icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Google Apps for Splunk
SHA256 checksum (google-apps-for-splunk_113.tgz) 95ccf3cd725fc90ee287966e35a1401f4734bd531b2ad85652c183669b279194
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Google Apps for Splunk

This app has been archived. Learn more about app archiving.
Admins: Please read about Splunk Enterprise 8.0 and the Python 2.7 end-of-life changes and impact on apps and upgradeshere.
This App pulls the data from your Google Apps for Work Domain using OAuth2 specifications. Please read the instructions CAREFULLY, and promptly report issues to the author.

Table of Contents


  • About GoogleAppsForSplunk
  • Release notes
  • Performance benchmarks
  • Support and resources


  • Hardware and software requirements
  • Installation steps
  • Deploy to single server instance
  • Deploy to distributed deployment
  • Deploy to distributed deployment with Search Head Clustering
  • Deploy to Splunk Cloud


  • Key concepts
  • Data types
  • Lookups
  • Configure GoogleAppsForSplunk
  • Troubleshooting
  • Upgrade
  • Example Use Case-based Scenario


About GoogleAppsForSplunk

Author Kyle Smith
App Version 1.1.3
Vendor Products Google Apps for Work utilizing OAuth2
Has index-time operations true, The included TA add-on must be placed on indexers
Create an index true
Implements summarization Current, the app does not generate summries

GoogleAppsForSplunk allows a Splunk® Enterprise administrator to interface with Google Apps for Work, consuming the usage and administrative logs provided by Google.

Scripts and binaries

This App provides the following scripts:

  • ga.py
  • This python file controls the ability to interface with the Google APIs.
  • ga_authorize.py
  • This Python custom endpoint allows the authorization of the App to Google Apps for Splunk from the command line.

Release notes

About this release

Version _VERSION of GoogleAppsForSplunk is compatible with:

Splunk Enterprise versions 6.2, 6.3, 6.4
Platforms Splunk Cloud, Splunk Enterprise
New features

GoogleAppsForSplunk includes the following new features:

  • Ability to consume log information using OAuth2 of the Google Apps for Works APIs
  • Converted the lookup files to KV Store lookups
Known issues

Version 1.0 of GoogleAppsForSplunk has the following known issues:

  • Google Apps Administration Dashboard
  • The lookup editors do not scale to 100% of their respective panels.
Third-party software attributions

Version 1.0 of GoogleAppsForSplunk incorporates the following third-party software or libraries.

Support and resources

Questions and answers

Access questions and answers specific to GoogleAppsForSplunk at Answers


Support is available via email at splunkapps@kyleasmith.info. You can also find the author on IRC (#splunk on efnet.org). Feel free to email or ping, most reponses will be within 1-2 business days.


Hardware and software requirements

Software requirements

Splunk Enterprise system requirements

Because this App runs on Splunk Enterprise, all of the Splunk Enterprise system requirements apply.


Download GoogleAppsForSplunk at https://splunkbase.splunk.com/app/2714/.

Installation steps

To install and configure this app on your supported platform, follow these steps:

  1. Install the Core app onto all Search Heads.
  2. Install the TA on all Indexers
  3. If you are using a Heavy Forwarder to pull external data, install the IA on the heavy forwarder and configure either through the GUI or on the server.
Deploy to single server instance

Follow these steps to install the app in a single server instance of Splunk Enterprise:

  1. Deploy as you would any App, and restart Splunk.
Deploy to Splunk Cloud
  1. Have your Splunk Cloud Support handle this installation.


Key concepts for GoogleAppsForSplunk

Configure GoogleAppsForSplunk

  1. Enable the Google Apps APIs and Authorize Splunk with Google Apps so that the modular input can pull data.
    a. Enable these APIS: Admin SDK, Apps Activity
  2. EDIT and enable the provided Data Inputs, replacing the domain with your domain information.

Troubleshoot GoogleAppsForSplunk

Not seeing data?
Probable misconfiguration
Check to make sure the APIs are enabled, authorized, and available to Splunk.

Release Notes

Version 1.1.3
Sept. 14, 2015

Fixed: Failure to create local folder on creation of credentials.
Fixed: App will only pull last 1 day of data. This prevents a memory killer on large domains that pulled 1 year of data.
Fixed: enforcing lowercase domain name on credential.


Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2020 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.