> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-cloud-platform.md).

# Google Cloud Platform

You can configure collecting Google Cloud Platform (GCP) logs using a standard data source, Cloud Service Provider (CSP) onboarding data source, or content pack integration (onboarded prior to July 26, 2026):

| Google Cloud Platform vendor                                                                                                                                                             | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Standard data source overview                                                                                                                                                            | If you use the Pub/Sub messaging service from Google Cloud Platform (GCP), forward logs and data to Cortex Cloud from your GCP instance using the Google Cloud Platform data source.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Link to standard data source instructions                                                                                                                                                | <p>The following types of logs can be ingested from Google Cloud Platform:</p><ul><li>Audit logs, including Google Kubernetes Engine (GKE) audit logs.</li><li>Generic logs</li><li>Google Cloud DNS logs</li><li>Network flow logs</li></ul><p>For more information, see <a href="/pages/fhdOVoabPxCz8Bq4T4mI">Ingest logs and data from a GCP Pub/Sub</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Link to full configuration Cloud Service Provider (CSP) onboarding data source instructions                                                                                              | [Onboard Google Cloud Platform](/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/onboard-google-cloud-platform.md)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Link to basic configuration Cloud Service Provider (CSP) onboarding data source instructions for Cortex XDR NG SIEM, Cortex XDR Enterprise license, and Cortex XDR Enterprise+ licenses. | [How to onboard Google Cloud Platform](/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/google-cloud-platform-cloud-onboarding/how-to-onboard-google-cloud-platform.md)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Links to content pack/ integration details (onboarded prior to July 26, 2026)                                                                                                            | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/GooglePubSub">Google Cloud Pub / Sub</a> content pack integrates with the Google Cloud Pub / Sub messaging service to enable you to send and receive messages between independent applications. It contains the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/google-pub-sub">Google Cloud Pub/Sub</a>: Use this integration to enable automated security operations and issue response through a series of dedicated commands that manage messaging topics, subscriptions, and message flow. For example, there are commands for listing, creating, updating, and deleting topics and subscriptions, publishing messages, and manually pulling or seeking messages for processing.</li></ul><p>This integration requires specific elevated permissions such as Project-Owner or Pub/Sub Admin.</p> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/cortex-cloud-data-sources-and-connectors/vendor-specific-data-sources/google/google-cloud-platform.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
