Repository navigation
[google_workspace] Gemini AI #19410
Description
Activity
- addedTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]
on Jun 5, 2026 infra-vault-gh-plugin-prod commented
on Jun 5, 2026 More actionsPinging @elastic/security-service-integrations (Team:Security-Service Integrations)
- addedIntegration:google_workspaceGoogle WorkspaceGoogle WorkspaceenhancementNew feature or requestNew feature or request
on Jun 5, 2026 tl;dr: This looks like a valid net-new enhancement (not already implemented):
google_workspacehas no Gemini support today, and the clean path is to add a new CEL-basedgeminidatastream modeled ondata_studio/chat/meet, plus docs/manifest/changelog and test fixtures.Recommendation
Proceed with implementation as a new
google_workspace.geminidatastream. I recommend cloning the CEL pattern used bydata_studio(same Reports API path shape), then adding Gemini-specific field mappings/pipeline logic and full package surfacing (manifest + docs + changelog + tests/mocks).Findings
-
Gemini is not currently present in the package
packages/google_workspace/manifest.yml:165-166enumerates supported app logs and does not include Gemini.packages/google_workspace/docs/README.md:14-35compatibility table lists supported services; no Gemini entry.packages/google_workspace/docs/README.md:69API host usage text lists existing report apps; no Gemini.
-
There is an established pattern for adding new report-application datastreams
packages/google_workspace/data_stream/data_studio/manifest.yml:113-118definesapplication_name_for_url: data_studio.packages/google_workspace/data_stream/data_studio/agent/stream/cel.yml.hbs:31,48builds/admin/reports/v1/activity/users/{user}/applications/{application_name_for_url}.packages/google_workspace/data_stream/data_studio/fields/base-fields.yml:14-17pinsevent.datasetper datastream (google_workspace.data_studio).
-
History indicates this is likely net-new, not duplicate
packages/google_workspace/changelog.yml:158-167includes prior "add (service) data stream" entries (Calendar/Data Studio).packages/google_workspace/changelog.yml:116-123includes Keep/Meet additions.packages/google_workspace/changelog.yml:221-223includes Chrome addition.
-
Testing/mocks are datastream-specific and must be extended
- Existing datastream test layout is consistent (for example
packages/google_workspace/data_stream/chat/_dev/test/...and peers under each stream). packages/google_workspace/_dev/deploy/docker/config.yml:378-412currently includes a mocked/applications/data_studioroute; Gemini needs equivalent mocked responses for system/pipeline tests.
- Existing datastream test layout is consistent (for example
-
GitHub related-item lookup limitation in this environment
- GitHub MCP issue/PR search responses for this topic were integrity-filtered, so I could not reliably inspect discussion content beyond local repository evidence.
Verification
I ran local checks in the workspace:
$ grep -RIn "gemini\|Gemini" packages/google_workspace || true # (no matches) $ grep -n "Collect access_transparency" packages/google_workspace/manifest.yml 165: title: "Collect access_transparency, admin, alert, context_aware_access, device, drive, gcp, groups, group_enterprise, login, rules, saml, token and user accounts logs (input: httpjson)" $ grep -n "### Chat\|### Meet\|### Keep\|### Gmail" packages/google_workspace/docs/README.md 3502:### Chat 3800:### Meet 4000:### Keep 4127:### Gmail $ elastic-package version bash: elastic-package: command not foundDetailed Action Plan
-
Create new datastream scaffold
- Add
packages/google_workspace/data_stream/gemini/by cloning a CEL stream closest to expected Gemini event shape (start withdata_studioorchat). - Set
application_name_for_urltogeminiin.../gemini/manifest.yml(pattern indata_stream/data_studio/manifest.yml:113-118). - Keep CEL request path pattern from
.../agent/stream/cel.yml.hbs(seedata_stream/data_studio/agent/stream/cel.yml.hbs:48).
- Add
-
Implement Gemini pipeline + schema
- Add Gemini field definitions in
.../gemini/fields/fields.ymland.../gemini/fields/base-fields.ymlwithevent.dataset: google_workspace.gemini(pattern indata_stream/data_studio/fields/base-fields.yml:14-17). - Add
.../gemini/elasticsearch/ingest_pipeline/default.ymlwith parameter flattening + ECS mapping and event categorization, following existing CEL streams.
- Add Gemini field definitions in
-
Add test fixtures and expected docs outputs
- Add
_dev/test/pipeline/test-gemini.log+test-gemini.log-expected.jsonand_dev/test/system/test-default-config.ymlunder the new datastream. - Extend mocked API responses in
packages/google_workspace/_dev/deploy/docker/config.ymlwith Gemini endpoint fixtures (same structure as existing/applications/<name>mocks).
- Add
-
Wire user-facing package metadata/docs
- Update
packages/google_workspace/manifest.yml:165-166lists to include Gemini in supported logs text. - Update
packages/google_workspace/_dev/build/docs/README.mdcompatibility/service lists and add Gemini section ({{event "gemini"}},{{fields "gemini"}}), then regeneratepackages/google_workspace/docs/README.mdvia normal package build flow.
- Update
-
Release note and version bump
- Add a new top entry in
packages/google_workspace/changelog.ymlfor "Add Gemini data stream" (same style as prior add-stream entries). - Ensure package version bump follows integrations release conventions.
- Add a new top entry in
Related Items
Type Link / File Relevance Issue #19410 Request to add Gemini AI audit log datastream File packages/google_workspace/manifest.yml:165-166Current supported app list; Gemini absent File packages/google_workspace/docs/README.md:14-35,69Compatibility + API host lists; Gemini absent File packages/google_workspace/data_stream/data_studio/manifest.yml:113-118Canonical application_name_for_urldatastream patternFile packages/google_workspace/data_stream/data_studio/agent/stream/cel.yml.hbs:31,48CEL request path pattern for Reports API app streams File packages/google_workspace/changelog.yml:116-123,158-167,221-223Prior new datastream additions (Keep/Meet/Calendar/Data Studio/Chrome) PR (history refs in changelog) #13836,#13732,#13461,#13364,#12171Prior implementation examples for adding new Google Workspace streams Limitation GitHub MCP issue/PR search results were integrity-filtered Could not fully inspect related issue/PR discussions in this run Note
🔒 Integrity filter blocked 50 items
The following items were blocked because they don't meet the GitHub integrity level.
- #19410
issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #19410
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #4588
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #15794
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #13732
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #12171
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #4285
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #8269
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #3677
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #3865
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #19198
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #19108
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #18837
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #18768
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #16701
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #16696
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - ... and 34 more items
To allow these resources, lower
min-integrityin your GitHub frontmatter:tools: github: min-integrity: approved # merged | approved | unapproved | none
What is this? | From workflow: Issue Triage
Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.
-
- addedTeam:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]
on Jul 8, 2026 - changed the title
[-][google_workspace] Add Gemini AI audit log datastream[/-][+][google_workspace] Gemini AI support[/+]on Sep 7, 2026 - changed the title
[-][google_workspace] Gemini AI support[/-][+][google_workspace] Gemini AI[/+]on Sep 7, 2026
Description
Google Workspace Gemini is Google's AI assistant, integrated across Gmail, Docs, Drive, Meet, Sheets, and Slides. It's widely deployed in enterprise Workspace environments and represents a growing AI-governance and compliance surface — users interact with Gemini directly within the tools they use for sensitive work every day.
Gemini usage is auditable via the Google Admin SDK Reports API, but Elastic currently has no support for this data. Security teams with Workspace already connected have a blind spot: they can see file access, logins, and admin changes, but not the AI activity happening alongside that same data.
This is a net new datastream following the same pattern as all other Workspace datastreams in the integration.
What this data does (and doesn't) give you
Setting expectations up front, because it shapes the realistic use cases:
What the Reports API exposes — usage metadata:
summarize_document,generate_text) and the UI entry pointWhat it does not expose:
The practical consequence: this datastream is about visibility and behavioral anomaly detection — who is using AI, where, and how much — not content-level inspection of what was shared with the AI. Correlation with sensitive-data access is temporal (same user/app around the same time as a Drive or Gmail event), not a field-level join.
Scope & data boundaries
This datastream collects Gemini usage metadata from the Admin SDK Reports API (
gemini_in_workspace_apps). It deliberately does not attempt to capture AI content, because of where that data lives:Net: the correlation story (AI usage ↔ file access ↔ DLP matches) works today using Drive + Rules + this new Gemini stream - no additional collection required.
Why this matters
What needs to be built
New datastream:
google_workspace.geminigemini_in_workspace_appsapplication)Sample event
{ "kind": "admin#reports#activity", "id": { "time": "2026-06-01T14:23:11.000Z", "uniqueQualifier": "-1234567890123456789", "applicationName": "gemini_in_workspace_apps", "customerId": "C03az79cb" }, "actor": { "email": "analyst@example.com", "profileId": "104328974627593847562" }, "ipAddress": "203.0.113.42", "events": [ { "type": "ai_usage_event", "name": "feature_utilization", "parameters": [ { "name": "app_name", "value": "docs" }, { "name": "action", "value": "summarize_document" }, { "name": "feature_source", "value": "side_panel" }, { "name": "event_category", "value": "active_summarize" } ] } ] }Key fields
actor.email/actor.profileIdipAddressevents[].namefeature_utilization— the AI usage eventapp_namegmail,docs,drive,meet,sheets,slides,chat,gemini_app, …)actiongenerate_text,summarize_file,generate_images_in_product, …)feature_sourceside_panel,help_me_write,chat_with_gemini, …)event_categoryactive_summarize,active_generate,active_conversations, …)Access requirements
Google Workspace Enterprise Standard or Plus with the Gemini Enterprise add-on. Development requires a Workspace Enterprise tenant with Gemini enabled.
References