Skip to content
Merged
Show file tree
Hide file tree
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions packages/gcp/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "2.39.0"
changes:
- description: Add `related.entity` field to audit logs.
type: enhancement
link: https://github.com/elastic/integrations/pull/11762
- version: "2.38.0"
changes:
- description: Add `policy_violation_info`, `metadata` and `related` fields to audit logs.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,10 @@
],
"user": [
"[email protected]"
],
"entity": [
"projects/elastic-beats",
"[email protected]"
]
},
"service": {
Expand Down Expand Up @@ -139,6 +143,10 @@
],
"user": [
"[email protected]"
],
"entity": [
"projects/elastic-beats/global/machineTypes",
"[email protected]"
]
},
"service": {
Expand Down Expand Up @@ -244,6 +252,10 @@
],
"user": [
"[email protected]"
],
"entity": [
"projects/elastic-beats/global/instances",
"[email protected]"
]
},
"service": {
Expand Down Expand Up @@ -336,6 +348,10 @@
],
"user": [
"[email protected]"
],
"entity": [
"projects/elastic-beats/global/instances",
"[email protected]"
]
},
"service": {
Expand Down Expand Up @@ -475,7 +491,8 @@
],
"user": [
"system:serviceaccount:cert-manager:cert-manager-webhook"
]
],
"entity": []
},
"service": {
"name": "k8s.io"
Expand Down Expand Up @@ -598,6 +615,10 @@
],
"user": [
"[email protected]"
],
"entity": [
"projects/foo/global/images/windows-server-2016-v20200805",
"[email protected]"
]
},
"service": {
Expand Down Expand Up @@ -689,6 +710,10 @@
],
"user": [
"[email protected]"
],
"entity": [
"projects/foo/zones/us-central1-a/instances/win10-test",
"[email protected]"
]
},
"service": {
Expand Down Expand Up @@ -792,7 +817,8 @@
],
"user": [
"[email protected]"
]
],
"entity": []
},
"service": {
"name": "k8s.io"
Expand Down Expand Up @@ -880,7 +906,8 @@
],
"user": [
"[email protected]"
]
],
"entity": []
},
"service": {
"name": "k8s.io"
Expand Down Expand Up @@ -965,7 +992,8 @@
],
"user": [
"system:anonymous"
]
],
"entity": []
},
"service": {
"name": "k8s.io"
Expand Down Expand Up @@ -1048,7 +1076,8 @@
],
"user": [
"system:serviceaccount:kube-system:generic-garbage-collector"
]
],
"entity": []
},
"service": {
"name": "k8s.io"
Expand Down Expand Up @@ -1131,6 +1160,12 @@
"related": {
"user": [
"[email protected]"
],
"entity": [
"projects/project",
"sub",
"[email protected]",
"//xxx@xxx"
]
},
"service": {
Expand Down Expand Up @@ -1266,6 +1301,7 @@
"type": "kubernetes"
},
"related": {
"entity": [],
"ip": [
"67.43.156.13"
],
Expand Down Expand Up @@ -1656,6 +1692,7 @@
"type": "kubernetes"
},
"related": {
"entity": [],
"ip": [
"10.142.0.152"
],
Expand Down Expand Up @@ -1747,6 +1784,9 @@
"type": "kubernetes"
},
"related": {
"entity": [
"serviceAccount:[email protected]"
],
"ip": [
"192.168.1.1"
],
Expand Down Expand Up @@ -1826,6 +1866,10 @@
"logger": "projects/elastic/logs/cloudaudit.googleapis.com%2Fdata_access"
},
"related": {
"entity": [
"projects/_/buckets/dataflow-staging-us-central1-xxx/objects/staging/jfxrt-xxx.jar",
"[email protected]"
],
"user": [
"[email protected]"
]
Expand Down Expand Up @@ -1909,6 +1953,9 @@
"type": "kubernetes"
},
"related": {
"entity": [
"serviceAccount:[email protected]"
],
"ip": [
"192.168.1.1"
],
Expand Down Expand Up @@ -1992,6 +2039,12 @@
"logger": "projects/elastic-beats/logs/cloudaudit.googleapis.com%2Fdata_access"
},
"related": {
"entity": [
"projects/project",
"sub",
"[email protected]",
"//xxx@xxx"
],
"user": [
"[email protected]"
]
Expand Down Expand Up @@ -2060,6 +2113,10 @@
"logger": "projects/elastic-siem/logs/cloudaudit.googleapis.com%2Fsystem_event"
},
"related": {
"entity": [
"projects/elastic-siem/zones/us-central1-c/instances/sep-perf-debian-11-155",
"[email protected]"
],
"user": [
"[email protected]"
]
Expand Down Expand Up @@ -2138,6 +2195,9 @@
"logger": "projects/elastic-siem/logs/cloudaudit.googleapis.com%2Fpolicy"
},
"related": {
"entity": [
"projects/elastic-siem"
],
"ip": [
"192.168.1.1"
]
Expand Down Expand Up @@ -2236,6 +2296,9 @@
"type": "kubernetes"
},
"related": {
"entity": [
"serviceAccount:[email protected]"
],
"ip": [
"192.168.1.1"
],
Expand Down Expand Up @@ -2311,6 +2374,9 @@
},
"type": "kubernetes"
},
"related": {
"entity": []
},
"service": {
"name": "container.googleapis.com"
},
Expand All @@ -2319,4 +2385,4 @@
]
}
]
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
{"insertId":"-30102re2sad8","logName":"projects/project-id/logs/cloudaudit.googleapis.com%2Factivity","protoPayload":{"@type":"type.googleapis.com/google.cloud.audit.AuditLog","authenticationInfo":{"principalEmail":"[email protected]","principalSubject":"serviceAccount:[email protected]","serviceAccountDelegationInfo":[{"principalSubject":"principal://iam.googleapis.com/projects/project-id/locations/global/workloadIdentityPools/..."}]},"authorizationInfo":[{"granted":true,"permission":"resourcemanager.projects.setIamPolicy","permissionType":"ADMIN_WRITE","resource":"projects/project-id","resourceAttributes":{"name":"projects/project-id","service":"cloudresourcemanager.googleapis.com","type":"cloudresourcemanager.googleapis.com/Project"}},{"granted":true,"permission":"resourcemanager.projects.setIamPolicy","permissionType":"ADMIN_WRITE","resource":"projects/project-id","resourceAttributes":{"name":"projects/project-id","service":"cloudresourcemanager.googleapis.com","type":"cloudresourcemanager.googleapis.com/Project"}}],"methodName":"SetIamPolicy","request":{"@type":"type.googleapis.com/google.iam.v1.SetIamPolicyRequest","policy":{"bindings":[{"members":["serviceAccount:[email protected]"],"role":"projects/project-id/roles/ThatRoleToo"},{"members":["serviceAccount:[email protected]"],"role":"projects/project-id/roles/x"},{"members":["serviceAccount:[email protected]"],"role":"projects/project-id/roles/this_role_as_well"},{"members":["serviceAccount:[email protected]","serviceAccount:[email protected]","serviceAccount:[email protected]"],"role":"roles/browser"},{"members":["serviceAccount:[email protected]","serviceAccount:[email protected]","serviceAccount:[email protected]"],"role":"roles/cloudasset.viewer"},{"members":["user:[email protected]"],"role":"roles/cloudkms.admin"},{"members":["group:[email protected]"],"role":"roles/owner"}],"etag":"BwYnObHBOBA="},"resource":"project-id"},"requestMetadata":{"callerIp":"192.168.0.1","callerSuppliedUserAgent":"google-cloud-sdk gcloud/501.0.0 command/gcloud.projects.add-iam-policy-binding invocation-id/e9e9e4b6f9294a7da9a2247dc101225a environment/None environment-version/None client-os/LINUX client-os-ver/5.15.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.4 term/ (Linux 5.15.0-1074-azure),gzip(gfe)","destinationAttributes":{},"requestAttributes":{}},"resourceName":"projects/project-id","response":{"@type":"type.googleapis.com/google.iam.v1.Policy","bindings":[{"members":["serviceAccount:[email protected]"],"role":"projects/project-id/roles/ThatRoleToo"},{"members":["serviceAccount:[email protected]"],"role":"projects/project-id/roles/random"}],"etag":"BwYnQ8iRtu0="},"serviceData":{"@type":"type.googleapis.com/google.iam.v1.logging.AuditData","policyDelta":{"bindingDeltas":[{"action":"ADD","member":"serviceAccount:[email protected]","role":"roles/resourcemanager.projectIamAdmin"}]}},"serviceName":"cloudresourcemanager.googleapis.com","status":{}},"receiveTimestamp":"2024-11-19T13:12:21.785498724Z","resource":{"labels":{"project_id":"project-id"},"type":"project"},"severity":"NOTICE","timestamp":"2024-11-19T13:12:20.942393Z"}
Loading