Skip to content

[google_workspace] Gemini AI #19410

Description

@jamiehynds

Description

Google Workspace Gemini is Google's AI assistant, integrated across Gmail, Docs, Drive, Meet, Sheets, and Slides. It's widely deployed in enterprise Workspace environments and represents a growing AI-governance and compliance surface — users interact with Gemini directly within the tools they use for sensitive work every day.

Gemini usage is auditable via the Google Admin SDK Reports API, but Elastic currently has no support for this data. Security teams with Workspace already connected have a blind spot: they can see file access, logins, and admin changes, but not the AI activity happening alongside that same data.

This is a net new datastream following the same pattern as all other Workspace datastreams in the integration.

What this data does (and doesn't) give you

Setting expectations up front, because it shapes the realistic use cases:

What the Reports API exposes — usage metadata:

  • Who used Gemini (actor, IP), in which Workspace app, and when
  • The category of action (e.g. summarize_document, generate_text) and the UI entry point
  • Engagement type and volume

What it does not expose:

  • Prompt or response content
  • The specific file/email/document operated on (no document ID or filename)
  • Any data classification or sensitivity signal

The practical consequence: this datastream is about visibility and behavioral anomaly detection — who is using AI, where, and how much — not content-level inspection of what was shared with the AI. Correlation with sensitive-data access is temporal (same user/app around the same time as a Drive or Gmail event), not a field-level join.

Scope & data boundaries

This datastream collects Gemini usage metadata from the Admin SDK Reports API (gemini_in_workspace_apps). It deliberately does not attempt to capture AI content, because of where that data lives:

  • Prompt/response content (in-app Gemini): Available only via Google Vault, which is an eDiscovery tool — on-demand, batch XML export with no streaming/event feed. There is no SIEM-style streaming path for Vault content from any vendor, so it is out of scope for this datastream. (Note: the integration's existing "Vault" datastream is the Vault audit log — admin actions like searches and holds — not retained conversation content.)
  • The specific file/data operated on: Not present in the Gemini event. Inferred by temporal correlation with the existing Drive datastream (file IDs, titles, access events), already collected by this integration.
  • Sensitivity signal: Provided by the existing Rules (DLP) datastream, already collected — correlate DLP rule matches with Gemini activity for the same user/time window.
  • Gemini API (Vertex AI) content: A separate product with full request/response logging to BigQuery, already addressed by the standalone Elastic GCP Vertex AI integration — not this integration.

Net: the correlation story (AI usage ↔ file access ↔ DLP matches) works today using Drive + Rules + this new Gemini stream - no additional collection required.

Why this matters

  • AI governance & visibility: As Gemini adoption grows, security teams need an audit trail of who is using it, in which apps, and whether usage aligns with policy. Elastic ingests these events and makes them searchable, dashboardable, and alertable alongside the rest of the Workspace estate.
  • Behavioral baselining: Bringing AI usage into the same data model as the rest of Workspace activity lets teams baseline normal usage and flag deviations (off-hours, volume spikes, first-time use by sensitive accounts).
  • Compliance & audit: Regulated industries need a durable, queryable record of AI tool usage to support GDPR, HIPAA, and internal acceptable-use requirements.
  • Admin oversight: Changes to Gemini feature availability and org-unit policies are configuration changes that should be monitored like any other. (Note: admin config-change events likely originate from a separate Admin SDK event source rather than the usage event below — to be confirmed during development.)

What needs to be built

New datastream: google_workspace.gemini

  • Collect Gemini audit events via the Admin SDK Reports API (gemini_in_workspace_apps application)
  • Cover user interactions across all Gemini-enabled Workspace apps, plus admin configuration events (source to be confirmed)
  • Dashboards: usage by user, org unit, and app; admin change timeline
  • Detection rules: see below

Sample event

⚠️ Illustrative sample. The structure and field names follow the Admin SDK Reports API documentation for the gemini_in_workspace_apps application; the values are representative. Google does not publish a populated example response, so a real captured event should be added during development from a Gemini-enabled tenant.

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2026-06-01T14:23:11.000Z",
    "uniqueQualifier": "-1234567890123456789",
    "applicationName": "gemini_in_workspace_apps",
    "customerId": "C03az79cb"
  },
  "actor": {
    "email": "analyst@example.com",
    "profileId": "104328974627593847562"
  },
  "ipAddress": "203.0.113.42",
  "events": [
    {
      "type": "ai_usage_event",
      "name": "feature_utilization",
      "parameters": [
        { "name": "app_name", "value": "docs" },
        { "name": "action", "value": "summarize_document" },
        { "name": "feature_source", "value": "side_panel" },
        { "name": "event_category", "value": "active_summarize" }
      ]
    }
  ]
}

Key fields

Field Description
actor.email / actor.profileId The user who invoked Gemini
ipAddress Source IP of the interaction
events[].name feature_utilization — the AI usage event
app_name Workspace app where it occurred (gmail, docs, drive, meet, sheets, slides, chat, gemini_app, …)
action Specific operation (generate_text, summarize_file, generate_images_in_product, …)
feature_source UI entry point (side_panel, help_me_write, chat_with_gemini, …)
event_category Engagement type (active_summarize, active_generate, active_conversations, …)

Access requirements

Google Workspace Enterprise Standard or Plus with the Gemini Enterprise add-on. Development requires a Workspace Enterprise tenant with Gemini enabled.

References

Activity

  1. infra-vault-gh-plugin-prod commented on Jun 5, 2026

    @infra-vault-gh-plugin-prod

    Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

  2. github-actions commented on Jun 5, 2026

    @github-actions
    Contributor

    tl;dr: This looks like a valid net-new enhancement (not already implemented): google_workspace has no Gemini support today, and the clean path is to add a new CEL-based gemini datastream modeled on data_studio/chat/meet, plus docs/manifest/changelog and test fixtures.

    Recommendation

    Proceed with implementation as a new google_workspace.gemini datastream. I recommend cloning the CEL pattern used by data_studio (same Reports API path shape), then adding Gemini-specific field mappings/pipeline logic and full package surfacing (manifest + docs + changelog + tests/mocks).

    Findings
    1. Gemini is not currently present in the package

      • packages/google_workspace/manifest.yml:165-166 enumerates supported app logs and does not include Gemini.
      • packages/google_workspace/docs/README.md:14-35 compatibility table lists supported services; no Gemini entry.
      • packages/google_workspace/docs/README.md:69 API host usage text lists existing report apps; no Gemini.
    2. There is an established pattern for adding new report-application datastreams

      • packages/google_workspace/data_stream/data_studio/manifest.yml:113-118 defines application_name_for_url: data_studio.
      • packages/google_workspace/data_stream/data_studio/agent/stream/cel.yml.hbs:31,48 builds /admin/reports/v1/activity/users/{user}/applications/{application_name_for_url}.
      • packages/google_workspace/data_stream/data_studio/fields/base-fields.yml:14-17 pins event.dataset per datastream (google_workspace.data_studio).
    3. History indicates this is likely net-new, not duplicate

      • packages/google_workspace/changelog.yml:158-167 includes prior "add (service) data stream" entries (Calendar/Data Studio).
      • packages/google_workspace/changelog.yml:116-123 includes Keep/Meet additions.
      • packages/google_workspace/changelog.yml:221-223 includes Chrome addition.
    4. Testing/mocks are datastream-specific and must be extended

      • Existing datastream test layout is consistent (for example packages/google_workspace/data_stream/chat/_dev/test/... and peers under each stream).
      • packages/google_workspace/_dev/deploy/docker/config.yml:378-412 currently includes a mocked /applications/data_studio route; Gemini needs equivalent mocked responses for system/pipeline tests.
    5. GitHub related-item lookup limitation in this environment

      • GitHub MCP issue/PR search responses for this topic were integrity-filtered, so I could not reliably inspect discussion content beyond local repository evidence.
    Verification

    I ran local checks in the workspace:

    $ grep -RIn "gemini\|Gemini" packages/google_workspace || true
    # (no matches)
    
    $ grep -n "Collect access_transparency" packages/google_workspace/manifest.yml
    165:        title: "Collect access_transparency, admin, alert, context_aware_access, device, drive, gcp, groups, group_enterprise, login, rules, saml, token and user accounts logs (input: httpjson)"
    
    $ grep -n "### Chat\|### Meet\|### Keep\|### Gmail" packages/google_workspace/docs/README.md
    3502:### Chat
    3800:### Meet
    4000:### Keep
    4127:### Gmail
    
    $ elastic-package version
    bash: elastic-package: command not found
    
    Detailed Action Plan
    1. Create new datastream scaffold

      • Add packages/google_workspace/data_stream/gemini/ by cloning a CEL stream closest to expected Gemini event shape (start with data_studio or chat).
      • Set application_name_for_url to gemini in .../gemini/manifest.yml (pattern in data_stream/data_studio/manifest.yml:113-118).
      • Keep CEL request path pattern from .../agent/stream/cel.yml.hbs (see data_stream/data_studio/agent/stream/cel.yml.hbs:48).
    2. Implement Gemini pipeline + schema

      • Add Gemini field definitions in .../gemini/fields/fields.yml and .../gemini/fields/base-fields.yml with event.dataset: google_workspace.gemini (pattern in data_stream/data_studio/fields/base-fields.yml:14-17).
      • Add .../gemini/elasticsearch/ingest_pipeline/default.yml with parameter flattening + ECS mapping and event categorization, following existing CEL streams.
    3. Add test fixtures and expected docs outputs

      • Add _dev/test/pipeline/test-gemini.log + test-gemini.log-expected.json and _dev/test/system/test-default-config.yml under the new datastream.
      • Extend mocked API responses in packages/google_workspace/_dev/deploy/docker/config.yml with Gemini endpoint fixtures (same structure as existing /applications/<name> mocks).
    4. Wire user-facing package metadata/docs

      • Update packages/google_workspace/manifest.yml:165-166 lists to include Gemini in supported logs text.
      • Update packages/google_workspace/_dev/build/docs/README.md compatibility/service lists and add Gemini section ({{event "gemini"}}, {{fields "gemini"}}), then regenerate packages/google_workspace/docs/README.md via normal package build flow.
    5. Release note and version bump

      • Add a new top entry in packages/google_workspace/changelog.yml for "Add Gemini data stream" (same style as prior add-stream entries).
      • Ensure package version bump follows integrations release conventions.
    Related Items
    Type Link / File Relevance
    Issue #19410 Request to add Gemini AI audit log datastream
    File packages/google_workspace/manifest.yml:165-166 Current supported app list; Gemini absent
    File packages/google_workspace/docs/README.md:14-35,69 Compatibility + API host lists; Gemini absent
    File packages/google_workspace/data_stream/data_studio/manifest.yml:113-118 Canonical application_name_for_url datastream pattern
    File packages/google_workspace/data_stream/data_studio/agent/stream/cel.yml.hbs:31,48 CEL request path pattern for Reports API app streams
    File packages/google_workspace/changelog.yml:116-123,158-167,221-223 Prior new datastream additions (Keep/Meet/Calendar/Data Studio/Chrome)
    PR (history refs in changelog) #13836, #13732, #13461, #13364, #12171 Prior implementation examples for adding new Google Workspace streams
    Limitation GitHub MCP issue/PR search results were integrity-filtered Could not fully inspect related issue/PR discussions in this run

    Note

    🔒 Integrity filter blocked 50 items

    The following items were blocked because they don't meet the GitHub integrity level.

    • #19410 issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #19410 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #4588 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #15794 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #13732 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #12171 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #4285 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #8269 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #3677 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #3865 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #19198 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #19108 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #18837 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #18768 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #16701 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #16696 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • ... and 34 more items

    To allow these resources, lower min-integrity in your GitHub frontmatter:

    tools:
      github:
        min-integrity: approved  # merged | approved | unapproved | none

    What is this? | From workflow: Issue Triage

    Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

  3. added
    Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]
    on Jul 8, 2026
  4. changed the title [-][google_workspace] Add Gemini AI audit log datastream[/-] [+][google_workspace] Gemini AI support[/+] on Sep 7, 2026
  5. changed the title [-][google_workspace] Gemini AI support[/-] [+][google_workspace] Gemini AI[/+] on Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions