跳至正文

Google Cloud Audit Logs Integration

Overview

Google Cloud Audit Logs provide visibility into administrative actions, data access, and system events across GCP services. KYRA MDR collects these logs via Pub/Sub export for cloud security monitoring and compliance.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Google Cloud project with Cloud Logging enabled
  • Service account with Pub/Sub and Logging permissions
  • Pub/Sub topic and subscription configured

Configuration

Configure GCP audit log export:

  1. Create a Pub/Sub topic for log export:
Terminal window
gcloud pubsub topics create kyra-mdr-logs
gcloud pubsub subscriptions create kyra-mdr-sub \
--topic=kyra-mdr-logs
  1. Create a log sink:
Terminal window
gcloud logging sinks create kyra-mdr-sink \
pubsub.googleapis.com/projects/<project>/topics/kyra-mdr-logs \
--log-filter='logName:"cloudaudit.googleapis.com"'
  1. Grant the sink service account publish access to the topic
  2. Configure the KYRA MDR collector:
collector-config.yaml
sources:
- type: gcp-audit
project_id: <project-id>
subscription: kyra-mdr-sub
credentials_file: /path/to/service-account.json

Collected Log Types

Log TypeDescriptionSecurity Use
Admin ActivityResource creation, modification, deletionChange management
Data AccessData read and write operationsData exfiltration detection
System EventGCP infrastructure eventsInfrastructure monitoring
Policy DeniedIAM policy violation eventsAccess control monitoring
VPC FlowNetwork traffic metadataNetwork security analysis
Cloud DNSDNS query and response logsDNS security monitoring

Troubleshooting

No logs in Pub/Sub: Verify the log sink is active with gcloud logging sinks describe kyra-mdr-sink.

Missing Data Access logs: Data Access logs are disabled by default. Enable them under IAM & Admin > Audit Logs.

High volume costs: GCP Pub/Sub charges per message. Use log filters on the sink to export only security-relevant logs.

Contact kyra@seekerslab.com for support.