Exabeam selected Google Cloud as the foundation for the New-Scale Security Operations Platform, delivering hyperscale storage and compute to meet today’s security challenges. Built on Google Cloud, Exabeam helps you collect the right data, reduce alert noise, and control rising storage costs.
As a valued Technology Alliance Partner, Exabeam integrates with Google Cloud and Google Workspace to accelerate threat detection, investigation, and response (TDIR). You can view and correlate detections across Google and your broader environment to understand the full scope of an incident. With context-aware risk scoring, Exabeam surfaces the most urgent alerts and cases, enabling your IT and security teams to act quickly and mitigate risks to users and devices.
What We Do With Google Cloud
Exabeam collects data through a single interface that unifies Google Cloud, Google Workspace, and log data from more than 290 IT and security vendors. This gives your security operations team enriched insights and risk scoring to detect threats faster and respond more effectively.

Securing AI Agents With Google Agentspace and Model Armor
AI agents are becoming essential to business operations, but they also introduce a new insider threat. Without visibility into their actions, you risk misuse, drift, or compromise going undetected.
Exabeam integrates with Google Agentspace and Model Armor to give you that visibility. Agentspace orchestrates enterprise AI workflows, while Model Armor provides detailed activity data on large language model (LLM) use. By ingesting this data into the New-Scale Platform, you can baseline both user and agent behavior, detect anomalies in real time, and respond quickly when something looks suspicious.
Exabeam Nova operationalizes this intelligence, scoring, explaining, and prioritizing risks so your team can secure the next generation of insider threats.
Integration Benefits
- Gain unified visibility into both user and agent activity.
- Detect and prioritize anomalous agent behavior with Exabeam Nova.
- Accelerate investigation and response with automated timelines and enriched context.
Integrations
Google Workspace
Endpoint | Audit Source: API | Events Included | Additional Source: API |
---|---|---|---|
Login | Reports API | Login Audit Activity | Stackdriver/Admin Activities |
Admin | Admin Activity | ||
Drive | Drive Audit Activity | ||
Token | Token Activity | ||
Mobile | Mobile Audit Activity | ||
Calendar | Calendar Audit Activity | ||
Groups | Groups Audit Activity | ||
GPlus | Google+ Audit Activity | ||
Rules | Rules Audit Activity | ||
SAML | SAML Audit Activity | ||
Gmail Logs | Gmail logs in BigQuery | Message Trace |
Google Cloud Platform
Service or Module Covered | Event Included |
---|---|
App Engine | Events related to admin activities in the App Engine PaaS service |
BigQuery | Events related to admin activities in the BigQuery service |
Cloud Dataflow | Events related to admin activities in the Cloud Dataflow service |
Cloud Dataproc | Events related to admin activities in the Cloud Dataproc service |
Cloud DNS | Events related to admin activities in the Cloud DNS service |
Cloud Identity and Access Management (IAM) | Events related to admin activities in the Cloud IAM service |
Cloud Key Management System (KMS) | Events related to admin activities in the Cloud KMS service |
Cloud Resource Manager | Events related to admin activities in the Cloud Resource Manager service |
Cloud SQL | Events related to admin activities in the Cloud SQL service |
Cloud Storage | Events related to admin activities in the Cloud Storage service |
Google Compute Engine (GCE) | Events related to admin activities in the GCE service |
Compute Engine Serial Port Access | Events related to admin activities in the Compute Engine Serial Port Access service |
Google Service Management | Events related to admin activities in the Google Service Management service |
BigQuery | Events related to data access in the BigQuery service |
Cloud Dataproc | Events related to data access in the Cloud Dataproc service |
Cloud DNS | Events related to data access in the Cloud DNS service |
Cloud Identity and Access Management (IAM) | Events related to admin activities in the Cloud IAM service |
Cloud Key Management System (KMS) | Events related to admin activities in the Cloud KMS service |
Cloud SQL | Events related to admin activities in the Cloud SQL service |
Cloud Storage | Events related to admin activities in the Cloud Storage service |
Google Compute Engine (GCE) | Events related to admin activities in the GCE service |
Google Service Management | Events related to admin activities in the Google Service Management service |
Google Agentspace | Events related to AI agent workflows and orchestration |
Google Model Armor | Events related to LLM activity, prompts, and responses |
Customer Benefits:
- Scale log ingestion and storage: Exabeam products use Google Cloud Run and Dataflow to deliver scalable ingestion, parsing, storage, and intelligent search. You can handle petabytes of log data and substantially reduce mean time to resolution (MTTR).
- Detect anomalous activity faster: Detect, investigate, and respond to abnormal activity that often goes undetected. By leveraging Google BigQuery and Looker, Exabeam enhances security analytics and dashboarding for deeper insight.
- Backed by Google AI technology: Use natural language search powered by Google and Exabeam Nova to quickly find events, understand threats, and determine the right response. Embedded Google Gemini in Exabeam Threat Center explanations helps your team communicate clearly across the organization.
- Available on Google Cloud Marketplace: Easily procure Exabeam through the Google Cloud Marketplace using your Google Cloud credits.
- Strengthen defenses by monitoring both users and agents: Extend the value of the partnership with new integrations for Google Agentspace and Model Armor, enabling you to baseline and monitor AI agent activity alongside user behavior to prevent misuse or compromise.
About Google Cloud
Google Cloud accelerates organizations’ ability to digitally transform their business with the best infrastructure, platform, industry solutions, and expertise. We deliver enterprise-grade solutions that leverage Google’s cutting-edge technology — all on the cleanest cloud in the industry. Customers in more than 200 countries and territories turn to Google Cloud as their trusted partner to enable growth and solve their most critical business problems.
Contact
Related Resources
Video: Google Cloud Marketplace Video Series: The SIEM Leader for Security Operations
Press Release: Exabeam Extends Proven Insider Threat Detection to AI Agents with Google Cloud
Press Release: Exabeam Partners with Google Cloud to Create Hyperscale Cloud-native SIEM and Cybersecurity Analytics Offerings
Blog: Integrating Exabeam with Google Cloud IDS
Brief: Exabeam and Google Cloud: Securing AI Agents and LLM Usage With Behavioral Analytics
Brief: Exabeam and Google Cloud
Learn More About Exabeam
Learn about the Exabeam platform and expand your knowledge of information security with our collection of white papers, podcasts, webinars, and more.
See Exabeam in Action
Request more information or request a demo of the industry’s most powerful platforms for threat detection, investigation, and response (TDIR).
Learn more:
- If self-hosted or cloud-native SIEM is right for you
- How to ingest and monitor data at cloud scale
- Why seeing abnormal user and device behavior is critical
- How to automatically score and profile user activity
- See the complete picture using incident timelines
- Why playbooks help make the next right decision
- Support compliance mandates
Award-Winning Leaders in Security