Google Cloud Audit Logs Integration
Overview
Google Cloud Audit Logs provide visibility into administrative actions, data access, and system events across GCP services. KYRA MDR collects these logs via Pub/Sub export for cloud security monitoring and compliance.
Prerequisites
- A KYRA MDR Collector installed and running
- Google Cloud project with Cloud Logging enabled
- Service account with Pub/Sub and Logging permissions
- Pub/Sub topic and subscription configured
Configuration
Configure GCP audit log export:
- Create a Pub/Sub topic for log export:
gcloud pubsub topics create kyra-mdr-logsgcloud pubsub subscriptions create kyra-mdr-sub \ --topic=kyra-mdr-logs- Create a log sink:
gcloud logging sinks create kyra-mdr-sink \ pubsub.googleapis.com/projects/<project>/topics/kyra-mdr-logs \ --log-filter='logName:"cloudaudit.googleapis.com"'- Grant the sink service account publish access to the topic
- Configure the KYRA MDR collector:
sources: - type: gcp-audit project_id: <project-id> subscription: kyra-mdr-sub credentials_file: /path/to/service-account.jsonCollected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Admin Activity | Resource creation, modification, deletion | Change management |
| Data Access | Data read and write operations | Data exfiltration detection |
| System Event | GCP infrastructure events | Infrastructure monitoring |
| Policy Denied | IAM policy violation events | Access control monitoring |
| VPC Flow | Network traffic metadata | Network security analysis |
| Cloud DNS | DNS query and response logs | DNS security monitoring |
Troubleshooting
No logs in Pub/Sub: Verify the log sink is active with gcloud logging sinks describe kyra-mdr-sink.
Missing Data Access logs: Data Access logs are disabled by default. Enable them under IAM & Admin > Audit Logs.
High volume costs: GCP Pub/Sub charges per message. Use log filters on the sink to export only security-relevant logs.
Contact kyra@seekerslab.com for support.