Export Google Workspace admin, login, and Drive audit activity via the Admin SDK Reports API for SIEM ingestion

domain: developers.google.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Authorize a service account with domain-wide delegation and the reports read-only OAuth scope, impersonating a super admin for the API calls.
  2. Call the activities list endpoint with applicationName set to admin, login, drive, or another supported report type, using eventName/filters parameters to narrow to security-relevant events.
  3. Page through results with a page token and control batch size with the max results parameter for large tenants.
  4. Use start/end time parameters to pull incremental windows on a schedule, keeping in mind the roughly 180-day maximum retention window for activity reports.
  5. Feed parsed activity records into a SIEM pipeline, mapping Google's event/parameter structure to the SIEM's normalized schema for admin and login events.

Known gotchas

Related routes

Export Microsoft 365 unified audit logs at scale using the Office 365 Management Activity API
learn.microsoft.com · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans