AI inventory

Gemini

SIEM · Splunk (demo) Google · Assistant · fixture host gemini.google.com

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
45
Medium
People
2
Usernames from the logs
Uploaded
7 MB
24 MB downloaded · 30 days
Events
560
2 source addresses
siemfixturesiem-only
Next steps

Recommended actions

  1. 01Gemini trains on data unless a business tier or opt-out is used. Verify which tier these users are on.
  2. 02Gemini appears only in Splunk (demo) logs, not in Microsoft 365 signals, so it is reaching the network from devices or accounts Microsoft does not see. Block or coach at the gateway, and check which sources are unmanaged.
Splunk (demo) · fixture

What the logs show

Hosts
HostEventsUploaded
gemini.google.com5607 MB
Top sources
10.20.5.14410
10.20.5.60150
Same app, other lanes

Related findings

  • Critical76GeminiCode · GitHub (demo)0 people
Who

People

Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.

PersonDepartmentSourceSign-ins · 30 dGranted
n/aSIEM logs0No direct grant
n/aSIEM logs0No direct grant
Why

Evidence

  1. siem_traffic · Sep 14, 2026
    Splunk (demo): 560 events to gemini.google.com from 2 users and 2 sources in 30 days, 7 MB uploaded
    Detail
    {
      "hosts": [
        {
          "host": "gemini.google.com",
          "events": 560,
          "bytesOut": 7340032
        }
      ],
      "bytesIn": 25165824,
      "bytesOut": 7340032,
      "topUsers": [
        {
          "user": "[email protected]",
          "events": 410
        },
        {
          "user": "[email protected]",
          "events": 150
        }
      ],
      "topSources": [
        {
          "events": 410,
          "source": "10.20.5.14"
        },
        {
          "events": 150,
          "source": "10.20.5.60"
        }
      ]
    }