ingest-google-workspace-login-ocsf
Installation
SKILL.md
ingest-google-workspace-login-ocsf
Convert verified Google Workspace Admin SDK Reports login audit payloads into
OCSF 1.8 IAM records by default, or the repo-owned native IAM projection when
--output-format native is selected.
Use when
- You have Admin SDK Reports
activities.listexports forapplicationName=loginand need OCSF output - You want to normalize Google Workspace login and 2-step-verification telemetry for SIEM, lake, MCP, or downstream detection use
- You need a portable identity event stream that preserves Workspace
id.time,id.uniqueQualifier, actor IDs, and raw login parameters - You want Workspace identity events represented as OCSF before feeding them into cross-vendor detections or evidence flows
Do NOT use
- On Google Cloud Audit Logs, Cloud Identity logs, or raw Entra / Okta payloads
- To collect live Workspace audit data by itself — upstream collection and auth stay outside this skill
- To infer ATT&CK techniques or create findings directly
- To mutate Workspace users, sessions, or 2-step settings