Connect read-only
Connect with Google OAuth and grant only the documented read-only permissions for the projects you choose.
Google Cloud security
Flare turns Google Cloud Audit Logs into ranked, explained findings—without complete-log retention, per-GB ingestion fees, or detection rules for your team to author.
How it works
Analyze Admin Activity, System Event, and Policy Denied logs. Data Access logs are included only when they are enabled in Google Cloud and separately authorized for Flare.
Connect with Google OAuth and grant only the documented read-only permissions for the projects you choose.
Flare assesses current-window evidence with available historical context, then ranks noteworthy activity by severity and explains why it matters.
Inspect selected source-event excerpts and ask follow-up questions using the retained analysis results and supporting evidence.
Built for small teams
Flare uses read-only access and retains analysis results with selected supporting evidence—not a complete copy of your logs.
Read the GCP Audit Log investigation guide →Review Google Cloud access requirements →Explore AWS CloudTrail audit coverage, access requirements and availability.
Explore AWS CloudTrail anomaly detection →Start with real evidence
Connect read-only or upload a focused JSON, NDJSON, CSV, or plain-text log file. Flare is free during the open beta.
Start free