Quickstart: GCP
How Fusion integrates to GCP
Netography Fusion has the following integration points to GCP:
Fusion ingests VPC flow logs from GCP.
Fusion ingests asset context from GCP for context enrichment.
Fusion ingests Cloud DNS resolver logs from GCP.
Diagram of GCP integration to Fusion
See Diagram: GCP Integration to Fusion
Video Guides
See the GCP π₯ Video Guidesto watch videos of the setup steps.
Steps to integrate to GCP
Each page in these instructions will walk you through the steps to integrate GCP with Netography Fusion:
Enable VPC flow logs
Create a Pub/Sub topic
Create a Cloud Logging Sink Pub/Sub for the topic
Logging sink design patterns
Create a Pub/Sub Pull Subscription to the topic
Give Netography's GCP service account permission to be added as a principal to the Pub/Sub subscription
Add Netography's GCP service account as a principal for the Pub/Sub subscription
Add GCP as a new traffic source in Netography Fusion
Adding Context Integration for GCP to Netography Fusion
Enabling Cloud DNS logging and adding Cloud DNS as a Traffic Source in Netography Fusion
Onboarding multiple projects and folders in a GCP organization
You can onboard an entire GCP organization or folder by following the steps outlined in these documents one time.
You only need to create 1 GCP Pub/Sub topic, 1 GCP Cloud aggregated Logging Sink, 1 GCP Pub/Sub Subscription, and 1 Fusion GCP flow source to onboard GCP VPC flow logs to Fusion for as many VPC, subnets, projects, and sub-folders you have in your GCP organization, or that are in a single folder in your GCP organization.
If you need more granular control over what enabled VPC flow logs should be routed to Netography, you can create 1 GCP Pub/Sub topic, 1 GCP Pub/Sub Subscription, 1 Fusion GCP flow source, and as many Cloud Logging Sinks as you need (eg 1 per project) all routed to the same topic.
Additional information on using an aggregated logging sink and its benefits and limitations are described in our document Logging sink design patterns.
If you have GCP organization policy constraints in place, you may be unable to perform these steps until you update the organizational policies.
If you receive an error referring to an organization policy, update the policy and retry. Updating an organization policy requires the Organization Policy Administrator role (roles/orgpolicy.policyAdmin).
Last updated