Skip to main content

Google Cloud security

GCP Audit Log anomaly detection for small security teams

Flare turns Google Cloud Audit Logs into ranked, explained findings—without complete-log retention, per-GB ingestion fees, or detection rules for your team to author.

How it works

Turn Google Cloud audit activity into an investigation queue

Analyze Admin Activity, System Event, and Policy Denied logs. Data Access logs are included only when they are enabled in Google Cloud and separately authorized for Flare.

01

Connect read-only

Connect with Google OAuth and grant only the documented read-only permissions for the projects you choose.

02

Review ranked findings

Flare assesses current-window evidence with available historical context, then ranks noteworthy activity by severity and explains why it matters.

03

Investigate the evidence

Inspect selected source-event excerpts and ask follow-up questions using the retained analysis results and supporting evidence.

Built for small teams

Useful audit-log answers without a SIEM project

Start with real evidence

See what changed in Google Cloud.

Connect read-only or upload a focused JSON, NDJSON, CSV, or plain-text log file. Flare is free during the open beta.

Start free