Gemini
SIEM · Splunk (demo) Google · Assistant · fixture host gemini.google.com
Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
45
Medium
People
2
Usernames from the logs
Uploaded
7 MB
24 MB downloaded · 30 days
Events
560
2 source addresses
siemfixturesiem-only
Next steps
Recommended actions
- 01Gemini trains on data unless a business tier or opt-out is used. Verify which tier these users are on.
- 02Gemini appears only in Splunk (demo) logs, not in Microsoft 365 signals, so it is reaching the network from devices or accounts Microsoft does not see. Block or coach at the gateway, and check which sources are unmanaged.
Splunk (demo) · fixture
What the logs show
Hosts
| Host | Events | Uploaded |
|---|---|---|
| gemini.google.com | 560 | 7 MB |
Top sources
10.20.5.14410
10.20.5.60150
Same app, other lanes
Related findings
- Critical76GeminiCode · GitHub (demo)0 people
Who
People
Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.
| Person | Department | Source | Sign-ins · 30 d | Granted |
|---|---|---|---|---|
| n/a | SIEM logs | 0 | No direct grant | |
| n/a | SIEM logs | 0 | No direct grant |
Why
Evidence
- siem_traffic · Sep 14, 2026Splunk (demo): 560 events to gemini.google.com from 2 users and 2 sources in 30 days, 7 MB uploaded
Detail
{ "hosts": [ { "host": "gemini.google.com", "events": 560, "bytesOut": 7340032 } ], "bytesIn": 25165824, "bytesOut": 7340032, "topUsers": [ { "user": "[email protected]", "events": 410 }, { "user": "[email protected]", "events": 150 } ], "topSources": [ { "events": 410, "source": "10.20.5.14" }, { "events": 150, "source": "10.20.5.60" } ] }