Chrome Management GoogleWorkspace-chrome
11 operations, identified by eventName in the audit log.
| eventName | Description |
|---|---|
| any | Source-only rules that filter on applicationName 'chrome' without specifying an eventName attribute here. |
| badNavigationEvent | A Chrome browser user navigated to a site blocked by Safe Browsing. |
| contentTransferEvent | A content transfer (upload or download) was detected by Chrome Enterprise. |
| dangerousDownloadEvent | A Chrome user downloaded a file flagged as dangerous by Safe Browsing. |
| unscannedFileEvent | A Chrome user attempted to download a file that could not be scanned for malware. |
| CHROME_OS_LOGIN_EVENT | A user logged in to a Chrome OS device. |
| CHROME_OS_LOGOUT_EVENT | A user logged out of a Chrome OS device. |
| CHROME_OS_LOGIN_FAILURE_EVENT | A login attempt on a Chrome OS device failed. |
| DLP_EVENT | A Chrome Enterprise data loss prevention policy was triggered. |
| PASSWORD_REUSE | A Chrome user reused a corporate password on a non-corporate site. |
| DEVICE_BOOT_STATE_CHANGE | A Chrome OS device changed its boot state (e.g. verified boot status changed). |
any: Chrome Management (any event)
#Description
Source-only rules that filter on applicationName 'chrome' without specifying an eventName attribute here.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Reports API: chrome activity events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/chrome
- Reports API activities.list reference https://developers.google.com/workspace/admin/reports/reference/rest/v1/activities/list
contentTransferEvent: Content Transfer Event
#Description
A content transfer (upload or download) was detected by Chrome Enterprise.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
Detection Rules #
View all rules referencing this event →YARA-L #
References #
- Chrome Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/chrome
dangerousDownloadEvent: Dangerous Download Event
#Description
A Chrome user downloaded a file flagged as dangerous by Safe Browsing.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
Detection Rules #
View all rules referencing this event →YARA-L #
References #
- Chrome Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/chrome
unscannedFileEvent: Unscanned File Event
#Description
A Chrome user attempted to download a file that could not be scanned for malware.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
Detection Rules #
View all rules referencing this event →YARA-L #
References #
- Chrome Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/chrome
CHROME_OS_LOGIN_EVENT: Chrome OS Login Event
#Description
A user logged in to a Chrome OS device.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Chrome Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/chrome
CHROME_OS_LOGOUT_EVENT: Chrome OS Logout Event
#Description
A user logged out of a Chrome OS device.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Chrome Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/chrome
CHROME_OS_LOGIN_FAILURE_EVENT: Chrome OS Login Failure
#Description
A login attempt on a Chrome OS device failed.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Chrome Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/chrome
DLP_EVENT: DLP Event
#Description
A Chrome Enterprise data loss prevention policy was triggered.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Chrome Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/chrome
PASSWORD_REUSE: Password Reuse
#Description
A Chrome user reused a corporate password on a non-corporate site.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Chrome Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/chrome
DEVICE_BOOT_STATE_CHANGE: Device Boot State Change
#Description
A Chrome OS device changed its boot state (e.g. verified boot status changed).
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Chrome Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/chrome