export.
- Go to the Security Command Center in the
Go to the Security Command Center
- Click Export.
- On the Export page that appears, configure the export:
- On the Entity Type drop-down list, select the kind of data that you want to export.
- On the Group Results By drop-down list, select how you want to
group the export data.
- The Filters list displays the filters you have selected for the entity type, if any.
- Under Display Results From, select the timestamp of the data you want to export.
- Under Export to, select the project to which you want to export the data.
- In the Export Path box, click Browse.
- On the Select object panel that appears, select an existing
Cloud Storage bucket or click Create new bucket.
- To create a bucket, enter a filename to save the data to in the File name box.
- After you select or create a bucket, click Select.
- When you're finished configuring the export, click Export JSON. If you
selected an existing file in the bucket, the Confirm Overwrite dialog
- To overwrite the existing file, click Confirm.
- To change the file you're writing to, click Cancel, then click Browse in the Export Path box and select or create a different file.
The configured data is saved to the Cloud Storage bucket you specified.
Downloading exported data
To download the exported JSON data, follow the steps below:
- Go to the Cloud Storage bucket:
- On the GCP Console, click the Export Notification. notifications OR
- Go to the GCP Console Storage Browser page and select the project and bucket to which you exported data.
- To download the JSON file, click the filename you entered when you exported the data.
- On the Save File dialog that appears, select the location where you want to save the JSON, and then click Save.
The JSON file is downloaded to the location you specified.
Export data using the Cloud SCC API
Exporting assets, findings, and marks using the Cloud SCC API uses the following methods:
If you specify a value in the
groupBy field, then the
GroupFindings method is used. If you don't specify a
groupBy value, then the
ListFindings method is used.
These APIs return either assets or findings with their full set of properties, attributes, and associated marks in JSON format. Output from these APIs is written to the storage location you specify, with the option to select the current reference time.