Splunk has a Google Cloud Platform add-on that can pull directly from Pub/Sub. Install the "Splunk Add-on for Google Cloud Platform" from Splunkbase Configure the add-on with the service account key ...