Compute Engine

methodNameDescriptionLog typeSampleRule
anyCatch-all entry for compute.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.activityNY
compute.acceleratorTypes.aggregatedListRetrieves an aggregated list of accelerator types. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.acceleratorTypes.getReturns the specified accelerator type.data_accessNN
compute.acceleratorTypes.listRetrieves a list of accelerator types that are available to the specified project.data_accessNN
compute.addresses.aggregatedListRetrieves an aggregated list of addresses. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.addresses.deleteDeletes the specified address resource.activityYN
compute.addresses.getReturns the specified address resource.data_accessYN
compute.addresses.insertCreates an address resource in the specified project by using the data included in the request.activityYN
compute.addresses.listRetrieves a list of addresses contained within the specified region.data_accessYN
compute.addresses.moveMoves the specified address resource.activityNN
compute.addresses.setLabelsSets the labels on an Address. To learn more about labels, read theLabeling Resources documentation.activityNN
compute.addresses.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.advice.calendarModeAdvise how, where and when to create the requested amount of instances with specified accelerators, within the specified time and location limits. The method recommends creating future reservations for the requested resources.activityNN
compute.autoscalers.aggregatedListRetrieves an aggregated list of autoscalers. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.autoscalers.deleteDeletes the specified autoscaler.activityNN
compute.autoscalers.getReturns the specified autoscaler resource.data_accessNN
compute.autoscalers.insertCreates an autoscaler in the specified project using the data included in the request.activityYN
compute.autoscalers.listRetrieves a list of autoscalers contained within the specified zone.data_accessNN
compute.autoscalers.patchUpdates an autoscaler in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.autoscalers.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.autoscalers.updateUpdates an autoscaler in the specified project using the data included in the request.activityNN
compute.backendBuckets.addSignedUrlKeyAdds a key for validating requests with signed URLs for this backend bucket.activityNN
compute.backendBuckets.aggregatedListRetrieves the list of all BackendBucket resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.backendBuckets.deleteDeletes the specified BackendBucket resource.activityYN
compute.backendBuckets.deleteSignedUrlKeyDeletes a key for validating requests with signed URLs for this backend bucket.activityNN
compute.backendBuckets.getReturns the specified BackendBucket resource.data_accessNN
compute.backendBuckets.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.backendBuckets.insertCreates a BackendBucket resource in the specified project using the data included in the request.activityYN
compute.backendBuckets.listRetrieves the list of BackendBucket resources available to the specified project.data_accessNN
compute.backendBuckets.listUsableRetrieves a list of all usable backend buckets in the specified project.data_accessNN
compute.backendBuckets.patchUpdates the specified BackendBucket resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.backendBuckets.setEdgeSecurityPolicySets the edge security policy for the specified backend bucket.activityNN
compute.backendBuckets.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.backendBuckets.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.backendBuckets.updateUpdates the specified BackendBucket resource with the data included in the request.activityNN
compute.backendServices.addSignedUrlKeyAdds a key for validating requests with signed URLs for this backend service.activityNN
compute.backendServices.aggregatedListRetrieves the list of all BackendService resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.backendServices.deleteDeletes the specified BackendService resource.activityNN
compute.backendServices.deleteSignedUrlKeyDeletes a key for validating requests with signed URLs for this backend service.activityNN
compute.backendServices.getReturns the specified BackendService resource.data_accessYN
compute.backendServices.getEffectiveSecurityPoliciesReturns effective security policies applied to this backend service.data_accessNN
compute.backendServices.getHealthGets the most recent health check results for this BackendService. Example request body: { "group": "/zones/us-east1-b/instanceGroups/lb-backend-example" }data_accessNN
compute.backendServices.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.backendServices.insertCreates a BackendService resource in the specified project using the data included in the request. For more information, see Backend services overview.activityYN
compute.backendServices.listRetrieves the list of BackendService resources available to the specified project.data_accessYN
compute.backendServices.listUsableRetrieves a list of all usable backend services in the specified project.data_accessNN
compute.backendServices.patchPatches the specified BackendService resource with the data included in the request. For more information, see Backend services overview. This method supports PATCH semantics and uses the JSON merge patch format and processing rules.activityNN
compute.backendServices.setEdgeSecurityPolicySets the edge security policy for the specified backend service.activityNN
compute.backendServices.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.backendServices.setSecurityPolicySets the Google Cloud Armor security policy for the specified backend service. For more information, seeGoogle Cloud Armor OverviewactivityNN
compute.backendServices.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.backendServices.updateUpdates the specified BackendService resource with the data included in the request. For more information, seeBackend services overview.activityNN
compute.crossSiteNetworks.deleteDeletes the specified cross-site network in the given scope.activityNN
compute.crossSiteNetworks.getReturns the specified cross-site network in the given scope.data_accessNN
compute.crossSiteNetworks.insertCreates a cross-site network in the specified project in the given scope using the parameters that are included in the request.activityNN
compute.crossSiteNetworks.listLists the cross-site networks for a project in the given scope.data_accessNN
compute.crossSiteNetworks.patchUpdates the specified cross-site network with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.diskTypes.aggregatedListRetrieves an aggregated list of disk types. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.diskTypes.getReturns the specified disk type.data_accessNN
compute.diskTypes.listRetrieves a list of disk types available to the specified project.data_accessNN
compute.disks.addResourcePoliciesAdds existing resource policies to a disk. You can only add one policy which will be applied to this disk for scheduling snapshot creation.activityNN
compute.disks.aggregatedListRetrieves an aggregated list of persistent disks. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.disks.bulkInsertBulk create a set of disks.activityNN
compute.disks.bulkSetLabelsSets the labels on many disks at once. To learn more about labels, read theLabeling Resources documentation.activityNN
compute.disks.createSnapshotCreates a snapshot of a specified persistent disk. For regular snapshot creation, consider using snapshots.insert instead, as that method supports more features, such as creating snapshots in a project different from the source disk project.activityYN
compute.disks.deleteDeletes the specified persistent disk. Deleting a disk removes its data permanently and is irreversible. However, deleting a disk does not delete any snapshots previously made from the disk. You must separatelydelete snapshots.activityYN
compute.disks.getReturns the specified persistent disk.data_accessYN
compute.disks.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.disks.insertCreates a persistent disk in the specified project using the data in the request. You can create a disk from a source (sourceImage, sourceSnapshot, orsourceDisk) or create an empty 500 GB data disk by omitting all properties. You can also create a disk that is larger than the default size by specifying the sizeGb property.activityYN
compute.disks.listRetrieves a list of persistent disks contained within the specified zone.data_accessYN
compute.disks.removeResourcePoliciesRemoves resource policies from a disk.activityNN
compute.disks.resizeResizes the specified persistent disk. You can only increase the size of the disk.activityYN
compute.disks.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityYY
compute.disks.setLabelsSets the labels on a disk. To learn more about labels, read theLabeling Resources documentation.activityYN
compute.disks.startAsyncReplicationStarts asynchronous replication. Must be invoked on the primary disk.activityNN
compute.disks.stopAsyncReplicationStops asynchronous replication. Can be invoked either on the primary or on the secondary disk.activityNN
compute.disks.stopGroupAsyncReplicationStops asynchronous replication for a consistency group of disks. Can be invoked either in the primary or secondary scope.activityNN
compute.disks.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.disks.updateUpdates the specified disk with the data included in the request. The update is performed only on selected fields included as part of update-mask.activityNN
compute.disks.updateKmsKeyRotates the customer-managed encryption key to the latest version for the specified persistent disk.activityNN
compute.externalVpnGateways.deleteDeletes the specified externalVpnGateway.activityYN
compute.externalVpnGateways.getReturns the specified externalVpnGateway. Get a list of available externalVpnGateways by making a list() request.data_accessYN
compute.externalVpnGateways.insertCreates a ExternalVpnGateway in the specified project using the data included in the request.activityYN
compute.externalVpnGateways.listRetrieves the list of ExternalVpnGateway available to the specified project.data_accessNN
compute.externalVpnGateways.setLabelsSets the labels on an ExternalVpnGateway. To learn more about labels, read the Labeling Resources documentation.activityNN
compute.externalVpnGateways.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.firewallPolicies.addAssociationInserts an association for the specified firewall policy.activityNN
compute.firewallPolicies.addRuleInserts a rule into a firewall policy.activityNN
compute.firewallPolicies.cloneRulesCopies rules to the specified firewall policy.activityNN
compute.firewallPolicies.deleteDeletes the specified policy.activityNN
compute.firewallPolicies.getReturns the specified firewall policy.data_accessNN
compute.firewallPolicies.getAssociationGets an association with the specified name.data_accessNN
compute.firewallPolicies.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.firewallPolicies.getRuleGets a rule of the specified priority.data_accessNN
compute.firewallPolicies.insertCreates a new policy in the specified project using the data included in the request.activityNN
compute.firewallPolicies.listLists all the policies that have been configured for the specified folder or organization.data_accessNN
compute.firewallPolicies.listAssociationsLists associations of a specified target, i.e., organization or folder.data_accessNN
compute.firewallPolicies.moveMoves the specified firewall policy.activityNN
compute.firewallPolicies.patchPatches the specified policy with the data included in the request.activityNN
compute.firewallPolicies.patchRulePatches a rule of the specified priority.activityNN
compute.firewallPolicies.removeAssociationRemoves an association for the specified firewall policy.activityNN
compute.firewallPolicies.removeRuleDeletes a rule of the specified priority.activityNN
compute.firewallPolicies.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.firewallPolicies.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.firewalls.deleteDeletes the specified firewall.activityYY
compute.firewalls.getReturns the specified firewall.data_accessYN
compute.firewalls.insertCreates a firewall rule in the specified project using the data included in the request.activityYY
compute.firewalls.listRetrieves the list of firewall rules available to the specified project.data_accessYN
compute.firewalls.patchPatches the specified firewall rule with the data included in the request.activityYY
compute.firewalls.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.firewalls.updateUpdates the specified firewall rule with the data included in the request.activityNY
compute.forwardingRules.aggregatedListRetrieves an aggregated list of forwarding rules. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.forwardingRules.deleteDeletes the specified ForwardingRule resource.activityYN
compute.forwardingRules.getReturns the specified ForwardingRule resource.data_accessYN
compute.forwardingRules.insertCreates a ForwardingRule resource in the specified project and region using the data included in the request.activityYN
compute.forwardingRules.listRetrieves a list of ForwardingRule resources available to the specified project and region.data_accessNN
compute.forwardingRules.patchUpdates the specified forwarding rule with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. Currently, you can only patch the network_tier field.activityNN
compute.forwardingRules.setLabelsSets the labels on the specified resource. To learn more about labels, read the Labeling Resources documentation.activityNN
compute.forwardingRules.setTargetChanges target URL for forwarding rule. The new target should be of the same type as the old target.activityNN
compute.futureReservations.aggregatedListRetrieves an aggregated list of future reservations. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.futureReservations.cancelCancel the specified future reservation.activityNN
compute.futureReservations.deleteDeletes the specified future reservation.activityNN
compute.futureReservations.getRetrieves information about the specified future reservation.data_accessNN
compute.futureReservations.insertCreates a new Future Reservation.activityNN
compute.futureReservations.listA list of all the future reservations that have been configured for the specified project in specified zone.data_accessNN
compute.futureReservations.updateUpdates the specified future reservation.activityNN
compute.globalAddresses.deleteDeletes the specified address resource.activityYN
compute.globalAddresses.getReturns the specified address resource.data_accessNN
compute.globalAddresses.insertCreates an address resource in the specified project by using the data included in the request.activityYN
compute.globalAddresses.listRetrieves a list of global addresses.data_accessNN
compute.globalAddresses.moveMoves the specified address resource from one project to another project.activityNN
compute.globalAddresses.setLabelsSets the labels on a GlobalAddress. To learn more about labels, read theLabeling Resources documentation.activityNN
compute.globalAddresses.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.globalForwardingRules.deleteDeletes the specified GlobalForwardingRule resource.activityNN
compute.globalForwardingRules.getReturns the specified GlobalForwardingRule resource. Gets a list of available forwarding rules by making a list() request.data_accessNN
compute.globalForwardingRules.insertCreates a GlobalForwardingRule resource in the specified project using the data included in the request.activityYN
compute.globalForwardingRules.listRetrieves a list of GlobalForwardingRule resources available to the specified project.data_accessNN
compute.globalForwardingRules.patchUpdates the specified forwarding rule with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. Currently, you can only patch the network_tier field.activityNN
compute.globalForwardingRules.setLabelsSets the labels on the specified resource. To learn more about labels, read the Labeling resources documentation.activityNN
compute.globalForwardingRules.setTargetChanges target URL for the GlobalForwardingRule resource. The new target should be of the same type as the old target.activityNN
compute.globalNetworkEndpointGroups.attachNetworkEndpointsAttach a network endpoint to the specified network endpoint group.activityNN
compute.globalNetworkEndpointGroups.deleteDeletes the specified network endpoint group.Note that the NEG cannot be deleted if there are backend services referencing it.activityNN
compute.globalNetworkEndpointGroups.detachNetworkEndpointsDetach the network endpoint from the specified network endpoint group.activityNN
compute.globalNetworkEndpointGroups.getReturns the specified network endpoint group.data_accessNN
compute.globalNetworkEndpointGroups.insertCreates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global APIactivityNN
compute.globalNetworkEndpointGroups.listRetrieves the list of network endpoint groups that are located in the specified project.data_accessNN
compute.globalNetworkEndpointGroups.listNetworkEndpointsLists the network endpoints in the specified network endpoint group.data_accessNN
compute.globalOperations.aggregatedListRetrieves an aggregated list of all operations. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.globalOperations.deleteDeletes the specified Operations resource.activityNN
compute.globalOperations.getRetrieves the specified Operations resource.data_accessYN
compute.globalOperations.listRetrieves a list of Operation resources contained within the specified project.data_accessNN
compute.globalOperations.waitWaits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method differs from the `GET` method in that it waits for no more than the default deadline (2 minutes) and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`.data_accessYN
compute.globalOrganizationOperations.deleteDeletes the specified Operations resource.activityNN
compute.globalOrganizationOperations.getRetrieves the specified Operations resource. Gets a list of operations by making a `list()` request.data_accessNN
compute.globalOrganizationOperations.listRetrieves a list of Operation resources contained within the specified organization.data_accessNN
compute.globalPublicDelegatedPrefixes.deleteDeletes the specified global PublicDelegatedPrefix.activityNN
compute.globalPublicDelegatedPrefixes.getReturns the specified global PublicDelegatedPrefix resource.data_accessNN
compute.globalPublicDelegatedPrefixes.insertCreates a global PublicDelegatedPrefix in the specified project using the parameters that are included in the request.activityNN
compute.globalPublicDelegatedPrefixes.listLists the global PublicDelegatedPrefixes for a project.data_accessNN
compute.globalPublicDelegatedPrefixes.patchPatches the specified global PublicDelegatedPrefix resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.globalVmExtensionPolicies.aggregatedListRetrieves the list of all VM Extension Policy resources available to the specified project. To prevent failure, it's recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.globalVmExtensionPolicies.deletePurge scoped resources (zonal policies) from a global VM extension policy, and then delete the global VM extension policy. Purge of the scoped resources is a pre-condition of the global VM extension policy deletion. The deletion of the global VM extension policy happens after the purge rollout is done, so it's not a part of the LRO. It's an automatic process that triggers in the backend.activityNN
compute.globalVmExtensionPolicies.getGets details of a global VM extension policy.data_accessNN
compute.globalVmExtensionPolicies.insertCreates a new project level GlobalVmExtensionPolicy.activityNN
compute.globalVmExtensionPolicies.listLists global VM extension policies.data_accessNN
compute.globalVmExtensionPolicies.updateUpdates a global VM extension policy.activityNN
compute.healthChecks.aggregatedListRetrieves the list of all HealthCheck resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.healthChecks.deleteDeletes the specified HealthCheck resource.activityNN
compute.healthChecks.getReturns the specified HealthCheck resource.data_accessNN
compute.healthChecks.insertCreates a HealthCheck resource in the specified project using the data included in the request.activityYN
compute.healthChecks.listRetrieves the list of HealthCheck resources available to the specified project.data_accessNN
compute.healthChecks.patchUpdates a HealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.healthChecks.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.healthChecks.updateUpdates a HealthCheck resource in the specified project using the data included in the request.activityNN
compute.httpHealthChecks.deleteDeletes the specified HttpHealthCheck resource.activityNN
compute.httpHealthChecks.getReturns the specified HttpHealthCheck resource.data_accessNN
compute.httpHealthChecks.insertCreates a HttpHealthCheck resource in the specified project using the data included in the request.activityYN
compute.httpHealthChecks.listRetrieves the list of HttpHealthCheck resources available to the specified project.data_accessNN
compute.httpHealthChecks.patchUpdates a HttpHealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.httpHealthChecks.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.httpHealthChecks.updateUpdates a HttpHealthCheck resource in the specified project using the data included in the request.activityNN
compute.httpsHealthChecks.deleteDeletes the specified HttpsHealthCheck resource.activityNN
compute.httpsHealthChecks.getReturns the specified HttpsHealthCheck resource.data_accessNN
compute.httpsHealthChecks.insertCreates a HttpsHealthCheck resource in the specified project using the data included in the request.activityNN
compute.httpsHealthChecks.listRetrieves the list of HttpsHealthCheck resources available to the specified project.data_accessNN
compute.httpsHealthChecks.patchUpdates a HttpsHealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.httpsHealthChecks.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.httpsHealthChecks.updateUpdates a HttpsHealthCheck resource in the specified project using the data included in the request.activityNN
compute.imageFamilyViews.getReturns the latest image that is part of an image family, is not deprecated and is rolled out in the specified zone.data_accessNN
compute.images.deleteDeletes the specified image.activityYN
compute.images.deprecateSets the deprecation status of an image. If an empty request body is given, clears the deprecation status instead.activityNN
compute.images.getReturns the specified image.data_accessYN
compute.images.getFromFamilyReturns the latest image that is part of an image family and is not deprecated. For more information on image families, seePublic image families documentation.data_accessNN
compute.images.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessYN
compute.images.insertCreates an image in the specified project using the data included in the request.activityYN
compute.images.listRetrieves the list of custom images available to the specified project. Custom images are images you create that belong to your project. This method does not get any images that belong to other projects, including publicly-available images, like Debian 8. If you want to get a list of publicly-available images, use this method to make a request to the respective image project, such as debian-cloud or windows-cloud.data_accessYN
compute.images.patchPatches the specified image with the data included in the request. Only the following fields can be modified: family, description, deprecation status.activityNN
compute.images.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityYY
compute.images.setLabelsSets the labels on an image. To learn more about labels, read theLabeling Resources documentation.activityNN
compute.images.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.instanceGroupManagerResizeRequests.cancelCancels the specified resize request and removes it from the queue. Cancelled resize request does no longer wait for the resources to be provisioned. Cancel is only possible for requests that are accepted in the queue.activityNN
compute.instanceGroupManagerResizeRequests.deleteDeletes the specified, inactive resize request. Requests that are still active cannot be deleted. Deleting request does not delete instances that were provisioned previously.activityNN
compute.instanceGroupManagerResizeRequests.getReturns all of the details about the specified resize request.data_accessNN
compute.instanceGroupManagerResizeRequests.insertCreates a new resize request that starts provisioning VMs immediately or queues VM creation.activityNN
compute.instanceGroupManagerResizeRequests.listRetrieves a list of resize requests that are contained in the managed instance group.data_accessNN
compute.instanceGroupManagers.abandonInstancesFlags the specified instances to be removed from the managed instance group. Abandoning an instance does not delete the instance, but it does remove the instance from any target pools that are applied by the managed instance group. This method reduces thetargetSize of the managed instance group by the number of instances that you abandon. This operation is marked asDONE when the action is scheduled even if the instances have not yet been removed from the group. You must separately verify the status of the abandoning action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.instanceGroupManagers.aggregatedListRetrieves the list of managed instance groups and groups them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.instanceGroupManagers.applyUpdatesToInstancesApplies changes to selected instances on the managed instance group. This method can be used to apply new overrides and/or new versions.activityNN
compute.instanceGroupManagers.createInstancesCreates instances with per-instance configurations in this managed instance group. Instances are created using the current instance template. Thecreate instances operation is marked DONE if thecreateInstances request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or actions with the listmanagedinstances method.activityNN
compute.instanceGroupManagers.deleteDeletes the specified managed instance group and all of the instances in that group. Note that the instance group must not belong to a backend service. Read Deleting an instance group for more information.activityYN
compute.instanceGroupManagers.deleteInstancesFlags the specified instances in the managed instance group for immediate deletion. The instances are also removed from any target pools of which they were a member. This method reduces thetargetSize of the managed instance group by the number of instances that you delete. This operation is marked as DONE when the action is scheduled even if the instances are still being deleted. You must separately verify the status of the deleting action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.instanceGroupManagers.deletePerInstanceConfigsDeletes selected per-instance configurations for the managed instance group.activityNN
compute.instanceGroupManagers.getReturns all of the details about the specified managed instance group.data_accessYN
compute.instanceGroupManagers.insertCreates a managed instance group using the information that you specify in the request. After the group is created, instances in the group are created using the specified instance template. This operation is marked as DONE when the group is created even if the instances in the group have not yet been created. You must separately verify the status of the individual instances with thelistmanagedinstances method. A managed instance group can have up to 1000 VM instances per group. Please contact Cloud Support if you need an increase in this limit.activityYN
compute.instanceGroupManagers.listRetrieves a list of managed instance groups that are contained within the specified project and zone.data_accessYN
compute.instanceGroupManagers.listErrorsLists all errors thrown by actions on instances for a given managed instance group. The filter and orderBy query parameters are not supported.data_accessNN
compute.instanceGroupManagers.listManagedInstancesLists all of the instances in the managed instance group. Each instance in the list has a currentAction, which indicates the action that the managed instance group is performing on the instance. For example, if the group is still creating an instance, the currentAction is CREATING. If a previous action failed, the list displays the errors for that failed action. The orderBy query parameter is not supported. The `pageToken` query parameter is supported only if the group's `listManagedInstancesResults` field is set to `PAGINATED`.data_accessYN
compute.instanceGroupManagers.listPerInstanceConfigsLists all of the per-instance configurations defined for the managed instance group. The orderBy query parameter is not supported.data_accessNN
compute.instanceGroupManagers.patchUpdates a managed instance group using the information that you specify in the request. This operation is marked as DONE when the group is patched even if the instances in the group are still in the process of being patched. You must separately verify the status of the individual instances with thelistManagedInstances method. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. If you update your group to specify a new template or instance configuration, it's possible that your intended specification for each VM in the group is different from the current state of that VM. To learn how to apply an updated configuration to the VMs in a MIG, seeUpdating instances in a MIG.activityNN
compute.instanceGroupManagers.patchPerInstanceConfigsInserts or patches per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.activityNN
compute.instanceGroupManagers.recreateInstancesFlags the specified VM instances in the managed instance group to be immediately recreated. Each instance is recreated using the group's current configuration. This operation is marked as DONE when the flag is set even if the instances have not yet been recreated. You must separately verify the status of each instance by checking itscurrentAction field; for more information, see Checking the status of managed instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.instanceGroupManagers.resizeResizes the managed instance group. If you increase the size, the group creates new instances using the current instance template. If you decrease the size, the group deletes instances. The resize operation is markedDONE when the resize actions are scheduled even if the group has not yet added or deleted any instances. You must separately verify the status of the creating or deleting actions with thelistmanagedinstances method. When resizing down, the instance group arbitrarily chooses the order in which VMs are deleted. The group takes into account some VM attributes when making the selection including: + The status of the VM instance. + The health of the VM instance. + The instance template version the VM is based on. + For regional managed instance groups, the location of the VM instance. This list is subject to change. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted.activityNN
compute.instanceGroupManagers.resumeInstancesFlags the specified instances in the managed instance group to be resumed. This method increases thetargetSize and decreases the targetSuspendedSize of the managed instance group by the number of instances that you resume. The resumeInstances operation is marked DONE if the resumeInstances request is successful. The underlying actions take additional time. You must separately verify the status of theRESUMING action with thelistmanagedinstances method. In this request, you can only specify instances that are suspended. For example, if an instance was previously suspended using the suspendInstances method, it can be resumed using the resumeInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are resumed. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.instanceGroupManagers.setInstanceTemplateSpecifies the instance template to use when creating new instances in this group. The templates for existing instances in the group do not change unless you run recreateInstances, runapplyUpdatesToInstances, or set the group'supdatePolicy.type to PROACTIVE.activityNN
compute.instanceGroupManagers.setTargetPoolsModifies the target pools to which all instances in this managed instance group are assigned. The target pools automatically apply to all of the instances in the managed instance group. This operation is markedDONE when you make the request even if the instances have not yet been added to their target pools. The change might take some time to apply to all of the instances in the group depending on the size of the group.activityNN
compute.instanceGroupManagers.startInstancesFlags the specified instances in the managed instance group to be started. This method increases thetargetSize and decreases the targetStoppedSize of the managed instance group by the number of instances that you start. The startInstances operation is marked DONE if the startInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTARTING action with thelistmanagedinstances method. In this request, you can only specify instances that are stopped. For example, if an instance was previously stopped using the stopInstances method, it can be started using the startInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are started. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.instanceGroupManagers.stopInstancesFlags the specified instances in the managed instance group to be immediately stopped. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetStoppedSize of the managed instance group by the number of instances that you stop. The stopInstances operation is marked DONE if the stopInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTOPPING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays stopping the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is stopped. Stopped instances can be started using the startInstances method. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.instanceGroupManagers.suspendInstancesFlags the specified instances in the managed instance group to be immediately suspended. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetSuspendedSize of the managed instance group by the number of instances that you suspend. The suspendInstances operation is marked DONE if the suspendInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSUSPENDING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays suspension of the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is suspended. Suspended instances can be resumed using the resumeInstances method. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.instanceGroupManagers.updatePerInstanceConfigsInserts or updates per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.activityNN
compute.instanceGroups.addInstancesAdds a list of instances to the specified instance group. All of the instances in the instance group must be in the same network/subnetwork. Read Adding instances for more information.activityNN
compute.instanceGroups.aggregatedListRetrieves the list of instance groups and sorts them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.instanceGroups.deleteDeletes the specified instance group. The instances in the group are not deleted. Note that instance group must not belong to a backend service. Read Deleting an instance group for more information.activityNN
compute.instanceGroups.getReturns the specified zonal instance group. Get a list of available zonal instance groups by making a list() request. For managed instance groups, use theinstanceGroupManagers or regionInstanceGroupManagers methods instead.data_accessNN
compute.instanceGroups.insertCreates an instance group in the specified project using the parameters that are included in the request.activityYN
compute.instanceGroups.listRetrieves the list of zonal instance group resources contained within the specified zone. For managed instance groups, use theinstanceGroupManagers or regionInstanceGroupManagers methods instead.data_accessNN
compute.instanceGroups.listInstancesLists the instances in the specified instance group. The orderBy query parameter is not supported. The filter query parameter is supported, but only for expressions that use `eq` (equal) or `ne` (not equal) operators.data_accessNN
compute.instanceGroups.removeInstancesRemoves one or more instances from the specified instance group, but does not delete those instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration before the VM instance is removed or deleted.activityYN
compute.instanceGroups.setNamedPortsSets the named ports for the specified instance group.activityYN
compute.instanceGroups.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.instanceSettings.getGet Instance settings.data_accessNN
compute.instanceSettings.patchPatch Instance settingsactivityNN
compute.instanceTemplates.aggregatedListRetrieves the list of all InstanceTemplates resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.instanceTemplates.deleteDeletes the specified instance template. Deleting an instance template is permanent and cannot be undone. It is not possible to delete templates that are already in use by a managed instance group.activityNN
compute.instanceTemplates.getReturns the specified instance template.data_accessNN
compute.instanceTemplates.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.instanceTemplates.insertCreates an instance template in the specified project using the data that is included in the request. If you are creating a new template to update an existing instance group, your new instance template must use the same network or, if applicable, the same subnetwork as the original template.activityYN
compute.instanceTemplates.listRetrieves a list of instance templates that are contained within the specified project.data_accessNN
compute.instanceTemplates.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.instanceTemplates.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.instances.addAccessConfigAdds an access config to an instance's network interface.activityNN
compute.instances.addNetworkInterfaceAdds one dynamic network interface to an active instance.activityNN
compute.instances.addResourcePoliciesAdds existing resource policies to an instance. You can only add one policy right now which will be applied to this instance for scheduling live migrations.activityNN
compute.instances.aggregatedListRetrieves an aggregated list of all of the instances in your project across all regions and zones. The performance of this method degrades when a filter is specified on a project that has a very large number of instances. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.instances.attachDiskAttaches an existing Disk resource to an instance. You must first create the disk before you can attach it. It is not possible to create and attach a disk at the same time. For more information, readAdding a persistent disk to your instance.activityYN
compute.instances.bulkInsertCreates multiple instances. Count specifies the number of instances to create. For more information, seeAbout bulk creation of VMs.activityNN
compute.instances.deleteDeletes the specified Instance resource.activityYN
compute.instances.deleteAccessConfigDeletes an access config from an instance's network interface.activityNN
compute.instances.deleteNetworkInterfaceDeletes one dynamic network interface from an active instance. InstancesDeleteNetworkInterfaceRequest indicates: - instance from which to delete, using project+zone+resource_id fields; - dynamic network interface to be deleted, using network_interface_name field;activityNN
compute.instances.detachDiskDetaches a disk from an instance.activityYN
compute.instances.getReturns the specified Instance resource.data_accessYN
compute.instances.getEffectiveFirewallsReturns effective firewalls applied to an interface of the instance.data_accessNN
compute.instances.getGuestAttributesReturns the specified guest attributes entry.data_accessNN
compute.instances.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.instances.getScreenshotReturns the screenshot from the specified instance.data_accessNN
compute.instances.getSerialPortOutputReturns the last 1 MB of serial port output from the specified instance.data_accessNN
compute.instances.getShieldedInstanceIdentityReturns the Shielded Instance Identity of an instancedata_accessNN
compute.instances.insertCreates an instance resource in the specified project using the data included in the request.activityYY
compute.instances.listRetrieves the list of instances contained within the specified zone.data_accessYN
compute.instances.listReferrersRetrieves a list of resources that refer to the VM instance specified in the request. For example, if the VM instance is part of a managed or unmanaged instance group, the referrers list includes the instance group. For more information, readViewing referrers to VM instances.data_accessNN
compute.instances.migrateOnHostMaintenanceGoogle-initiated live migration of a VM to new host hardware. Appears in system_event audit logs (cloudaudit.googleapis.com/system_event), not admin_activity. Not user-callable; emitted by GCE infrastructure.system_eventNN
compute.instances.performMaintenancePerform a manual maintenance on the instance.activityNN
compute.instances.removeResourcePoliciesRemoves resource policies from an instance.activityNN
compute.instances.reportHostAsFaultyMark the host as faulty and try to restart the instance on a new host.activityNN
compute.instances.resetPerforms a reset on the instance. This is a hard reset. The VM does not do a graceful shutdown. For more information, seeResetting an instance.activityYN
compute.instances.resumeResumes an instance that was suspended using theinstances().suspend method.activityNN
compute.instances.sendDiagnosticInterruptSends diagnostic interrupt to the instance.activityNN
compute.instances.setDeletionProtectionSets deletion protection on the instance.activityYN
compute.instances.setDiskAutoDeleteSets the auto-delete flag for a disk attached to an instance.activityNN
compute.instances.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.instances.setLabelsSets labels on an instance. To learn more about labels, read theLabeling Resources documentation.activityYN
compute.instances.setMachineResourcesChanges the number and/or type of accelerator for a stopped instance to the values specified in the request.activityNN
compute.instances.setMachineTypeChanges the machine type for a stopped instance to the machine type specified in the request.activityYN
compute.instances.setMetadataSets metadata for the specified instance to the data included in the request.activityYY
compute.instances.setMinCpuPlatformChanges the minimum CPU platform that this instance should use. This method can only be called on a stopped instance. For more information, readSpecifying a Minimum CPU Platform.activityNN
compute.instances.setNameSets name of an instance.activityNN
compute.instances.setSchedulingSets an instance's scheduling options. You can only call this method on astopped instance, that is, a VM instance that is in a `TERMINATED` state. SeeInstance Life Cycle for more information on the possible instance states. For more information about setting scheduling options for a VM, seeSet VM host maintenance policy.activityYN
compute.instances.setSecurityPolicySets the Google Cloud Armor security policy for the specified instance. For more information, seeGoogle Cloud Armor OverviewactivityNN
compute.instances.setServiceAccountSets the service account on the instance.activityNN
compute.instances.setShieldedInstanceIntegrityPolicySets the Shielded Instance integrity policy for an instance. You can only use this method on a running instance. This method supports PATCH semantics and uses the JSON merge patch format and processing rules.activityNN
compute.instances.setTagsSets network tags for the specified instance to the data included in the request.activityYN
compute.instances.simulateMaintenanceEventSimulates a host maintenance event on a VM. For more information, see Simulate a host maintenance event.activityYN
compute.instances.startStarts an instance that was stopped using the stopInstance method.activityYN
compute.instances.startWithEncryptionKeyStarts an instance that was stopped using theinstances().stop method. For more information, seeRestart an instance.activityNN
compute.instances.stopStops a running instance, shutting it down cleanly.activityYN
compute.instances.suspendThis method suspends a running instance, saving its state to persistent storage, and allows you to resume the instance at a later time. Suspended instances have no compute costs (cores or RAM), and incur only storage charges for the saved VM memory and localSSD data. Any charged resources the virtual machine was using, such as persistent disks and static IP addresses, will continue to be charged while the instance is suspended. For more information, see Suspending and resuming an instance.activityNN
compute.instances.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.instances.updateUpdates an instance only if the necessary resources are available. This method can update only a specific set of instance properties. See Updating a running instance for a list of updatable instance properties.activityNN
compute.instances.updateAccessConfigUpdates the specified access config from an instance's network interface with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.instances.updateDisplayDeviceUpdates the Display config for a VM instance. You can only use this method on a stopped VM instance. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.instances.updateNetworkInterfaceUpdates an instance's network interface. This method can only update an interface's alias IP range and attached network. See Modifying alias IP ranges for an existing instance for instructions on changing alias IP ranges. See Migrating a VM between networks for instructions on migrating an interface. This method follows PATCH semantics.activityNN
compute.instances.updateShieldedInstanceConfigUpdates the Shielded Instance config for an instance. You can only use this method on a stopped instance. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityYN
compute.instantSnapshotGroups.deletedeletes a Zonal InstantSnapshotGroup resourceactivityNN
compute.instantSnapshotGroups.getreturns the specified InstantSnapshotGroup resource in the specified zone.data_accessNN
compute.instantSnapshotGroups.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.instantSnapshotGroups.insertinserts a Zonal InstantSnapshotGroup resourceactivityNN
compute.instantSnapshotGroups.listretrieves the list of InstantSnapshotGroup resources contained within the specified zone.data_accessNN
compute.instantSnapshotGroups.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.instantSnapshotGroups.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.instantSnapshots.aggregatedListRetrieves an aggregated list of instantSnapshots. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.instantSnapshots.deleteDeletes the specified InstantSnapshot resource. Keep in mind that deleting a single instantSnapshot might not necessarily delete all the data on that instantSnapshot. If any data on the instantSnapshot that is marked for deletion is needed for subsequent instantSnapshots, the data will be moved to the next corresponding instantSnapshot. For more information, seeDeleting instantSnapshots.activityNN
compute.instantSnapshots.getReturns the specified InstantSnapshot resource in the specified zone.data_accessNN
compute.instantSnapshots.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.instantSnapshots.insertCreates an instant snapshot in the specified zone.activityNN
compute.instantSnapshots.listRetrieves the list of InstantSnapshot resources contained within the specified zone.data_accessNN
compute.instantSnapshots.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.instantSnapshots.setLabelsSets the labels on a instantSnapshot in the given zone. To learn more about labels, read the Labeling Resources documentation.activityNN
compute.instantSnapshots.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.interconnectAttachmentGroups.deleteDeletes the specified InterconnectAttachmentGroup in the given scopeactivityNN
compute.interconnectAttachmentGroups.getReturns the specified InterconnectAttachmentGroup resource in the given scope.data_accessNN
compute.interconnectAttachmentGroups.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.interconnectAttachmentGroups.getOperationalStatusReturns the InterconnectAttachmentStatuses for the specified InterconnectAttachmentGroup resource.data_accessNN
compute.interconnectAttachmentGroups.insertCreates a InterconnectAttachmentGroup in the specified project in the given scope using the parameters that are included in the request.activityNN
compute.interconnectAttachmentGroups.listLists the InterconnectAttachmentGroups for a project in the given scope.data_accessNN
compute.interconnectAttachmentGroups.patchPatches the specified InterconnectAttachmentGroup resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.interconnectAttachmentGroups.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.interconnectAttachmentGroups.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.interconnectAttachments.aggregatedListRetrieves an aggregated list of interconnect attachments. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.interconnectAttachments.deleteDeletes the specified interconnect attachment.activityNN
compute.interconnectAttachments.getReturns the specified interconnect attachment.data_accessNN
compute.interconnectAttachments.insertCreates an InterconnectAttachment in the specified project using the data included in the request.activityNN
compute.interconnectAttachments.listRetrieves the list of interconnect attachments contained within the specified region.data_accessNN
compute.interconnectAttachments.patchUpdates the specified interconnect attachment with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.interconnectAttachments.setLabelsSets the labels on an InterconnectAttachment. To learn more about labels, read the Labeling Resources documentation.activityNN
compute.interconnectGroups.createMembersCreate Interconnects with redundancy by creating them in a specified interconnect group.activityNN
compute.interconnectGroups.deleteDeletes the specified InterconnectGroup in the given scopeactivityNN
compute.interconnectGroups.getReturns the specified InterconnectGroup resource in the given scope.data_accessNN
compute.interconnectGroups.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.interconnectGroups.getOperationalStatusReturns the interconnectStatuses for the specified InterconnectGroup.data_accessNN
compute.interconnectGroups.insertCreates a InterconnectGroup in the specified project in the given scope using the parameters that are included in the request.activityNN
compute.interconnectGroups.listLists the InterconnectGroups for a project in the given scope.data_accessNN
compute.interconnectGroups.patchPatches the specified InterconnectGroup resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.interconnectGroups.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.interconnectGroups.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.interconnectLocations.getReturns the details for the specified interconnect location. Gets a list of available interconnect locations by making a list() request.data_accessNN
compute.interconnectLocations.listRetrieves the list of interconnect locations available to the specified project.data_accessNN
compute.interconnectRemoteLocations.getReturns the details for the specified interconnect remote location. Gets a list of available interconnect remote locations by making alist() request.data_accessNN
compute.interconnectRemoteLocations.listRetrieves the list of interconnect remote locations available to the specified project.data_accessNN
compute.interconnects.deleteDeletes the specified Interconnect.activityNN
compute.interconnects.getReturns the specified Interconnect. Get a list of available Interconnects by making a list() request.data_accessNN
compute.interconnects.getDiagnosticsReturns the interconnectDiagnostics for the specified Interconnect. In the event of a global outage, do not use this API to make decisions about where to redirect your network traffic. Unlike a VLAN attachment, which is regional, a Cloud Interconnect connection is a global resource. A global outage can prevent this API from functioning properly.data_accessNN
compute.interconnects.getMacsecConfigReturns the interconnectMacsecConfig for the specified Interconnect.data_accessNN
compute.interconnects.insertCreates an Interconnect in the specified project using the data included in the request.activityNN
compute.interconnects.listRetrieves the list of Interconnects available to the specified project.data_accessNN
compute.interconnects.patchUpdates the specified Interconnect with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.interconnects.setLabelsSets the labels on an Interconnect. To learn more about labels, read the Labeling Resources documentation.activityNN
compute.licenseCodes.getReturn a specified license code. License codes are mirrored across all projects that have permissions to read the License Code. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.data_accessNN
compute.licenseCodes.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.data_accessNN
compute.licenseCodes.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.activityNN
compute.licenseCodes.testIamPermissionsReturns permissions that a caller has on the specified resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.data_accessNN
compute.licenses.deleteDeletes the specified license. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.activityNN
compute.licenses.getReturns the specified License resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.data_accessNN
compute.licenses.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.data_accessNN
compute.licenses.insertCreate a License resource in the specified project. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.activityNN
compute.licenses.listRetrieves the list of licenses available in the specified project. This method does not get any licenses that belong to other projects, including licenses attached to publicly-available images, like Debian 9. If you want to get a list of publicly-available licenses, use this method to make a request to the respective image project, such as debian-cloud orwindows-cloud. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.data_accessNN
compute.licenses.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.activityNN
compute.licenses.testIamPermissionsReturns permissions that a caller has on the specified resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.data_accessNN
compute.licenses.updateUpdates a License resource in the specified project. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.activityNN
compute.machineImages.deleteDeletes the specified machine image. Deleting a machine image is permanent and cannot be undone.activityNN
compute.machineImages.getReturns the specified machine image.data_accessNN
compute.machineImages.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.machineImages.insertCreates a machine image in the specified project using the data that is included in the request. If you are creating a new machine image to update an existing instance, your new machine image should use the same network or, if applicable, the same subnetwork as the original instance.activityNN
compute.machineImages.listRetrieves a list of machine images that are contained within the specified project.data_accessNN
compute.machineImages.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.machineImages.setLabelsSets the labels on a machine image. To learn more about labels, read theLabeling Resources documentation.activityNN
compute.machineImages.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.machineTypes.aggregatedListRetrieves an aggregated list of machine types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.machineTypes.getReturns the specified machine type.data_accessNN
compute.machineTypes.listRetrieves a list of machine types available to the specified project.data_accessNN
compute.networkAttachments.aggregatedListRetrieves the list of all NetworkAttachment resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.networkAttachments.deleteDeletes the specified NetworkAttachment in the given scopeactivityNN
compute.networkAttachments.getReturns the specified NetworkAttachment resource in the given scope.data_accessNN
compute.networkAttachments.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.networkAttachments.insertCreates a NetworkAttachment in the specified project in the given scope using the parameters that are included in the request.activityNN
compute.networkAttachments.listLists the NetworkAttachments for a project in the given scope.data_accessNN
compute.networkAttachments.patchPatches the specified NetworkAttachment resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.networkAttachments.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.networkAttachments.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.networkEdgeSecurityServices.aggregatedListRetrieves the list of all NetworkEdgeSecurityService resources available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.networkEdgeSecurityServices.deleteDeletes the specified service.activityNN
compute.networkEdgeSecurityServices.getGets a specified NetworkEdgeSecurityService.data_accessNN
compute.networkEdgeSecurityServices.insertCreates a new service in the specified project using the data included in the request.activityNN
compute.networkEdgeSecurityServices.patchPatches the specified policy with the data included in the request.activityNN
compute.networkEndpointGroups.aggregatedListRetrieves the list of network endpoint groups and sorts them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.networkEndpointGroups.attachNetworkEndpointsAttach a list of network endpoints to the specified network endpoint group.activityNN
compute.networkEndpointGroups.deleteDeletes the specified network endpoint group. The network endpoints in the NEG and the VM instances they belong to are not terminated when the NEG is deleted. Note that the NEG cannot be deleted if there are backend services referencing it.activityYN
compute.networkEndpointGroups.detachNetworkEndpointsDetach a list of network endpoints from the specified network endpoint group.activityNN
compute.networkEndpointGroups.getReturns the specified network endpoint group.data_accessNN
compute.networkEndpointGroups.insertCreates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global APIactivityYN
compute.networkEndpointGroups.listRetrieves the list of network endpoint groups that are located in the specified project and zone.data_accessNN
compute.networkEndpointGroups.listNetworkEndpointsLists the network endpoints in the specified network endpoint group.data_accessNN
compute.networkEndpointGroups.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.networkFirewallPolicies.addAssociationInserts an association for the specified firewall policy.activityNN
compute.networkFirewallPolicies.addPacketMirroringRuleInserts a packet mirroring rule into a firewall policy.activityNN
compute.networkFirewallPolicies.addRuleInserts a rule into a firewall policy.activityNN
compute.networkFirewallPolicies.aggregatedListRetrieves an aggregated list of network firewall policies, listing network firewall policies from all applicable scopes (global and regional) and grouping the results per scope. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.networkFirewallPolicies.cloneRulesCopies rules to the specified firewall policy.activityNN
compute.networkFirewallPolicies.deleteDeletes the specified policy.activityNN
compute.networkFirewallPolicies.getReturns the specified network firewall policy.data_accessNN
compute.networkFirewallPolicies.getAssociationGets an association with the specified name.data_accessNN
compute.networkFirewallPolicies.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.networkFirewallPolicies.getPacketMirroringRuleGets a packet mirroring rule of the specified priority.data_accessNN
compute.networkFirewallPolicies.getRuleGets a rule of the specified priority.data_accessNN
compute.networkFirewallPolicies.insertCreates a new policy in the specified project using the data included in the request.activityNN
compute.networkFirewallPolicies.listLists all the policies that have been configured for the specified project.data_accessNN
compute.networkFirewallPolicies.patchPatches the specified policy with the data included in the request.activityNN
compute.networkFirewallPolicies.patchPacketMirroringRulePatches a packet mirroring rule of the specified priority.activityNN
compute.networkFirewallPolicies.patchRulePatches a rule of the specified priority.activityNN
compute.networkFirewallPolicies.removeAssociationRemoves an association for the specified firewall policy.activityNN
compute.networkFirewallPolicies.removePacketMirroringRuleDeletes a packet mirroring rule of the specified priority.activityNN
compute.networkFirewallPolicies.removeRuleDeletes a rule of the specified priority.activityNN
compute.networkFirewallPolicies.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.networkFirewallPolicies.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.networkProfiles.getReturns the specified network profile.data_accessNN
compute.networkProfiles.listRetrieves a list of network profiles available to the specified project.data_accessNN
compute.networks.addPeeringAdds a peering to the specified network.activityYN
compute.networks.cancelRequestRemovePeeringCancel requests to remove a peering from the specified network. Applicable only for PeeringConnection with update_strategy=CONSENSUS. Cancels a request to remove a peering from the specified network.activityNN
compute.networks.deleteDeletes the specified network.activityYY
compute.networks.getReturns the specified network.data_accessYN
compute.networks.getEffectiveFirewallsReturns the effective firewalls on a given network.data_accessNN
compute.networks.insertCreates a network in the specified project using the data included in the request.activityYN
compute.networks.listRetrieves the list of networks available to the specified project.data_accessYN
compute.networks.listPeeringRoutesLists the peering routes exchanged over peering connection.data_accessNN
compute.networks.patchPatches the specified network with the data included in the request. Only routingConfig can be modified.activityNN
compute.networks.removePeeringRemoves a peering from the specified network.activityYN
compute.networks.requestRemovePeeringRequests to remove a peering from the specified network. Applicable only for PeeringConnection with update_strategy=CONSENSUS.activityNN
compute.networks.switchToCustomModeSwitches the network mode from auto subnet mode to custom subnet mode.activityNN
compute.networks.updatePeeringUpdates the specified network peering with the data included in the request. You can only modify the NetworkPeering.export_custom_routes field and the NetworkPeering.import_custom_routes field.activityNN
compute.nodeGroups.addNodesAdds specified number of nodes to the node group.activityNN
compute.nodeGroups.aggregatedListRetrieves an aggregated list of node groups. Note: use nodeGroups.listNodes for more details about each group. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.nodeGroups.deleteDeletes the specified NodeGroup resource.activityNN
compute.nodeGroups.deleteNodesDeletes specified nodes from the node group.activityNN
compute.nodeGroups.getReturns the specified NodeGroup. Get a list of available NodeGroups by making a list() request. Note: the "nodes" field should not be used. Use nodeGroups.listNodes instead.data_accessNN
compute.nodeGroups.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.nodeGroups.insertCreates a NodeGroup resource in the specified project using the data included in the request.activityNN
compute.nodeGroups.listRetrieves a list of node groups available to the specified project. Note: use nodeGroups.listNodes for more details about each group.data_accessNN
compute.nodeGroups.listNodesLists nodes in the node group.data_accessNN
compute.nodeGroups.patchUpdates the specified node group.activityNN
compute.nodeGroups.performMaintenancePerform maintenance on a subset of nodes in the node group.activityNN
compute.nodeGroups.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.nodeGroups.setNodeTemplateUpdates the node template of the node group.activityNN
compute.nodeGroups.simulateMaintenanceEventSimulates maintenance event on specified nodes from the node group.activityNN
compute.nodeGroups.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.nodeTemplates.aggregatedListRetrieves an aggregated list of node templates. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.nodeTemplates.deleteDeletes the specified NodeTemplate resource.activityNN
compute.nodeTemplates.getReturns the specified node template.data_accessNN
compute.nodeTemplates.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.nodeTemplates.insertCreates a NodeTemplate resource in the specified project using the data included in the request.activityNN
compute.nodeTemplates.listRetrieves a list of node templates available to the specified project.data_accessNN
compute.nodeTemplates.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.nodeTemplates.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.nodeTypes.aggregatedListRetrieves an aggregated list of node types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.nodeTypes.getReturns the specified node type.data_accessNN
compute.nodeTypes.listRetrieves a list of node types available to the specified project.data_accessNN
compute.organizationSecurityPolicies.addAssociationInserts an association for the specified security policy. This has billing implications. Projects in the hierarchy with effective hierarchical security policies will be automatically enrolled into Cloud Armor Enterprise if not already enrolled. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.addAssociation instead.activityNN
compute.organizationSecurityPolicies.addRuleInserts a rule into a security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.addRule instead.activityNN
compute.organizationSecurityPolicies.copyRulesCopies rules to the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.cloneRules instead.activityNN
compute.organizationSecurityPolicies.deleteDeletes the specified policy. Use this API to remove Cloud Armor policies. Previously, alpha and beta versions of this API were used to remove firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.delete instead.activityNN
compute.organizationSecurityPolicies.getList all of the ordered rules present in a single specified policy. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.get instead.data_accessNN
compute.organizationSecurityPolicies.getAssociationGets an association with the specified name. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.getAssociation instead.data_accessNN
compute.organizationSecurityPolicies.getRuleGets a rule at the specified priority. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.getRule instead.data_accessNN
compute.organizationSecurityPolicies.insertCreates a new policy in the specified organization using the data included in the request. Use this API to add Cloud Armor policies. Previously, alpha and beta versions of this API were used to add firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.insert instead.activityNN
compute.organizationSecurityPolicies.listList all the policies that have been configured for the specified organization. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.list instead.data_accessNN
compute.organizationSecurityPolicies.listAssociationsLists associations of a specified target, i.e., organization or folder. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.listAssociations instead.data_accessNN
compute.organizationSecurityPolicies.listPreconfiguredExpressionSetsGets the current list of preconfigured Web Application Firewall (WAF) expressions.data_accessNN
compute.organizationSecurityPolicies.moveMoves the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.move instead.activityNN
compute.organizationSecurityPolicies.patchPatches the specified policy with the data included in the request. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.patch instead.activityNN
compute.organizationSecurityPolicies.patchRulePatches a rule at the specified priority. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.patchRule instead.activityNN
compute.organizationSecurityPolicies.removeAssociationRemoves an association for the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.removeAssociation instead.activityNN
compute.organizationSecurityPolicies.removeRuleDeletes a rule at the specified priority. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.removeRule instead.activityNN
compute.packetMirrorings.aggregatedListRetrieves an aggregated list of packetMirrorings. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYY
compute.packetMirrorings.deleteDeletes the specified PacketMirroring resource.activityYY
compute.packetMirrorings.getReturns the specified PacketMirroring resource.data_accessYY
compute.packetMirrorings.insertCreates a PacketMirroring resource in the specified project and region using the data included in the request.activityYY
compute.packetMirrorings.listRetrieves a list of PacketMirroring resources available to the specified project and region.data_accessYY
compute.packetMirrorings.patchPatches the specified PacketMirroring resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.activityYY
compute.packetMirrorings.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.previewFeatures.getReturns the details of the given PreviewFeature.data_accessNN
compute.previewFeatures.listReturns the details of the given PreviewFeature.data_accessNN
compute.previewFeatures.updatePatches the given PreviewFeature. This method is used to enable or disable a PreviewFeature.activityNN
compute.projects.disableXpnHostDisable this project as a shared VPC host project.activityNN
compute.projects.disableXpnResourceDisable a service resource (also known as service project) associated with this host project.activityNN
compute.projects.enableXpnHostEnable this project as a shared VPC host project.activityNN
compute.projects.enableXpnResourceEnable service resource (a.k.a service project) for a host project, so that subnets in the host project can be used by instances in the service project.activityNN
compute.projects.getReturns the specified Project resource. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request.data_accessYN
compute.projects.getXpnHostGets the shared VPC host project that this project links to. May be empty if no link exists.data_accessNN
compute.projects.getXpnResourcesGets service resources (a.k.a service project) associated with this host project.data_accessNN
compute.projects.listXpnHostsLists all shared VPC host projects visible to the user in an organization.data_accessNN
compute.projects.moveDiskMoves a persistent disk from one zone to another. *Note*: The moveDisk API will be deprecated on September 29, 2026. Starting September 29, 2025, you can't use the moveDisk API on new projects. To move a disk to a different region or zone, follow the steps in Change the location of a disk. Projects that already use the moveDisk API can continue usage until September 29, 2026. Starting November 1, 2025, API responses will include a warning message in the response body about the upcoming deprecation. You can skip the message to continue using the service without interruption.activityNN
compute.projects.moveInstanceMoves an instance and its attached persistent disks from one zone to another. *Note*: Moving VMs or disks by using this method might cause unexpected behavior. For more information, see the known issue. [Deprecated] This method is deprecated. See moving instance across zones instead.activityNN
compute.projects.setCloudArmorTierSets the Cloud Armor tier of the project. To set ENTERPRISE or above the billing account of the project must be subscribed to Cloud Armor Enterprise. See Subscribing to Cloud Armor Enterprise for more information.activityYN
compute.projects.setCommonInstanceMetadataSets metadata common to all instances within the specified project using the data included in the request.activityYY
compute.projects.setDefaultNetworkTierSets the default network tier of the project. The default network tier is used when an address/forwardingRule/instance is created without specifying the network tier field.activityNN
compute.projects.setUsageExportBucketEnables the usage export feature and sets theusage export bucket where reports are stored. If you provide an empty request body using this method, the usage export feature will be disabled.activityNN
compute.publicAdvertisedPrefixes.announceAnnounces the specified PublicAdvertisedPrefixactivityNN
compute.publicAdvertisedPrefixes.deleteDeletes the specified PublicAdvertisedPrefixactivityNN
compute.publicAdvertisedPrefixes.getReturns the specified PublicAdvertisedPrefix resource.data_accessNN
compute.publicAdvertisedPrefixes.insertCreates a PublicAdvertisedPrefix in the specified project using the parameters that are included in the request.activityNN
compute.publicAdvertisedPrefixes.listLists the PublicAdvertisedPrefixes for a project.data_accessNN
compute.publicAdvertisedPrefixes.patchPatches the specified Router resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.publicAdvertisedPrefixes.withdrawWithdraws the specified PublicAdvertisedPrefixactivityNN
compute.publicDelegatedPrefixes.aggregatedListLists all PublicDelegatedPrefix resources owned by the specific project across all scopes. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.publicDelegatedPrefixes.announceAnnounces the specified PublicDelegatedPrefix in the given region.activityNN
compute.publicDelegatedPrefixes.deleteDeletes the specified PublicDelegatedPrefix in the given region.activityNN
compute.publicDelegatedPrefixes.getReturns the specified PublicDelegatedPrefix resource in the given region.data_accessNN
compute.publicDelegatedPrefixes.insertCreates a PublicDelegatedPrefix in the specified project in the given region using the parameters that are included in the request.activityNN
compute.publicDelegatedPrefixes.listLists the PublicDelegatedPrefixes for a project in the given region.data_accessNN
compute.publicDelegatedPrefixes.patchPatches the specified PublicDelegatedPrefix resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.publicDelegatedPrefixes.withdrawWithdraws the specified PublicDelegatedPrefix in the given region.activityNN
compute.regionAutoscalers.deleteDeletes the specified autoscaler.activityNN
compute.regionAutoscalers.getReturns the specified autoscaler.data_accessNN
compute.regionAutoscalers.insertCreates an autoscaler in the specified project using the data included in the request.activityNN
compute.regionAutoscalers.listRetrieves a list of autoscalers contained within the specified region.data_accessNN
compute.regionAutoscalers.patchUpdates an autoscaler in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.regionAutoscalers.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionAutoscalers.updateUpdates an autoscaler in the specified project using the data included in the request.activityNN
compute.regionBackendBuckets.deleteDeletes the specified regional BackendBucket resource.activityNN
compute.regionBackendBuckets.getReturns the specified regional BackendBucket resource.data_accessNN
compute.regionBackendBuckets.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.regionBackendBuckets.insertCreates a RegionBackendBucket in the specified project in the given scope using the parameters that are included in the request.activityNN
compute.regionBackendBuckets.listRetrieves the list of BackendBucket resources available to the specified project in the given region.data_accessNN
compute.regionBackendBuckets.listUsableRetrieves a list of all usable backend buckets in the specified project in the given region.data_accessNN
compute.regionBackendBuckets.patchUpdates the specified BackendBucket resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.regionBackendBuckets.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.regionBackendBuckets.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionBackendServices.deleteDeletes the specified regional BackendService resource.activityYN
compute.regionBackendServices.getReturns the specified regional BackendService resource.data_accessYN
compute.regionBackendServices.getHealthGets the most recent health check results for this regional BackendService.data_accessNN
compute.regionBackendServices.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.regionBackendServices.insertCreates a regional BackendService resource in the specified project using the data included in the request. For more information, see Backend services overview.activityYN
compute.regionBackendServices.listRetrieves the list of regional BackendService resources available to the specified project in the given region.data_accessNN
compute.regionBackendServices.listUsableRetrieves a list of all usable backend services in the specified project in the given region.data_accessNN
compute.regionBackendServices.patchUpdates the specified regional BackendService resource with the data included in the request. For more information, see Understanding backend services This method supports PATCH semantics and uses the JSON merge patch format and processing rules.activityNN
compute.regionBackendServices.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.regionBackendServices.setSecurityPolicySets the Google Cloud Armor security policy for the specified backend service. For more information, seeGoogle Cloud Armor OverviewactivityNN
compute.regionBackendServices.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionBackendServices.updateUpdates the specified regional BackendService resource with the data included in the request. For more information, see Backend services overview.activityNN
compute.regionCommitments.aggregatedListRetrieves an aggregated list of commitments by region. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.regionCommitments.getReturns the specified commitment resource.data_accessNN
compute.regionCommitments.insertCreates a commitment in the specified project using the data included in the request.activityNN
compute.regionCommitments.listRetrieves a list of commitments contained within the specified region.data_accessNN
compute.regionCommitments.updateUpdates the specified commitment with the data included in the request. Update is performed only on selected fields included as part of update-mask. Only the following fields can be updated: auto_renew and plan.activityNN
compute.regionCompositeHealthChecks.aggregatedListRetrieves the list of all CompositeHealthCheck resources (all regional) available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.regionCompositeHealthChecks.deleteDeletes the specified CompositeHealthCheck in the given regionactivityNN
compute.regionCompositeHealthChecks.getReturns the specified CompositeHealthCheck resource in the given region.data_accessNN
compute.regionCompositeHealthChecks.getHealthGets the most recent health check results for this regional CompositeHealthCheck.data_accessNN
compute.regionCompositeHealthChecks.insertCreate a CompositeHealthCheck in the specified project in the given region using the parameters that are included in the request.activityNN
compute.regionCompositeHealthChecks.listLists the CompositeHealthChecks for a project in the given region.data_accessNN
compute.regionCompositeHealthChecks.patchUpdates the specified regional CompositeHealthCheck resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.regionCompositeHealthChecks.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionDiskTypes.getReturns the specified regional disk type.data_accessNN
compute.regionDiskTypes.listRetrieves a list of regional disk types available to the specified project.data_accessNN
compute.regionDisks.addResourcePoliciesAdds existing resource policies to a regional disk. You can only add one policy which will be applied to this disk for scheduling snapshot creation.activityNN
compute.regionDisks.bulkInsertBulk create a set of disks.activityNN
compute.regionDisks.createSnapshotCreates a snapshot of a specified persistent disk. For regular snapshot creation, consider using snapshots.insert instead, as that method supports more features, such as creating snapshots in a project different from the source disk project.activityNN
compute.regionDisks.deleteDeletes the specified regional persistent disk. Deleting a regional disk removes all the replicas of its data permanently and is irreversible. However, deleting a disk does not delete anysnapshots previously made from the disk. You must separatelydelete snapshots.activityNN
compute.regionDisks.getReturns a specified regional persistent disk.data_accessNN
compute.regionDisks.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.regionDisks.insertCreates a persistent regional disk in the specified project using the data included in the request.activityNN
compute.regionDisks.listRetrieves the list of persistent disks contained within the specified region.data_accessYN
compute.regionDisks.removeResourcePoliciesRemoves resource policies from a regional disk.activityNN
compute.regionDisks.resizeResizes the specified regional persistent disk.activityNN
compute.regionDisks.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.regionDisks.setLabelsSets the labels on the target regional disk.activityNN
compute.regionDisks.startAsyncReplicationStarts asynchronous replication. Must be invoked on the primary disk.activityNN
compute.regionDisks.stopAsyncReplicationStops asynchronous replication. Can be invoked either on the primary or on the secondary disk.activityNN
compute.regionDisks.stopGroupAsyncReplicationStops asynchronous replication for a consistency group of disks. Can be invoked either in the primary or secondary scope.activityNN
compute.regionDisks.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionDisks.updateUpdate the specified disk with the data included in the request. Update is performed only on selected fields included as part of update-mask.activityNN
compute.regionDisks.updateKmsKeyRotates the customer-managed encryption key to the latest version for the specified persistent disk.activityNN
compute.regionHealthAggregationPolicies.aggregatedListRetrieves the list of all HealthAggregationPolicy resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.regionHealthAggregationPolicies.deleteDeletes the specified HealthAggregationPolicy in the given region.activityNN
compute.regionHealthAggregationPolicies.getReturns the specified HealthAggregationPolicy resource in the given region.data_accessNN
compute.regionHealthAggregationPolicies.insertCreate a HealthAggregationPolicy in the specified project in the given region using the parameters that are included in the request.activityNN
compute.regionHealthAggregationPolicies.listLists the HealthAggregationPolicies for a project in the given region.data_accessNN
compute.regionHealthAggregationPolicies.patchUpdates the specified regional HealthAggregationPolicy resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.regionHealthAggregationPolicies.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionHealthCheckServices.aggregatedListRetrieves the list of all HealthCheckService resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.regionHealthCheckServices.deleteDeletes the specified regional HealthCheckService.activityNN
compute.regionHealthCheckServices.getReturns the specified regional HealthCheckService resource.data_accessNN
compute.regionHealthCheckServices.insertCreates a regional HealthCheckService resource in the specified project and region using the data included in the request.activityNN
compute.regionHealthCheckServices.listLists all the HealthCheckService resources that have been configured for the specified project in the given region.data_accessNN
compute.regionHealthCheckServices.patchUpdates the specified regional HealthCheckService resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.regionHealthCheckServices.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionHealthChecks.deleteDeletes the specified HealthCheck resource.activityYN
compute.regionHealthChecks.getReturns the specified HealthCheck resource.data_accessYN
compute.regionHealthChecks.insertCreates a HealthCheck resource in the specified project using the data included in the request.activityYN
compute.regionHealthChecks.listRetrieves the list of HealthCheck resources available to the specified project.data_accessNN
compute.regionHealthChecks.patchUpdates a HealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.regionHealthChecks.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionHealthChecks.updateUpdates a HealthCheck resource in the specified project using the data included in the request.activityNN
compute.regionHealthSources.aggregatedListRetrieves the list of all HealthSource resources (all regional) available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.regionHealthSources.deleteDeletes the specified HealthSource in the given regionactivityNN
compute.regionHealthSources.getReturns the specified HealthSource resource in the given region.data_accessNN
compute.regionHealthSources.getHealthGets the most recent health check results for this regional HealthSource.data_accessNN
compute.regionHealthSources.insertCreate a HealthSource in the specified project in the given region using the parameters that are included in the request.activityNN
compute.regionHealthSources.listLists the HealthSources for a project in the given region.data_accessNN
compute.regionHealthSources.patchUpdates the specified regional HealthSource resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.regionHealthSources.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionInstanceGroupManagerResizeRequests.cancelCancels the specified resize request. Cancelled resize request no longer waits for the resources to be provisioned. Cancel is only possible for requests that are in accepted state.activityNN
compute.regionInstanceGroupManagerResizeRequests.deleteDeletes the specified, inactive resize request. Requests that are still active cannot be deleted. Deleting request does not delete instances that were provisioned previously.activityNN
compute.regionInstanceGroupManagerResizeRequests.getReturns all of the details about the specified resize request.data_accessNN
compute.regionInstanceGroupManagerResizeRequests.insertCreates a new Resize Request that starts provisioning VMs immediately or queues VM creation.activityNN
compute.regionInstanceGroupManagerResizeRequests.listRetrieves a list of Resize Requests that are contained in the managed instance group.data_accessNN
compute.regionInstanceGroupManagers.abandonInstancesFlags the specified instances to be immediately removed from the managed instance group. Abandoning an instance does not delete the instance, but it does remove the instance from any target pools that are applied by the managed instance group. This method reduces thetargetSize of the managed instance group by the number of instances that you abandon. This operation is marked asDONE when the action is scheduled even if the instances have not yet been removed from the group. You must separately verify the status of the abandoning action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.regionInstanceGroupManagers.applyUpdatesToInstancesApply updates to selected instances the managed instance group.activityNN
compute.regionInstanceGroupManagers.createInstancesCreates instances with per-instance configurations in this regional managed instance group. Instances are created using the current instance template. The create instances operation is marked DONE if the createInstances request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or actions with the listmanagedinstances method.activityNN
compute.regionInstanceGroupManagers.deleteDeletes the specified managed instance group and all of the instances in that group.activityNN
compute.regionInstanceGroupManagers.deleteInstancesFlags the specified instances in the managed instance group to be immediately deleted. The instances are also removed from any target pools of which they were a member. This method reduces thetargetSize of the managed instance group by the number of instances that you delete. The deleteInstances operation is marked DONE if the deleteInstances request is successful. The underlying actions take additional time. You must separately verify the status of thedeleting action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.regionInstanceGroupManagers.deletePerInstanceConfigsDeletes selected per-instance configurations for the managed instance group.activityNN
compute.regionInstanceGroupManagers.getReturns all of the details about the specified managed instance group.data_accessNN
compute.regionInstanceGroupManagers.insertCreates a managed instance group using the information that you specify in the request. After the group is created, instances in the group are created using the specified instance template. This operation is marked as DONE when the group is created even if the instances in the group have not yet been created. You must separately verify the status of the individual instances with thelistmanagedinstances method. A regional managed instance group can contain up to 2000 instances.activityNN
compute.regionInstanceGroupManagers.listRetrieves the list of managed instance groups that are contained within the specified region.data_accessNN
compute.regionInstanceGroupManagers.listErrorsLists all errors thrown by actions on instances for a given regional managed instance group. The filter andorderBy query parameters are not supported.data_accessNN
compute.regionInstanceGroupManagers.listManagedInstancesLists the instances in the managed instance group and instances that are scheduled to be created. The list includes any current actions that the group has scheduled for its instances. The orderBy query parameter is not supported. The `pageToken` query parameter is supported only if the group's `listManagedInstancesResults` field is set to `PAGINATED`.data_accessNN
compute.regionInstanceGroupManagers.listPerInstanceConfigsLists all of the per-instance configurations defined for the managed instance group. The orderBy query parameter is not supported.data_accessNN
compute.regionInstanceGroupManagers.patchUpdates a managed instance group using the information that you specify in the request. This operation is marked as DONE when the group is patched even if the instances in the group are still in the process of being patched. You must separately verify the status of the individual instances with the listmanagedinstances method. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. If you update your group to specify a new template or instance configuration, it's possible that your intended specification for each VM in the group is different from the current state of that VM. To learn how to apply an updated configuration to the VMs in a MIG, seeUpdating instances in a MIG.activityNN
compute.regionInstanceGroupManagers.patchPerInstanceConfigsInserts or patches per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.activityNN
compute.regionInstanceGroupManagers.recreateInstancesFlags the specified VM instances in the managed instance group to be immediately recreated. Each instance is recreated using the group's current configuration. This operation is marked as DONE when the flag is set even if the instances have not yet been recreated. You must separately verify the status of each instance by checking itscurrentAction field; for more information, see Checking the status of managed instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.regionInstanceGroupManagers.resizeChanges the intended size of the managed instance group. If you increase the size, the group creates new instances using the current instance template. If you decrease the size, the group deletes one or more instances. The resize operation is marked DONE if theresize request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or deleting actions with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted.activityNN
compute.regionInstanceGroupManagers.resumeInstancesFlags the specified instances in the managed instance group to be resumed. This method increases thetargetSize and decreases the targetSuspendedSize of the managed instance group by the number of instances that you resume. The resumeInstances operation is marked DONE if the resumeInstances request is successful. The underlying actions take additional time. You must separately verify the status of theRESUMING action with thelistmanagedinstances method. In this request, you can only specify instances that are suspended. For example, if an instance was previously suspended using the suspendInstances method, it can be resumed using the resumeInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are resumed. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.regionInstanceGroupManagers.setInstanceTemplateSets the instance template to use when creating new instances or recreating instances in this group. Existing instances are not affected.activityNN
compute.regionInstanceGroupManagers.setTargetPoolsModifies the target pools to which all new instances in this group are assigned. Existing instances in the group are not affected.activityNN
compute.regionInstanceGroupManagers.startInstancesFlags the specified instances in the managed instance group to be started. This method increases thetargetSize and decreases the targetStoppedSize of the managed instance group by the number of instances that you start. The startInstances operation is marked DONE if the startInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTARTING action with thelistmanagedinstances method. In this request, you can only specify instances that are stopped. For example, if an instance was previously stopped using the stopInstances method, it can be started using the startInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are started. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.regionInstanceGroupManagers.stopInstancesFlags the specified instances in the managed instance group to be immediately stopped. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetStoppedSize of the managed instance group by the number of instances that you stop. The stopInstances operation is marked DONE if the stopInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTOPPING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays stopping the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is stopped. Stopped instances can be started using the startInstances method. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.regionInstanceGroupManagers.suspendInstancesFlags the specified instances in the managed instance group to be immediately suspended. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetSuspendedSize of the managed instance group by the number of instances that you suspend. The suspendInstances operation is marked DONE if the suspendInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSUSPENDING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays suspension of the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is suspended. Suspended instances can be resumed using the resumeInstances method. You can specify a maximum of 1000 instances with this method per request.activityNN
compute.regionInstanceGroupManagers.updatePerInstanceConfigsInserts or updates per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.activityNN
compute.regionInstanceGroups.getReturns the specified instance group resource.data_accessNN
compute.regionInstanceGroups.listRetrieves the list of instance group resources contained within the specified region.data_accessNN
compute.regionInstanceGroups.listInstancesLists the instances in the specified instance group and displays information about the named ports. Depending on the specified options, this method can list all instances or only the instances that are running. The orderBy query parameter is not supported.data_accessNN
compute.regionInstanceGroups.setNamedPortsSets the named ports for the specified regional instance group.activityNN
compute.regionInstanceGroups.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionInstanceTemplates.deleteDeletes the specified instance template. Deleting an instance template is permanent and cannot be undone.activityYN
compute.regionInstanceTemplates.getReturns the specified instance template.data_accessNN
compute.regionInstanceTemplates.insertCreates an instance template in the specified project and region using the global instance template whose URL is included in the request.activityNN
compute.regionInstanceTemplates.listRetrieves a list of instance templates that are contained within the specified project and region.data_accessNN
compute.regionInstances.bulkInsertCreates multiple instances in a given region. Count specifies the number of instances to create.activityNN
compute.regionInstantSnapshotGroups.deletedeletes a Regional InstantSnapshotGroup resourceactivityNN
compute.regionInstantSnapshotGroups.getreturns the specified InstantSnapshotGroup resource in the specified region.data_accessNN
compute.regionInstantSnapshotGroups.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.regionInstantSnapshotGroups.insertcreates a Regional InstantSnapshotGroup resourceactivityNN
compute.regionInstantSnapshotGroups.listretrieves the list of InstantSnapshotGroup resources contained within the specified region.data_accessNN
compute.regionInstantSnapshotGroups.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.regionInstantSnapshotGroups.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionInstantSnapshots.deleteDeletes the specified InstantSnapshot resource. Keep in mind that deleting a single instantSnapshot might not necessarily delete all the data on that instantSnapshot. If any data on the instantSnapshot that is marked for deletion is needed for subsequent instantSnapshots, the data will be moved to the next corresponding instantSnapshot. For more information, seeDeleting instantSnapshots.activityNN
compute.regionInstantSnapshots.getReturns the specified InstantSnapshot resource in the specified region.data_accessNN
compute.regionInstantSnapshots.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.regionInstantSnapshots.insertCreates an instant snapshot in the specified region.activityNN
compute.regionInstantSnapshots.listRetrieves the list of InstantSnapshot resources contained within the specified region.data_accessNN
compute.regionInstantSnapshots.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.regionInstantSnapshots.setLabelsSets the labels on a instantSnapshot in the given region. To learn more about labels, read the Labeling Resources documentation.activityNN
compute.regionInstantSnapshots.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionNetworkEndpointGroups.attachNetworkEndpointsAttach a list of network endpoints to the specified network endpoint group.activityNN
compute.regionNetworkEndpointGroups.deleteDeletes the specified network endpoint group. Note that the NEG cannot be deleted if it is configured as a backend of a backend service.activityNN
compute.regionNetworkEndpointGroups.detachNetworkEndpointsDetach the network endpoint from the specified network endpoint group.activityNN
compute.regionNetworkEndpointGroups.getReturns the specified network endpoint group.data_accessNN
compute.regionNetworkEndpointGroups.insertCreates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global APIactivityNN
compute.regionNetworkEndpointGroups.listRetrieves the list of regional network endpoint groups available to the specified project in the given region.data_accessNN
compute.regionNetworkEndpointGroups.listNetworkEndpointsLists the network endpoints in the specified network endpoint group.data_accessNN
compute.regionNetworkFirewallPolicies.addAssociationInserts an association for the specified network firewall policy.activityNN
compute.regionNetworkFirewallPolicies.addRuleInserts a rule into a network firewall policy.activityNN
compute.regionNetworkFirewallPolicies.cloneRulesCopies rules to the specified network firewall policy.activityNN
compute.regionNetworkFirewallPolicies.deleteDeletes the specified network firewall policy.activityNN
compute.regionNetworkFirewallPolicies.getReturns the specified network firewall policy.data_accessNN
compute.regionNetworkFirewallPolicies.getAssociationGets an association with the specified name.data_accessNN
compute.regionNetworkFirewallPolicies.getEffectiveFirewallsReturns the effective firewalls on a given network.data_accessNN
compute.regionNetworkFirewallPolicies.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.regionNetworkFirewallPolicies.getRuleGets a rule of the specified priority.data_accessNN
compute.regionNetworkFirewallPolicies.insertCreates a new network firewall policy in the specified project and region.activityNN
compute.regionNetworkFirewallPolicies.listLists all the network firewall policies that have been configured for the specified project in the given region.data_accessNN
compute.regionNetworkFirewallPolicies.patchPatches the specified network firewall policy.activityNN
compute.regionNetworkFirewallPolicies.patchRulePatches a rule of the specified priority.activityNN
compute.regionNetworkFirewallPolicies.removeAssociationRemoves an association for the specified network firewall policy.activityNN
compute.regionNetworkFirewallPolicies.removeRuleDeletes a rule of the specified priority.activityNN
compute.regionNetworkFirewallPolicies.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.regionNetworkFirewallPolicies.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionNotificationEndpoints.aggregatedListRetrieves the list of all NotificationEndpoint resources, regional and global, available to the specified project.data_accessNN
compute.regionNotificationEndpoints.deleteDeletes the specified NotificationEndpoint in the given regionactivityNN
compute.regionNotificationEndpoints.getReturns the specified NotificationEndpoint resource in the given region.data_accessNN
compute.regionNotificationEndpoints.insertCreate a NotificationEndpoint in the specified project in the given region using the parameters that are included in the request.activityNN
compute.regionNotificationEndpoints.listLists the NotificationEndpoints for a project in the given region.data_accessNN
compute.regionNotificationEndpoints.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionOperations.deleteDeletes the specified region-specific Operations resource.activityNN
compute.regionOperations.getRetrieves the specified region-specific Operations resource.data_accessYN
compute.regionOperations.listRetrieves a list of Operation resources contained within the specified region.data_accessNN
compute.regionOperations.waitWaits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method differs from the `GET` method in that it waits for no more than the default deadline (2 minutes) and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`.data_accessYN
compute.regionSecurityPolicies.addRuleInserts a rule into a security policy.activityNN
compute.regionSecurityPolicies.deleteDeletes the specified policy.activityNN
compute.regionSecurityPolicies.getList all of the ordered rules present in a single specified policy.data_accessNN
compute.regionSecurityPolicies.getRuleGets a rule at the specified priority.data_accessNN
compute.regionSecurityPolicies.insertCreates a new policy in the specified project using the data included in the request.activityNN
compute.regionSecurityPolicies.listList all the policies that have been configured for the specified project and region.data_accessNN
compute.regionSecurityPolicies.patchPatches the specified policy with the data included in the request. To clear fields in the policy, leave the fields empty and specify them in the updateMask. This cannot be used to be update the rules in the policy. Please use the per rule methods like addRule, patchRule, and removeRule instead.activityNN
compute.regionSecurityPolicies.patchRulePatches a rule at the specified priority. To clear fields in the rule, leave the fields empty and specify them in the updateMask.activityNN
compute.regionSecurityPolicies.removeRuleDeletes a rule at the specified priority.activityNN
compute.regionSecurityPolicies.setLabelsSets the labels on a security policy. To learn more about labels, read the Labeling Resources documentation.activityNN
compute.regionSnapshotSettings.getGet region snapshot settings.data_accessNN
compute.regionSnapshotSettings.patchPatch region snapshot settings.activityNN
compute.regionSnapshots.deleteDeletes the specified Snapshot resource. Keep in mind that deleting a single snapshot might not necessarily delete all the data on that snapshot. If any data on the snapshot that is marked for deletion is needed for subsequent snapshots, the data will be moved to the next corresponding snapshot. For more information, seeDeleting snapshots.activityNN
compute.regionSnapshots.getReturns the specified Snapshot resource.data_accessNN
compute.regionSnapshots.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.regionSnapshots.insertCreates a snapshot in the specified region using the data included in the request.activityNN
compute.regionSnapshots.listRetrieves the list of Snapshot resources contained within the specified region.data_accessNN
compute.regionSnapshots.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.regionSnapshots.setLabelsSets the labels on a regional snapshot. To learn more about labels, read the Labeling Resources documentation.activityNN
compute.regionSnapshots.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.regionSnapshots.updateKmsKeyRotates the customer-managed encryption key to the latest version for the specified snapshot.activityNN
compute.regionSslCertificates.deleteDeletes the specified SslCertificate resource in the region.activityNN
compute.regionSslCertificates.getReturns the specified SslCertificate resource in the specified region. Get a list of available SSL certificates by making a list() request.data_accessNN
compute.regionSslCertificates.insertCreates a SslCertificate resource in the specified project and region using the data included in the requestactivityNN
compute.regionSslCertificates.listRetrieves the list of SslCertificate resources available to the specified project in the specified region.data_accessNN
compute.regionSslPolicies.deleteDeletes the specified SSL policy. The SSL policy resource can be deleted only if it is not in use by any TargetHttpsProxy or TargetSslProxy resources.activityNN
compute.regionSslPolicies.getLists all of the ordered rules present in a single specified policy.data_accessNN
compute.regionSslPolicies.insertCreates a new policy in the specified project and region using the data included in the request.activityNN
compute.regionSslPolicies.listLists all the SSL policies that have been configured for the specified project and region.data_accessNN
compute.regionSslPolicies.listAvailableFeaturesLists all features that can be specified in the SSL policy when using custom profile.data_accessNN
compute.regionSslPolicies.patchPatches the specified SSL policy with the data included in the request.activityNN
compute.regionTargetHttpProxies.deleteDeletes the specified TargetHttpProxy resource.activityNN
compute.regionTargetHttpProxies.getReturns the specified TargetHttpProxy resource in the specified region.data_accessNN
compute.regionTargetHttpProxies.insertCreates a TargetHttpProxy resource in the specified project and region using the data included in the request.activityNN
compute.regionTargetHttpProxies.listRetrieves the list of TargetHttpProxy resources available to the specified project in the specified region.data_accessNN
compute.regionTargetHttpProxies.setUrlMapChanges the URL map for TargetHttpProxy.activityNN
compute.regionTargetHttpsProxies.deleteDeletes the specified TargetHttpsProxy resource.activityNN
compute.regionTargetHttpsProxies.getReturns the specified TargetHttpsProxy resource in the specified region.data_accessNN
compute.regionTargetHttpsProxies.insertCreates a TargetHttpsProxy resource in the specified project and region using the data included in the request.activityNN
compute.regionTargetHttpsProxies.listRetrieves the list of TargetHttpsProxy resources available to the specified project in the specified region.data_accessNN
compute.regionTargetHttpsProxies.patchPatches the specified regional TargetHttpsProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.regionTargetHttpsProxies.setSslCertificatesReplaces SslCertificates for TargetHttpsProxy.activityNN
compute.regionTargetHttpsProxies.setUrlMapChanges the URL map for TargetHttpsProxy.activityNN
compute.regionTargetTcpProxies.deleteDeletes the specified TargetTcpProxy resource.activityNN
compute.regionTargetTcpProxies.getReturns the specified TargetTcpProxy resource.data_accessNN
compute.regionTargetTcpProxies.insertCreates a TargetTcpProxy resource in the specified project and region using the data included in the request.activityNN
compute.regionTargetTcpProxies.listRetrieves a list of TargetTcpProxy resources available to the specified project in a given region.data_accessNN
compute.regionUrlMaps.deleteDeletes the specified UrlMap resource.activityNN
compute.regionUrlMaps.getReturns the specified UrlMap resource.data_accessNN
compute.regionUrlMaps.insertCreates a UrlMap resource in the specified project using the data included in the request.activityNN
compute.regionUrlMaps.listRetrieves the list of UrlMap resources available to the specified project in the specified region.data_accessNN
compute.regionUrlMaps.patchPatches the specified UrlMap resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.regionUrlMaps.updateUpdates the specified UrlMap resource with the data included in the request.activityNN
compute.regionUrlMaps.validateRuns static validation for the UrlMap. In particular, the tests of the provided UrlMap will be run. Calling this method does NOT create the UrlMap.activityNN
compute.regionZones.listRetrieves the list of Zone resources under the specific region available to the specified project.data_accessNN
compute.regions.getReturns the specified Region resource. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request. This method fails if the quota information is unavailable for the region and if the organization policy constraint compute.requireBasicQuotaInResponse is enforced. This constraint, when enforced, disables the fail-open behaviour when quota information (the `items.quotas` field) is unavailable for the region. It is recommended to use the default setting for the constraint unless your application requires the fail-closed behaviour for this method.data_accessNN
compute.regions.listRetrieves the list of region resources available to the specified project. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `items.quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request. This method fails if the quota information is unavailable for the region and if the organization policy constraint compute.requireBasicQuotaInResponse is enforced. This constraint, when enforced, disables the fail-open behaviour when quota information (the `items.quotas` field) is unavailable for the region. It is recommended to use the default setting for the constraint unless your application requires the fail-closed behaviour for this method.data_accessYN
compute.reservationBlocks.getRetrieves information about the specified reservation block.data_accessNN
compute.reservationBlocks.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.reservationBlocks.listRetrieves a list of reservation blocks under a single reservation.data_accessNN
compute.reservationBlocks.performMaintenanceAllows customers to perform maintenance on a reservation blockactivityNN
compute.reservationBlocks.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.reservationBlocks.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.reservationSlots.getRetrieves information about the specified reservation slot.data_accessNN
compute.reservationSlots.getVersionAllows customers to get SBOM versions of a reservation slot.data_accessNN
compute.reservationSlots.listRetrieves a list of reservation slots under a single reservation.data_accessNN
compute.reservationSlots.updateUpdate a reservation slot in the specified sub-block.activityNN
compute.reservationSubBlocks.getRetrieves information about the specified reservation subBlock.data_accessNN
compute.reservationSubBlocks.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.reservationSubBlocks.getVersionAllows customers to get SBOM versions of a reservation subBlock.data_accessNN
compute.reservationSubBlocks.listRetrieves a list of reservation subBlocks under a single reservation.data_accessNN
compute.reservationSubBlocks.performMaintenanceAllows customers to perform maintenance on a reservation subBlockactivityNN
compute.reservationSubBlocks.reportFaultyAllows customers to report a faulty subBlock.activityNN
compute.reservationSubBlocks.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.reservationSubBlocks.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.reservations.aggregatedListRetrieves an aggregated list of reservations. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.reservations.deleteDeletes the specified reservation.activityYN
compute.reservations.getRetrieves information about the specified reservation.data_accessNN
compute.reservations.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.reservations.insertCreates a new reservation. For more information, readReserving zonal resources.activityYN
compute.reservations.listA list of all the reservations that have been configured for the specified project in specified zone.data_accessNN
compute.reservations.performMaintenancePerform maintenance on an extended reservationactivityNN
compute.reservations.resizeResizes the reservation (applicable to standalone reservations only). For more information, readModifying reservations.activityNN
compute.reservations.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.reservations.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.reservations.updateUpdate share settings of the reservation.activityNN
compute.resourcePolicies.aggregatedListRetrieves an aggregated list of resource policies. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.resourcePolicies.deleteDeletes the specified resource policy.activityYN
compute.resourcePolicies.getRetrieves all information of the specified resource policy.data_accessNN
compute.resourcePolicies.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.resourcePolicies.insertCreates a new resource policy.activityYN
compute.resourcePolicies.listA list all the resource policies that have been configured for the specified project in specified region.data_accessYN
compute.resourcePolicies.patchModify the specified resource policy.activityNN
compute.resourcePolicies.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.resourcePolicies.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.rolloutPlans.deleteDeletes a RolloutPlan.activityNN
compute.rolloutPlans.getGets details of a single project-scoped RolloutPlan.data_accessNN
compute.rolloutPlans.insertCreates a new RolloutPlan in a given project and location.activityNN
compute.rolloutPlans.listLists RolloutPlans in a given project and location.data_accessNN
compute.rollouts.advanceAdvances a Rollout to the next wave, or completes it if no waves remain.activityNN
compute.rollouts.cancelCancels a Rollout.activityNN
compute.rollouts.deleteDeletes a Rollout.activityNN
compute.rollouts.getGets details of a single project-scoped Rollout.data_accessNN
compute.rollouts.listLists Rollouts in a given project and location.data_accessNN
compute.rollouts.pausePauses a Rollout.activityNN
compute.rollouts.resumeResumes a Rollout.activityNN
compute.routers.aggregatedListRetrieves an aggregated list of routers. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.routers.deleteDeletes the specified Router resource.activityYN
compute.routers.deleteRoutePolicyDeletes Route PolicyactivityNN
compute.routers.getReturns the specified Router resource.data_accessYN
compute.routers.getNatIpInfoRetrieves runtime NAT IP information.data_accessNN
compute.routers.getNatMappingInfoRetrieves runtime Nat mapping information of VM endpoints.data_accessNN
compute.routers.getRoutePolicyReturns specified Route Policydata_accessNN
compute.routers.getRouterStatusRetrieves runtime information of the specified router.data_accessNN
compute.routers.insertCreates a Router resource in the specified project and region using the data included in the request.activityYN
compute.routers.listRetrieves a list of Router resources available to the specified project.data_accessYN
compute.routers.listBgpRoutesRetrieves a list of router bgp routes available to the specified project.data_accessNN
compute.routers.listRoutePoliciesRetrieves a list of router route policy subresources available to the specified project.data_accessNN
compute.routers.patchPatches the specified Router resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.routers.patchRoutePolicyPatches Route PolicyactivityNN
compute.routers.previewPreview fields auto-generated during router create andupdate operations. Calling this method does NOT create or update the router.activityNN
compute.routers.updateUpdates the specified Router resource with the data included in the request. This method conforms toPUT semantics, which requests that the state of the target resource be created or replaced with the state defined by the representation enclosed in the request message payload.activityNN
compute.routers.updateRoutePolicyUpdates or creates new Route PolicyactivityNN
compute.routes.deleteDeletes the specified Route resource.activityYY
compute.routes.getReturns the specified Route resource.data_accessYN
compute.routes.insertCreates a Route resource in the specified project using the data included in the request.activityYY
compute.routes.listRetrieves the list of Route resources available to the specified project.data_accessYN
compute.routes.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.securityPolicies.addRuleInserts a rule into a security policy.activityYN
compute.securityPolicies.aggregatedListRetrieves the list of all SecurityPolicy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.securityPolicies.deleteDeletes the specified policy.activityNN
compute.securityPolicies.getList all of the ordered rules present in a single specified policy.data_accessNN
compute.securityPolicies.getRuleGets a rule at the specified priority.data_accessNN
compute.securityPolicies.insertCreates a new policy in the specified project using the data included in the request.activityYN
compute.securityPolicies.listList all the policies that have been configured for the specified project.data_accessNN
compute.securityPolicies.listPreconfiguredExpressionSetsGets the current list of preconfigured Web Application Firewall (WAF) expressions.data_accessNN
compute.securityPolicies.patchPatches the specified policy with the data included in the request. To clear fields in the policy, leave the fields empty and specify them in the updateMask. This cannot be used to be update the rules in the policy. Please use the per rule methods like addRule, patchRule, and removeRule instead.activityNN
compute.securityPolicies.patchRulePatches a rule at the specified priority. To clear fields in the rule, leave the fields empty and specify them in the updateMask.activityNN
compute.securityPolicies.removeRuleDeletes a rule at the specified priority.activityNN
compute.securityPolicies.setLabelsSets the labels on a security policy. To learn more about labels, read the Labeling Resources documentation.activityNN
compute.serviceAttachments.aggregatedListRetrieves the list of all ServiceAttachment resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.serviceAttachments.deleteDeletes the specified ServiceAttachment in the given scopeactivityNN
compute.serviceAttachments.getReturns the specified ServiceAttachment resource in the given scope.data_accessNN
compute.serviceAttachments.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.serviceAttachments.insertCreates a ServiceAttachment in the specified project in the given scope using the parameters that are included in the request.activityNN
compute.serviceAttachments.listLists the ServiceAttachments for a project in the given scope.data_accessNN
compute.serviceAttachments.patchPatches the specified ServiceAttachment resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.serviceAttachments.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.serviceAttachments.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.snapshotSettings.getGet snapshot settings.data_accessNN
compute.snapshotSettings.patchPatch snapshot settings.activityNN
compute.snapshots.deleteDeletes the specified Snapshot resource. Keep in mind that deleting a single snapshot might not necessarily delete all the data on that snapshot. If any data on the snapshot that is marked for deletion is needed for subsequent snapshots, the data will be moved to the next corresponding snapshot. For more information, seeDeleting snapshots.activityYY
compute.snapshots.getReturns the specified Snapshot resource.data_accessYN
compute.snapshots.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessYN
compute.snapshots.insertCreates a snapshot in the specified project using the data included in the request. For regular snapshot creation, consider using this method instead of disks.createSnapshot, as this method supports more features, such as creating snapshots in a project different from the source disk project.activityYY
compute.snapshots.listRetrieves the list of Snapshot resources contained within the specified project.data_accessYN
compute.snapshots.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityYY
compute.snapshots.setLabelsSets the labels on a snapshot. To learn more about labels, read theLabeling Resources documentation.activityNN
compute.snapshots.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.snapshots.updateKmsKeyRotates the customer-managed encryption key to the latest version for the specified snapshot.activityNN
compute.sslCertificates.aggregatedListRetrieves the list of all SslCertificate resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.sslCertificates.deleteDeletes the specified SslCertificate resource.activityNN
compute.sslCertificates.getReturns the specified SslCertificate resource.data_accessNN
compute.sslCertificates.insertCreates a SslCertificate resource in the specified project using the data included in the request.activityYN
compute.sslCertificates.listRetrieves the list of SslCertificate resources available to the specified project.data_accessNN
compute.sslPolicies.aggregatedListRetrieves the list of all SslPolicy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.sslPolicies.deleteDeletes the specified SSL policy. The SSL policy resource can be deleted only if it is not in use by any TargetHttpsProxy or TargetSslProxy resources.activityYN
compute.sslPolicies.getLists all of the ordered rules present in a single specified policy.data_accessNN
compute.sslPolicies.insertReturns the specified SSL policy resource.activityYN
compute.sslPolicies.listLists all the SSL policies that have been configured for the specified project.data_accessNN
compute.sslPolicies.listAvailableFeaturesLists all features that can be specified in the SSL policy when using custom profile.data_accessNN
compute.sslPolicies.patchPatches the specified SSL policy with the data included in the request.activityNN
compute.storagePoolTypes.aggregatedListRetrieves an aggregated list of storage pool types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.storagePoolTypes.getReturns the specified storage pool type.data_accessNN
compute.storagePoolTypes.listRetrieves a list of storage pool types available to the specified project.data_accessNN
compute.storagePools.aggregatedListRetrieves an aggregated list of storage pools. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.storagePools.deleteDeletes the specified storage pool. Deleting a storagePool removes its data permanently and is irreversible. However, deleting a storagePool does not delete any snapshots previously made from the storagePool. You must separately delete snapshots.activityNN
compute.storagePools.getReturns a specified storage pool. Gets a list of available storage pools by making a list() request.data_accessNN
compute.storagePools.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.storagePools.insertCreates a storage pool in the specified project using the data in the request.activityNN
compute.storagePools.listRetrieves a list of storage pools contained within the specified zone.data_accessNN
compute.storagePools.listDisksLists the disks in a specified storage pool.data_accessNN
compute.storagePools.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityNN
compute.storagePools.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.storagePools.updateUpdates the specified storagePool with the data included in the request. The update is performed only on selected fields included as part of update-mask. Only the following fields can be modified: pool_provisioned_capacity_gb, pool_provisioned_iops and pool_provisioned_throughput.activityNN
compute.subnetworks.aggregatedListRetrieves an aggregated list of subnetworks. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.subnetworks.deleteDeletes the specified subnetwork.activityYN
compute.subnetworks.expandIpCidrRangeExpands the IP CIDR range of the subnetwork to a specified value.activityYN
compute.subnetworks.getReturns the specified subnetwork.data_accessYN
compute.subnetworks.getIamPolicyGets the access control policy for a resource. May be empty if no such policy or resource exists.data_accessNN
compute.subnetworks.insertCreates a subnetwork in the specified project using the data included in the request.activityYN
compute.subnetworks.listRetrieves a list of subnetworks available to the specified project.data_accessNN
compute.subnetworks.listUsableRetrieves an aggregated list of all usable subnetworks in the project.data_accessNN
compute.subnetworks.patchPatches the specified subnetwork with the data included in the request. Only certain fields can be updated with a patch request as indicated in the field descriptions. You must specify the current fingerprint of the subnetwork resource being patched.activityYY
compute.subnetworks.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy.activityYN
compute.subnetworks.setPrivateIpGoogleAccessSet whether VMs in this subnet can access Google services without assigning external IP addresses through Private Google Access.activityYN
compute.subnetworks.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.targetGrpcProxies.deleteDeletes the specified TargetGrpcProxy in the given scopeactivityNN
compute.targetGrpcProxies.getReturns the specified TargetGrpcProxy resource in the given scope.data_accessNN
compute.targetGrpcProxies.insertCreates a TargetGrpcProxy in the specified project in the given scope using the parameters that are included in the request.activityNN
compute.targetGrpcProxies.listLists the TargetGrpcProxies for a project in the given scope.data_accessNN
compute.targetGrpcProxies.patchPatches the specified TargetGrpcProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.targetHttpProxies.aggregatedListRetrieves the list of all TargetHttpProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.targetHttpProxies.deleteDeletes the specified TargetHttpProxy resource.activityNN
compute.targetHttpProxies.getReturns the specified TargetHttpProxy resource.data_accessNN
compute.targetHttpProxies.insertCreates a TargetHttpProxy resource in the specified project using the data included in the request.activityYN
compute.targetHttpProxies.listRetrieves the list of TargetHttpProxy resources available to the specified project.data_accessNN
compute.targetHttpProxies.patchPatches the specified TargetHttpProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.targetHttpProxies.setUrlMapChanges the URL map for TargetHttpProxy.activityNN
compute.targetHttpsProxies.aggregatedListRetrieves the list of all TargetHttpsProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.targetHttpsProxies.deleteDeletes the specified TargetHttpsProxy resource.activityNN
compute.targetHttpsProxies.getReturns the specified TargetHttpsProxy resource.data_accessNN
compute.targetHttpsProxies.insertCreates a TargetHttpsProxy resource in the specified project using the data included in the request.activityNN
compute.targetHttpsProxies.listRetrieves the list of TargetHttpsProxy resources available to the specified project.data_accessNN
compute.targetHttpsProxies.patchPatches the specified TargetHttpsProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.targetHttpsProxies.setCertificateMapChanges the Certificate Map for TargetHttpsProxy.activityNN
compute.targetHttpsProxies.setQuicOverrideSets the QUIC override policy for TargetHttpsProxy.activityNN
compute.targetHttpsProxies.setSslCertificatesReplaces SslCertificates for TargetHttpsProxy.activityNN
compute.targetHttpsProxies.setSslPolicySets the SSL policy for TargetHttpsProxy. The SSL policy specifies the server-side support for SSL features. This affects connections between clients and the HTTPS proxy load balancer. They do not affect the connection between the load balancer and the backends.activityNN
compute.targetHttpsProxies.setUrlMapChanges the URL map for TargetHttpsProxy.activityNN
compute.targetInstances.aggregatedListRetrieves an aggregated list of target instances. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.targetInstances.deleteDeletes the specified TargetInstance resource.activityNN
compute.targetInstances.getReturns the specified TargetInstance resource.data_accessNN
compute.targetInstances.insertCreates a TargetInstance resource in the specified project and zone using the data included in the request.activityNN
compute.targetInstances.listRetrieves a list of TargetInstance resources available to the specified project and zone.data_accessNN
compute.targetInstances.setSecurityPolicySets the Google Cloud Armor security policy for the specified target instance. For more information, seeGoogle Cloud Armor OverviewactivityNN
compute.targetInstances.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.targetPools.addHealthCheckAdds health check URLs to a target pool.activityNN
compute.targetPools.addInstanceAdds an instance to a target pool.activityNN
compute.targetPools.aggregatedListRetrieves an aggregated list of target pools. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.targetPools.deleteDeletes the specified target pool.activityNN
compute.targetPools.getReturns the specified target pool.data_accessNN
compute.targetPools.getHealthGets the most recent health check results for each IP for the instance that is referenced by the given target pool.data_accessNN
compute.targetPools.insertCreates a target pool in the specified project and region using the data included in the request.activityYN
compute.targetPools.listRetrieves a list of target pools available to the specified project and region.data_accessNN
compute.targetPools.removeHealthCheckRemoves health check URL from a target pool.activityNN
compute.targetPools.removeInstanceRemoves instance URL from a target pool.activityNN
compute.targetPools.setBackupChanges a backup target pool's configurations.activityNN
compute.targetPools.setSecurityPolicySets the Google Cloud Armor security policy for the specified target pool. For more information, seeGoogle Cloud Armor OverviewactivityNN
compute.targetPools.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.targetSslProxies.deleteDeletes the specified TargetSslProxy resource.activityNN
compute.targetSslProxies.getReturns the specified TargetSslProxy resource.data_accessNN
compute.targetSslProxies.insertCreates a TargetSslProxy resource in the specified project using the data included in the request.activityNN
compute.targetSslProxies.listRetrieves the list of TargetSslProxy resources available to the specified project.data_accessNN
compute.targetSslProxies.setBackendServiceChanges the BackendService for TargetSslProxy.activityNN
compute.targetSslProxies.setCertificateMapChanges the Certificate Map for TargetSslProxy.activityNN
compute.targetSslProxies.setProxyHeaderChanges the ProxyHeaderType for TargetSslProxy.activityNN
compute.targetSslProxies.setSslCertificatesChanges SslCertificates for TargetSslProxy.activityNN
compute.targetSslProxies.setSslPolicySets the SSL policy for TargetSslProxy. The SSL policy specifies the server-side support for SSL features. This affects connections between clients and the load balancer. They do not affect the connection between the load balancer and the backends.activityNN
compute.targetSslProxies.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.targetTcpProxies.aggregatedListRetrieves the list of all TargetTcpProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.targetTcpProxies.deleteDeletes the specified TargetTcpProxy resource.activityNN
compute.targetTcpProxies.getReturns the specified TargetTcpProxy resource.data_accessNN
compute.targetTcpProxies.insertCreates a TargetTcpProxy resource in the specified project using the data included in the request.activityNN
compute.targetTcpProxies.listRetrieves the list of TargetTcpProxy resources available to the specified project.data_accessNN
compute.targetTcpProxies.setBackendServiceChanges the BackendService for TargetTcpProxy.activityNN
compute.targetTcpProxies.setProxyHeaderChanges the ProxyHeaderType for TargetTcpProxy.activityNN
compute.targetTcpProxies.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.targetVpnGateways.aggregatedListRetrieves an aggregated list of target VPN gateways. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.targetVpnGateways.deleteDeletes the specified target VPN gateway.activityYN
compute.targetVpnGateways.getReturns the specified target VPN gateway.data_accessYN
compute.targetVpnGateways.insertCreates a target VPN gateway in the specified project and region using the data included in the request.activityYN
compute.targetVpnGateways.listRetrieves a list of target VPN gateways available to the specified project and region.data_accessNN
compute.targetVpnGateways.setLabelsSets the labels on a TargetVpnGateway. To learn more about labels, read theLabeling Resources documentation.activityNN
compute.urlMaps.aggregatedListRetrieves the list of all UrlMap resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.urlMaps.deleteDeletes the specified UrlMap resource.activityNN
compute.urlMaps.getReturns the specified UrlMap resource.data_accessNN
compute.urlMaps.insertCreates a UrlMap resource in the specified project using the data included in the request.activityYN
compute.urlMaps.invalidateCacheInitiates a cache invalidation operation, invalidating the specified path, scoped to the specified UrlMap. For more information, see Invalidating cached content.activityNN
compute.urlMaps.listRetrieves the list of UrlMap resources available to the specified project.data_accessNN
compute.urlMaps.patchPatches the specified UrlMap resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.activityNN
compute.urlMaps.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.urlMaps.updateUpdates the specified UrlMap resource with the data included in the request.activityNN
compute.urlMaps.validateRuns static validation for the UrlMap. In particular, the tests of the provided UrlMap will be run. Calling this method does NOT create the UrlMap.activityNN
compute.vpnGateways.aggregatedListRetrieves an aggregated list of VPN gateways. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessNN
compute.vpnGateways.deleteDeletes the specified VPN gateway.activityYN
compute.vpnGateways.getReturns the specified VPN gateway.data_accessYN
compute.vpnGateways.getStatusReturns the status for the specified VPN gateway.data_accessNN
compute.vpnGateways.insertCreates a VPN gateway in the specified project and region using the data included in the request.activityYN
compute.vpnGateways.listRetrieves a list of VPN gateways available to the specified project and region.data_accessNN
compute.vpnGateways.setLabelsSets the labels on a VpnGateway. To learn more about labels, read theLabeling Resources documentation.activityNN
compute.vpnGateways.testIamPermissionsReturns permissions that a caller has on the specified resource.data_accessNN
compute.vpnTunnels.aggregatedListRetrieves an aggregated list of VPN tunnels. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.data_accessYN
compute.vpnTunnels.deleteDeletes the specified VPN Tunnel resource.activityYY
compute.vpnTunnels.getReturns the specified VpnTunnel resource.data_accessYN
compute.vpnTunnels.insertCreates a VpnTunnel resource in the specified project and region using the data included in the request.activityYY
compute.vpnTunnels.listRetrieves a list of VpnTunnel resources contained in the specified project and region.data_accessNN
compute.vpnTunnels.setLabelsSets the labels on a VpnTunnel. To learn more about labels, read theLabeling Resources documentation.activityNN
compute.wireGroups.deleteDeletes the specified wire group in the given scope.activityNN
compute.wireGroups.getGets the specified wire group resource in the given scope.data_accessNN
compute.wireGroups.insertCreates a wire group in the specified project in the given scope using the parameters that are included in the request.activityNN
compute.wireGroups.listLists the wire groups for a project in the given scope.data_accessNN
compute.wireGroups.patchUpdates the specified wire group resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.activityNN
compute.zoneOperations.deleteDeletes the specified zone-specific Operations resource.activityNN
compute.zoneOperations.getRetrieves the specified zone-specific Operations resource.data_accessYN
compute.zoneOperations.listRetrieves a list of Operation resources contained within the specified zone.data_accessNN
compute.zoneOperations.waitWaits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method waits for no more than the 2 minutes and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`.data_accessYN
compute.zoneVmExtensionPolicies.deleteDeletes a specified zone VM extension policy within a project.activityNN
compute.zoneVmExtensionPolicies.getRetrieves details of a specific zone VM extension policy within a project.data_accessNN
compute.zoneVmExtensionPolicies.insertCreates a new zone-level VM extension policy within a project.activityNN
compute.zoneVmExtensionPolicies.listLists all VM extension policies within a specific zone for a project.data_accessNN
compute.zoneVmExtensionPolicies.updateModifies an existing zone VM extension policy within a project.activityNN
compute.zones.getReturns the specified Zone resource.data_accessNN
compute.zones.listRetrieves the list of Zone resources available to the specified project.data_accessYN
compute.reservations.listConsumableReservationsList the reservations a project is allowed to consume.data_accessYN

any: compute.googleapis.com (any method)

#
ServiceName
compute.googleapis.com

Description

Catch-all entry for compute.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
GCPUserIp (kusto rule field)is_not_null2 ruleskusto
GCPUserIp (kusto rule field)neprivate2 ruleskusto
VMOperation (kusto rule field)eqinsert2 ruleskusto
Severity (kusto rule field)eqNOTICE1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • GCP Audit Logs - Open Firewall Rule Created or Modified source high: Detects when a Google Cloud Platform firewall rule is created or modified to allow traffic from any source (0.0.0.0/0 or 0.0.0.0). Open firewall rules expose resources to the internet and can significantly increase the attack surface of cloud infrastructure. This may indicate a misconfiguration, lack of security awareness, or malicious activity to create backdoor access. Adversaries may create or modify firewall rules to enable persistent access or facilitate lateral movement. This rule monitors firewall insert and patch operations where sourceRanges include unrestricted access patterns.T1133, T1562, T1562.001, T1562.004
  • Cross-Cloud Suspicious Compute resource creation in GCP source low: This detection identifies potential suspicious activity across multi-cloud environments by combining AWS GuardDuty findings with GCP Audit Logs. It focuses on AWS activities related to unauthorized access, credential abuse, and unusual behaviors, as well as GCP instances creation with non-Google service account users. The query aims to provide a comprehensive view of cross-cloud security incidents for proactive threat detection and response.T1059, T1069, T1078, T1547, T1548, T1552
  • Suspicious VM Instance Creation Activity Detected source medium: This detection identifies high-severity alerts across various Microsoft security products, including Microsoft Defender XDR and Microsoft Entra ID, and correlates them with instances of Google Cloud VM creation. It focuses on instances where VMs were created within a short timeframe of high-severity alerts, potentially indicating suspicious activity.T1078, T1106, T1526

compute.acceleratorTypes.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of accelerator types. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-qkprxdd337q",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "f98043f4-0f0c-49a8-87cf-5a6a1aa7a659"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.acceleratorTypes.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.acceleratorTypes.aggregatedList",
    "numResponseItems": "174",
    "request": {
      "@type": "type.googleapis.com/compute.acceleratorTypes.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.accelerator-types.list invocation-id/098c934ed73d416883a95875b984939f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:40.300776Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/acceleratorTypes",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:40.781499677Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.acceleratorTypes.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:40.113008Z"
}

compute.acceleratorTypes.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified accelerator type.

Data Access audit logs are disabled by default.

compute.acceleratorTypes.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of accelerator types that are available to the specified project.

Data Access audit logs are disabled by default.

compute.addresses.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of addresses. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-gx57kae1rw0u",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "d76a696e-2d16-431e-8e4a-a62c9c340b35"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.addresses.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.addresses.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.addresses.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.list invocation-id/ea7aaee947ee44a1bfd3e44433c20c8e environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:26.755047Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/addresses",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:27.768107147Z",
  "resource": {
    "labels": {
      "location": "global",
      "project_id": "example-project-id",
      "reserved_address_id": ""
    },
    "type": "gce_reserved_address"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:26.671109Z"
}

compute.addresses.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified address resource.

Example Audit Log Entry #

{
  "insertId": "-qluhtce1xekj",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "b67cbd07-0aa5-47f0-822f-d6928729fa68"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782744130263-65565769c1864-a09711bf-0fb552de",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.addresses.deleteInternal",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
          "service": "compute",
          "type": "compute.addresses"
        }
      }
    ],
    "methodName": "v1.compute.addresses.delete",
    "request": {
      "@type": "type.googleapis.com/compute.addresses.delete"
    },
    "requestMetadata": {
      "callerIp": "private",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:42:11.047799Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "6341651908594186925",
      "insertTime": "2026-06-29T07:42:10.989-07:00",
      "name": "operation-1782744130263-65565769c1864-a09711bf-0fb552de",
      "operationType": "delete",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782744130263-65565769c1864-a09711bf-0fb552de",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/6341651908594186925",
      "startTime": "2026-06-29T07:42:11.007-07:00",
      "status": "RUNNING",
      "targetId": "4742281296736108351",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
      "user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:42:12.036038037Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "reserved_address_id": "4742281296736108351"
    },
    "type": "gce_reserved_address"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:42:10.316308Z"
}

compute.addresses.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified address resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-o4q3zee3dbzy",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "b2207c35-1025-445b-a670-e95687dfe9e5"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.addresses.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
          "service": "compute",
          "type": "compute.addresses"
        }
      }
    ],
    "methodName": "v1.compute.addresses.get",
    "request": {
      "@type": "type.googleapis.com/compute.addresses.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.create invocation-id/b5afe11eca0c4cb4976cb7d45d6e5fa9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:57.161127Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:57.695646512Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "reserved_address_id": "8707194920272646109"
    },
    "type": "gce_reserved_address"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:20:57.079378Z"
}

compute.addresses.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an address resource in the specified project by using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-81m2fde2asfa",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9a227fdf-d92c-4cd1-8411-c58cdea6129e"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782739249968-6556453b8b4f2-65eb49e3-95a2a27f",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.addresses.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
          "service": "compute",
          "type": "compute.addresses"
        }
      }
    ],
    "methodName": "v1.compute.addresses.insert",
    "request": {
      "@type": "type.googleapis.com/compute.addresses.insert",
      "name": "dwgen-dw739065"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.create invocation-id/b5afe11eca0c4cb4976cb7d45d6e5fa9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:50.293376Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "798636759271329757",
      "insertTime": "2026-06-29T06:20:50.260-07:00",
      "name": "operation-1782739249968-6556453b8b4f2-65eb49e3-95a2a27f",
      "operationType": "insert",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782739249968-6556453b8b4f2-65eb49e3-95a2a27f",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/798636759271329757",
      "startTime": "2026-06-29T06:20:50.265-07:00",
      "status": "RUNNING",
      "targetId": "8707194920272646109",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:50.643550018Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "reserved_address_id": "8707194920272646109"
    },
    "type": "gce_reserved_address"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T13:20:50.033933Z"
}

compute.addresses.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of addresses contained within the specified region.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-3a8dv5e7qzco",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "ccbfbaf6-f02f-44ac-aa03-3c47241a9054"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.addresses.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.addresses.list",
    "request": {
      "@type": "type.googleapis.com/compute.addresses.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.list invocation-id/345a3836fc8542ae86e7e13d2e9ccb07 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:37:31.630682Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/addresses",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:37:32.610254515Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "reserved_address_id": ""
    },
    "type": "gce_reserved_address"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T15:37:31.593989Z"
}

compute.addresses.move: move

#
ServiceName
compute.googleapis.com

Description

Moves the specified address resource.

compute.addresses.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on an Address. To learn more about labels, read theLabeling Resources documentation.

compute.addresses.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.advice.calendarMode: calendarMode

#
ServiceName
compute.googleapis.com

Description

Advise how, where and when to create the requested amount of instances with specified accelerators, within the specified time and location limits. The method recommends creating future reservations for the requested resources.

compute.autoscalers.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of autoscalers. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.autoscalers.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified autoscaler.

compute.autoscalers.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified autoscaler resource.

Data Access audit logs are disabled by default.

compute.autoscalers.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an autoscaler in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-j3w3ibe5nm1k",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a0fa2f1f-f310-4146-b966-8491ea0296bd"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745502771-65565c86ae940-e0b83d49-c6e19dc5",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.autoscalers.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/autoscalers/dwn3-dw745304-0hxp",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/autoscalers/dwn3-dw745304-0hxp",
          "service": "compute",
          "type": "compute.autoscalers"
        }
      },
      {
        "granted": true,
        "permission": "compute.instanceGroupManagers.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
          "service": "compute",
          "type": "compute.instanceGroupManagers"
        }
      }
    ],
    "methodName": "v1.compute.autoscalers.insert",
    "request": {
      "@type": "type.googleapis.com/compute.autoscalers.insert",
      "autoscalingPolicy": {
        "maxNumReplicas": "2",
        "minNumReplicas": "0"
      },
      "name": "dwn3-dw745304-0hxp",
      "target": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-groups.managed.set-autoscaling invocation-id/a542d70e2ac54b66a331659b7052ec43 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:05:03.018735Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/autoscalers/dwn3-dw745304-0hxp",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "3498777969783945073",
      "insertTime": "2026-06-29T08:05:02.938-07:00",
      "name": "operation-1782745502771-65565c86ae940-e0b83d49-c6e19dc5",
      "operationType": "compute.autoscalers.insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782745502771-65565c86ae940-e0b83d49-c6e19dc5",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/3498777969783945073",
      "startTime": "2026-06-29T08:05:02.943-07:00",
      "status": "RUNNING",
      "targetId": "8603239420171073393",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/autoscalers/dwn3-dw745304-0hxp",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:05:03.557547786Z",
  "resource": {
    "labels": {
      "autoscaler_id": "8603239420171073393",
      "location": "us-central1-a",
      "project_id": "example-project-id"
    },
    "type": "gce_autoscaler"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:05:02.736149Z"
}

compute.autoscalers.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of autoscalers contained within the specified zone.

Data Access audit logs are disabled by default.

compute.autoscalers.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates an autoscaler in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.autoscalers.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.autoscalers.update: update

#
ServiceName
compute.googleapis.com

Description

Updates an autoscaler in the specified project using the data included in the request.

compute.backendBuckets.addSignedUrlKey: addSignedUrlKey

#
ServiceName
compute.googleapis.com

Description

Adds a key for validating requests with signed URLs for this backend bucket.

compute.backendBuckets.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all BackendBucket resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.backendBuckets.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified BackendBucket resource.

Example Audit Log Entry #

{
  "insertId": "w7o09aeg8ale",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "f8127176-af54-448b-bafe-6edcfe5f9034"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782747082755-6556626978d23-9d277378-cc903e66",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.backendBuckets.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
          "service": "compute",
          "type": "compute.backendBuckets"
        }
      }
    ],
    "methodName": "v1.compute.backendBuckets.delete",
    "request": {
      "@type": "type.googleapis.com/compute.backendBuckets.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-buckets.delete invocation-id/8b838c546bff4d7bb535c021ca3844dc environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:31:22.970845Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "8247178286211215653",
      "insertTime": "2026-06-29T08:31:22.852-07:00",
      "name": "operation-1782747082755-6556626978d23-9d277378-cc903e66",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782747082755-6556626978d23-9d277378-cc903e66",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/8247178286211215653",
      "startTime": "2026-06-29T08:31:22.857-07:00",
      "status": "RUNNING",
      "targetId": "9153106374927790504",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/backendBuckets/dwbb-dw746783",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:31:23.283965096Z",
  "resource": {
    "labels": {
      "backend_bucket_id": "9153106374927790504",
      "project_id": "example-project-id"
    },
    "type": "gce_backend_bucket"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:31:22.717372Z"
}

compute.backendBuckets.deleteSignedUrlKey: deleteSignedUrlKey

#
ServiceName
compute.googleapis.com

Description

Deletes a key for validating requests with signed URLs for this backend bucket.

compute.backendBuckets.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified BackendBucket resource.

Data Access audit logs are disabled by default.

compute.backendBuckets.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.backendBuckets.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a BackendBucket resource in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "y4u4tbe7siby",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "d4b5a414-df18-4fdc-af0d-0c1093d95e1a"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746951729-655661ec84229-b362823f-f7845f94",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.backendBuckets.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
          "service": "compute",
          "type": "compute.backendBuckets"
        }
      }
    ],
    "methodName": "v1.compute.backendBuckets.insert",
    "request": {
      "@type": "type.googleapis.com/compute.backendBuckets.insert",
      "bucketName": "dwbb-dw746783",
      "enableCdn": false,
      "name": "dwbb-dw746783"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-buckets.create invocation-id/74f8289ff9954fd3afc1ac3ea0ad9532 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:29:12.244413Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "39143132380475816",
      "insertTime": "2026-06-29T08:29:11.885-07:00",
      "name": "operation-1782746951729-655661ec84229-b362823f-f7845f94",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782746951729-655661ec84229-b362823f-f7845f94",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/39143132380475816",
      "startTime": "2026-06-29T08:29:11.888-07:00",
      "status": "RUNNING",
      "targetId": "9153106374927790504",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/backendBuckets/dwbb-dw746783",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:29:12.527683763Z",
  "resource": {
    "labels": {
      "backend_bucket_id": "9153106374927790504",
      "project_id": "example-project-id"
    },
    "type": "gce_backend_bucket"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:29:11.704555Z"
}

compute.backendBuckets.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of BackendBucket resources available to the specified project.

Data Access audit logs are disabled by default.

compute.backendBuckets.listUsable: listUsable

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of all usable backend buckets in the specified project.

Data Access audit logs are disabled by default.

compute.backendBuckets.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified BackendBucket resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.backendBuckets.setEdgeSecurityPolicy: setEdgeSecurityPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the edge security policy for the specified backend bucket.

compute.backendBuckets.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.backendBuckets.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.backendBuckets.update: update

#
ServiceName
compute.googleapis.com

Description

Updates the specified BackendBucket resource with the data included in the request.

compute.backendServices.addSignedUrlKey: addSignedUrlKey

#
ServiceName
compute.googleapis.com

Description

Adds a key for validating requests with signed URLs for this backend service.

compute.backendServices.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all BackendService resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "vxhk4mdlumk",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "64d85f3c-aeb6-4d59-b00d-554a789a3882"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.backendServices.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.backendServices.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.backendServices.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-services.list invocation-id/b37e14813184495399c8084e3384921a environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:29.448224Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/backendServices",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:29.752707604Z",
  "resource": {
    "labels": {
      "backend_service_id": "",
      "location": "global",
      "project_id": "example-project-id"
    },
    "type": "gce_backend_service"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:29.335272Z"
}

compute.backendServices.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified BackendService resource.

compute.backendServices.deleteSignedUrlKey: deleteSignedUrlKey

#
ServiceName
compute.googleapis.com

Description

Deletes a key for validating requests with signed URLs for this backend service.

compute.backendServices.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified BackendService resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-4fkxnae12mgg",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "e76b29b0-f855-4105-b0ab-bc93b6d4b713"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "110162197178770594910"
      },
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
      "principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.backendServices.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/backendServices/k8s-ingress-svc-acct-permission-check-probe",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/backendServices/k8s-ingress-svc-acct-permission-check-probe",
          "service": "compute",
          "type": "compute.backendServices"
        }
      }
    ],
    "methodName": "v1.compute.backendServices.get",
    "request": {
      "@type": "type.googleapis.com/compute.backendServices.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 Kubernetes/0.0.0 (linux amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:39:47.532900Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/backendServices/k8s-ingress-svc-acct-permission-check-probe",
    "serviceName": "compute.googleapis.com",
    "status": {
      "code": 5,
      "message": "The resource 'projects/example-project-id/global/backendServices/k8s-ingress-svc-acct-permission-check-probe' was not found"
    }
  },
  "receiveTimestamp": "2026-06-29T14:39:48.378923912Z",
  "resource": {
    "labels": {
      "backend_service_id": "0",
      "location": "global",
      "project_id": "example-project-id"
    },
    "type": "gce_backend_service"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T14:39:47.467641Z"
}

compute.backendServices.getEffectiveSecurityPolicies: getEffectiveSecurityPolicies

#
ServiceName
compute.googleapis.com

Description

Returns effective security policies applied to this backend service.

Data Access audit logs are disabled by default.

compute.backendServices.getHealth: getHealth

#
ServiceName
compute.googleapis.com

Description

Gets the most recent health check results for this BackendService. Example request body: { "group": "/zones/us-east1-b/instanceGroups/lb-backend-example" }

Data Access audit logs are disabled by default.

compute.backendServices.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.backendServices.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a BackendService resource in the specified project using the data included in the request. For more information, see Backend services overview.

Example Audit Log Entry #

{
  "insertId": "kjqm4ld68m2",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "fabab22c-7e17-4fa7-a694-78f16840dc24"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745406113-65565c2a80653-8b3a4929-a02bbfc1",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.backendServices.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/backendServices/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/backendServices/dwn3-dw745304",
          "service": "compute",
          "type": "compute.backendServices"
        }
      }
    ],
    "methodName": "v1.compute.backendServices.insert",
    "request": {
      "@type": "type.googleapis.com/compute.backendServices.insert",
      "healthChecks": [
        "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/healthChecks/dwn3-dw745304"
      ],
      "name": "dwn3-dw745304",
      "portName": "http",
      "protocol": "HTTP",
      "timeoutSec": "30"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-services.create invocation-id/9ee923ad72444eadb52cde40c047aeb2 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:03:26.726188Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/backendServices/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "2034658459352250321",
      "insertTime": "2026-06-29T08:03:26.531-07:00",
      "name": "operation-1782745406113-65565c2a80653-8b3a4929-a02bbfc1",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745406113-65565c2a80653-8b3a4929-a02bbfc1",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2034658459352250321",
      "startTime": "2026-06-29T08:03:26.534-07:00",
      "status": "RUNNING",
      "targetId": "8155814126983002065",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/backendServices/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:03:27.644584217Z",
  "resource": {
    "labels": {
      "backend_service_id": "8155814126983002065",
      "location": "global",
      "project_id": "example-project-id"
    },
    "type": "gce_backend_service"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:03:26.196728Z"
}

compute.backendServices.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of BackendService resources available to the specified project.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-q1ju39ehikl0",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "8c13bf3d-a7b9-4b68-8a7b-8b62bb560164"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.backendServices.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.backendServices.list",
    "request": {
      "@type": "type.googleapis.com/compute.backendServices.list"
    },
    "requestMetadata": {
      "callerIp": "private",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:40:10.210535Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/backendServices",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:40:10.244320418Z",
  "resource": {
    "labels": {
      "backend_service_id": "",
      "location": "global",
      "project_id": "example-project-id"
    },
    "type": "gce_backend_service"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:40:10.163141Z"
}

compute.backendServices.listUsable: listUsable

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of all usable backend services in the specified project.

Data Access audit logs are disabled by default.

compute.backendServices.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified BackendService resource with the data included in the request. For more information, see Backend services overview. This method supports PATCH semantics and uses the JSON merge patch format and processing rules.

compute.backendServices.setEdgeSecurityPolicy: setEdgeSecurityPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the edge security policy for the specified backend service.

compute.backendServices.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.backendServices.setSecurityPolicy: setSecurityPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the Google Cloud Armor security policy for the specified backend service. For more information, seeGoogle Cloud Armor Overview

compute.backendServices.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.backendServices.update: update

#
ServiceName
compute.googleapis.com

Description

Updates the specified BackendService resource with the data included in the request. For more information, seeBackend services overview.

compute.crossSiteNetworks.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified cross-site network in the given scope.

compute.crossSiteNetworks.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified cross-site network in the given scope.

Data Access audit logs are disabled by default.

compute.crossSiteNetworks.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a cross-site network in the specified project in the given scope using the parameters that are included in the request.

compute.crossSiteNetworks.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the cross-site networks for a project in the given scope.

Data Access audit logs are disabled by default.

compute.crossSiteNetworks.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified cross-site network with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.diskTypes.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of disk types. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-da0gcfe5lmkg",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "157ddb05-f185-443a-a509-19332543bf9a"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.diskTypes.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.diskTypes.aggregatedList",
    "numResponseItems": "174",
    "request": {
      "@type": "type.googleapis.com/compute.diskTypes.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disk-types.list invocation-id/e42e5d7a7bdb46fca5a7e0a737f7d0f8 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:42.066364Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/diskTypes",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:42.165744875Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.diskTypes.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:41.940959Z"
}

compute.diskTypes.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified disk type.

Data Access audit logs are disabled by default.

compute.diskTypes.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of disk types available to the specified project.

Data Access audit logs are disabled by default.

compute.disks.addResourcePolicies: addResourcePolicies

#
ServiceName
compute.googleapis.com

Description

Adds existing resource policies to a disk. You can only add one policy which will be applied to this disk for scheduling snapshot creation.

compute.disks.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of persistent disks. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "o52fdzd3in6",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "f70b750d-2e14-48aa-a20e-517e1cf030fc"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.disks.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.disks.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.disks.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.list invocation-id/33943f07842c4255a3521c9168fd6c6d environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:16.989490Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/disks",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:17.521503370Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.disks.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:16.918158Z"
}

compute.disks.bulkInsert: bulkInsert

#
ServiceName
compute.googleapis.com

Description

Bulk create a set of disks.

compute.disks.bulkSetLabels: bulkSetLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on many disks at once. To learn more about labels, read theLabeling Resources documentation.

compute.disks.createSnapshot: createSnapshot

#
ServiceName
compute.googleapis.com

Description

Creates a snapshot of a specified persistent disk. For regular snapshot creation, consider using snapshots.insert instead, as that method supports more features, such as creating snapshots in a project different from the source disk project.

Example Audit Log Entry #

{
  "insertId": "-o4qyyve3d0mq",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "6cfcd3a7-76c2-46dd-88d4-f16d893ab4d4"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743858003-655656661c00b-5043920b-eb14d557",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.disks.createSnapshot",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
          "service": "compute",
          "type": "compute.disks"
        }
      },
      {
        "granted": true,
        "permission": "compute.snapshots.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/snapshots/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/snapshots/dwg2-dw743447",
          "service": "compute",
          "type": "compute.snapshots"
        }
      },
      {
        "granted": true,
        "permission": "compute.snapshots.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/snapshots/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/snapshots/dwg2-dw743447",
          "service": "compute",
          "type": "compute.snapshots"
        }
      }
    ],
    "methodName": "v1.compute.disks.createSnapshot",
    "request": {
      "@type": "type.googleapis.com/compute.disks.createSnapshot",
      "guestFlush": false,
      "name": "dwg2-dw743447"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.snapshot invocation-id/b2c31cc6aed14ec89b974a9093f05120 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:37:38.900130Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "US"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "1097498485150662109",
      "insertTime": "2026-06-29T07:37:38.157-07:00",
      "name": "operation-1782743858003-655656661c00b-5043920b-eb14d557",
      "operationType": "createSnapshot",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743858003-655656661c00b-5043920b-eb14d557",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/1097498485150662109",
      "startTime": "2026-06-29T07:37:38.162-07:00",
      "status": "RUNNING",
      "targetId": "5595570648524995674",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:37:38.921205567Z",
  "resource": {
    "labels": {
      "disk_id": "5595570648524995674",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_disk"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:37:37.967443Z"
}

compute.disks.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified persistent disk. Deleting a disk removes its data permanently and is irreversible. However, deleting a disk does not delete any snapshots previously made from the disk. You must separatelydelete snapshots.

Example Audit Log Entry #

{
  "insertId": "978wxae79vfe",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "430978a5-67eb-437b-85b3-3d27ad63639b"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782747023637-6556623117cba-97d75530-49db3aaa",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.disks.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
          "service": "compute",
          "type": "compute.disks"
        }
      }
    ],
    "methodName": "v1.compute.disks.delete",
    "request": {
      "@type": "type.googleapis.com/compute.disks.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.delete invocation-id/65a8b593091342178330684dfc110ef6 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:30:23.778475Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "4425269679013966176",
      "insertTime": "2026-06-29T08:30:23.739-07:00",
      "name": "operation-1782747023637-6556623117cba-97d75530-49db3aaa",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782747023637-6556623117cba-97d75530-49db3aaa",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/4425269679013966176",
      "startTime": "2026-06-29T08:30:23.748-07:00",
      "status": "RUNNING",
      "targetId": "6960107639937118366",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:30:24.082630172Z",
  "resource": {
    "labels": {
      "disk_id": "6960107639937118366",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_disk"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:30:23.609716Z"
}

compute.disks.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified persistent disk.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-315klte57gx2",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "4e7f0b77-1b17-4f9b-9c60-3ff56f1b8617"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.disks.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwd7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwd7201353",
          "service": "compute",
          "type": "compute.disks"
        }
      }
    ],
    "methodName": "v1.compute.disks.get",
    "request": {
      "@type": "type.googleapis.com/compute.disks.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.create invocation-id/5814964eb3484ae9ba022179278c2614 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:21:49.889553Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwd7201353",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:21:50.155057500Z",
  "resource": {
    "labels": {
      "disk_id": "553183922380285299",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_disk"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:21:49.823606Z"
}

compute.disks.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.disks.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a persistent disk in the specified project using the data in the request. You can create a disk from a source (sourceImage, sourceSnapshot, orsourceDisk) or create an empty 500 GB data disk by omitting all properties. You can also create a disk that is larger than the default size by specifying the sizeGb property.

Example Audit Log Entry #

{
  "insertId": "3dldice3zank",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "7a2e56b3-72e9-42e3-9b23-f0234bfcb42a"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.disks.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
          "service": "compute",
          "type": "compute.disks"
        }
      }
    ],
    "methodName": "v1.compute.disks.insert",
    "request": {
      "@type": "type.googleapis.com/compute.disks.insert",
      "name": "dwg2-dw743447",
      "sizeGb": "10"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.create invocation-id/afc1ad74d6584e5584d7b097afe66852 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:37:30.919808Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
    "serviceName": "compute.googleapis.com",
    "status": {
      "code": 6,
      "message": "The resource 'projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447' already exists"
    }
  },
  "receiveTimestamp": "2026-06-29T14:37:31.929624377Z",
  "resource": {
    "labels": {
      "disk_id": "5595570648524995674",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_disk"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T14:37:30.844659Z"
}

compute.disks.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of persistent disks contained within the specified zone.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-bngn6reb409g",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "1442007e-4bc9-4013-b6af-6a330ea54358"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "110162197178770594910"
      },
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
      "principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.disks.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.disks.list",
    "request": {
      "@type": "type.googleapis.com/compute.disks.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GCE CSI Driver/v1.23.1-gke.14 (linux amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:39:36.147419Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-b"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-b/disks",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:39:36.364360921Z",
  "resource": {
    "labels": {
      "disk_id": "",
      "project_id": "example-project-id",
      "zone": "us-central1-b"
    },
    "type": "gce_disk"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:39:36.087532Z"
}

compute.disks.removeResourcePolicies: removeResourcePolicies

#
ServiceName
compute.googleapis.com

Description

Removes resource policies from a disk.

compute.disks.resize: resize

#
ServiceName
compute.googleapis.com

Description

Resizes the specified persistent disk. You can only increase the size of the disk.

Example Audit Log Entry #

{
  "insertId": "aacx1ie1oz5u",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "64ff41fe-4667-4b4a-a757-c57bf1674388"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746739546-655661222991d-114b4c2d-1988f1ac",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.disks.resize",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
          "service": "compute",
          "type": "compute.disks"
        }
      }
    ],
    "methodName": "v1.compute.disks.resize",
    "request": {
      "@type": "type.googleapis.com/compute.disks.resize",
      "sizeGb": "20"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.resize invocation-id/9d7667bf067649d7a7f918b834daf1ad environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:25:39.707759Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "8752018324255092892",
      "insertTime": "2026-06-29T08:25:39.655-07:00",
      "name": "operation-1782746739546-655661222991d-114b4c2d-1988f1ac",
      "operationType": "resize",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746739546-655661222991d-114b4c2d-1988f1ac",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/8752018324255092892",
      "startTime": "2026-06-29T08:25:39.672-07:00",
      "status": "RUNNING",
      "targetId": "6960107639937118366",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:25:39.911159526Z",
  "resource": {
    "labels": {
      "disk_id": "6960107639937118366",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_disk"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:25:39.508593Z"
}

compute.disks.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

Example Audit Log Entry #

{
  "insertId": "-x8wxeqe5r63q",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "0be16acf-81e9-4971-a0c2-33cf2a05ef3a"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.disks.setIamPolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
          "service": "compute",
          "type": "compute.disks"
        }
      }
    ],
    "methodName": "v1.compute.disks.setIamPolicy",
    "request": {
      "@type": "type.googleapis.com/compute.disks.setIamPolicy",
      "policy": {
        "bindings": [
          {
            "members": [
              "user:user@example.com"
            ],
            "role": "roles/compute.networkUser"
          }
        ],
        "version": "3"
      }
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.set-iam-policy invocation-id/2aa31bd7faa54566990708f54615cf35 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:25:42.241052Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
    "response": {
      "@type": "type.googleapis.com/error",
      "error": {
        "code": 400,
        "errors": [
          {
            "domain": "global",
            "message": "Role roles/compute.networkUser is not supported for this resource.",
            "reason": "invalidIamPolicy"
          }
        ],
        "message": "Role roles/compute.networkUser is not supported for this resource."
      }
    },
    "serviceName": "compute.googleapis.com",
    "status": {
      "code": 3,
      "message": "Role roles/compute.networkUser is not supported for this resource."
    }
  },
  "receiveTimestamp": "2026-06-29T15:25:43.018418271Z",
  "resource": {
    "labels": {
      "disk_id": "6960107639937118366",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_disk"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T15:25:42.174914Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
protoPayload.response.error (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

compute.disks.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a disk. To learn more about labels, read theLabeling Resources documentation.

Example Audit Log Entry #

{
  "insertId": "xbaoc8e6bk7u",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "2c010051-83ef-42ec-93a2-c22466e0e791"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746743778-6556612632c8d-6b7809c2-b0b409a6",
    "last": true,
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.disks.setLabels",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
          "service": "compute",
          "type": "compute.disks"
        }
      }
    ],
    "methodName": "v1.compute.disks.setLabels",
    "request": {
      "@type": "type.googleapis.com/compute.disks.setLabels",
      "labelFingerprint": "�e�J�|�#",
      "labels": [
        {
          "key": "env",
          "value": "dw"
        }
      ]
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.add-labels invocation-id/7aab7c7b1ada40a2a2607bd7755dc902 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:25:43.878129Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "endTime": "2026-06-29T08:25:43.845-07:00",
      "id": "2121917952695414936",
      "insertTime": "2026-06-29T08:25:43.836-07:00",
      "name": "operation-1782746743778-6556612632c8d-6b7809c2-b0b409a6",
      "operationType": "setLabels",
      "progress": "100",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746743778-6556612632c8d-6b7809c2-b0b409a6",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/2121917952695414936",
      "startTime": "2026-06-29T08:25:43.843-07:00",
      "status": "DONE",
      "targetId": "6960107639937118366",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:25:44.766679415Z",
  "resource": {
    "labels": {
      "disk_id": "6960107639937118366",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_disk"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:25:43.748731Z"
}

compute.disks.startAsyncReplication: startAsyncReplication

#
ServiceName
compute.googleapis.com

Description

Starts asynchronous replication. Must be invoked on the primary disk.

compute.disks.stopAsyncReplication: stopAsyncReplication

#
ServiceName
compute.googleapis.com

Description

Stops asynchronous replication. Can be invoked either on the primary or on the secondary disk.

compute.disks.stopGroupAsyncReplication: stopGroupAsyncReplication

#
ServiceName
compute.googleapis.com

Description

Stops asynchronous replication for a consistency group of disks. Can be invoked either in the primary or secondary scope.

compute.disks.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.disks.update: update

#
ServiceName
compute.googleapis.com

Description

Updates the specified disk with the data included in the request. The update is performed only on selected fields included as part of update-mask.

compute.disks.updateKmsKey: updateKmsKey

#
ServiceName
compute.googleapis.com

Description

Rotates the customer-managed encryption key to the latest version for the specified persistent disk.

compute.externalVpnGateways.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified externalVpnGateway.

Example Audit Log Entry #

{
  "insertId": "d36kkbdvefi",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9c179ed8-7fb8-455f-9e64-62ce1f1d8ea5"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750832555-655670618f7c5-39544f00-581d1630",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.externalVpnGateways.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
          "service": "compute",
          "type": "compute.externalVpnGateways"
        }
      }
    ],
    "methodName": "v1.compute.externalVpnGateways.delete",
    "request": {
      "@type": "type.googleapis.com/compute.externalVpnGateways.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.external-vpn-gateways.delete invocation-id/53a6affa988d47b089acf386ddb40195 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:33:52.773531Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "3634290948251263135",
      "insertTime": "2026-06-29T09:33:52.647-07:00",
      "name": "operation-1782750832555-655670618f7c5-39544f00-581d1630",
      "operationType": "compute.externalVpnGateways.delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782750832555-655670618f7c5-39544f00-581d1630",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/3634290948251263135",
      "startTime": "2026-06-29T09:33:52.659-07:00",
      "status": "RUNNING",
      "targetId": "4449701621952094941",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/externalVpnGateways/dwegw7201353",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:33:52.860279240Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.externalVpnGateways.delete",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:33:52.493736Z"
}

compute.externalVpnGateways.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified externalVpnGateway. Get a list of available externalVpnGateways by making a list() request.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "gxkp3dee7eqs",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "b9c2013e-fefb-4c6e-a25c-be4fa65ca949"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.externalVpnGateways.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
          "service": "compute",
          "type": "compute.externalVpnGateways"
        }
      }
    ],
    "methodName": "v1.compute.externalVpnGateways.get",
    "request": {
      "@type": "type.googleapis.com/compute.externalVpnGateways.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.external-vpn-gateways.create invocation-id/74c392d77ec7477a81dd10cf8ac4dfb9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:24:20.327802Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:24:20.916907948Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.externalVpnGateways.get",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:24:20.218759Z"
}

compute.externalVpnGateways.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a ExternalVpnGateway in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-xuk6f8e5bhvc",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "d41f2c1c-a6b9-4eec-9c92-b28d9f6669ea"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750258265-65566e3ddfbe8-024b9f1a-3b1bab39",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.externalVpnGateways.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
          "service": "compute",
          "type": "compute.externalVpnGateways"
        }
      }
    ],
    "methodName": "v1.compute.externalVpnGateways.insert",
    "request": {
      "@type": "type.googleapis.com/compute.externalVpnGateways.insert",
      "interfaces": [
        {
          "id": "0",
          "ipAddress": "203.0.113.5"
        }
      ],
      "name": "dwegw7201353",
      "redundancyType": "SINGLE_IP_INTERNALLY_REDUNDANT"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.external-vpn-gateways.create invocation-id/74c392d77ec7477a81dd10cf8ac4dfb9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:24:18.659973Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "1121347094220579549",
      "insertTime": "2026-06-29T09:24:18.388-07:00",
      "name": "operation-1782750258265-65566e3ddfbe8-024b9f1a-3b1bab39",
      "operationType": "compute.externalVpnGateways.insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782750258265-65566e3ddfbe8-024b9f1a-3b1bab39",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/1121347094220579549",
      "startTime": "2026-06-29T09:24:18.393-07:00",
      "status": "RUNNING",
      "targetId": "4449701621952094941",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/externalVpnGateways/dwegw7201353",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:24:18.785123581Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.externalVpnGateways.insert",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:24:18.241953Z"
}

compute.externalVpnGateways.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of ExternalVpnGateway available to the specified project.

Data Access audit logs are disabled by default.

compute.externalVpnGateways.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on an ExternalVpnGateway. To learn more about labels, read the Labeling Resources documentation.

compute.externalVpnGateways.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.firewallPolicies.addAssociation: addAssociation

#
ServiceName
compute.googleapis.com

Description

Inserts an association for the specified firewall policy.

compute.firewallPolicies.addRule: addRule

#
ServiceName
compute.googleapis.com

Description

Inserts a rule into a firewall policy.

compute.firewallPolicies.cloneRules: cloneRules

#
ServiceName
compute.googleapis.com

Description

Copies rules to the specified firewall policy.

compute.firewallPolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified policy.

compute.firewallPolicies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified firewall policy.

Data Access audit logs are disabled by default.

compute.firewallPolicies.getAssociation: getAssociation

#
ServiceName
compute.googleapis.com

Description

Gets an association with the specified name.

Data Access audit logs are disabled by default.

compute.firewallPolicies.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.firewallPolicies.getRule: getRule

#
ServiceName
compute.googleapis.com

Description

Gets a rule of the specified priority.

Data Access audit logs are disabled by default.

compute.firewallPolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new policy in the specified project using the data included in the request.

compute.firewallPolicies.list: list

#
ServiceName
compute.googleapis.com

Description

Lists all the policies that have been configured for the specified folder or organization.

Data Access audit logs are disabled by default.

compute.firewallPolicies.listAssociations: listAssociations

#
ServiceName
compute.googleapis.com

Description

Lists associations of a specified target, i.e., organization or folder.

Data Access audit logs are disabled by default.

compute.firewallPolicies.move: move

#
ServiceName
compute.googleapis.com

Description

Moves the specified firewall policy.

compute.firewallPolicies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified policy with the data included in the request.

compute.firewallPolicies.patchRule: patchRule

#
ServiceName
compute.googleapis.com

Description

Patches a rule of the specified priority.

compute.firewallPolicies.removeAssociation: removeAssociation

#
ServiceName
compute.googleapis.com

Description

Removes an association for the specified firewall policy.

compute.firewallPolicies.removeRule: removeRule

#
ServiceName
compute.googleapis.com

Description

Deletes a rule of the specified priority.

compute.firewallPolicies.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.firewallPolicies.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.firewalls.delete: Delete firewall rule

#
ServiceName
compute.googleapis.com

Description

Deletes the specified firewall.

Example Audit Log Entry #

{
  "insertId": "p1bbz6dddqk",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "3bb2eb19-ede2-4eae-baec-c0cb62ee443f"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782744010897-655656f7eb789-1b8b5be4-2b778aac",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.firewalls.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/firewalls/gke-dwgke-dw743447-265a84d2-exkubelet",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/firewalls/gke-dwgke-dw743447-265a84d2-exkubelet",
          "service": "compute",
          "type": "compute.firewalls"
        }
      },
      {
        "granted": true,
        "permission": "compute.networks.updatePolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/default",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/default",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.firewalls.delete",
    "request": {
      "@type": "type.googleapis.com/compute.firewalls.delete"
    },
    "requestMetadata": {
      "callerIp": "private",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:40:11.429940Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/firewalls/gke-dwgke-dw743447-265a84d2-exkubelet",
    "resourceOriginalState": {
      "@type": "compute.googleapis.com/delete.state",
      "creationTimestamp": "2026-06-29T07:32:38.631-07:00",
      "denieds": [
        {
          "IPProtocol": "tcp",
          "ports": [
            "10255"
          ]
        }
      ],
      "description": "",
      "direction": "INGRESS",
      "disabled": false,
      "enableLogging": false,
      "id": "8682464889424264425",
      "logConfig": {
        "enable": false
      },
      "name": "gke-dwgke-dw743447-265a84d2-exkubelet",
      "network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/default",
      "priority": "1000",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/gke-dwgke-dw743447-265a84d2-exkubelet",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/8682464889424264425",
      "sourceRanges": [
        "0.0.0.0/0"
      ],
      "targetTags": [
        "gke-dwgke-dw743447-265a84d2-node"
      ]
    },
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "2020390200037817636",
      "insertTime": "2026-06-29T07:40:11.205-07:00",
      "name": "operation-1782744010897-655656f7eb789-1b8b5be4-2b778aac",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782744010897-655656f7eb789-1b8b5be4-2b778aac",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2020390200037817636",
      "startTime": "2026-06-29T07:40:11.244-07:00",
      "status": "RUNNING",
      "targetId": "8682464889424264425",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/gke-dwgke-dw743447-265a84d2-exkubelet",
      "user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:40:12.336833330Z",
  "resource": {
    "labels": {
      "firewall_rule_id": "8682464889424264425",
      "project_id": "example-project-id"
    },
    "type": "gce_firewall_rule"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:40:10.983424Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • GCP Firewall Rule Deletion source medium: Identifies when a firewall rule is deleted in Google Cloud Platform (GCP) for Virtual Private Cloud (VPC) or App Engine. These firewall rules can be configured to allow or deny connections to or from virtual machine (VM) instances or specific applications. An adversary may delete a firewall rule in order to weaken their target's security controls.T1562, T1562.007

Panther #

compute.firewalls.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified firewall.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-8k385se5oc70",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "b9dd475b-3460-4330-9197-900b4861ffae"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.firewalls.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/firewalls/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/firewalls/dwgen-dw739065",
          "service": "compute",
          "type": "compute.firewalls"
        }
      }
    ],
    "methodName": "v1.compute.firewalls.get",
    "request": {
      "@type": "type.googleapis.com/compute.firewalls.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.firewall-rules.create invocation-id/b9c37dbd896c42b985609ea1a5ff0e1b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:48.675128Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/firewalls/dwgen-dw739065",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:49.568658753Z",
  "resource": {
    "labels": {
      "firewall_rule_id": "6445511313097478084",
      "project_id": "example-project-id"
    },
    "type": "gce_firewall_rule"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:20:48.576484Z"
}

compute.firewalls.insert: Insert firewall rule

#
ServiceName
compute.googleapis.com

Description

Creates a firewall rule in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-4xmq76d4xjy",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "86947610-9c75-40af-9fc2-8c813fe0efac"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782739243566-655645357054d-883f888e-284c2eb9",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.firewalls.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/firewalls/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/firewalls/dwgen-dw739065",
          "service": "compute",
          "type": "compute.firewalls"
        }
      },
      {
        "granted": true,
        "permission": "compute.networks.updatePolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/dwgen-dw739065",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.firewalls.insert",
    "request": {
      "@type": "type.googleapis.com/compute.firewalls.insert",
      "alloweds": [
        {
          "IPProtocol": "tcp",
          "ports": [
            "22"
          ]
        }
      ],
      "direction": "INGRESS",
      "name": "dwgen-dw739065",
      "network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwgen-dw739065",
      "sourceRanges": [
        "10.8.0.0/24"
      ]
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.firewall-rules.create invocation-id/b9c37dbd896c42b985609ea1a5ff0e1b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:44.100557Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/firewalls/dwgen-dw739065",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "8277527470017597380",
      "insertTime": "2026-06-29T06:20:43.899-07:00",
      "name": "operation-1782739243566-655645357054d-883f888e-284c2eb9",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782739243566-655645357054d-883f888e-284c2eb9",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/8277527470017597380",
      "startTime": "2026-06-29T06:20:43.936-07:00",
      "status": "RUNNING",
      "targetId": "6445511313097478084",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/dwgen-dw739065",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:44.665409680Z",
  "resource": {
    "labels": {
      "firewall_rule_id": "6445511313097478084",
      "project_id": "example-project-id"
    },
    "type": "gce_firewall_rule"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T13:20:43.646289Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • GCP Firewall Rule Creation source low: Identifies when a firewall rule is created in Google Cloud Platform (GCP) for Virtual Private Cloud (VPC) or App Engine. These firewall rules can be configured to allow or deny connections to or from virtual machine (VM) instances or specific applications. An adversary may create a new firewall rule in order to weaken their target's security controls and allow more permissive ingress or egress traffic flows for their benefit.T1562, T1562.007

YARA-L #

Panther #

compute.firewalls.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of firewall rules available to the specified project.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-ksf4xoe4cf6g",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "7a71e88b-ef10-44f5-8b2b-4f34ff99a525"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.firewalls.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.firewalls.list",
    "numResponseItems": "4",
    "request": {
      "@type": "type.googleapis.com/compute.firewalls.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.firewall-rules.list invocation-id/c1cb0a3178ae4efcae5c1e333f60955b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:57.986196Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/firewalls",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:58.439463135Z",
  "resource": {
    "labels": {
      "firewall_rule_id": "",
      "project_id": "example-project-id"
    },
    "type": "gce_firewall_rule"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:57.921053Z"
}

compute.firewalls.patch: Patch firewall rule

#
ServiceName
compute.googleapis.com

Description

Patches the specified firewall rule with the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-hgwc5ud8wg8",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "6c752747-7957-4722-a964-94488f2ef76c"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743724697-655655e6fa6f8-8263b121-cf8db9a8",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.firewalls.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/firewalls/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/firewalls/dwg2-dw743447",
          "service": "compute",
          "type": "compute.firewalls"
        }
      },
      {
        "granted": true,
        "permission": "compute.firewalls.update",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/firewalls/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/firewalls/dwg2-dw743447",
          "service": "compute",
          "type": "compute.firewalls"
        }
      },
      {
        "granted": true,
        "permission": "compute.networks.updatePolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/dwg2-dw743447",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.firewalls.patch",
    "request": {
      "@type": "type.googleapis.com/compute.firewalls.patch",
      "alloweds": [
        {
          "IPProtocol": "tcp",
          "ports": [
            "22"
          ]
        },
        {
          "IPProtocol": "tcp",
          "ports": [
            "80"
          ]
        }
      ],
      "description": "",
      "direction": "INGRESS",
      "logConfig": {
        "enable": false
      },
      "name": "dwg2-dw743447",
      "network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwg2-dw743447",
      "priority": "1000",
      "sourceRanges": [
        "10.9.0.0/24"
      ]
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.firewall-rules.update invocation-id/c6323f0a21bc4e17b01224f54083ed54 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:35:25.517822Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/firewalls/dwg2-dw743447",
    "resourceOriginalState": {
      "@type": "compute.googleapis.com/patch.state",
      "alloweds": [
        {
          "IPProtocol": "tcp",
          "ports": [
            "22"
          ]
        }
      ],
      "creationTimestamp": "2026-06-29T07:35:18.445-07:00",
      "description": "",
      "direction": "INGRESS",
      "disabled": false,
      "enableLogging": false,
      "id": "854235574774479945",
      "logConfig": {
        "enable": false
      },
      "name": "dwg2-dw743447",
      "network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwg2-dw743447",
      "priority": "1000",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/dwg2-dw743447",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/854235574774479945",
      "sourceRanges": [
        "10.9.0.0/24"
      ]
    },
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "5435957740976421954",
      "insertTime": "2026-06-29T07:35:25.319-07:00",
      "name": "operation-1782743724697-655655e6fa6f8-8263b121-cf8db9a8",
      "operationType": "patch",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782743724697-655655e6fa6f8-8263b121-cf8db9a8",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/5435957740976421954",
      "startTime": "2026-06-29T07:35:25.322-07:00",
      "status": "RUNNING",
      "targetId": "854235574774479945",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/dwg2-dw743447",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:35:25.722373560Z",
  "resource": {
    "labels": {
      "firewall_rule_id": "854235574774479945",
      "project_id": "example-project-id"
    },
    "type": "gce_firewall_rule"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:35:24.782058Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • GCP Firewall Rule Modification source medium: Identifies when a firewall rule is modified in Google Cloud Platform (GCP) for Virtual Private Cloud (VPC) or App Engine. These firewall rules can be modified to allow or deny connections to or from virtual machine (VM) instances or specific applications. An adversary may modify an existing firewall rule in order to weaken their target's security controls and allow more permissive ingress or egress traffic flows for their benefit.T1562, T1562.007

Panther #

compute.firewalls.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.firewalls.update: Update firewall rule

#
ServiceName
compute.googleapis.com

Description

Updates the specified firewall rule with the data included in the request.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

compute.forwardingRules.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of forwarding rules. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "a9yp7pe18gqc",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "c96b243a-60e0-47b9-871e-30049ac69bbe"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.forwardingRules.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.forwardingRules.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.forwardingRules.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.forwarding-rules.list invocation-id/813f468e67674e3e8ea4ef0693c358ba environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:28.081489Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/forwardingRules",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:28.169535752Z",
  "resource": {
    "labels": {
      "forwarding_rule_id": "",
      "project_id": "example-project-id",
      "region": "global"
    },
    "type": "gce_forwarding_rule"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:27.976490Z"
}

compute.forwardingRules.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified ForwardingRule resource.

Example Audit Log Entry #

{
  "insertId": "-wpoyi8dpcg4",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "8790bfb0-75ff-4f05-89b7-1375fc7748c3"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782744101494-6556574e52036-0867aad4-85a6a0c5",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.forwardingRules.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
          "service": "compute",
          "type": "compute.forwardingRules"
        }
      },
      {
        "granted": true,
        "permission": "compute.forwardingRules.pscDelete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
          "service": "compute",
          "type": "compute.forwardingRules"
        }
      }
    ],
    "methodName": "v1.compute.forwardingRules.delete",
    "request": {
      "@type": "type.googleapis.com/compute.forwardingRules.delete"
    },
    "requestMetadata": {
      "callerIp": "private",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:41:41.818793Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "8233641262258797258",
      "insertTime": "2026-06-29T07:41:41.738-07:00",
      "name": "operation-1782744101494-6556574e52036-0867aad4-85a6a0c5",
      "operationType": "deleteRegionPscForwardingRule",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782744101494-6556574e52036-0867aad4-85a6a0c5",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/8233641262258797258",
      "startTime": "2026-06-29T07:41:41.759-07:00",
      "status": "RUNNING",
      "targetId": "2318136879392701578",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
      "user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:41:41.960562757Z",
  "resource": {
    "labels": {
      "forwarding_rule_id": "2318136879392701578",
      "project_id": "example-project-id",
      "region": "us-central1"
    },
    "type": "gce_forwarding_rule"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:41:41.561642Z"
}

compute.forwardingRules.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified ForwardingRule resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-l2krt0e2keqi",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "42fe0927-16d1-462d-b8cf-0cd7073633e2"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.forwardingRules.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
          "service": "compute",
          "type": "compute.forwardingRules"
        }
      }
    ],
    "methodName": "v1.compute.forwardingRules.get",
    "request": {
      "@type": "type.googleapis.com/compute.forwardingRules.get"
    },
    "requestMetadata": {
      "callerIp": "private",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:41:41.487818Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:41:42.068440975Z",
  "resource": {
    "labels": {
      "forwarding_rule_id": "2318136879392701578",
      "project_id": "example-project-id",
      "region": "us-central1"
    },
    "type": "gce_forwarding_rule"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:41:41.420268Z"
}

compute.forwardingRules.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a ForwardingRule resource in the specified project and region using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "821c3se5nvu6",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "beede198-5d50-4249-a668-a64688d02026"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743653528-655655a31b48d-832c548a-8736b7c2",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.forwardingRules.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
          "service": "compute",
          "type": "compute.forwardingRules"
        }
      },
      {
        "granted": true,
        "permission": "compute.forwardingRules.pscCreate",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
          "service": "compute",
          "type": "compute.forwardingRules"
        }
      },
      {
        "granted": true,
        "permission": "compute.networks.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/default",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/default",
          "service": "compute",
          "type": "compute.networks"
        }
      },
      {
        "granted": true,
        "permission": "compute.addresses.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
          "service": "compute",
          "type": "compute.addresses"
        }
      }
    ],
    "methodName": "v1.compute.forwardingRules.insert",
    "request": {
      "@type": "type.googleapis.com/compute.forwardingRules.insert",
      "IPAddress": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
      "name": "gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
      "network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/default",
      "target": "projects/c085ef9d0ad1ab7fep-tp/regions/us-central1/serviceAttachments/gke-265a84d2523e48fa99a3-4293-c798-sa"
    },
    "requestMetadata": {
      "callerIp": "private",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:34:14.060757Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "347555886273608842",
      "insertTime": "2026-06-29T07:34:13.969-07:00",
      "name": "operation-1782743653528-655655a31b48d-832c548a-8736b7c2",
      "operationType": "createRegionPscForwardingRule",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782743653528-655655a31b48d-832c548a-8736b7c2",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/347555886273608842",
      "startTime": "2026-06-29T07:34:13.981-07:00",
      "status": "RUNNING",
      "targetId": "2318136879392701578",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
      "user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:34:14.121798391Z",
  "resource": {
    "labels": {
      "forwarding_rule_id": "2318136879392701578",
      "project_id": "example-project-id",
      "region": "us-central1"
    },
    "type": "gce_forwarding_rule"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:34:13.571434Z"
}

compute.forwardingRules.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of ForwardingRule resources available to the specified project and region.

Data Access audit logs are disabled by default.

compute.forwardingRules.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified forwarding rule with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. Currently, you can only patch the network_tier field.

compute.forwardingRules.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on the specified resource. To learn more about labels, read the Labeling Resources documentation.

compute.forwardingRules.setTarget: setTarget

#
ServiceName
compute.googleapis.com

Description

Changes target URL for forwarding rule. The new target should be of the same type as the old target.

compute.futureReservations.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of future reservations. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.futureReservations.cancel: cancel

#
ServiceName
compute.googleapis.com

Description

Cancel the specified future reservation.

compute.futureReservations.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified future reservation.

compute.futureReservations.get: get

#
ServiceName
compute.googleapis.com

Description

Retrieves information about the specified future reservation.

Data Access audit logs are disabled by default.

compute.futureReservations.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new Future Reservation.

compute.futureReservations.list: list

#
ServiceName
compute.googleapis.com

Description

A list of all the future reservations that have been configured for the specified project in specified zone.

Data Access audit logs are disabled by default.

compute.futureReservations.update: update

#
ServiceName
compute.googleapis.com

Description

Updates the specified future reservation.

compute.globalAddresses.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified address resource.

Example Audit Log Entry #

{
  "insertId": "96k0rtd68jo",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "03a75f4c-bad8-49ba-8fb2-5d2cad651775"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782747111155-655662848e8da-f3a4b041-6e552434",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.globalAddresses.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/addresses/dwga-dw746783",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/addresses/dwga-dw746783",
          "service": "compute",
          "type": "compute.globalAddresses"
        }
      }
    ],
    "methodName": "v1.compute.globalAddresses.delete",
    "request": {
      "@type": "type.googleapis.com/compute.globalAddresses.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.delete invocation-id/fb9ce2157370463eb3ec7c88bb17adca environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:31:51.639256Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/addresses/dwga-dw746783",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "2827387436532707592",
      "insertTime": "2026-06-29T08:31:51.481-07:00",
      "name": "operation-1782747111155-655662848e8da-f3a4b041-6e552434",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782747111155-655662848e8da-f3a4b041-6e552434",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2827387436532707592",
      "startTime": "2026-06-29T08:31:51.484-07:00",
      "status": "RUNNING",
      "targetId": "8192489518443475373",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/addresses/dwga-dw746783",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:31:52.531334684Z",
  "resource": {
    "labels": {
      "location": "global",
      "project_id": "example-project-id",
      "reserved_address_id": "8192489518443475373"
    },
    "type": "gce_reserved_address"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:31:51.235080Z"
}

compute.globalAddresses.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified address resource.

Data Access audit logs are disabled by default.

compute.globalAddresses.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an address resource in the specified project by using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-hg6sg6d1z3e",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "b64abb06-286f-42e9-b5ae-d29de7f3ab8c"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746945875-655661e6eef15-3faa63fd-4ea2c377",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.globalAddresses.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/addresses/dwga-dw746783",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/addresses/dwga-dw746783",
          "service": "compute",
          "type": "compute.globalAddresses"
        }
      }
    ],
    "methodName": "v1.compute.globalAddresses.insert",
    "request": {
      "@type": "type.googleapis.com/compute.globalAddresses.insert",
      "ipVersion": "IPV4",
      "name": "dwga-dw746783"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.create invocation-id/c6c3ed5f52a54859aa14194fad3447d5 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:29:06.313137Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/addresses/dwga-dw746783",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "5453971430816297389",
      "insertTime": "2026-06-29T08:29:06.165-07:00",
      "name": "operation-1782746945875-655661e6eef15-3faa63fd-4ea2c377",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782746945875-655661e6eef15-3faa63fd-4ea2c377",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/5453971430816297389",
      "startTime": "2026-06-29T08:29:06.168-07:00",
      "status": "RUNNING",
      "targetId": "8192489518443475373",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/addresses/dwga-dw746783",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:29:06.622173103Z",
  "resource": {
    "labels": {
      "location": "global",
      "project_id": "example-project-id",
      "reserved_address_id": "8192489518443475373"
    },
    "type": "gce_reserved_address"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:29:05.940202Z"
}

compute.globalAddresses.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of global addresses.

Data Access audit logs are disabled by default.

compute.globalAddresses.move: move

#
ServiceName
compute.googleapis.com

Description

Moves the specified address resource from one project to another project.

compute.globalAddresses.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a GlobalAddress. To learn more about labels, read theLabeling Resources documentation.

compute.globalAddresses.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.globalForwardingRules.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified GlobalForwardingRule resource.

compute.globalForwardingRules.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified GlobalForwardingRule resource. Gets a list of available forwarding rules by making a list() request.

Data Access audit logs are disabled by default.

compute.globalForwardingRules.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a GlobalForwardingRule resource in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "jhh08md5qq8",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "92cd3eec-692f-4ace-9350-5dd6a4e712fd"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745432588-65565c43c0008-c0038248-b2d064de",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.targetHttpProxies.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
          "service": "compute",
          "type": "compute.targetHttpProxies"
        }
      },
      {
        "granted": true,
        "permission": "compute.globalForwardingRules.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/forwardingRules/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/forwardingRules/dwn3-dw745304",
          "service": "compute",
          "type": "compute.globalForwardingRules"
        }
      }
    ],
    "methodName": "v1.compute.globalForwardingRules.insert",
    "request": {
      "@type": "type.googleapis.com/compute.globalForwardingRules.insert",
      "loadBalancingScheme": "EXTERNAL",
      "name": "dwn3-dw745304",
      "portRange": "80",
      "target": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/targetHttpProxies/dwn3-dw745304"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.forwarding-rules.create invocation-id/07e1ea7331be49ff857dd4b77bf0a35a environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:03:53.254217Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/forwardingRules/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "822885693652940727",
      "insertTime": "2026-06-29T08:03:53.027-07:00",
      "name": "operation-1782745432588-65565c43c0008-c0038248-b2d064de",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745432588-65565c43c0008-c0038248-b2d064de",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/822885693652940727",
      "startTime": "2026-06-29T08:03:53.029-07:00",
      "status": "RUNNING",
      "targetId": "3603505146659551159",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/forwardingRules/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:03:54.052964535Z",
  "resource": {
    "labels": {
      "forwarding_rule_id": "3603505146659551159",
      "project_id": "example-project-id",
      "region": "global"
    },
    "type": "gce_forwarding_rule"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:03:52.652167Z"
}

compute.globalForwardingRules.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of GlobalForwardingRule resources available to the specified project.

Data Access audit logs are disabled by default.

compute.globalForwardingRules.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified forwarding rule with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. Currently, you can only patch the network_tier field.

compute.globalForwardingRules.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on the specified resource. To learn more about labels, read the Labeling resources documentation.

compute.globalForwardingRules.setTarget: setTarget

#
ServiceName
compute.googleapis.com

Description

Changes target URL for the GlobalForwardingRule resource. The new target should be of the same type as the old target.

compute.globalNetworkEndpointGroups.attachNetworkEndpoints: attachNetworkEndpoints

#
ServiceName
compute.googleapis.com

Description

Attach a network endpoint to the specified network endpoint group.

compute.globalNetworkEndpointGroups.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified network endpoint group.Note that the NEG cannot be deleted if there are backend services referencing it.

compute.globalNetworkEndpointGroups.detachNetworkEndpoints: detachNetworkEndpoints

#
ServiceName
compute.googleapis.com

Description

Detach the network endpoint from the specified network endpoint group.

compute.globalNetworkEndpointGroups.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified network endpoint group.

Data Access audit logs are disabled by default.

compute.globalNetworkEndpointGroups.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global API

compute.globalNetworkEndpointGroups.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of network endpoint groups that are located in the specified project.

Data Access audit logs are disabled by default.

compute.globalNetworkEndpointGroups.listNetworkEndpoints: listNetworkEndpoints

#
ServiceName
compute.googleapis.com

Description

Lists the network endpoints in the specified network endpoint group.

Data Access audit logs are disabled by default.

compute.globalOperations.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of all operations. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-pscaw9dlcvk",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a46e66ad-db46-4e57-923d-c06a758f225f"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.globalOperations.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.globalOperations.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.globalOperations.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.operations.list invocation-id/5af3ea2d9a0446e0ab60c469c3afe543 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:02.255613Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/operations",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:19:03.254248297Z",
  "resource": {
    "labels": {
      "location": "global",
      "operation_name": "",
      "project_id": "example-project-id"
    },
    "type": "gce_operation"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:19:01.999629Z"
}

compute.globalOperations.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified Operations resource.

compute.globalOperations.get: get

#
ServiceName
compute.googleapis.com

Description

Retrieves the specified Operations resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "w7dymie13thm",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "3cf5fc26-08cb-4539-b650-c614ce9a3a0a"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.globalOperations.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/operations/operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/operations/operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
          "service": "compute",
          "type": "compute.globalOperations"
        }
      }
    ],
    "methodName": "v1.compute.globalOperations.get",
    "request": {
      "@type": "type.googleapis.com/compute.globalOperations.get"
    },
    "requestMetadata": {
      "callerIp": "private",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:41:25.194129Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/operations/operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:41:25.679317511Z",
  "resource": {
    "labels": {
      "location": "global",
      "operation_name": "operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
      "project_id": "example-project-id"
    },
    "type": "gce_operation"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:41:25.125679Z"
}

compute.globalOperations.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of Operation resources contained within the specified project.

Data Access audit logs are disabled by default.

compute.globalOperations.wait: wait

#
ServiceName
compute.googleapis.com

Description

Waits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method differs from the `GET` method in that it waits for no more than the default deadline (2 minutes) and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "o78ts4d6l8m",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "d3b76fcd-4990-46dc-a6ed-3ad1e199cab8"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.globalOperations.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/operations/operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/operations/operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
          "service": "compute",
          "type": "compute.globalOperations"
        }
      }
    ],
    "methodName": "v1.compute.globalOperations.wait",
    "request": {
      "@type": "type.googleapis.com/compute.globalOperations.wait"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.create invocation-id/4ffe3c8ff74e4802bb2de389b3abfd97 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:22.192191Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/operations/operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:22.866504633Z",
  "resource": {
    "labels": {
      "location": "global",
      "operation_name": "operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
      "project_id": "example-project-id"
    },
    "type": "gce_operation"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:20:12.257154Z"
}

compute.globalOrganizationOperations.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified Operations resource.

compute.globalOrganizationOperations.get: get

#
ServiceName
compute.googleapis.com

Description

Retrieves the specified Operations resource. Gets a list of operations by making a `list()` request.

Data Access audit logs are disabled by default.

compute.globalOrganizationOperations.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of Operation resources contained within the specified organization.

Data Access audit logs are disabled by default.

compute.globalPublicDelegatedPrefixes.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified global PublicDelegatedPrefix.

compute.globalPublicDelegatedPrefixes.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified global PublicDelegatedPrefix resource.

Data Access audit logs are disabled by default.

compute.globalPublicDelegatedPrefixes.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a global PublicDelegatedPrefix in the specified project using the parameters that are included in the request.

compute.globalPublicDelegatedPrefixes.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the global PublicDelegatedPrefixes for a project.

Data Access audit logs are disabled by default.

compute.globalPublicDelegatedPrefixes.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified global PublicDelegatedPrefix resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.

compute.globalVmExtensionPolicies.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all VM Extension Policy resources available to the specified project. To prevent failure, it's recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.globalVmExtensionPolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Purge scoped resources (zonal policies) from a global VM extension policy, and then delete the global VM extension policy. Purge of the scoped resources is a pre-condition of the global VM extension policy deletion. The deletion of the global VM extension policy happens after the purge rollout is done, so it's not a part of the LRO. It's an automatic process that triggers in the backend.

compute.globalVmExtensionPolicies.get: get

#
ServiceName
compute.googleapis.com

Description

Gets details of a global VM extension policy.

Data Access audit logs are disabled by default.

compute.globalVmExtensionPolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new project level GlobalVmExtensionPolicy.

compute.globalVmExtensionPolicies.list: list

#
ServiceName
compute.googleapis.com

Description

Lists global VM extension policies.

Data Access audit logs are disabled by default.

compute.globalVmExtensionPolicies.update: update

#
ServiceName
compute.googleapis.com

Description

Updates a global VM extension policy.

compute.healthChecks.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all HealthCheck resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-il53hbd3wk6",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "f3ab90fd-cc16-4621-b6be-9f125cd32e15"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.healthChecks.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.healthChecks.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.healthChecks.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.health-checks.list invocation-id/650fe4e282de442897f5d3bfa317d1a6 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:33.313676Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/healthChecks",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:33.926492711Z",
  "resource": {
    "labels": {
      "health_check_id": "",
      "project_id": "example-project-id"
    },
    "type": "gce_health_check"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:33.226446Z"
}

compute.healthChecks.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified HealthCheck resource.

compute.healthChecks.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified HealthCheck resource.

Data Access audit logs are disabled by default.

compute.healthChecks.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a HealthCheck resource in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-n0vxgoddaio",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "32891bf4-dd38-43e0-a3da-991f4e9362c4"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745398248-65565c230032b-915006d0-31077acb",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.healthChecks.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/healthChecks/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/healthChecks/dwn3-dw745304",
          "service": "compute",
          "type": "compute.healthChecks"
        }
      }
    ],
    "methodName": "v1.compute.healthChecks.insert",
    "request": {
      "@type": "type.googleapis.com/compute.healthChecks.insert",
      "checkIntervalSec": "5",
      "healthyThreshold": "2",
      "httpHealthCheck": {
        "port": "80",
        "portSpecification": "USE_FIXED_PORT",
        "proxyHeader": "NONE",
        "requestPath": "/"
      },
      "name": "dwn3-dw745304",
      "timeoutSec": "5",
      "type": "HTTP",
      "unhealthyThreshold": "2"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.health-checks.create.http invocation-id/d889e6716d484701b62e8d354aa5fe41 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:03:19.026016Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/healthChecks/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "3358878850454861785",
      "insertTime": "2026-06-29T08:03:18.350-07:00",
      "name": "operation-1782745398248-65565c230032b-915006d0-31077acb",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745398248-65565c230032b-915006d0-31077acb",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/3358878850454861785",
      "startTime": "2026-06-29T08:03:18.357-07:00",
      "status": "RUNNING",
      "targetId": "681147439262939097",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/healthChecks/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:03:19.568052887Z",
  "resource": {
    "labels": {
      "health_check_id": "681147439262939097",
      "project_id": "example-project-id"
    },
    "type": "gce_health_check"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:03:18.218406Z"
}

compute.healthChecks.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of HealthCheck resources available to the specified project.

Data Access audit logs are disabled by default.

compute.healthChecks.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates a HealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.healthChecks.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.healthChecks.update: update

#
ServiceName
compute.googleapis.com

Description

Updates a HealthCheck resource in the specified project using the data included in the request.

compute.httpHealthChecks.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified HttpHealthCheck resource.

compute.httpHealthChecks.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified HttpHealthCheck resource.

Data Access audit logs are disabled by default.

compute.httpHealthChecks.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a HttpHealthCheck resource in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "auy5a7dtna6",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "c1bb1f98-df6c-4497-acf7-f28680eb62bf"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745402243-65565c26cf804-50cf965c-8cd92d35",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.httpHealthChecks.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/httpHealthChecks/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/httpHealthChecks/dwn3-dw745304",
          "service": "compute",
          "type": "compute.httpHealthChecks"
        }
      }
    ],
    "methodName": "v1.compute.httpHealthChecks.insert",
    "request": {
      "@type": "type.googleapis.com/compute.httpHealthChecks.insert",
      "checkIntervalSec": "5",
      "healthyThreshold": "2",
      "name": "dwn3-dw745304",
      "port": "80",
      "requestPath": "/",
      "timeoutSec": "5",
      "unhealthyThreshold": "2"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.http-health-checks.create invocation-id/09c964e472444e928fb91e6a4769da24 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:03:22.696997Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/httpHealthChecks/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "7193487255039588309",
      "insertTime": "2026-06-29T08:03:22.313-07:00",
      "name": "operation-1782745402243-65565c26cf804-50cf965c-8cd92d35",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745402243-65565c26cf804-50cf965c-8cd92d35",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/7193487255039588309",
      "startTime": "2026-06-29T08:03:22.324-07:00",
      "status": "RUNNING",
      "targetId": "2584761422561884117",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/httpHealthChecks/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:03:23.596022795Z",
  "resource": {
    "labels": {
      "health_check_id": "2584761422561884117",
      "project_id": "example-project-id"
    },
    "type": "gce_health_check"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:03:22.203815Z"
}

compute.httpHealthChecks.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of HttpHealthCheck resources available to the specified project.

Data Access audit logs are disabled by default.

compute.httpHealthChecks.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates a HttpHealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.httpHealthChecks.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.httpHealthChecks.update: update

#
ServiceName
compute.googleapis.com

Description

Updates a HttpHealthCheck resource in the specified project using the data included in the request.

compute.httpsHealthChecks.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified HttpsHealthCheck resource.

compute.httpsHealthChecks.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified HttpsHealthCheck resource.

Data Access audit logs are disabled by default.

compute.httpsHealthChecks.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a HttpsHealthCheck resource in the specified project using the data included in the request.

compute.httpsHealthChecks.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of HttpsHealthCheck resources available to the specified project.

Data Access audit logs are disabled by default.

compute.httpsHealthChecks.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates a HttpsHealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.httpsHealthChecks.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.httpsHealthChecks.update: update

#
ServiceName
compute.googleapis.com

Description

Updates a HttpsHealthCheck resource in the specified project using the data included in the request.

compute.imageFamilyViews.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the latest image that is part of an image family, is not deprecated and is rolled out in the specified zone.

Data Access audit logs are disabled by default.

compute.images.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified image.

Example Audit Log Entry #

{
  "insertId": "-1nmsk4dfg1a",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a9b7796b-da46-484e-b643-5c2d6152ce44"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750893821-6556709bfcdf2-8f369141-1b5de419",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.images.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/images/dwimg7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/images/dwimg7201353",
          "service": "compute",
          "type": "compute.images"
        }
      }
    ],
    "methodName": "v1.compute.images.delete",
    "request": {
      "@type": "type.googleapis.com/compute.images.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.delete invocation-id/8e6fca578ae744948398be0ec867ddbb environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:34:54.107342Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/images/dwimg7201353",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "7375611902957658178",
      "insertTime": "2026-06-29T09:34:53.971-07:00",
      "name": "operation-1782750893821-6556709bfcdf2-8f369141-1b5de419",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782750893821-6556709bfcdf2-8f369141-1b5de419",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/7375611902957658178",
      "startTime": "2026-06-29T09:34:53.979-07:00",
      "status": "RUNNING",
      "targetId": "2102812314665166192",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/images/dwimg7201353",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:34:54.333277595Z",
  "resource": {
    "labels": {
      "image_id": "2102812314665166192",
      "project_id": "example-project-id"
    },
    "type": "gce_image"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:34:53.779678Z"
}

compute.images.deprecate: deprecate

#
ServiceName
compute.googleapis.com

Description

Sets the deprecation status of an image. If an empty request body is given, clears the deprecation status instead.

compute.images.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified image.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "imv94de8g2vm",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9b8a44f5-73e3-4471-824e-7dc1d48b7bcc"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.images.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/images/dwimg7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/images/dwimg7201353",
          "service": "compute",
          "type": "compute.images"
        }
      }
    ],
    "methodName": "v1.compute.images.get",
    "request": {
      "@type": "type.googleapis.com/compute.images.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.create invocation-id/db552a7c776f4859b55b88660d0dfece environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:22:10.941139Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/images/dwimg7201353",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:22:11.193215424Z",
  "resource": {
    "labels": {
      "image_id": "2102812314665166192",
      "project_id": "example-project-id"
    },
    "type": "gce_image"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:22:10.100037Z"
}

compute.images.getFromFamily: getFromFamily

#
ServiceName
compute.googleapis.com

Description

Returns the latest image that is part of an image family and is not deprecated. For more information on image families, seePublic image families documentation.

Data Access audit logs are disabled by default.

compute.images.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-xigftje294r0",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "4ab44c8c-e1bc-4b53-97b8-5a23f02c0f69"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.images.getIamPolicy",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/images/dwimg7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/images/dwimg7201353",
          "service": "compute",
          "type": "compute.images"
        }
      }
    ],
    "methodName": "v1.compute.images.getIamPolicy",
    "request": {
      "@type": "type.googleapis.com/compute.images.getIamPolicy",
      "optionsRequestedPolicyVersion": "3"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.add-iam-policy-binding invocation-id/4e1305315d774dd7956df13292bf3847 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:22:12.540172Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/images/dwimg7201353",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:22:13.194244811Z",
  "resource": {
    "labels": {
      "image_id": "2102812314665166192",
      "project_id": "example-project-id"
    },
    "type": "gce_image"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:22:12.379689Z"
}

compute.images.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an image in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "vd2ljid4fl0",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "46d726b1-bffc-49a9-a0a6-b84dfc29faa0"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.images.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/images/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/images/dwg2-dw743447",
          "service": "compute",
          "type": "compute.images"
        }
      },
      {
        "granted": true,
        "permission": "compute.disks.useReadOnly",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
          "service": "compute",
          "type": "compute.disks"
        }
      }
    ],
    "methodName": "v1.compute.images.insert",
    "request": {
      "@type": "type.googleapis.com/compute.images.insert",
      "name": "dwg2-dw743447",
      "sourceDisk": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
      "sourceType": "RAW"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.create invocation-id/7369f3ed5f84474abd89b1c4ccd0b473 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:38:58.652253Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us"
      ]
    },
    "resourceName": "projects/example-project-id/global/images/dwg2-dw743447",
    "serviceName": "compute.googleapis.com",
    "status": {
      "code": 3,
      "message": "com.google.apps.framework.request.StatusException: <eye3 title='INVALID_ARGUMENT'/> generic::INVALID_ARGUMENT: The disk resource 'projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447' is already being used by 'projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447'"
    }
  },
  "receiveTimestamp": "2026-06-29T14:38:58.893529541Z",
  "resource": {
    "labels": {
      "image_id": "",
      "project_id": "example-project-id"
    },
    "type": "gce_image"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T14:38:58.359563Z"
}

compute.images.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of custom images available to the specified project. Custom images are images you create that belong to your project. This method does not get any images that belong to other projects, including publicly-available images, like Debian 8. If you want to get a list of publicly-available images, use this method to make a request to the respective image project, such as debian-cloud or windows-cloud.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "i1lqyze2hmce",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "550f4e25-9496-4d5f-9dd7-dbc26e0ce168"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.images.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.images.list",
    "request": {
      "@type": "type.googleapis.com/compute.images.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.list invocation-id/4edabe620cd94f8dbf8c0704ba22df76 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:18.598416Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/images",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:19.144001039Z",
  "resource": {
    "labels": {
      "image_id": "",
      "project_id": "example-project-id"
    },
    "type": "gce_image"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:18.527169Z"
}

compute.images.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified image with the data included in the request. Only the following fields can be modified: family, description, deprecation status.

compute.images.setIamPolicy: Set image IAM policy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

Example Audit Log Entry #

{
  "insertId": "-nualo9e7gz96",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a84c4564-f203-4820-8834-ef43f4bee33a"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.images.setIamPolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/images/dwimg7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/images/dwimg7201353",
          "service": "compute",
          "type": "compute.images"
        }
      }
    ],
    "methodName": "v1.compute.images.setIamPolicy",
    "request": {
      "@type": "type.googleapis.com/compute.images.setIamPolicy",
      "policy": {
        "bindings": [
          {
            "members": [
              "user:user@example.com"
            ],
            "role": "roles/compute.imageUser"
          }
        ],
        "etag": "\u0000 \u0001",
        "version": "3"
      }
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.add-iam-policy-binding invocation-id/4e1305315d774dd7956df13292bf3847 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:22:13.126852Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/images/dwimg7201353",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:22:13.729414065Z",
  "resource": {
    "labels": {
      "image_id": "2102812314665166192",
      "project_id": "example-project-id"
    },
    "type": "gce_image"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:22:12.879476Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
protoPayload.response.error (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

compute.images.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on an image. To learn more about labels, read theLabeling Resources documentation.

compute.images.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.instanceGroupManagerResizeRequests.cancel: cancel

#
ServiceName
compute.googleapis.com

Description

Cancels the specified resize request and removes it from the queue. Cancelled resize request does no longer wait for the resources to be provisioned. Cancel is only possible for requests that are accepted in the queue.

compute.instanceGroupManagerResizeRequests.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified, inactive resize request. Requests that are still active cannot be deleted. Deleting request does not delete instances that were provisioned previously.

compute.instanceGroupManagerResizeRequests.get: get

#
ServiceName
compute.googleapis.com

Description

Returns all of the details about the specified resize request.

Data Access audit logs are disabled by default.

compute.instanceGroupManagerResizeRequests.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new resize request that starts provisioning VMs immediately or queues VM creation.

compute.instanceGroupManagerResizeRequests.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of resize requests that are contained in the managed instance group.

Data Access audit logs are disabled by default.

compute.instanceGroupManagers.abandonInstances: abandonInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances to be removed from the managed instance group. Abandoning an instance does not delete the instance, but it does remove the instance from any target pools that are applied by the managed instance group. This method reduces thetargetSize of the managed instance group by the number of instances that you abandon. This operation is marked asDONE when the action is scheduled even if the instances have not yet been removed from the group. You must separately verify the status of the abandoning action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.

compute.instanceGroupManagers.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of managed instance groups and groups them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.instanceGroupManagers.applyUpdatesToInstances: applyUpdatesToInstances

#
ServiceName
compute.googleapis.com

Description

Applies changes to selected instances on the managed instance group. This method can be used to apply new overrides and/or new versions.

compute.instanceGroupManagers.createInstances: createInstances

#
ServiceName
compute.googleapis.com

Description

Creates instances with per-instance configurations in this managed instance group. Instances are created using the current instance template. Thecreate instances operation is marked DONE if thecreateInstances request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or actions with the listmanagedinstances method.

compute.instanceGroupManagers.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified managed instance group and all of the instances in that group. Note that the instance group must not belong to a backend service. Read Deleting an instance group for more information.

Example Audit Log Entry #

{
  "insertId": "1p6mmle2hwia",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "62a07eaf-a7d8-4e79-bffe-60b4c74da171"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceGroupManagers.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
          "service": "compute",
          "type": "compute.instanceGroupManagers"
        }
      },
      {
        "granted": true,
        "permission": "compute.instanceGroups.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
          "service": "compute",
          "type": "compute.instanceGroups"
        }
      }
    ],
    "methodName": "v1.compute.instanceGroupManagers.delete",
    "request": {
      "@type": "type.googleapis.com/compute.instanceGroupManagers.delete"
    },
    "requestMetadata": {
      "callerIp": "private",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:40:11.651369Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "4956059394064203044",
      "insertTime": "2026-06-29T07:40:11.614-07:00",
      "name": "operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
      "operationType": "compute.instanceGroupManagers.delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/4956059394064203044",
      "startTime": "2026-06-29T07:40:11.618-07:00",
      "status": "RUNNING",
      "targetId": "1685950597165956322",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
      "user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:40:11.784159677Z",
  "resource": {
    "labels": {
      "instance_group_manager_id": "1685950597165956322",
      "instance_group_manager_name": "gke-dwgke-dw743447-default-pool-d20f3f37-grp",
      "location": "us-central1-a",
      "project_id": "example-project-id"
    },
    "type": "gce_instance_group_manager"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:40:11.539378Z"
}

compute.instanceGroupManagers.deleteInstances: deleteInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances in the managed instance group for immediate deletion. The instances are also removed from any target pools of which they were a member. This method reduces thetargetSize of the managed instance group by the number of instances that you delete. This operation is marked as DONE when the action is scheduled even if the instances are still being deleted. You must separately verify the status of the deleting action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.

compute.instanceGroupManagers.deletePerInstanceConfigs: deletePerInstanceConfigs

#
ServiceName
compute.googleapis.com

Description

Deletes selected per-instance configurations for the managed instance group.

compute.instanceGroupManagers.get: get

#
ServiceName
compute.googleapis.com

Description

Returns all of the details about the specified managed instance group.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "tpalqwe77ipw",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "90e13af1-8556-441b-8b89-b624c3f7df00"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceGroupManagers.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
          "service": "compute",
          "type": "compute.instanceGroupManagers"
        }
      }
    ],
    "methodName": "v1.compute.instanceGroupManagers.get",
    "request": {
      "@type": "type.googleapis.com/compute.instanceGroupManagers.get"
    },
    "requestMetadata": {
      "callerIp": "private",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:45:16.554263Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
    "serviceName": "compute.googleapis.com",
    "status": {
      "code": 5,
      "message": "The resource 'projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp' was not found"
    }
  },
  "receiveTimestamp": "2026-06-29T14:45:16.693762735Z",
  "resource": {
    "labels": {
      "instance_group_manager_id": "0",
      "instance_group_manager_name": "gke-dwgke-dw743447-default-pool-d20f3f37-grp",
      "location": "us-central1-a",
      "project_id": "example-project-id"
    },
    "type": "gce_instance_group_manager"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T14:45:16.501910Z"
}

compute.instanceGroupManagers.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a managed instance group using the information that you specify in the request. After the group is created, instances in the group are created using the specified instance template. This operation is marked as DONE when the group is created even if the instances in the group have not yet been created. You must separately verify the status of the individual instances with thelistmanagedinstances method. A managed instance group can have up to 1000 VM instances per group. Please contact Cloud Support if you need an increase in this limit.

Example Audit Log Entry #

{
  "insertId": "-8tusg9e9vddc",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a53cde13-994a-425a-a98b-19e47439782b"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745481589-65565c727b46b-74638acf-0963a398",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceGroupManagers.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
          "service": "compute",
          "type": "compute.instanceGroupManagers"
        }
      },
      {
        "granted": true,
        "permission": "compute.instances.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwn3-dw745304-0000",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwn3-dw745304-0000",
          "service": "compute",
          "type": "compute.instances"
        }
      },
      {
        "granted": true,
        "permission": "compute.disks.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwn3-dw745304-0000",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwn3-dw745304-0000",
          "service": "compute",
          "type": "compute.disks"
        }
      },
      {
        "granted": true,
        "permission": "compute.subnetworks.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      },
      {
        "granted": true,
        "permission": "compute.instances.setMetadata",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwn3-dw745304-0000",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwn3-dw745304-0000",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instanceGroupManagers.insert",
    "request": {
      "@type": "type.googleapis.com/compute.instanceGroupManagers.insert",
      "instanceTemplate": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/instanceTemplates/dwn3-dw745304",
      "name": "dwn3-dw745304",
      "targetSize": "0"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-groups.managed.create invocation-id/7e67413d65f54759bfafd552a4d923d4 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:04:43.235256Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "6067619727955408740",
      "insertTime": "2026-06-29T08:04:43.182-07:00",
      "name": "operation-1782745481589-65565c727b46b-74638acf-0963a398",
      "operationType": "compute.instanceGroupManagers.insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782745481589-65565c727b46b-74638acf-0963a398",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/6067619727955408740",
      "startTime": "2026-06-29T08:04:43.186-07:00",
      "status": "RUNNING",
      "targetId": "345848323240834916",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:04:43.693330607Z",
  "resource": {
    "labels": {
      "instance_group_manager_id": "345848323240834916",
      "instance_group_manager_name": "dwn3-dw745304",
      "location": "us-central1-a",
      "project_id": "example-project-id"
    },
    "type": "gce_instance_group_manager"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:04:41.655635Z"
}

compute.instanceGroupManagers.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of managed instance groups that are contained within the specified project and zone.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "w7t0nwe4yf04",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a61b2872-e37a-4b5f-9e2e-de55f324c314"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceGroupManagers.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.instanceGroupManagers.list",
    "request": {
      "@type": "type.googleapis.com/compute.instanceGroupManagers.list"
    },
    "requestMetadata": {
      "callerIp": "private",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:45:18.719038Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:45:19.409278616Z",
  "resource": {
    "labels": {
      "instance_group_manager_id": "",
      "instance_group_manager_name": "",
      "location": "us-central1-a",
      "project_id": "example-project-id"
    },
    "type": "gce_instance_group_manager"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:45:18.685570Z"
}

compute.instanceGroupManagers.listErrors: listErrors

#
ServiceName
compute.googleapis.com

Description

Lists all errors thrown by actions on instances for a given managed instance group. The filter and orderBy query parameters are not supported.

Data Access audit logs are disabled by default.

compute.instanceGroupManagers.listManagedInstances: listManagedInstances

#
ServiceName
compute.googleapis.com

Description

Lists all of the instances in the managed instance group. Each instance in the list has a currentAction, which indicates the action that the managed instance group is performing on the instance. For example, if the group is still creating an instance, the currentAction is CREATING. If a previous action failed, the list displays the errors for that failed action. The orderBy query parameter is not supported. The `pageToken` query parameter is supported only if the group's `listManagedInstancesResults` field is set to `PAGINATED`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-3vex0udzg1u",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "09a44e07-6edf-4a1d-8800-e08c22147835"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceGroupManagers.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
          "service": "compute",
          "type": "compute.instanceGroupManagers"
        }
      }
    ],
    "methodName": "v1.compute.instanceGroupManagers.listManagedInstances",
    "request": {
      "@type": "type.googleapis.com/compute.instanceGroupManagers.listManagedInstances"
    },
    "requestMetadata": {
      "callerIp": "private",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:42:00.570559Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:42:01.028859167Z",
  "resource": {
    "labels": {
      "instance_group_manager_id": "1685950597165956322",
      "instance_group_manager_name": "gke-dwgke-dw743447-default-pool-d20f3f37-grp",
      "location": "us-central1-a",
      "project_id": "example-project-id"
    },
    "type": "gce_instance_group_manager"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:42:00.502057Z"
}

compute.instanceGroupManagers.listPerInstanceConfigs: listPerInstanceConfigs

#
ServiceName
compute.googleapis.com

Description

Lists all of the per-instance configurations defined for the managed instance group. The orderBy query parameter is not supported.

Data Access audit logs are disabled by default.

compute.instanceGroupManagers.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates a managed instance group using the information that you specify in the request. This operation is marked as DONE when the group is patched even if the instances in the group are still in the process of being patched. You must separately verify the status of the individual instances with thelistManagedInstances method. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. If you update your group to specify a new template or instance configuration, it's possible that your intended specification for each VM in the group is different from the current state of that VM. To learn how to apply an updated configuration to the VMs in a MIG, seeUpdating instances in a MIG.

compute.instanceGroupManagers.patchPerInstanceConfigs: patchPerInstanceConfigs

#
ServiceName
compute.googleapis.com

Description

Inserts or patches per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.

compute.instanceGroupManagers.recreateInstances: recreateInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified VM instances in the managed instance group to be immediately recreated. Each instance is recreated using the group's current configuration. This operation is marked as DONE when the flag is set even if the instances have not yet been recreated. You must separately verify the status of each instance by checking itscurrentAction field; for more information, see Checking the status of managed instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.

compute.instanceGroupManagers.resize: resize

#
ServiceName
compute.googleapis.com

Description

Resizes the managed instance group. If you increase the size, the group creates new instances using the current instance template. If you decrease the size, the group deletes instances. The resize operation is markedDONE when the resize actions are scheduled even if the group has not yet added or deleted any instances. You must separately verify the status of the creating or deleting actions with thelistmanagedinstances method. When resizing down, the instance group arbitrarily chooses the order in which VMs are deleted. The group takes into account some VM attributes when making the selection including: + The status of the VM instance. + The health of the VM instance. + The instance template version the VM is based on. + For regional managed instance groups, the location of the VM instance. This list is subject to change. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted.

compute.instanceGroupManagers.resumeInstances: resumeInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances in the managed instance group to be resumed. This method increases thetargetSize and decreases the targetSuspendedSize of the managed instance group by the number of instances that you resume. The resumeInstances operation is marked DONE if the resumeInstances request is successful. The underlying actions take additional time. You must separately verify the status of theRESUMING action with thelistmanagedinstances method. In this request, you can only specify instances that are suspended. For example, if an instance was previously suspended using the suspendInstances method, it can be resumed using the resumeInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are resumed. You can specify a maximum of 1000 instances with this method per request.

compute.instanceGroupManagers.setInstanceTemplate: setInstanceTemplate

#
ServiceName
compute.googleapis.com

Description

Specifies the instance template to use when creating new instances in this group. The templates for existing instances in the group do not change unless you run recreateInstances, runapplyUpdatesToInstances, or set the group'supdatePolicy.type to PROACTIVE.

compute.instanceGroupManagers.setTargetPools: setTargetPools

#
ServiceName
compute.googleapis.com

Description

Modifies the target pools to which all instances in this managed instance group are assigned. The target pools automatically apply to all of the instances in the managed instance group. This operation is markedDONE when you make the request even if the instances have not yet been added to their target pools. The change might take some time to apply to all of the instances in the group depending on the size of the group.

compute.instanceGroupManagers.startInstances: startInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances in the managed instance group to be started. This method increases thetargetSize and decreases the targetStoppedSize of the managed instance group by the number of instances that you start. The startInstances operation is marked DONE if the startInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTARTING action with thelistmanagedinstances method. In this request, you can only specify instances that are stopped. For example, if an instance was previously stopped using the stopInstances method, it can be started using the startInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are started. You can specify a maximum of 1000 instances with this method per request.

compute.instanceGroupManagers.stopInstances: stopInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances in the managed instance group to be immediately stopped. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetStoppedSize of the managed instance group by the number of instances that you stop. The stopInstances operation is marked DONE if the stopInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTOPPING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays stopping the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is stopped. Stopped instances can be started using the startInstances method. You can specify a maximum of 1000 instances with this method per request.

compute.instanceGroupManagers.suspendInstances: suspendInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances in the managed instance group to be immediately suspended. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetSuspendedSize of the managed instance group by the number of instances that you suspend. The suspendInstances operation is marked DONE if the suspendInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSUSPENDING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays suspension of the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is suspended. Suspended instances can be resumed using the resumeInstances method. You can specify a maximum of 1000 instances with this method per request.

compute.instanceGroupManagers.updatePerInstanceConfigs: updatePerInstanceConfigs

#
ServiceName
compute.googleapis.com

Description

Inserts or updates per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.

compute.instanceGroups.addInstances: addInstances

#
ServiceName
compute.googleapis.com

Description

Adds a list of instances to the specified instance group. All of the instances in the instance group must be in the same network/subnetwork. Read Adding instances for more information.

compute.instanceGroups.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of instance groups and sorts them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "cspgjwe6akq6",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "6ffaf0d4-0a5a-4a13-9d00-f4a5eb8998d3"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceGroups.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.instanceGroups.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.instanceGroups.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-groups.list invocation-id/3713116eaa63429aa5926242b2f6e5b0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:35.912021Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/instanceGroups",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:36.925169374Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.instanceGroups.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:35.851309Z"
}

compute.instanceGroups.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified instance group. The instances in the group are not deleted. Note that instance group must not belong to a backend service. Read Deleting an instance group for more information.

compute.instanceGroups.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified zonal instance group. Get a list of available zonal instance groups by making a list() request. For managed instance groups, use theinstanceGroupManagers or regionInstanceGroupManagers methods instead.

Data Access audit logs are disabled by default.

compute.instanceGroups.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an instance group in the specified project using the parameters that are included in the request.

Example Audit Log Entry #

{
  "insertId": "50063md3cli",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a53cde13-994a-425a-a98b-19e47439782b"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745485069-65565c75ccb7b-75b04204-44600cd1",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceGroups.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
          "service": "compute",
          "type": "compute.instanceGroups"
        }
      }
    ],
    "methodName": "v1.compute.instanceGroups.insert",
    "request": {
      "@type": "type.googleapis.com/compute.instanceGroups.insert",
      "description": "This instance group is controlled by Instance Group Manager 'dwn3-dw745304'. To modify instances in this group, use the Instance Group Manager API: https://cloud.google.com/compute/docs/reference/latest/instanceGroupManagers",
      "name": "dwn3-dw745304",
      "network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn3-dw745304",
      "requestId": "a85c428f-5380-3ba8-846f-54d37e249e43"
    },
    "requestMetadata": {
      "callerSuppliedUserAgent": "GCE Managed Instance Group",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:04:46.246015Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/000000000000/zones/us-central1-a/instanceGroups/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "clientOperationId": "a85c428f-5380-3ba8-846f-54d37e249e43",
      "id": "3853369069582366561",
      "insertTime": "2026-06-29T08:04:46.207-07:00",
      "name": "operation-1782745485069-65565c75ccb7b-75b04204-44600cd1",
      "operationType": "compute.instanceGroups.insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782745485069-65565c75ccb7b-75b04204-44600cd1",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/3853369069582366561",
      "startTime": "2026-06-29T08:04:46.211-07:00",
      "status": "RUNNING",
      "targetId": "577154529996257121",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:04:46.839546323Z",
  "resource": {
    "labels": {
      "instance_group_id": "577154529996257121",
      "instance_group_name": "dwn3-dw745304",
      "location": "us-central1-a",
      "project_id": "example-project-id"
    },
    "type": "gce_instance_group"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:04:45.037214Z"
}

compute.instanceGroups.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of zonal instance group resources contained within the specified zone. For managed instance groups, use theinstanceGroupManagers or regionInstanceGroupManagers methods instead.

Data Access audit logs are disabled by default.

compute.instanceGroups.listInstances: listInstances

#
ServiceName
compute.googleapis.com

Description

Lists the instances in the specified instance group. The orderBy query parameter is not supported. The filter query parameter is supported, but only for expressions that use `eq` (equal) or `ne` (not equal) operators.

Data Access audit logs are disabled by default.

compute.instanceGroups.removeInstances: removeInstances

#
ServiceName
compute.googleapis.com

Description

Removes one or more instances from the specified instance group, but does not delete those instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration before the VM instance is removed or deleted.

Example Audit Log Entry #

{
  "insertId": "-jnmjked85oi",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "62a07eaf-a7d8-4e79-bffe-60b4c74da171"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782744012776-655656f9b6533-39a8caae-8d2370f8",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
      "principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceGroups.update",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
          "service": "compute",
          "type": "compute.instanceGroups"
        }
      }
    ],
    "methodName": "v1.compute.instanceGroups.removeInstances",
    "request": {
      "@type": "type.googleapis.com/compute.instanceGroups.removeInstances",
      "instances": [
        {
          "instance": "https://www.googleapis.com/compute/v1/projects/000000000000/zones/us-central1-a/instances/gke-dwgke-dw743447-default-pool-d20f3f37-s2rw"
        }
      ],
      "requestId": "74ba3e1c-b051-4234-89e1-238de676d9ff"
    },
    "requestMetadata": {
      "callerSuppliedUserAgent": "GCE Managed Instance Group for GKE",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:40:12.869962Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/000000000000/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
    "response": {
      "@type": "type.googleapis.com/operation",
      "clientOperationId": "74ba3e1c-b051-4234-89e1-238de676d9ff",
      "id": "2725981313053965603",
      "insertTime": "2026-06-29T07:40:12.842-07:00",
      "name": "operation-1782744012776-655656f9b6533-39a8caae-8d2370f8",
      "operationType": "compute.instanceGroups.removeInstances",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782744012776-655656f9b6533-39a8caae-8d2370f8",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/2725981313053965603",
      "startTime": "2026-06-29T07:40:12.846-07:00",
      "status": "RUNNING",
      "targetId": "7820809400904269055",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
      "user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:40:13.837104183Z",
  "resource": {
    "labels": {
      "instance_group_id": "7820809400904269055",
      "instance_group_name": "gke-dwgke-dw743447-default-pool-d20f3f37-grp",
      "location": "us-central1-a",
      "project_id": "example-project-id"
    },
    "type": "gce_instance_group"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:40:12.749902Z"
}

compute.instanceGroups.setNamedPorts: setNamedPorts

#
ServiceName
compute.googleapis.com

Description

Sets the named ports for the specified instance group.

Example Audit Log Entry #

{
  "insertId": "ve9s30dxc9g",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "44c3d8a8-fe67-462c-9e24-47442927b3fa"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745505522-65565c894e1cc-6ebd8cf7-5ac43db4",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceGroups.update",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
          "service": "compute",
          "type": "compute.instanceGroups"
        }
      },
      {
        "granted": true,
        "permission": "compute.instanceGroupManagers.update",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
          "service": "compute",
          "type": "compute.instanceGroupManagers"
        }
      }
    ],
    "methodName": "v1.compute.instanceGroups.setNamedPorts",
    "request": {
      "@type": "type.googleapis.com/compute.instanceGroups.setNamedPorts",
      "fingerprint": "�e�J�|�#",
      "namedPorts": [
        {
          "name": "http",
          "port": "80"
        }
      ]
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-groups.managed.set-named-ports invocation-id/a3f63a4e9b654fd1911ec959188c8e04 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:05:05.823823Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "2091809115258959694",
      "insertTime": "2026-06-29T08:05:05.734-07:00",
      "name": "operation-1782745505522-65565c894e1cc-6ebd8cf7-5ac43db4",
      "operationType": "compute.instanceGroups.setNamedPorts",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782745505522-65565c894e1cc-6ebd8cf7-5ac43db4",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/2091809115258959694",
      "startTime": "2026-06-29T08:05:05.759-07:00",
      "status": "RUNNING",
      "targetId": "577154529996257121",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:05:06.783285141Z",
  "resource": {
    "labels": {
      "instance_group_id": "577154529996257121",
      "instance_group_name": "dwn3-dw745304",
      "location": "us-central1-a",
      "project_id": "example-project-id"
    },
    "type": "gce_instance_group"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:05:05.577760Z"
}

compute.instanceGroups.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.instanceSettings.get: get

#
ServiceName
compute.googleapis.com

Description

Get Instance settings.

Data Access audit logs are disabled by default.

compute.instanceSettings.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patch Instance settings

compute.instanceTemplates.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all InstanceTemplates resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-cfdl6ee5e9oc",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "b78e21bb-bc45-472e-a767-328ec82eb72d"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceTemplates.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.instanceTemplates.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.instanceTemplates.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-templates.list invocation-id/930603099a79484eb82778f47acf32b0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:37.254012Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/instanceTemplates",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:37.342101398Z",
  "resource": {
    "labels": {
      "instance_template_id": "",
      "instance_template_name": "",
      "project_id": "example-project-id"
    },
    "type": "gce_instance_template"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:37.087908Z"
}

compute.instanceTemplates.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified instance template. Deleting an instance template is permanent and cannot be undone. It is not possible to delete templates that are already in use by a managed instance group.

compute.instanceTemplates.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified instance template.

Data Access audit logs are disabled by default.

compute.instanceTemplates.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.instanceTemplates.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an instance template in the specified project using the data that is included in the request. If you are creating a new template to update an existing instance group, your new instance template must use the same network or, if applicable, the same subnetwork as the original template.

Example Audit Log Entry #

{
  "insertId": "-skhss4e1vyny",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a4c6ada8-3b32-4b38-a891-79839d619128"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745477457-65565c6e8a700-e695b3c6-bb88279a",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceTemplates.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/instanceTemplates/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/instanceTemplates/dwn3-dw745304",
          "service": "compute",
          "type": "compute.instanceTemplates"
        }
      }
    ],
    "methodName": "v1.compute.instanceTemplates.insert",
    "request": {
      "@type": "type.googleapis.com/compute.instanceTemplates.insert",
      "name": "dwn3-dw745304",
      "properties": {
        "canIpForward": false,
        "disks": [
          {
            "autoDelete": true,
            "boot": true,
            "initializeParams": {
              "sourceImage": "https://compute.googleapis.com/compute/v1/projects/debian-cloud/global/images/family/debian-12"
            },
            "mode": "READ_WRITE",
            "type": "PERSISTENT"
          }
        ],
        "machineType": "e2-micro",
        "networkInterfaces": [
          {
            "network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn3-dw745304",
            "subnetwork": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304"
          }
        ],
        "scheduling": {
          "automaticRestart": true
        },
        "serviceAccounts": [
          {
            "email": "default",
            "scopes": [
              "https://www.googleapis.com/auth/devstorage.read_only",
              "https://www.googleapis.com/auth/logging.write",
              "https://www.googleapis.com/auth/monitoring.write",
              "https://www.googleapis.com/auth/pubsub",
              "https://www.googleapis.com/auth/service.management.readonly",
              "https://www.googleapis.com/auth/servicecontrol",
              "https://www.googleapis.com/auth/trace.append"
            ]
          }
        ]
      }
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-templates.create invocation-id/5a3d91579d004ed39da655a0fe8e7d5c environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:04:38.617699Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/instanceTemplates/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "5920604410457569130",
      "insertTime": "2026-06-29T08:04:38.013-07:00",
      "name": "operation-1782745477457-65565c6e8a700-e695b3c6-bb88279a",
      "operationType": "compute.instanceTemplates.insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745477457-65565c6e8a700-e695b3c6-bb88279a",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/5920604410457569130",
      "startTime": "2026-06-29T08:04:38.021-07:00",
      "status": "RUNNING",
      "targetId": "8340466719637059434",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/instanceTemplates/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:04:38.922494070Z",
  "resource": {
    "labels": {
      "instance_template_id": "8340466719637059434",
      "instance_template_name": "dwn3-dw745304",
      "project_id": "example-project-id"
    },
    "type": "gce_instance_template"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:04:37.443345Z"
}

compute.instanceTemplates.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of instance templates that are contained within the specified project.

Data Access audit logs are disabled by default.

compute.instanceTemplates.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.instanceTemplates.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.instances.addAccessConfig: addAccessConfig

#
ServiceName
compute.googleapis.com

Description

Adds an access config to an instance's network interface.

compute.instances.addNetworkInterface: addNetworkInterface

#
ServiceName
compute.googleapis.com

Description

Adds one dynamic network interface to an active instance.

compute.instances.addResourcePolicies: addResourcePolicies

#
ServiceName
compute.googleapis.com

Description

Adds existing resource policies to an instance. You can only add one policy right now which will be applied to this instance for scheduling live migrations.

compute.instances.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of all of the instances in your project across all regions and zones. The performance of this method degrades when a filter is specified on a project that has a very large number of instances. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-itsf8hd9oq6",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "859732ab-aaf8-4568-b210-a38c8c8be283"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.instances.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.instances.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.list invocation-id/2d3139518284463aa5b59952a1f85319 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:15.606661Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/instances",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:16.566105439Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.instances.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:15.505076Z"
}

compute.instances.attachDisk: attachDisk

#
ServiceName
compute.googleapis.com

Description

Attaches an existing Disk resource to an instance. You must first create the disk before you can attach it. It is not possible to create and attach a disk at the same time. For more information, readAdding a persistent disk to your instance.

Example Audit Log Entry #

{
  "insertId": "-e55srie5utqm",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "dce0bcf8-17be-4032-87b0-984b3e642e4b"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743852172-655656608c53d-43528019-ebf883b6",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.attachDisk",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
          "service": "compute",
          "type": "compute.instances"
        }
      },
      {
        "granted": true,
        "permission": "compute.instances.attachDisk",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
          "service": "compute",
          "type": "compute.instances"
        }
      },
      {
        "granted": true,
        "permission": "compute.disks.use",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
          "service": "compute",
          "type": "compute.disks"
        }
      }
    ],
    "metadata": {
      "newlyAttachedDisks": [
        "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447"
      ]
    },
    "methodName": "v1.compute.instances.attachDisk",
    "request": {
      "@type": "type.googleapis.com/compute.instances.attachDisk",
      "mode": "READ_WRITE",
      "source": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
      "type": "PERSISTENT"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.attach-disk invocation-id/831f1871873b4bf89423683252cbf706 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:37:32.444925Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "5682035452659318211",
      "insertTime": "2026-06-29T07:37:32.400-07:00",
      "name": "operation-1782743852172-655656608c53d-43528019-ebf883b6",
      "operationType": "attachDisk",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743852172-655656608c53d-43528019-ebf883b6",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/5682035452659318211",
      "startTime": "2026-06-29T07:37:32.413-07:00",
      "status": "RUNNING",
      "targetId": "8625152016897752154",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:37:33.403599438Z",
  "resource": {
    "labels": {
      "instance_id": "8625152016897752154",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:37:32.138847Z"
}

compute.instances.bulkInsert: bulkInsert

#
ServiceName
compute.googleapis.com

Description

Creates multiple instances. Count specifies the number of instances to create. For more information, seeAbout bulk creation of VMs.

compute.instances.delete: Delete instance

#
ServiceName
compute.googleapis.com

Description

Deletes the specified Instance resource.

Example Audit Log Entry #

{
  "insertId": "-rf4oqfe3rqoi",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "3f730e65-c1fb-4c1a-924e-30eb647dfb04"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782739364482-655645a8c0d32-75bbae64-ac155e53",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.delete",
    "request": {
      "@type": "type.googleapis.com/compute.instances.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.delete invocation-id/0212d0008d6c48538b97a407d580cc5f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:22:44.702678Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "257884863283056459",
      "insertTime": "2026-06-29T06:22:44.643-07:00",
      "name": "operation-1782739364482-655645a8c0d32-75bbae64-ac155e53",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782739364482-655645a8c0d32-75bbae64-ac155e53",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/257884863283056459",
      "startTime": "2026-06-29T06:22:44.659-07:00",
      "status": "RUNNING",
      "targetId": "6832792478432612219",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:22:44.944124935Z",
  "resource": {
    "labels": {
      "instance_id": "6832792478432612219",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T13:22:44.528790Z"
}

compute.instances.deleteAccessConfig: deleteAccessConfig

#
ServiceName
compute.googleapis.com

Description

Deletes an access config from an instance's network interface.

compute.instances.deleteNetworkInterface: deleteNetworkInterface

#
ServiceName
compute.googleapis.com

Description

Deletes one dynamic network interface from an active instance. InstancesDeleteNetworkInterfaceRequest indicates: - instance from which to delete, using project+zone+resource_id fields; - dynamic network interface to be deleted, using network_interface_name field;

compute.instances.detachDisk: detachDisk

#
ServiceName
compute.googleapis.com

Description

Detaches a disk from an instance.

Example Audit Log Entry #

{
  "insertId": "-s8ztz9e5x406",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "3e52829c-95a6-4be8-a27c-9d8ce576ed1e"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.detachDisk",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
          "service": "compute",
          "type": "compute.instances"
        }
      },
      {
        "granted": true,
        "permission": "compute.instances.detachDisk",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.detachDisk",
    "request": {
      "@type": "type.googleapis.com/compute.instances.detachDisk",
      "deviceName": "persistent-disk-0"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.detach-disk invocation-id/600a917e325b4964a9d4a28e12a56bac environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:37:36.746066Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
    "serviceName": "compute.googleapis.com",
    "status": {
      "code": 3,
      "message": "com.google.apps.framework.request.StatusException: <eye3 title='INVALID_ARGUMENT'/> generic::INVALID_ARGUMENT: To detach the boot disk, the instance must be in TERMINATED state."
    }
  },
  "receiveTimestamp": "2026-06-29T14:37:37.103650910Z",
  "resource": {
    "labels": {
      "instance_id": "8625152016897752154",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T14:37:36.643490Z"
}

compute.instances.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified Instance resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-2zon9ze5iuae",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "adf2b608-1267-45a6-81e0-adb137dd4652"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.get",
    "request": {
      "@type": "type.googleapis.com/compute.instances.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.create invocation-id/d3a99ae5add44e01b925c5905c2c65e4 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:22:41.441586Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:22:42.106687928Z",
  "resource": {
    "labels": {
      "instance_id": "6832792478432612219",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:22:41.347029Z"
}

compute.instances.getEffectiveFirewalls: getEffectiveFirewalls

#
ServiceName
compute.googleapis.com

Description

Returns effective firewalls applied to an interface of the instance.

Data Access audit logs are disabled by default.

compute.instances.getGuestAttributes: getGuestAttributes

#
ServiceName
compute.googleapis.com

Description

Returns the specified guest attributes entry.

Data Access audit logs are disabled by default.

compute.instances.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.instances.getScreenshot: getScreenshot

#
ServiceName
compute.googleapis.com

Description

Returns the screenshot from the specified instance.

Data Access audit logs are disabled by default.

compute.instances.getSerialPortOutput: getSerialPortOutput

#
ServiceName
compute.googleapis.com

Description

Returns the last 1 MB of serial port output from the specified instance.

Data Access audit logs are disabled by default.

compute.instances.getShieldedInstanceIdentity: getShieldedInstanceIdentity

#
ServiceName
compute.googleapis.com

Description

Returns the Shielded Instance Identity of an instance

Data Access audit logs are disabled by default.

compute.instances.insert: Insert instance

#
ServiceName
compute.googleapis.com

Description

Creates an instance resource in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-e3f928e3ga12",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9f284959-8561-48b5-8d51-a7b1f59fbc11"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782739348249-65564599459f9-31ad5434-c32a2182",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
          "service": "compute",
          "type": "compute.instances"
        }
      },
      {
        "granted": true,
        "permission": "compute.disks.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwgen-dw739065",
          "service": "compute",
          "type": "compute.disks"
        }
      },
      {
        "granted": true,
        "permission": "compute.subnetworks.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      },
      {
        "granted": true,
        "permission": "compute.instances.setServiceAccount",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "metadata": {
      "usedResources": {
        "attachedDisks": [
          {
            "isBootDisk": true,
            "sourceImage": "https://www.googleapis.com/compute/v1/projects/707281592825/global/images/debian-12-bookworm-v20260609",
            "sourceImageId": "1449487925682397051"
          }
        ]
      }
    },
    "methodName": "v1.compute.instances.insert",
    "request": {
      "@type": "type.googleapis.com/compute.instances.insert",
      "canIpForward": false,
      "deletionProtection": false,
      "disks": [
        {
          "autoDelete": true,
          "boot": true,
          "initializeParams": {
            "sourceImage": "https://compute.googleapis.com/compute/v1/projects/debian-cloud/zones/-/imageFamilyViews/debian-12"
          },
          "mode": "READ_WRITE",
          "type": "PERSISTENT"
        }
      ],
      "machineType": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/machineTypes/e2-micro",
      "name": "dwgen-dw739065",
      "networkInterfaces": [
        {
          "network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwgen-dw739065",
          "subnetwork": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065"
        }
      ],
      "scheduling": {
        "automaticRestart": true
      },
      "serviceAccounts": [
        {
          "email": "default",
          "scopes": [
            "https://www.googleapis.com/auth/devstorage.read_only",
            "https://www.googleapis.com/auth/logging.write",
            "https://www.googleapis.com/auth/monitoring.write",
            "https://www.googleapis.com/auth/pubsub",
            "https://www.googleapis.com/auth/service.management.readonly",
            "https://www.googleapis.com/auth/servicecontrol",
            "https://www.googleapis.com/auth/trace.append"
          ]
        }
      ]
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.create invocation-id/d3a99ae5add44e01b925c5905c2c65e4 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:22:29.317225Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "1827009396319702906",
      "insertTime": "2026-06-29T06:22:29.259-07:00",
      "name": "operation-1782739348249-65564599459f9-31ad5434-c32a2182",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782739348249-65564599459f9-31ad5434-c32a2182",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/1827009396319702906",
      "startTime": "2026-06-29T06:22:29.260-07:00",
      "status": "RUNNING",
      "targetId": "6832792478432612219",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:22:29.474987645Z",
  "resource": {
    "labels": {
      "instance_id": "6832792478432612219",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T13:22:28.317183Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
protoPayload.response.error (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • GCP compute.instances.create Privilege Escalation source high: Detects compute.instances.create method for privilege escalation in GCP. This rule identifies when users create compute instances with service accounts that may lead to privilege escalation. Known good service accounts (GKE, Kubernetes, compute automation) are excluded to reduce false positives.T1548

compute.instances.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of instances contained within the specified zone.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-gvpyildz3ls",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "38ee7910-9033-4434-b350-841b56b9358b"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.instances.list",
    "request": {
      "@type": "type.googleapis.com/compute.instances.list"
    },
    "requestMetadata": {
      "callerIp": "private",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:45:18.566574Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:45:19.179629259Z",
  "resource": {
    "labels": {
      "instance_id": "",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:45:18.485852Z"
}

compute.instances.listReferrers: listReferrers

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of resources that refer to the VM instance specified in the request. For example, if the VM instance is part of a managed or unmanaged instance group, the referrers list includes the instance group. For more information, readViewing referrers to VM instances.

Data Access audit logs are disabled by default.

compute.instances.migrateOnHostMaintenance: migrateOnHostMaintenance

#
ServiceName
compute.googleapis.com

Description

Google-initiated live migration of a VM to new host hardware. Appears in system_event audit logs (cloudaudit.googleapis.com/system_event), not admin_activity. Not user-callable; emitted by GCE infrastructure.

compute.instances.performMaintenance: performMaintenance

#
ServiceName
compute.googleapis.com

Description

Perform a manual maintenance on the instance.

compute.instances.removeResourcePolicies: removeResourcePolicies

#
ServiceName
compute.googleapis.com

Description

Removes resource policies from an instance.

compute.instances.reportHostAsFaulty: reportHostAsFaulty

#
ServiceName
compute.googleapis.com

Description

Mark the host as faulty and try to restart the instance on a new host.

compute.instances.reset: reset

#
ServiceName
compute.googleapis.com

Description

Performs a reset on the instance. This is a hard reset. The VM does not do a graceful shutdown. For more information, seeResetting an instance.

Example Audit Log Entry #

{
  "insertId": "l40d5ke7szkk",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "27ce5016-a489-4df2-bb6a-e29b4fc953f2"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743814685-6556563ccc280-2a348516-04852af5",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.reset",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.reset",
    "request": {
      "@type": "type.googleapis.com/compute.instances.reset"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.reset invocation-id/846fad68d9444087a2964f89190bc7f0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:36:54.808986Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "5195633674857430505",
      "insertTime": "2026-06-29T07:36:54.764-07:00",
      "name": "operation-1782743814685-6556563ccc280-2a348516-04852af5",
      "operationType": "reset",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743814685-6556563ccc280-2a348516-04852af5",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/5195633674857430505",
      "startTime": "2026-06-29T07:36:54.778-07:00",
      "status": "RUNNING",
      "targetId": "8625152016897752154",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:36:55.215287288Z",
  "resource": {
    "labels": {
      "instance_id": "8625152016897752154",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:36:54.660973Z"
}

compute.instances.resume: resume

#
ServiceName
compute.googleapis.com

Description

Resumes an instance that was suspended using theinstances().suspend method.

compute.instances.sendDiagnosticInterrupt: sendDiagnosticInterrupt

#
ServiceName
compute.googleapis.com

Description

Sends diagnostic interrupt to the instance.

compute.instances.setDeletionProtection: setDeletionProtection

#
ServiceName
compute.googleapis.com

Description

Sets deletion protection on the instance.

Example Audit Log Entry #

{
  "insertId": "wqya8he2pwsu",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9be27c43-5b44-464d-9f14-ba4a1947ef7e"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746089523-65565eb6407bc-2c494aae-d0a8b144",
    "last": true,
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.setDeletionProtection",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.setDeletionProtection",
    "request": {
      "@type": "type.googleapis.com/compute.instances.setDeletionProtection",
      "deletionProtection": false
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.update invocation-id/76794def4fba4ae68d9cfb0a68b7d6ac environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:14:49.807226Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "endTime": "2026-06-29T08:14:49.757-07:00",
      "id": "7526662050172318982",
      "insertTime": "2026-06-29T08:14:49.729-07:00",
      "name": "operation-1782746089523-65565eb6407bc-2c494aae-d0a8b144",
      "operationType": "setDeletionProtection",
      "progress": "100",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746089523-65565eb6407bc-2c494aae-d0a8b144",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/7526662050172318982",
      "startTime": "2026-06-29T08:14:49.757-07:00",
      "status": "DONE",
      "targetId": "7874721179023389984",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:14:49.831220538Z",
  "resource": {
    "labels": {
      "instance_id": "7874721179023389984",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:14:49.578034Z"
}

compute.instances.setDiskAutoDelete: setDiskAutoDelete

#
ServiceName
compute.googleapis.com

Description

Sets the auto-delete flag for a disk attached to an instance.

compute.instances.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.instances.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets labels on an instance. To learn more about labels, read theLabeling Resources documentation.

Example Audit Log Entry #

{
  "insertId": "-lcuq8zd933y",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "028556a2-d06b-4dcd-ba01-47b86211366d"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743746550-655655fbd1c6c-8fd2de16-7bbeb6e0",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.setLabels",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.setLabels",
    "request": {
      "@type": "type.googleapis.com/compute.instances.setLabels",
      "labelFingerprint": "�e�J�|�#",
      "labels": [
        {
          "key": "env",
          "value": "dw"
        }
      ]
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.add-labels invocation-id/fa92fcadcb2a4b7da8498f1dd16d1e1b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:35:46.797701Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "1403337265143299117",
      "insertTime": "2026-06-29T07:35:46.758-07:00",
      "name": "operation-1782743746550-655655fbd1c6c-8fd2de16-7bbeb6e0",
      "operationType": "compute.instance.setLabels",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743746550-655655fbd1c6c-8fd2de16-7bbeb6e0",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/1403337265143299117",
      "startTime": "2026-06-29T07:35:46.760-07:00",
      "status": "RUNNING",
      "targetId": "8625152016897752154",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:35:47.295194898Z",
  "resource": {
    "labels": {
      "instance_id": "8625152016897752154",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:35:46.610646Z"
}

compute.instances.setMachineResources: setMachineResources

#
ServiceName
compute.googleapis.com

Description

Changes the number and/or type of accelerator for a stopped instance to the values specified in the request.

compute.instances.setMachineType: setMachineType

#
ServiceName
compute.googleapis.com

Description

Changes the machine type for a stopped instance to the machine type specified in the request.

Example Audit Log Entry #

{
  "insertId": "-u6xl5ed8jjy",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "b930cfd9-d215-451b-82d1-9d045c89a3c1"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743789380-65565624aa52c-6470aa91-b8bbe025",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.setMachineType",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.setMachineType",
    "request": {
      "@type": "type.googleapis.com/compute.instances.setMachineType",
      "machineType": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/machineTypes/e2-small"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.set-machine-type invocation-id/dec895b1fd3c40a192d642b6bb70e151 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:36:29.675048Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "3980272502637018114",
      "insertTime": "2026-06-29T07:36:29.600-07:00",
      "name": "operation-1782743789380-65565624aa52c-6470aa91-b8bbe025",
      "operationType": "setMachineType",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743789380-65565624aa52c-6470aa91-b8bbe025",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/3980272502637018114",
      "startTime": "2026-06-29T07:36:29.626-07:00",
      "status": "RUNNING",
      "targetId": "8625152016897752154",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:36:29.762500589Z",
  "resource": {
    "labels": {
      "instance_id": "8625152016897752154",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:36:29.428814Z"
}

References #

compute.instances.setMetadata: Set instance metadata

#
ServiceName
compute.googleapis.com

Description

Sets metadata for the specified instance to the data included in the request.

Example Audit Log Entry #

{
  "insertId": "v3xocbdko2q",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "add18352-440d-4301-9bb2-7c703dbc5231"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743755029-65565603e7d81-43af4565-66dabc0c",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.setMetadata",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "metadata": {
      "@type": "type.googleapis.com/google.cloud.audit.GceInstanceAuditMetadata",
      "instanceMetadataDelta": {
        "addedMetadataKeys": [
          "dwk"
        ]
      }
    },
    "methodName": "v1.compute.instances.setMetadata",
    "request": {
      "@type": "type.googleapis.com/compute.instances.setMetadata"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.add-metadata invocation-id/c5e59ff0ab5149719ead1164a3d0ca53 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:35:55.259710Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "4541556348049898532",
      "insertTime": "2026-06-29T07:35:55.205-07:00",
      "name": "operation-1782743755029-65565603e7d81-43af4565-66dabc0c",
      "operationType": "setMetadata",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743755029-65565603e7d81-43af4565-66dabc0c",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/4541556348049898532",
      "startTime": "2026-06-29T07:35:55.214-07:00",
      "status": "RUNNING",
      "targetId": "8625152016897752154",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:35:56.149233070Z",
  "resource": {
    "labels": {
      "instance_id": "8625152016897752154",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:35:55.092178Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

compute.instances.setMinCpuPlatform: setMinCpuPlatform

#
ServiceName
compute.googleapis.com

Description

Changes the minimum CPU platform that this instance should use. This method can only be called on a stopped instance. For more information, readSpecifying a Minimum CPU Platform.

compute.instances.setName: setName

#
ServiceName
compute.googleapis.com

Description

Sets name of an instance.

compute.instances.setScheduling: setScheduling

#
ServiceName
compute.googleapis.com

Description

Sets an instance's scheduling options. You can only call this method on astopped instance, that is, a VM instance that is in a `TERMINATED` state. SeeInstance Life Cycle for more information on the possible instance states. For more information about setting scheduling options for a VM, seeSet VM host maintenance policy.

Example Audit Log Entry #

{
  "insertId": "-yobzz1dg1k8",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "dfae2500-e9bc-4b48-9889-834b6d47cde0"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746078001-65565eab43945-b2fdba3b-d72a3c55",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.setScheduling",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.setScheduling",
    "request": {
      "@type": "type.googleapis.com/compute.instances.setScheduling",
      "automaticRestart": true
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.set-scheduling invocation-id/9491c7d6868d4eeca76313a62a5e6010 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:14:38.450531Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "8390035611510060337",
      "insertTime": "2026-06-29T08:14:38.393-07:00",
      "name": "operation-1782746078001-65565eab43945-b2fdba3b-d72a3c55",
      "operationType": "setScheduling",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746078001-65565eab43945-b2fdba3b-d72a3c55",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/8390035611510060337",
      "startTime": "2026-06-29T08:14:38.416-07:00",
      "status": "RUNNING",
      "targetId": "7874721179023389984",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:14:38.989371228Z",
  "resource": {
    "labels": {
      "instance_id": "7874721179023389984",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:14:38.075339Z"
}

compute.instances.setSecurityPolicy: setSecurityPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the Google Cloud Armor security policy for the specified instance. For more information, seeGoogle Cloud Armor Overview

compute.instances.setServiceAccount: Set instance service account

#
ServiceName
compute.googleapis.com

Description

Sets the service account on the instance.

compute.instances.setShieldedInstanceIntegrityPolicy: setShieldedInstanceIntegrityPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the Shielded Instance integrity policy for an instance. You can only use this method on a running instance. This method supports PATCH semantics and uses the JSON merge patch format and processing rules.

compute.instances.setTags: Set instance tags

#
ServiceName
compute.googleapis.com

Description

Sets network tags for the specified instance to the data included in the request.

Example Audit Log Entry #

{
  "insertId": "jzrer0dvtv4",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "3bf1a16f-a737-4c58-9154-96802a2d6d58"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743750498-655655ff9591d-48fb5bde-900efc56",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.setTags",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.setTags",
    "request": {
      "@type": "type.googleapis.com/compute.instances.setTags",
      "fingerprint": "�e�J�|�#",
      "tags": [
        "dwtag"
      ]
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.add-tags invocation-id/b32dedfc008848cab4894296fc179677 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:35:50.735933Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "1166672317886970921",
      "insertTime": "2026-06-29T07:35:50.684-07:00",
      "name": "operation-1782743750498-655655ff9591d-48fb5bde-900efc56",
      "operationType": "setTags",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743750498-655655ff9591d-48fb5bde-900efc56",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/1166672317886970921",
      "startTime": "2026-06-29T07:35:50.704-07:00",
      "status": "RUNNING",
      "targetId": "8625152016897752154",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:35:51.102450342Z",
  "resource": {
    "labels": {
      "instance_id": "8625152016897752154",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:35:50.588376Z"
}

compute.instances.simulateMaintenanceEvent: simulateMaintenanceEvent

#
ServiceName
compute.googleapis.com

Description

Simulates a host maintenance event on a VM. For more information, see Simulate a host maintenance event.

Example Audit Log Entry #

{
  "insertId": "-mfuitke6wqfu",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "b689ee1a-2822-4d19-b1f4-889316b3ccd2"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746083973-65565eb0f584c-fcd3ee82-102d6c30",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.simulateMaintenanceEvent",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.simulateMaintenanceEvent",
    "request": {
      "@type": "type.googleapis.com/compute.instances.simulateMaintenanceEvent"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.simulate-maintenance-event invocation-id/6f7b69a6c77e4acbac88dff56630ff87 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:14:44.138929Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "3890946893801272587",
      "insertTime": "2026-06-29T08:14:44.082-07:00",
      "name": "operation-1782746083973-65565eb0f584c-fcd3ee82-102d6c30",
      "operationType": "simulateMaintenanceEvent",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746083973-65565eb0f584c-fcd3ee82-102d6c30",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/3890946893801272587",
      "startTime": "2026-06-29T08:14:44.099-07:00",
      "status": "RUNNING",
      "targetId": "7874721179023389984",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:14:44.348259732Z",
  "resource": {
    "labels": {
      "instance_id": "7874721179023389984",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:14:43.925899Z"
}

compute.instances.start: Start instance

#
ServiceName
compute.googleapis.com

Description

Starts an instance that was stopped using the stopInstance method.

Example Audit Log Entry #

{
  "insertId": "78c42xdhomk",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "b5a50223-9d8c-4f85-a753-17c05932cdd1"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743791870-655656270a277-ee9a6bea-898081d8",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.start",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.start",
    "request": {
      "@type": "type.googleapis.com/compute.instances.start"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.start invocation-id/9e228f59439a4eb0a073ae5d07220c1c environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:36:32.318324Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "5697850376941681695",
      "insertTime": "2026-06-29T07:36:32.236-07:00",
      "name": "operation-1782743791870-655656270a277-ee9a6bea-898081d8",
      "operationType": "start",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743791870-655656270a277-ee9a6bea-898081d8",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/5697850376941681695",
      "startTime": "2026-06-29T07:36:32.266-07:00",
      "status": "RUNNING",
      "targetId": "8625152016897752154",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:36:32.880013442Z",
  "resource": {
    "labels": {
      "instance_id": "8625152016897752154",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:36:31.920398Z"
}

compute.instances.startWithEncryptionKey: startWithEncryptionKey

#
ServiceName
compute.googleapis.com

Description

Starts an instance that was stopped using theinstances().stop method. For more information, seeRestart an instance.

compute.instances.stop: Stop instance

#
ServiceName
compute.googleapis.com

Description

Stops a running instance, shutting it down cleanly.

Example Audit Log Entry #

{
  "insertId": "-4ov19xe6aqh6",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "20cc77ee-276e-46a3-81f1-f750a8fea0cc"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743758948-65565607a499a-6b0c45b8-83cea4ed",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.stop",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.stop",
    "request": {
      "@type": "type.googleapis.com/compute.instances.stop"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.stop invocation-id/ddebc192be3d4544a6e587e4cd020eca environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:35:59.096605Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "7917026563939318816",
      "insertTime": "2026-06-29T07:35:59.059-07:00",
      "name": "operation-1782743758948-65565607a499a-6b0c45b8-83cea4ed",
      "operationType": "stop",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743758948-65565607a499a-6b0c45b8-83cea4ed",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/7917026563939318816",
      "startTime": "2026-06-29T07:35:59.067-07:00",
      "status": "RUNNING",
      "targetId": "8625152016897752154",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:35:59.365101356Z",
  "resource": {
    "labels": {
      "instance_id": "8625152016897752154",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:35:58.917057Z"
}

compute.instances.suspend: suspend

#
ServiceName
compute.googleapis.com

Description

This method suspends a running instance, saving its state to persistent storage, and allows you to resume the instance at a later time. Suspended instances have no compute costs (cores or RAM), and incur only storage charges for the saved VM memory and localSSD data. Any charged resources the virtual machine was using, such as persistent disks and static IP addresses, will continue to be charged while the instance is suspended. For more information, see Suspending and resuming an instance.

compute.instances.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.instances.update: update

#
ServiceName
compute.googleapis.com

Description

Updates an instance only if the necessary resources are available. This method can update only a specific set of instance properties. See Updating a running instance for a list of updatable instance properties.

compute.instances.updateAccessConfig: updateAccessConfig

#
ServiceName
compute.googleapis.com

Description

Updates the specified access config from an instance's network interface with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.instances.updateDisplayDevice: updateDisplayDevice

#
ServiceName
compute.googleapis.com

Description

Updates the Display config for a VM instance. You can only use this method on a stopped VM instance. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.instances.updateNetworkInterface: updateNetworkInterface

#
ServiceName
compute.googleapis.com

Description

Updates an instance's network interface. This method can only update an interface's alias IP range and attached network. See Modifying alias IP ranges for an existing instance for instructions on changing alias IP ranges. See Migrating a VM between networks for instructions on migrating an interface. This method follows PATCH semantics.

compute.instances.updateShieldedInstanceConfig: updateShieldedInstanceConfig

#
ServiceName
compute.googleapis.com

Description

Updates the Shielded Instance config for an instance. You can only use this method on a stopped instance. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

Example Audit Log Entry #

{
  "insertId": "205zaye7f7vg",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "d945faca-066d-45fa-a95d-5f460f8e9bdd"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instances.updateShieldedInstanceConfig",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
          "service": "compute",
          "type": "compute.instances"
        }
      }
    ],
    "methodName": "v1.compute.instances.updateShieldedInstanceConfig",
    "request": {
      "@type": "type.googleapis.com/compute.instances.updateShieldedInstanceConfig",
      "enableSecureBoot": true
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.update invocation-id/7e4cb1bff7b64c91a0a114dcd73a7db1 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:14:42.614675Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
    "serviceName": "compute.googleapis.com",
    "status": {
      "code": 3,
      "message": "com.google.apps.framework.request.StatusException: <eye3 title='INVALID_ARGUMENT'/> generic::INVALID_ARGUMENT: Instance should be in the STOPPED state."
    }
  },
  "receiveTimestamp": "2026-06-29T15:14:42.770550186Z",
  "resource": {
    "labels": {
      "instance_id": "7874721179023389984",
      "project_id": "example-project-id",
      "zone": "us-central1-a"
    },
    "type": "gce_instance"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T15:14:42.506739Z"
}

compute.instantSnapshotGroups.delete: delete

#
ServiceName
compute.googleapis.com

Description

deletes a Zonal InstantSnapshotGroup resource

compute.instantSnapshotGroups.get: get

#
ServiceName
compute.googleapis.com

Description

returns the specified InstantSnapshotGroup resource in the specified zone.

Data Access audit logs are disabled by default.

compute.instantSnapshotGroups.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.instantSnapshotGroups.insert: insert

#
ServiceName
compute.googleapis.com

Description

inserts a Zonal InstantSnapshotGroup resource

compute.instantSnapshotGroups.list: list

#
ServiceName
compute.googleapis.com

Description

retrieves the list of InstantSnapshotGroup resources contained within the specified zone.

Data Access audit logs are disabled by default.

compute.instantSnapshotGroups.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.instantSnapshotGroups.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.instantSnapshots.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of instantSnapshots. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.instantSnapshots.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified InstantSnapshot resource. Keep in mind that deleting a single instantSnapshot might not necessarily delete all the data on that instantSnapshot. If any data on the instantSnapshot that is marked for deletion is needed for subsequent instantSnapshots, the data will be moved to the next corresponding instantSnapshot. For more information, seeDeleting instantSnapshots.

compute.instantSnapshots.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified InstantSnapshot resource in the specified zone.

Data Access audit logs are disabled by default.

compute.instantSnapshots.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.instantSnapshots.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an instant snapshot in the specified zone.

compute.instantSnapshots.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of InstantSnapshot resources contained within the specified zone.

Data Access audit logs are disabled by default.

compute.instantSnapshots.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.instantSnapshots.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a instantSnapshot in the given zone. To learn more about labels, read the Labeling Resources documentation.

compute.instantSnapshots.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.interconnectAttachmentGroups.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified InterconnectAttachmentGroup in the given scope

compute.interconnectAttachmentGroups.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified InterconnectAttachmentGroup resource in the given scope.

Data Access audit logs are disabled by default.

compute.interconnectAttachmentGroups.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.interconnectAttachmentGroups.getOperationalStatus: getOperationalStatus

#
ServiceName
compute.googleapis.com

Description

Returns the InterconnectAttachmentStatuses for the specified InterconnectAttachmentGroup resource.

Data Access audit logs are disabled by default.

compute.interconnectAttachmentGroups.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a InterconnectAttachmentGroup in the specified project in the given scope using the parameters that are included in the request.

compute.interconnectAttachmentGroups.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the InterconnectAttachmentGroups for a project in the given scope.

Data Access audit logs are disabled by default.

compute.interconnectAttachmentGroups.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified InterconnectAttachmentGroup resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.

compute.interconnectAttachmentGroups.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.interconnectAttachmentGroups.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.interconnectAttachments.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of interconnect attachments. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.interconnectAttachments.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified interconnect attachment.

compute.interconnectAttachments.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified interconnect attachment.

Data Access audit logs are disabled by default.

compute.interconnectAttachments.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an InterconnectAttachment in the specified project using the data included in the request.

compute.interconnectAttachments.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of interconnect attachments contained within the specified region.

Data Access audit logs are disabled by default.

compute.interconnectAttachments.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified interconnect attachment with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.interconnectAttachments.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on an InterconnectAttachment. To learn more about labels, read the Labeling Resources documentation.

compute.interconnectGroups.createMembers: createMembers

#
ServiceName
compute.googleapis.com

Description

Create Interconnects with redundancy by creating them in a specified interconnect group.

compute.interconnectGroups.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified InterconnectGroup in the given scope

compute.interconnectGroups.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified InterconnectGroup resource in the given scope.

Data Access audit logs are disabled by default.

compute.interconnectGroups.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.interconnectGroups.getOperationalStatus: getOperationalStatus

#
ServiceName
compute.googleapis.com

Description

Returns the interconnectStatuses for the specified InterconnectGroup.

Data Access audit logs are disabled by default.

compute.interconnectGroups.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a InterconnectGroup in the specified project in the given scope using the parameters that are included in the request.

compute.interconnectGroups.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the InterconnectGroups for a project in the given scope.

Data Access audit logs are disabled by default.

compute.interconnectGroups.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified InterconnectGroup resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.

compute.interconnectGroups.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.interconnectGroups.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.interconnectLocations.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the details for the specified interconnect location. Gets a list of available interconnect locations by making a list() request.

Data Access audit logs are disabled by default.

compute.interconnectLocations.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of interconnect locations available to the specified project.

Data Access audit logs are disabled by default.

compute.interconnectRemoteLocations.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the details for the specified interconnect remote location. Gets a list of available interconnect remote locations by making alist() request.

Data Access audit logs are disabled by default.

compute.interconnectRemoteLocations.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of interconnect remote locations available to the specified project.

Data Access audit logs are disabled by default.

compute.interconnects.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified Interconnect.

compute.interconnects.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified Interconnect. Get a list of available Interconnects by making a list() request.

Data Access audit logs are disabled by default.

compute.interconnects.getDiagnostics: getDiagnostics

#
ServiceName
compute.googleapis.com

Description

Returns the interconnectDiagnostics for the specified Interconnect. In the event of a global outage, do not use this API to make decisions about where to redirect your network traffic. Unlike a VLAN attachment, which is regional, a Cloud Interconnect connection is a global resource. A global outage can prevent this API from functioning properly.

Data Access audit logs are disabled by default.

compute.interconnects.getMacsecConfig: getMacsecConfig

#
ServiceName
compute.googleapis.com

Description

Returns the interconnectMacsecConfig for the specified Interconnect.

Data Access audit logs are disabled by default.

compute.interconnects.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an Interconnect in the specified project using the data included in the request.

compute.interconnects.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of Interconnects available to the specified project.

Data Access audit logs are disabled by default.

compute.interconnects.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified Interconnect with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.interconnects.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on an Interconnect. To learn more about labels, read the Labeling Resources documentation.

compute.licenseCodes.get: get

#
ServiceName
compute.googleapis.com

Description

Return a specified license code. License codes are mirrored across all projects that have permissions to read the License Code. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

Data Access audit logs are disabled by default.

compute.licenseCodes.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

Data Access audit logs are disabled by default.

compute.licenseCodes.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

compute.licenseCodes.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

Data Access audit logs are disabled by default.

compute.licenses.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified license. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

compute.licenses.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified License resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

Data Access audit logs are disabled by default.

compute.licenses.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

Data Access audit logs are disabled by default.

compute.licenses.insert: insert

#
ServiceName
compute.googleapis.com

Description

Create a License resource in the specified project. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

compute.licenses.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of licenses available in the specified project. This method does not get any licenses that belong to other projects, including licenses attached to publicly-available images, like Debian 9. If you want to get a list of publicly-available licenses, use this method to make a request to the respective image project, such as debian-cloud orwindows-cloud. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

Data Access audit logs are disabled by default.

compute.licenses.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

compute.licenses.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

Data Access audit logs are disabled by default.

compute.licenses.update: update

#
ServiceName
compute.googleapis.com

Description

Updates a License resource in the specified project. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.

compute.machineImages.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified machine image. Deleting a machine image is permanent and cannot be undone.

compute.machineImages.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified machine image.

Data Access audit logs are disabled by default.

compute.machineImages.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.machineImages.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a machine image in the specified project using the data that is included in the request. If you are creating a new machine image to update an existing instance, your new machine image should use the same network or, if applicable, the same subnetwork as the original instance.

compute.machineImages.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of machine images that are contained within the specified project.

Data Access audit logs are disabled by default.

compute.machineImages.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.machineImages.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a machine image. To learn more about labels, read theLabeling Resources documentation.

compute.machineImages.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.machineTypes.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of machine types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-1dujd6e82pik",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "4fccf947-da17-489c-942a-ee9c28f393a7"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.machineTypes.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.machineTypes.aggregatedList",
    "numResponseItems": "174",
    "request": {
      "@type": "type.googleapis.com/compute.machineTypes.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.machine-types.list invocation-id/e886be2aae2c4fd093fbe0707c3bfc99 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:38.745828Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/machineTypes",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:39.007032476Z",
  "resource": {
    "labels": {
      "method": "compute.machineTypes.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com"
    },
    "type": "audited_resource"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:38.489101Z"
}

compute.machineTypes.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified machine type.

Data Access audit logs are disabled by default.

compute.machineTypes.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of machine types available to the specified project.

Data Access audit logs are disabled by default.

compute.networkAttachments.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all NetworkAttachment resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "jg2adgdeaxe",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "f112729a-b4f8-49c1-b95e-830a686d0cc2"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.networkAttachments.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.networkAttachments.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.networkAttachments.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.network-attachments.list invocation-id/5f8a323239a245f8bd650dc406fecc7f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:37:21.932350Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/networkAttachments",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:37:22.783706353Z",
  "resource": {
    "labels": {
      "method": "compute.networkAttachments.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com"
    },
    "type": "audited_resource"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T15:37:21.764309Z"
}

compute.networkAttachments.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified NetworkAttachment in the given scope

compute.networkAttachments.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified NetworkAttachment resource in the given scope.

Data Access audit logs are disabled by default.

compute.networkAttachments.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.networkAttachments.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a NetworkAttachment in the specified project in the given scope using the parameters that are included in the request.

compute.networkAttachments.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the NetworkAttachments for a project in the given scope.

Data Access audit logs are disabled by default.

compute.networkAttachments.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified NetworkAttachment resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.

compute.networkAttachments.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.networkAttachments.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.networkEdgeSecurityServices.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all NetworkEdgeSecurityService resources available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.networkEdgeSecurityServices.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified service.

compute.networkEdgeSecurityServices.get: get

#
ServiceName
compute.googleapis.com

Description

Gets a specified NetworkEdgeSecurityService.

Data Access audit logs are disabled by default.

compute.networkEdgeSecurityServices.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new service in the specified project using the data included in the request.

compute.networkEdgeSecurityServices.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified policy with the data included in the request.

compute.networkEndpointGroups.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of network endpoint groups and sorts them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-k7y0nbe548ny",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9e04a39a-16f1-44ff-a78c-6752232ea4e5"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.networkEndpointGroups.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.networkEndpointGroups.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.networkEndpointGroups.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.network-endpoint-groups.list invocation-id/6e13d01c96994bc4afa24167a350e74a environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:51.977958Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/networkEndpointGroups",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:52.400218554Z",
  "resource": {
    "labels": {
      "network_id": "",
      "project_id": "example-project-id"
    },
    "type": "gce_network"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:51.895857Z"
}

compute.networkEndpointGroups.attachNetworkEndpoints: attachNetworkEndpoints

#
ServiceName
compute.googleapis.com

Description

Attach a list of network endpoints to the specified network endpoint group.

compute.networkEndpointGroups.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified network endpoint group. The network endpoints in the NEG and the VM instances they belong to are not terminated when the NEG is deleted. Note that the NEG cannot be deleted if there are backend services referencing it.

Example Audit Log Entry #

{
  "insertId": "-xi95u4dngjq",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "8c5d3f0e-47db-413a-8de4-8d57f45fd9de"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782747011019-655662250f4d6-5cc50f10-1982011f",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.networkEndpointGroups.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
          "service": "compute",
          "type": "compute.networkEndpointGroups"
        }
      }
    ],
    "methodName": "v1.compute.networkEndpointGroups.delete",
    "request": {
      "@type": "type.googleapis.com/compute.networkEndpointGroups.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.network-endpoint-groups.delete invocation-id/51e420b32ad64f02a666a5938e138619 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:30:11.273389Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "4338565224294461804",
      "insertTime": "2026-06-29T08:30:11.231-07:00",
      "name": "operation-1782747011019-655662250f4d6-5cc50f10-1982011f",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782747011019-655662250f4d6-5cc50f10-1982011f",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/4338565224294461804",
      "startTime": "2026-06-29T08:30:11.234-07:00",
      "status": "RUNNING",
      "targetId": "7803364244475293840",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:30:12.109634471Z",
  "resource": {
    "labels": {
      "network_id": "7803364244475293840",
      "project_id": "example-project-id"
    },
    "type": "gce_network"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:30:11.092254Z"
}

compute.networkEndpointGroups.detachNetworkEndpoints: detachNetworkEndpoints

#
ServiceName
compute.googleapis.com

Description

Detach a list of network endpoints from the specified network endpoint group.

compute.networkEndpointGroups.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified network endpoint group.

Data Access audit logs are disabled by default.

compute.networkEndpointGroups.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global API

Example Audit Log Entry #

{
  "insertId": "64bq3re1qiis",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "bb8fa697-4d82-4999-bd56-690f3a3327df"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746750858-6556612cf33b9-6c2eb5eb-743b7c3c",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.networkEndpointGroups.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
          "service": "compute",
          "type": "compute.networkEndpointGroups"
        }
      },
      {
        "granted": true,
        "permission": "compute.subnetworks.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      }
    ],
    "methodName": "v1.compute.networkEndpointGroups.insert",
    "request": {
      "@type": "type.googleapis.com/compute.networkEndpointGroups.insert",
      "name": "dwn4-dw745960",
      "network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn4-dw745960",
      "networkEndpointType": "GCE_VM_IP_PORT",
      "subnetwork": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.network-endpoint-groups.create invocation-id/828354231b78464fb10d8b7394a916cc environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:25:51.399857Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "7407171911059189904",
      "insertTime": "2026-06-29T08:25:51.365-07:00",
      "name": "operation-1782746750858-6556612cf33b9-6c2eb5eb-743b7c3c",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746750858-6556612cf33b9-6c2eb5eb-743b7c3c",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/7407171911059189904",
      "startTime": "2026-06-29T08:25:51.369-07:00",
      "status": "RUNNING",
      "targetId": "7803364244475293840",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:25:51.678512110Z",
  "resource": {
    "labels": {
      "network_id": "7803364244475293840",
      "project_id": "example-project-id"
    },
    "type": "gce_network"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:25:50.910626Z"
}

compute.networkEndpointGroups.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of network endpoint groups that are located in the specified project and zone.

Data Access audit logs are disabled by default.

compute.networkEndpointGroups.listNetworkEndpoints: listNetworkEndpoints

#
ServiceName
compute.googleapis.com

Description

Lists the network endpoints in the specified network endpoint group.

Data Access audit logs are disabled by default.

compute.networkEndpointGroups.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.networkFirewallPolicies.addAssociation: addAssociation

#
ServiceName
compute.googleapis.com

Description

Inserts an association for the specified firewall policy.

compute.networkFirewallPolicies.addPacketMirroringRule: addPacketMirroringRule

#
ServiceName
compute.googleapis.com

Description

Inserts a packet mirroring rule into a firewall policy.

compute.networkFirewallPolicies.addRule: addRule

#
ServiceName
compute.googleapis.com

Description

Inserts a rule into a firewall policy.

compute.networkFirewallPolicies.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of network firewall policies, listing network firewall policies from all applicable scopes (global and regional) and grouping the results per scope. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.networkFirewallPolicies.cloneRules: cloneRules

#
ServiceName
compute.googleapis.com

Description

Copies rules to the specified firewall policy.

compute.networkFirewallPolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified policy.

compute.networkFirewallPolicies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified network firewall policy.

Data Access audit logs are disabled by default.

compute.networkFirewallPolicies.getAssociation: getAssociation

#
ServiceName
compute.googleapis.com

Description

Gets an association with the specified name.

Data Access audit logs are disabled by default.

compute.networkFirewallPolicies.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.networkFirewallPolicies.getPacketMirroringRule: getPacketMirroringRule

#
ServiceName
compute.googleapis.com

Description

Gets a packet mirroring rule of the specified priority.

Data Access audit logs are disabled by default.

compute.networkFirewallPolicies.getRule: getRule

#
ServiceName
compute.googleapis.com

Description

Gets a rule of the specified priority.

Data Access audit logs are disabled by default.

compute.networkFirewallPolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new policy in the specified project using the data included in the request.

compute.networkFirewallPolicies.list: list

#
ServiceName
compute.googleapis.com

Description

Lists all the policies that have been configured for the specified project.

Data Access audit logs are disabled by default.

compute.networkFirewallPolicies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified policy with the data included in the request.

compute.networkFirewallPolicies.patchPacketMirroringRule: patchPacketMirroringRule

#
ServiceName
compute.googleapis.com

Description

Patches a packet mirroring rule of the specified priority.

compute.networkFirewallPolicies.patchRule: patchRule

#
ServiceName
compute.googleapis.com

Description

Patches a rule of the specified priority.

compute.networkFirewallPolicies.removeAssociation: removeAssociation

#
ServiceName
compute.googleapis.com

Description

Removes an association for the specified firewall policy.

compute.networkFirewallPolicies.removePacketMirroringRule: removePacketMirroringRule

#
ServiceName
compute.googleapis.com

Description

Deletes a packet mirroring rule of the specified priority.

compute.networkFirewallPolicies.removeRule: removeRule

#
ServiceName
compute.googleapis.com

Description

Deletes a rule of the specified priority.

compute.networkFirewallPolicies.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.networkFirewallPolicies.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.networkProfiles.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified network profile.

Data Access audit logs are disabled by default.

compute.networkProfiles.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of network profiles available to the specified project.

Data Access audit logs are disabled by default.

compute.networks.addPeering: addPeering

#
ServiceName
compute.googleapis.com

Description

Adds a peering to the specified network.

Example Audit Log Entry #

{
  "insertId": "swl1e8do8be",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "57ee88c9-d544-45be-99c8-588c6fd6abe4"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746058046-65565e983bbe0-bfbc59ed-46cbb925",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.networks.addPeering",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/dwn4-dw745960",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.networks.addPeering",
    "request": {
      "@type": "type.googleapis.com/compute.networks.addPeering",
      "networkPeering": {
        "exchangeSubnetRoutes": true,
        "name": "dwpeer-dw745960",
        "network": "projects/example-project-id/global/networks/dwn4-dw745960b"
      }
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.peerings.create invocation-id/6f98affa682140c5b259b9c06bdd7231 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:14:18.622865Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/networks/dwn4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "1873623054340273445",
      "insertTime": "2026-06-29T08:14:18.506-07:00",
      "name": "operation-1782746058046-65565e983bbe0-bfbc59ed-46cbb925",
      "operationType": "addPeering",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782746058046-65565e983bbe0-bfbc59ed-46cbb925",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/1873623054340273445",
      "startTime": "2026-06-29T08:14:18.512-07:00",
      "status": "RUNNING",
      "targetId": "5998021114363590006",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn4-dw745960",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:14:19.321410593Z",
  "resource": {
    "labels": {
      "network_id": "5998021114363590006",
      "project_id": "example-project-id"
    },
    "type": "gce_network"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:14:18.133068Z"
}

compute.networks.cancelRequestRemovePeering: cancelRequestRemovePeering

#
ServiceName
compute.googleapis.com

Description

Cancel requests to remove a peering from the specified network. Applicable only for PeeringConnection with update_strategy=CONSENSUS. Cancels a request to remove a peering from the specified network.

compute.networks.delete: Delete network

#
ServiceName
compute.googleapis.com

Description

Deletes the specified network.

Example Audit Log Entry #

{
  "insertId": "-nagnkyd7u2c",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "bbc34177-c63e-4b25-b5cb-6b1f6ced00bb"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782747031605-65566238b0fc0-1b4af7a4-1abf6c3c",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.networks.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/dwn4-dw745960b",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/dwn4-dw745960b",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.networks.delete",
    "request": {
      "@type": "type.googleapis.com/compute.networks.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.delete invocation-id/299cef3c715d4158a4219838ef2b2401 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:30:32.042641Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/networks/dwn4-dw745960b",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "1851171834354938232",
      "insertTime": "2026-06-29T08:30:31.874-07:00",
      "name": "operation-1782747031605-65566238b0fc0-1b4af7a4-1abf6c3c",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782747031605-65566238b0fc0-1b4af7a4-1abf6c3c",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/1851171834354938232",
      "startTime": "2026-06-29T08:30:31.879-07:00",
      "status": "RUNNING",
      "targetId": "7566947103947044178",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn4-dw745960b",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:30:32.626677364Z",
  "resource": {
    "labels": {
      "network_id": "7566947103947044178",
      "project_id": "example-project-id"
    },
    "type": "gce_network"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:30:31.655236Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • GCP Virtual Private Cloud Network Deletion source medium: Identifies when a Virtual Private Cloud (VPC) network is deleted in Google Cloud Platform (GCP). A VPC network is a virtual version of a physical network within a GCP project. Each VPC network has its own subnets, routes, and firewall, as well as other elements. An adversary may delete a VPC network in order to disrupt their target's network and business operations.T1485, T1562, T1562.007

compute.networks.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified network.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-e4v3uue6k7h4",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "3e10409f-6f55-402d-8756-9275f9c6e9b6"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.networks.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/networks/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/dwgen-dw739065",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.networks.get",
    "request": {
      "@type": "type.googleapis.com/compute.networks.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.create invocation-id/4ffe3c8ff74e4802bb2de389b3abfd97 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:22.443917Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/networks/dwgen-dw739065",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:23.016580549Z",
  "resource": {
    "labels": {
      "network_id": "7671908098842284004",
      "project_id": "example-project-id"
    },
    "type": "gce_network"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:20:22.333850Z"
}

compute.networks.getEffectiveFirewalls: getEffectiveFirewalls

#
ServiceName
compute.googleapis.com

Description

Returns the effective firewalls on a given network.

Data Access audit logs are disabled by default.

compute.networks.insert: Insert network

#
ServiceName
compute.googleapis.com

Description

Creates a network in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-fr5a60dbv3a",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "566f4e3e-4778-4185-b608-f9cc91a81118"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.networks.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/dwgen-dw739065",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.networks.insert",
    "request": {
      "@type": "type.googleapis.com/compute.networks.insert",
      "autoCreateSubnetworks": false,
      "name": "dwgen-dw739065",
      "routingConfig": {
        "routingMode": "REGIONAL"
      }
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.create invocation-id/4ffe3c8ff74e4802bb2de389b3abfd97 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:12.125945Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/networks/dwgen-dw739065",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "6594312761464836068",
      "insertTime": "2026-06-29T06:20:11.961-07:00",
      "name": "operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/6594312761464836068",
      "startTime": "2026-06-29T06:20:11.965-07:00",
      "status": "RUNNING",
      "targetId": "7671908098842284004",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwgen-dw739065",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:12.928400261Z",
  "resource": {
    "labels": {
      "network_id": "7671908098842284004",
      "project_id": "example-project-id"
    },
    "type": "gce_network"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T13:20:11.709111Z"
}

compute.networks.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of networks available to the specified project.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-gm52fddl6t8",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "855573e7-3d5c-48eb-b3ba-dc5081dd99a3"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.networks.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.networks.list",
    "numResponseItems": "1",
    "request": {
      "@type": "type.googleapis.com/compute.networks.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.list invocation-id/bf953e2e98db48dbbb5a5a2e83bc37c8 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:24.064659Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/networks",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:24.920445819Z",
  "resource": {
    "labels": {
      "network_id": "",
      "project_id": "example-project-id"
    },
    "type": "gce_network"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:23.877108Z"
}

compute.networks.listPeeringRoutes: listPeeringRoutes

#
ServiceName
compute.googleapis.com

Description

Lists the peering routes exchanged over peering connection.

Data Access audit logs are disabled by default.

compute.networks.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified network with the data included in the request. Only routingConfig can be modified.

compute.networks.removePeering: removePeering

#
ServiceName
compute.googleapis.com

Description

Removes a peering from the specified network.

Example Audit Log Entry #

{
  "insertId": "-4ocutgdnh8u",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "cd9572bf-faef-4718-9442-86c762e7479e"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746987347-6556620e7bc5c-2a4d935a-4d1f9c95",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.networks.removePeering",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/dwn4-dw745960",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.networks.removePeering",
    "request": {
      "@type": "type.googleapis.com/compute.networks.removePeering",
      "name": "dwpeer-dw745960"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.peerings.delete invocation-id/d8698bae2b5c4336a93609946ee302df environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:29:47.850685Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/networks/dwn4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "4418389987514331524",
      "insertTime": "2026-06-29T08:29:47.682-07:00",
      "name": "operation-1782746987347-6556620e7bc5c-2a4d935a-4d1f9c95",
      "operationType": "removePeering",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782746987347-6556620e7bc5c-2a4d935a-4d1f9c95",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/4418389987514331524",
      "startTime": "2026-06-29T08:29:47.685-07:00",
      "status": "RUNNING",
      "targetId": "5998021114363590006",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn4-dw745960",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:29:48.515057058Z",
  "resource": {
    "labels": {
      "network_id": "5998021114363590006",
      "project_id": "example-project-id"
    },
    "type": "gce_network"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:29:47.453854Z"
}

compute.networks.requestRemovePeering: requestRemovePeering

#
ServiceName
compute.googleapis.com

Description

Requests to remove a peering from the specified network. Applicable only for PeeringConnection with update_strategy=CONSENSUS.

compute.networks.switchToCustomMode: switchToCustomMode

#
ServiceName
compute.googleapis.com

Description

Switches the network mode from auto subnet mode to custom subnet mode.

compute.networks.updatePeering: updatePeering

#
ServiceName
compute.googleapis.com

Description

Updates the specified network peering with the data included in the request. You can only modify the NetworkPeering.export_custom_routes field and the NetworkPeering.import_custom_routes field.

compute.nodeGroups.addNodes: addNodes

#
ServiceName
compute.googleapis.com

Description

Adds specified number of nodes to the node group.

compute.nodeGroups.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of node groups. Note: use nodeGroups.listNodes for more details about each group. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.nodeGroups.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified NodeGroup resource.

compute.nodeGroups.deleteNodes: deleteNodes

#
ServiceName
compute.googleapis.com

Description

Deletes specified nodes from the node group.

compute.nodeGroups.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified NodeGroup. Get a list of available NodeGroups by making a list() request. Note: the "nodes" field should not be used. Use nodeGroups.listNodes instead.

Data Access audit logs are disabled by default.

compute.nodeGroups.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.nodeGroups.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a NodeGroup resource in the specified project using the data included in the request.

compute.nodeGroups.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of node groups available to the specified project. Note: use nodeGroups.listNodes for more details about each group.

Data Access audit logs are disabled by default.

compute.nodeGroups.listNodes: listNodes

#
ServiceName
compute.googleapis.com

Description

Lists nodes in the node group.

Data Access audit logs are disabled by default.

compute.nodeGroups.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified node group.

compute.nodeGroups.performMaintenance: performMaintenance

#
ServiceName
compute.googleapis.com

Description

Perform maintenance on a subset of nodes in the node group.

compute.nodeGroups.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.nodeGroups.setNodeTemplate: setNodeTemplate

#
ServiceName
compute.googleapis.com

Description

Updates the node template of the node group.

compute.nodeGroups.simulateMaintenanceEvent: simulateMaintenanceEvent

#
ServiceName
compute.googleapis.com

Description

Simulates maintenance event on specified nodes from the node group.

compute.nodeGroups.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.nodeTemplates.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of node templates. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.nodeTemplates.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified NodeTemplate resource.

compute.nodeTemplates.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified node template.

Data Access audit logs are disabled by default.

compute.nodeTemplates.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.nodeTemplates.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a NodeTemplate resource in the specified project using the data included in the request.

compute.nodeTemplates.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of node templates available to the specified project.

Data Access audit logs are disabled by default.

compute.nodeTemplates.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.nodeTemplates.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.nodeTypes.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of node types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.nodeTypes.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified node type.

Data Access audit logs are disabled by default.

compute.nodeTypes.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of node types available to the specified project.

Data Access audit logs are disabled by default.

compute.organizationSecurityPolicies.addAssociation: addAssociation

#
ServiceName
compute.googleapis.com

Description

Inserts an association for the specified security policy. This has billing implications. Projects in the hierarchy with effective hierarchical security policies will be automatically enrolled into Cloud Armor Enterprise if not already enrolled. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.addAssociation instead.

compute.organizationSecurityPolicies.addRule: addRule

#
ServiceName
compute.googleapis.com

Description

Inserts a rule into a security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.addRule instead.

compute.organizationSecurityPolicies.copyRules: copyRules

#
ServiceName
compute.googleapis.com

Description

Copies rules to the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.cloneRules instead.

compute.organizationSecurityPolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified policy. Use this API to remove Cloud Armor policies. Previously, alpha and beta versions of this API were used to remove firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.delete instead.

compute.organizationSecurityPolicies.get: get

#
ServiceName
compute.googleapis.com

Description

List all of the ordered rules present in a single specified policy. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.get instead.

Data Access audit logs are disabled by default.

compute.organizationSecurityPolicies.getAssociation: getAssociation

#
ServiceName
compute.googleapis.com

Description

Gets an association with the specified name. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.getAssociation instead.

Data Access audit logs are disabled by default.

compute.organizationSecurityPolicies.getRule: getRule

#
ServiceName
compute.googleapis.com

Description

Gets a rule at the specified priority. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.getRule instead.

Data Access audit logs are disabled by default.

compute.organizationSecurityPolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new policy in the specified organization using the data included in the request. Use this API to add Cloud Armor policies. Previously, alpha and beta versions of this API were used to add firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.insert instead.

compute.organizationSecurityPolicies.list: list

#
ServiceName
compute.googleapis.com

Description

List all the policies that have been configured for the specified organization. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.list instead.

Data Access audit logs are disabled by default.

compute.organizationSecurityPolicies.listAssociations: listAssociations

#
ServiceName
compute.googleapis.com

Description

Lists associations of a specified target, i.e., organization or folder. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.listAssociations instead.

Data Access audit logs are disabled by default.

compute.organizationSecurityPolicies.listPreconfiguredExpressionSets: listPreconfiguredExpressionSets

#
ServiceName
compute.googleapis.com

Description

Gets the current list of preconfigured Web Application Firewall (WAF) expressions.

Data Access audit logs are disabled by default.

compute.organizationSecurityPolicies.move: move

#
ServiceName
compute.googleapis.com

Description

Moves the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.move instead.

compute.organizationSecurityPolicies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified policy with the data included in the request. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.patch instead.

compute.organizationSecurityPolicies.patchRule: patchRule

#
ServiceName
compute.googleapis.com

Description

Patches a rule at the specified priority. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.patchRule instead.

compute.organizationSecurityPolicies.removeAssociation: removeAssociation

#
ServiceName
compute.googleapis.com

Description

Removes an association for the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.removeAssociation instead.

compute.organizationSecurityPolicies.removeRule: removeRule

#
ServiceName
compute.googleapis.com

Description

Deletes a rule at the specified priority. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.removeRule instead.

compute.packetMirrorings.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of packetMirrorings. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "9pwzume1ynmy",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "ee17f931-057e-4a18-bb35-5b76758edef9"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.packetMirrorings.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.packetMirrorings.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.packetMirrorings.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.list invocation-id/12a11e65a9734e288f42ced4ac87959f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:37:23.884617Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/packetMirrorings",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:37:24.601686865Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.packetMirrorings.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T15:37:23.786228Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

compute.packetMirrorings.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified PacketMirroring resource.

Example Audit Log Entry #

{
  "insertId": "6fkv3oe8ix0q",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "721c42a7-3d22-4d7d-9aab-2f830c6d7e1d"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750573622-65566f6a9f549-542a1129-6e0b02dc",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.packetMirrorings.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
          "service": "compute",
          "type": "compute.packetMirrorings"
        }
      }
    ],
    "methodName": "v1.compute.packetMirrorings.delete",
    "request": {
      "@type": "type.googleapis.com/compute.packetMirrorings.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.delete invocation-id/648641e189024ef68ee97594d0066733 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:29:33.796222Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "7757216706370413442",
      "insertTime": "2026-06-29T09:29:33.742-07:00",
      "name": "operation-1782750573622-65566f6a9f549-542a1129-6e0b02dc",
      "operationType": "delete",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750573622-65566f6a9f549-542a1129-6e0b02dc",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/7757216706370413442",
      "startTime": "2026-06-29T09:29:33.754-07:00",
      "status": "RUNNING",
      "targetId": "5883760359926342587",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:29:33.918274137Z",
  "resource": {
    "labels": {
      "packet_mirroring_id": "5883760359926342587",
      "project_id": "example-project-id",
      "region": "us-central1"
    },
    "type": "gce_packet_mirroring"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:29:33.585710Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

compute.packetMirrorings.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified PacketMirroring resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-6n8gzve2y5xo",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a3476c5e-deb3-4197-946a-7a9c08ffbe05"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.packetMirrorings.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
          "service": "compute",
          "type": "compute.packetMirrorings"
        }
      }
    ],
    "methodName": "v1.compute.packetMirrorings.get",
    "request": {
      "@type": "type.googleapis.com/compute.packetMirrorings.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.update invocation-id/909c1465c63c451aa5009abeb4a6ee3b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:29:32.263379Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:29:32.414511169Z",
  "resource": {
    "labels": {
      "packet_mirroring_id": "5883760359926342587",
      "project_id": "example-project-id",
      "region": "us-central1"
    },
    "type": "gce_packet_mirroring"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:29:32.207427Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

compute.packetMirrorings.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a PacketMirroring resource in the specified project and region using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "p91rdme7do96",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "00b92107-2c5f-40b1-82c6-23dbfc0c2df3"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750548249-65566f526ca8c-4ad47fd8-d63cd051",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.packetMirrorings.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
          "service": "compute",
          "type": "compute.packetMirrorings"
        }
      },
      {
        "granted": true,
        "permission": "compute.forwardingRules.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061",
          "service": "compute",
          "type": "compute.forwardingRules"
        }
      },
      {
        "granted": true,
        "permission": "compute.subnetworks.mirror",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      }
    ],
    "methodName": "v1.compute.packetMirrorings.insert",
    "request": {
      "@type": "type.googleapis.com/compute.packetMirrorings.insert",
      "collectorIlb": {
        "url": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061"
      },
      "enable": "TRUE",
      "mirroredResources": {
        "subnetworks": [
          {
            "url": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061"
          }
        ]
      },
      "name": "dwpm7b671061",
      "network": {
        "url": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn7b671061"
      }
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.create invocation-id/b20d4da1176b48d4973146e22e4c4fa6 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:29:08.563964Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "6865284541681968059",
      "insertTime": "2026-06-29T09:29:08.421-07:00",
      "name": "operation-1782750548249-65566f526ca8c-4ad47fd8-d63cd051",
      "operationType": "insert",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750548249-65566f526ca8c-4ad47fd8-d63cd051",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/6865284541681968059",
      "startTime": "2026-06-29T09:29:08.425-07:00",
      "status": "RUNNING",
      "targetId": "5883760359926342587",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:29:08.665374197Z",
  "resource": {
    "labels": {
      "packet_mirroring_id": "5883760359926342587",
      "project_id": "example-project-id",
      "region": "us-central1"
    },
    "type": "gce_packet_mirroring"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:29:08.217873Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

compute.packetMirrorings.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of PacketMirroring resources available to the specified project and region.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-wgflnle2gvf0",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "2d39a0f6-15fe-424f-8df7-fac0980c12bf"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.packetMirrorings.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.packetMirrorings.list",
    "numResponseItems": "1",
    "request": {
      "@type": "type.googleapis.com/compute.packetMirrorings.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.list invocation-id/42567f1762b5484798b4f5f11663e269 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:29:22.645628Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/packetMirrorings",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:29:23.175555774Z",
  "resource": {
    "labels": {
      "packet_mirroring_id": "",
      "project_id": "example-project-id",
      "region": "us-central1"
    },
    "type": "gce_packet_mirroring"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:29:22.578243Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

compute.packetMirrorings.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified PacketMirroring resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.

Example Audit Log Entry #

{
  "insertId": "1g9dnwe50pay",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "fb2682a3-c230-46ff-9ae0-c92e95b46f2a"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750564824-65566f623b6c9-4a5ccf5f-22efac3c",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.packetMirrorings.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
          "service": "compute",
          "type": "compute.packetMirrorings"
        }
      },
      {
        "granted": true,
        "permission": "compute.packetMirrorings.update",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
          "service": "compute",
          "type": "compute.packetMirrorings"
        }
      },
      {
        "granted": true,
        "permission": "compute.forwardingRules.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061",
          "service": "compute",
          "type": "compute.forwardingRules"
        }
      },
      {
        "granted": true,
        "permission": "compute.subnetworks.mirror",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      }
    ],
    "methodName": "v1.compute.packetMirrorings.patch",
    "request": {
      "@type": "type.googleapis.com/compute.packetMirrorings.patch",
      "collectorIlb": {
        "url": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061"
      },
      "enable": "FALSE",
      "filter": {
        "direction": "BOTH"
      },
      "mirroredResources": {
        "subnetworks": [
          {
            "url": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061"
          }
        ]
      },
      "name": "dwpm7b671061",
      "network": {
        "url": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn7b671061"
      },
      "priority": "1000",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.update invocation-id/909c1465c63c451aa5009abeb4a6ee3b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:29:25.272499Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "7232922343376364426",
      "insertTime": "2026-06-29T09:29:25.096-07:00",
      "name": "operation-1782750564824-65566f623b6c9-4a5ccf5f-22efac3c",
      "operationType": "patch",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750564824-65566f623b6c9-4a5ccf5f-22efac3c",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/7232922343376364426",
      "startTime": "2026-06-29T09:29:25.113-07:00",
      "status": "RUNNING",
      "targetId": "5883760359926342587",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:29:25.572437637Z",
  "resource": {
    "labels": {
      "packet_mirroring_id": "5883760359926342587",
      "project_id": "example-project-id",
      "region": "us-central1"
    },
    "type": "gce_packet_mirroring"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:29:24.786248Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

compute.packetMirrorings.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.previewFeatures.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the details of the given PreviewFeature.

Data Access audit logs are disabled by default.

compute.previewFeatures.list: list

#
ServiceName
compute.googleapis.com

Description

Returns the details of the given PreviewFeature.

Data Access audit logs are disabled by default.

compute.previewFeatures.update: update

#
ServiceName
compute.googleapis.com

Description

Patches the given PreviewFeature. This method is used to enable or disable a PreviewFeature.

compute.projects.disableXpnHost: disableXpnHost

#
ServiceName
compute.googleapis.com

Description

Disable this project as a shared VPC host project.

compute.projects.disableXpnResource: disableXpnResource

#
ServiceName
compute.googleapis.com

Description

Disable a service resource (also known as service project) associated with this host project.

compute.projects.enableXpnHost: enableXpnHost

#
ServiceName
compute.googleapis.com

Description

Enable this project as a shared VPC host project.

compute.projects.enableXpnResource: enableXpnResource

#
ServiceName
compute.googleapis.com

Description

Enable service resource (a.k.a service project) for a host project, so that subnets in the host project can be used by instances in the service project.

compute.projects.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified Project resource. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-7h2u9de25o6a",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "4b7d3ecc-01de-43f1-a0fb-cd317550139e"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.projects.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "compute",
          "type": "compute.projects"
        }
      }
    ],
    "methodName": "v1.compute.projects.get",
    "request": {
      "@type": "type.googleapis.com/compute.projects.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.project-info.describe invocation-id/be8c61d7c6b24697a507bc7327b66878 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:05.918295Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:19:06.055587708Z",
  "resource": {
    "labels": {
      "project_id": "000000000000"
    },
    "type": "gce_project"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:19:05.720255Z"
}

compute.projects.getXpnHost: getXpnHost

#
ServiceName
compute.googleapis.com

Description

Gets the shared VPC host project that this project links to. May be empty if no link exists.

Data Access audit logs are disabled by default.

compute.projects.getXpnResources: getXpnResources

#
ServiceName
compute.googleapis.com

Description

Gets service resources (a.k.a service project) associated with this host project.

Data Access audit logs are disabled by default.

compute.projects.listXpnHosts: listXpnHosts

#
ServiceName
compute.googleapis.com

Description

Lists all shared VPC host projects visible to the user in an organization.

Data Access audit logs are disabled by default.

compute.projects.moveDisk: moveDisk

#
ServiceName
compute.googleapis.com

Description

Moves a persistent disk from one zone to another. *Note*: The moveDisk API will be deprecated on September 29, 2026. Starting September 29, 2025, you can't use the moveDisk API on new projects. To move a disk to a different region or zone, follow the steps in Change the location of a disk. Projects that already use the moveDisk API can continue usage until September 29, 2026. Starting November 1, 2025, API responses will include a warning message in the response body about the upcoming deprecation. You can skip the message to continue using the service without interruption.

compute.projects.moveInstance: moveInstance

#
ServiceName
compute.googleapis.com

Description

Moves an instance and its attached persistent disks from one zone to another. *Note*: Moving VMs or disks by using this method might cause unexpected behavior. For more information, see the known issue. [Deprecated] This method is deprecated. See moving instance across zones instead.

compute.projects.setCloudArmorTier: setCloudArmorTier

#
ServiceName
compute.googleapis.com

Description

Sets the Cloud Armor tier of the project. To set ENTERPRISE or above the billing account of the project must be subscribed to Cloud Armor Enterprise. See Subscribing to Cloud Armor Enterprise for more information.

Example Audit Log Entry #

{
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "user@domain.com"
    },
    "requestMetadata": {
      "callerIp": "8.8.8.8",
      "callerSuppliedUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.36,gzip(gfe),gzip(gfe)",
      "requestAttributes": {
        "time": "2021-09-13T02:52:16.762326Z",
        "auth": {}
      },
      "destinationAttributes": {}
    },
    "serviceName": "compute.googleapis.com",
    "methodName": "v1.compute.projects.setCommonInstanceMetadata",
    "authorizationInfo": [
      {
        "permission": "compute.projects.setCommonInstanceMetadata",
        "granted": true,
        "resourceAttributes": {
          "service": "compute",
          "name": "projects/gsec-monitoring-prod",
          "type": "compute.projects"
        }
      },
      {
        "permission": "iam.serviceAccounts.actAs",
        "granted": true,
        "resourceAttributes": {
          "service": "compute",
          "name": "projects/gsec-monitoring-prod",
          "type": "compute.projects"
        }
      }
    ],
    "resourceName": "projects/gsec-monitoring-prod",
    "request": {
      "@type": "type.googleapis.com/compute.projects.setCommonInstanceMetadata"
    },
    "response": {
      "progress": "0",
      "@type": "type.googleapis.com/operation",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/gsec-monitoring-prod",
      "startTime": "2021-09-12T19:52:16.415-07:00",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/gsec-monitoring-prod/global/operations/operation-1631501536060-5cbd78d81e54a-d0e05d0c-dc9f8e1f",
      "user": "user@domain.com",
      "name": "operation-1631501536060-5cbd78d81e54a-d0e05d0c-dc9f8e1f",
      "targetId": "598897393088",
      "operationType": "compute.projects.setCommonInstanceMetadata",
      "id": "967174441535734287",
      "insertTime": "2021-09-12T19:52:16.411-07:00",
      "status": "RUNNING",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/gsec-monitoring-prod/global/operations/967174441535734287"
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    }
  },
  "insertId": "-9pd595e2pu3i",
  "resource": {
    "type": "gce_project",
    "labels": {
      "project_id": "598897393088"
    }
  },
  "timestamp": "2021-09-13T02:52:16.113032Z",
  "severity": "NOTICE",
  "logName": "projects/gsec-monitoring-prod/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "id": "operation-1631501536060-5cbd78d81e54a-d0e05d0c-dc9f8e1f",
    "producer": "compute.googleapis.com",
    "first": true
  },
  "receiveTimestamp": "2021-09-13T02:52:16.847984195Z"
}

References #

compute.projects.setCommonInstanceMetadata: setCommonInstanceMetadata

#
ServiceName
compute.googleapis.com

Description

Sets metadata common to all instances within the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "9gjtmcd3swk",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "3c66288a-c958-49d1-8109-6e95aeb0a051"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782744266581-655657ebc247a-96caa119-ba492a3e",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.projects.setCommonInstanceMetadata",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "compute",
          "type": "compute.projects"
        }
      },
      {
        "granted": true,
        "permission": "iam.serviceAccounts.actAs",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "compute",
          "type": "compute.projects"
        }
      }
    ],
    "methodName": "v1.compute.projects.setCommonInstanceMetadata",
    "request": {
      "@type": "type.googleapis.com/compute.projects.setCommonInstanceMetadata"
    },
    "requestMetadata": {
      "callerIp": "private",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:44:27.030039Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "4061165445698239013",
      "insertTime": "2026-06-29T07:44:26.851-07:00",
      "name": "operation-1782744266581-655657ebc247a-96caa119-ba492a3e",
      "operationType": "compute.projects.setCommonInstanceMetadata",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782744266581-655657ebc247a-96caa119-ba492a3e",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/4061165445698239013",
      "setCommonInstanceMetadataOperationMetadata": {
        "clientOperationId": "operation-1782744266581-655657ebc247a-96caa119-ba492a3e"
      },
      "startTime": "2026-06-29T07:44:26.855-07:00",
      "status": "RUNNING",
      "targetId": "000000000000",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id",
      "user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:44:27.750031191Z",
  "resource": {
    "labels": {
      "project_id": "000000000000"
    },
    "type": "gce_project"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:44:26.636187Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

compute.projects.setDefaultNetworkTier: setDefaultNetworkTier

#
ServiceName
compute.googleapis.com

Description

Sets the default network tier of the project. The default network tier is used when an address/forwardingRule/instance is created without specifying the network tier field.

compute.projects.setUsageExportBucket: setUsageExportBucket

#
ServiceName
compute.googleapis.com

Description

Enables the usage export feature and sets theusage export bucket where reports are stored. If you provide an empty request body using this method, the usage export feature will be disabled.

compute.publicAdvertisedPrefixes.announce: announce

#
ServiceName
compute.googleapis.com

Description

Announces the specified PublicAdvertisedPrefix

compute.publicAdvertisedPrefixes.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified PublicAdvertisedPrefix

compute.publicAdvertisedPrefixes.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified PublicAdvertisedPrefix resource.

Data Access audit logs are disabled by default.

compute.publicAdvertisedPrefixes.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a PublicAdvertisedPrefix in the specified project using the parameters that are included in the request.

compute.publicAdvertisedPrefixes.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the PublicAdvertisedPrefixes for a project.

Data Access audit logs are disabled by default.

compute.publicAdvertisedPrefixes.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified Router resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.

compute.publicAdvertisedPrefixes.withdraw: withdraw

#
ServiceName
compute.googleapis.com

Description

Withdraws the specified PublicAdvertisedPrefix

compute.publicDelegatedPrefixes.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Lists all PublicDelegatedPrefix resources owned by the specific project across all scopes. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.publicDelegatedPrefixes.announce: announce

#
ServiceName
compute.googleapis.com

Description

Announces the specified PublicDelegatedPrefix in the given region.

compute.publicDelegatedPrefixes.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified PublicDelegatedPrefix in the given region.

compute.publicDelegatedPrefixes.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified PublicDelegatedPrefix resource in the given region.

Data Access audit logs are disabled by default.

compute.publicDelegatedPrefixes.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a PublicDelegatedPrefix in the specified project in the given region using the parameters that are included in the request.

compute.publicDelegatedPrefixes.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the PublicDelegatedPrefixes for a project in the given region.

Data Access audit logs are disabled by default.

compute.publicDelegatedPrefixes.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified PublicDelegatedPrefix resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.

compute.publicDelegatedPrefixes.withdraw: withdraw

#
ServiceName
compute.googleapis.com

Description

Withdraws the specified PublicDelegatedPrefix in the given region.

compute.regionAutoscalers.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified autoscaler.

compute.regionAutoscalers.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified autoscaler.

Data Access audit logs are disabled by default.

compute.regionAutoscalers.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an autoscaler in the specified project using the data included in the request.

compute.regionAutoscalers.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of autoscalers contained within the specified region.

Data Access audit logs are disabled by default.

compute.regionAutoscalers.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates an autoscaler in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.regionAutoscalers.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionAutoscalers.update: update

#
ServiceName
compute.googleapis.com

Description

Updates an autoscaler in the specified project using the data included in the request.

compute.regionBackendBuckets.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified regional BackendBucket resource.

compute.regionBackendBuckets.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified regional BackendBucket resource.

Data Access audit logs are disabled by default.

compute.regionBackendBuckets.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.regionBackendBuckets.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a RegionBackendBucket in the specified project in the given scope using the parameters that are included in the request.

compute.regionBackendBuckets.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of BackendBucket resources available to the specified project in the given region.

Data Access audit logs are disabled by default.

compute.regionBackendBuckets.listUsable: listUsable

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of all usable backend buckets in the specified project in the given region.

Data Access audit logs are disabled by default.

compute.regionBackendBuckets.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified BackendBucket resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.regionBackendBuckets.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.regionBackendBuckets.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionBackendServices.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified regional BackendService resource.

Example Audit Log Entry #

{
  "insertId": "-gmgbhse440aq",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "f89756da-e103-41e0-adaa-deb39aec5e4e"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.regionBackendServices.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
          "service": "compute",
          "type": "compute.regionBackendServices"
        }
      }
    ],
    "methodName": "v1.compute.regionBackendServices.delete",
    "request": {
      "@type": "type.googleapis.com/compute.regionBackendServices.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-services.delete invocation-id/542ea518361d48c19be1d86f122bafc0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:30:18.136903Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
    "response": {
      "@type": "type.googleapis.com/error",
      "error": {
        "code": 404,
        "errors": [
          {
            "domain": "global",
            "message": "The resource 'projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r' was not found",
            "reason": "notFound"
          }
        ],
        "message": "The resource 'projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r' was not found"
      }
    },
    "serviceName": "compute.googleapis.com",
    "status": {
      "code": 5,
      "message": "The resource 'projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r' was not found"
    }
  },
  "receiveTimestamp": "2026-06-29T15:30:18.982324522Z",
  "resource": {
    "labels": {
      "backend_service_id": "",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gce_backend_service"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T15:30:18.038557Z"
}

compute.regionBackendServices.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified regional BackendService resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "dxe0bve2r1b4",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "ac4a014f-8254-46d1-9582-0241e35cfe75"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.regionBackendServices.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/backendServices/dwbs7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/backendServices/dwbs7b671061",
          "service": "compute",
          "type": "compute.regionBackendServices"
        }
      }
    ],
    "methodName": "v1.compute.regionBackendServices.get",
    "request": {
      "@type": "type.googleapis.com/compute.regionBackendServices.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-services.create invocation-id/70b5567d41044d699a0a24b9098c09c9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:28:49.222772Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/backendServices/dwbs7b671061",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:28:49.990748802Z",
  "resource": {
    "labels": {
      "backend_service_id": "4206856783692506070",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gce_backend_service"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:28:49.172962Z"
}

compute.regionBackendServices.getHealth: getHealth

#
ServiceName
compute.googleapis.com

Description

Gets the most recent health check results for this regional BackendService.

Data Access audit logs are disabled by default.

compute.regionBackendServices.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.regionBackendServices.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a regional BackendService resource in the specified project using the data included in the request. For more information, see Backend services overview.

Example Audit Log Entry #

{
  "insertId": "-xspuxae19ouy",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "47606930-1b30-4796-9931-df79c4bd098f"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.regionBackendServices.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
          "service": "compute",
          "type": "compute.regionBackendServices"
        }
      }
    ],
    "methodName": "v1.compute.regionBackendServices.insert",
    "request": {
      "@type": "type.googleapis.com/compute.regionBackendServices.insert",
      "healthChecks": [
        "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r"
      ],
      "loadBalancingScheme": "INTERNAL",
      "name": "dwn4-dw745960r",
      "protocol": "HTTP",
      "timeoutSec": "30"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-services.create invocation-id/5916b03dff864ccaa7adfd152174c783 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:25:49.483938Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
    "response": {
      "@type": "type.googleapis.com/error",
      "error": {
        "code": 400,
        "errors": [
          {
            "domain": "global",
            "message": "Invalid value for field 'resource.protocol': 'HTTP'. Protocol for an INTERNAL backend service must be one of TCP/UDP/UNSPECIFIED.",
            "reason": "invalid"
          }
        ],
        "message": "Invalid value for field 'resource.protocol': 'HTTP'. Protocol for an INTERNAL backend service must be one of TCP/UDP/UNSPECIFIED."
      }
    },
    "serviceName": "compute.googleapis.com",
    "status": {
      "code": 3,
      "message": "Invalid value for field 'resource.protocol': 'HTTP'. Protocol for an INTERNAL backend service must be one of TCP/UDP/UNSPECIFIED."
    }
  },
  "receiveTimestamp": "2026-06-29T15:25:49.557679184Z",
  "resource": {
    "labels": {
      "backend_service_id": "",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gce_backend_service"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T15:25:49.427767Z"
}

compute.regionBackendServices.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of regional BackendService resources available to the specified project in the given region.

Data Access audit logs are disabled by default.

compute.regionBackendServices.listUsable: listUsable

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of all usable backend services in the specified project in the given region.

Data Access audit logs are disabled by default.

compute.regionBackendServices.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified regional BackendService resource with the data included in the request. For more information, see Understanding backend services This method supports PATCH semantics and uses the JSON merge patch format and processing rules.

compute.regionBackendServices.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.regionBackendServices.setSecurityPolicy: setSecurityPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the Google Cloud Armor security policy for the specified backend service. For more information, seeGoogle Cloud Armor Overview

compute.regionBackendServices.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionBackendServices.update: update

#
ServiceName
compute.googleapis.com

Description

Updates the specified regional BackendService resource with the data included in the request. For more information, see Backend services overview.

compute.regionCommitments.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of commitments by region. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.regionCommitments.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified commitment resource.

Data Access audit logs are disabled by default.

compute.regionCommitments.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a commitment in the specified project using the data included in the request.

compute.regionCommitments.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of commitments contained within the specified region.

Data Access audit logs are disabled by default.

compute.regionCommitments.update: update

#
ServiceName
compute.googleapis.com

Description

Updates the specified commitment with the data included in the request. Update is performed only on selected fields included as part of update-mask. Only the following fields can be updated: auto_renew and plan.

compute.regionCompositeHealthChecks.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all CompositeHealthCheck resources (all regional) available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.regionCompositeHealthChecks.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified CompositeHealthCheck in the given region

compute.regionCompositeHealthChecks.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified CompositeHealthCheck resource in the given region.

Data Access audit logs are disabled by default.

compute.regionCompositeHealthChecks.getHealth: getHealth

#
ServiceName
compute.googleapis.com

Description

Gets the most recent health check results for this regional CompositeHealthCheck.

Data Access audit logs are disabled by default.

compute.regionCompositeHealthChecks.insert: insert

#
ServiceName
compute.googleapis.com

Description

Create a CompositeHealthCheck in the specified project in the given region using the parameters that are included in the request.

compute.regionCompositeHealthChecks.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the CompositeHealthChecks for a project in the given region.

Data Access audit logs are disabled by default.

compute.regionCompositeHealthChecks.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified regional CompositeHealthCheck resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.regionCompositeHealthChecks.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionDiskTypes.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified regional disk type.

Data Access audit logs are disabled by default.

compute.regionDiskTypes.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of regional disk types available to the specified project.

Data Access audit logs are disabled by default.

compute.regionDisks.addResourcePolicies: addResourcePolicies

#
ServiceName
compute.googleapis.com

Description

Adds existing resource policies to a regional disk. You can only add one policy which will be applied to this disk for scheduling snapshot creation.

compute.regionDisks.bulkInsert: bulkInsert

#
ServiceName
compute.googleapis.com

Description

Bulk create a set of disks.

compute.regionDisks.createSnapshot: createSnapshot

#
ServiceName
compute.googleapis.com

Description

Creates a snapshot of a specified persistent disk. For regular snapshot creation, consider using snapshots.insert instead, as that method supports more features, such as creating snapshots in a project different from the source disk project.

compute.regionDisks.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified regional persistent disk. Deleting a regional disk removes all the replicas of its data permanently and is irreversible. However, deleting a disk does not delete anysnapshots previously made from the disk. You must separatelydelete snapshots.

compute.regionDisks.get: get

#
ServiceName
compute.googleapis.com

Description

Returns a specified regional persistent disk.

Data Access audit logs are disabled by default.

compute.regionDisks.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.regionDisks.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a persistent regional disk in the specified project using the data included in the request.

compute.regionDisks.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of persistent disks contained within the specified region.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "8mqwiye83i5o",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "b4ffd947-dd16-4980-aa8c-47a98f06cc15"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "110162197178770594910"
      },
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
      "principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.disks.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.regionDisks.list",
    "request": {
      "@type": "type.googleapis.com/compute.regionDisks.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GCE CSI Driver/v1.23.1-gke.14 (linux amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:39:35.631396Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/disks",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:39:36.367158866Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "method": "compute.regionDisks.list",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:39:35.585884Z"
}

compute.regionDisks.removeResourcePolicies: removeResourcePolicies

#
ServiceName
compute.googleapis.com

Description

Removes resource policies from a regional disk.

compute.regionDisks.resize: resize

#
ServiceName
compute.googleapis.com

Description

Resizes the specified regional persistent disk.

compute.regionDisks.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.regionDisks.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on the target regional disk.

compute.regionDisks.startAsyncReplication: startAsyncReplication

#
ServiceName
compute.googleapis.com

Description

Starts asynchronous replication. Must be invoked on the primary disk.

compute.regionDisks.stopAsyncReplication: stopAsyncReplication

#
ServiceName
compute.googleapis.com

Description

Stops asynchronous replication. Can be invoked either on the primary or on the secondary disk.

compute.regionDisks.stopGroupAsyncReplication: stopGroupAsyncReplication

#
ServiceName
compute.googleapis.com

Description

Stops asynchronous replication for a consistency group of disks. Can be invoked either in the primary or secondary scope.

compute.regionDisks.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionDisks.update: update

#
ServiceName
compute.googleapis.com

Description

Update the specified disk with the data included in the request. Update is performed only on selected fields included as part of update-mask.

compute.regionDisks.updateKmsKey: updateKmsKey

#
ServiceName
compute.googleapis.com

Description

Rotates the customer-managed encryption key to the latest version for the specified persistent disk.

compute.regionHealthAggregationPolicies.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all HealthAggregationPolicy resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.regionHealthAggregationPolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified HealthAggregationPolicy in the given region.

compute.regionHealthAggregationPolicies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified HealthAggregationPolicy resource in the given region.

Data Access audit logs are disabled by default.

compute.regionHealthAggregationPolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Create a HealthAggregationPolicy in the specified project in the given region using the parameters that are included in the request.

compute.regionHealthAggregationPolicies.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the HealthAggregationPolicies for a project in the given region.

Data Access audit logs are disabled by default.

compute.regionHealthAggregationPolicies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified regional HealthAggregationPolicy resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.regionHealthAggregationPolicies.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionHealthCheckServices.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all HealthCheckService resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.regionHealthCheckServices.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified regional HealthCheckService.

compute.regionHealthCheckServices.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified regional HealthCheckService resource.

Data Access audit logs are disabled by default.

compute.regionHealthCheckServices.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a regional HealthCheckService resource in the specified project and region using the data included in the request.

compute.regionHealthCheckServices.list: list

#
ServiceName
compute.googleapis.com

Description

Lists all the HealthCheckService resources that have been configured for the specified project in the given region.

Data Access audit logs are disabled by default.

compute.regionHealthCheckServices.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified regional HealthCheckService resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.regionHealthCheckServices.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionHealthChecks.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified HealthCheck resource.

Example Audit Log Entry #

{
  "insertId": "9psldie31d62",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "733e5ee6-f45a-4e1c-8de9-dc855f3475b2"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782747019471-6556622d1ea45-96290638-25c420aa",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.regionHealthChecks.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
          "service": "compute",
          "type": "compute.regionHealthChecks"
        }
      }
    ],
    "methodName": "v1.compute.regionHealthChecks.delete",
    "request": {
      "@type": "type.googleapis.com/compute.regionHealthChecks.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.health-checks.delete invocation-id/48dd6eabe8eb42ba9fed59ddcb96e08f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:30:19.616034Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "6148536400710938980",
      "insertTime": "2026-06-29T08:30:19.569-07:00",
      "name": "operation-1782747019471-6556622d1ea45-96290638-25c420aa",
      "operationType": "delete",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782747019471-6556622d1ea45-96290638-25c420aa",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/6148536400710938980",
      "startTime": "2026-06-29T08:30:19.580-07:00",
      "status": "RUNNING",
      "targetId": "1848293291438583956",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:30:19.855510334Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "method": "compute.regionHealthChecks.delete",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:30:19.418402Z"
}

compute.regionHealthChecks.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified HealthCheck resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-4flto5e1ajqg",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "18942c9c-a039-4d95-807c-fb0ecf38fff6"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.regionHealthChecks.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/healthChecks/dwhc7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/healthChecks/dwhc7b671061",
          "service": "compute",
          "type": "compute.regionHealthChecks"
        }
      }
    ],
    "methodName": "v1.compute.regionHealthChecks.get",
    "request": {
      "@type": "type.googleapis.com/compute.regionHealthChecks.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.health-checks.create.tcp invocation-id/d5316bd401884f0bacd838ecc172493b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:28:40.040373Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/healthChecks/dwhc7b671061",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:28:40.637204026Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "method": "compute.regionHealthChecks.get",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:28:39.972550Z"
}

compute.regionHealthChecks.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a HealthCheck resource in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-rpyzoeair46",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "fef368a9-1767-40d3-ae46-814187126032"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746746998-6556612944df9-9b059968-7274b096",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.regionHealthChecks.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
          "service": "compute",
          "type": "compute.regionHealthChecks"
        }
      }
    ],
    "methodName": "v1.compute.regionHealthChecks.insert",
    "request": {
      "@type": "type.googleapis.com/compute.regionHealthChecks.insert",
      "checkIntervalSec": "5",
      "healthyThreshold": "2",
      "httpHealthCheck": {
        "port": "80",
        "portSpecification": "USE_FIXED_PORT",
        "proxyHeader": "NONE",
        "requestPath": "/"
      },
      "name": "dwn4-dw745960r",
      "timeoutSec": "5",
      "type": "HTTP",
      "unhealthyThreshold": "2"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.health-checks.create.http invocation-id/0c651f5221d74899a6ee7a5c994186ed environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:25:47.163857Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "718011800694501524",
      "insertTime": "2026-06-29T08:25:47.097-07:00",
      "name": "operation-1782746746998-6556612944df9-9b059968-7274b096",
      "operationType": "insert",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782746746998-6556612944df9-9b059968-7274b096",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/718011800694501524",
      "startTime": "2026-06-29T08:25:47.104-07:00",
      "status": "RUNNING",
      "targetId": "1848293291438583956",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:25:47.643191790Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "method": "compute.regionHealthChecks.insert",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:25:46.975047Z"
}

compute.regionHealthChecks.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of HealthCheck resources available to the specified project.

Data Access audit logs are disabled by default.

compute.regionHealthChecks.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates a HealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.regionHealthChecks.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionHealthChecks.update: update

#
ServiceName
compute.googleapis.com

Description

Updates a HealthCheck resource in the specified project using the data included in the request.

compute.regionHealthSources.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all HealthSource resources (all regional) available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.regionHealthSources.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified HealthSource in the given region

compute.regionHealthSources.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified HealthSource resource in the given region.

Data Access audit logs are disabled by default.

compute.regionHealthSources.getHealth: getHealth

#
ServiceName
compute.googleapis.com

Description

Gets the most recent health check results for this regional HealthSource.

Data Access audit logs are disabled by default.

compute.regionHealthSources.insert: insert

#
ServiceName
compute.googleapis.com

Description

Create a HealthSource in the specified project in the given region using the parameters that are included in the request.

compute.regionHealthSources.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the HealthSources for a project in the given region.

Data Access audit logs are disabled by default.

compute.regionHealthSources.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified regional HealthSource resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.regionHealthSources.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionInstanceGroupManagerResizeRequests.cancel: cancel

#
ServiceName
compute.googleapis.com

Description

Cancels the specified resize request. Cancelled resize request no longer waits for the resources to be provisioned. Cancel is only possible for requests that are in accepted state.

compute.regionInstanceGroupManagerResizeRequests.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified, inactive resize request. Requests that are still active cannot be deleted. Deleting request does not delete instances that were provisioned previously.

compute.regionInstanceGroupManagerResizeRequests.get: get

#
ServiceName
compute.googleapis.com

Description

Returns all of the details about the specified resize request.

Data Access audit logs are disabled by default.

compute.regionInstanceGroupManagerResizeRequests.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new Resize Request that starts provisioning VMs immediately or queues VM creation.

compute.regionInstanceGroupManagerResizeRequests.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of Resize Requests that are contained in the managed instance group.

Data Access audit logs are disabled by default.

compute.regionInstanceGroupManagers.abandonInstances: abandonInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances to be immediately removed from the managed instance group. Abandoning an instance does not delete the instance, but it does remove the instance from any target pools that are applied by the managed instance group. This method reduces thetargetSize of the managed instance group by the number of instances that you abandon. This operation is marked asDONE when the action is scheduled even if the instances have not yet been removed from the group. You must separately verify the status of the abandoning action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.

compute.regionInstanceGroupManagers.applyUpdatesToInstances: applyUpdatesToInstances

#
ServiceName
compute.googleapis.com

Description

Apply updates to selected instances the managed instance group.

compute.regionInstanceGroupManagers.createInstances: createInstances

#
ServiceName
compute.googleapis.com

Description

Creates instances with per-instance configurations in this regional managed instance group. Instances are created using the current instance template. The create instances operation is marked DONE if the createInstances request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or actions with the listmanagedinstances method.

compute.regionInstanceGroupManagers.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified managed instance group and all of the instances in that group.

compute.regionInstanceGroupManagers.deleteInstances: deleteInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances in the managed instance group to be immediately deleted. The instances are also removed from any target pools of which they were a member. This method reduces thetargetSize of the managed instance group by the number of instances that you delete. The deleteInstances operation is marked DONE if the deleteInstances request is successful. The underlying actions take additional time. You must separately verify the status of thedeleting action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.

compute.regionInstanceGroupManagers.deletePerInstanceConfigs: deletePerInstanceConfigs

#
ServiceName
compute.googleapis.com

Description

Deletes selected per-instance configurations for the managed instance group.

compute.regionInstanceGroupManagers.get: get

#
ServiceName
compute.googleapis.com

Description

Returns all of the details about the specified managed instance group.

Data Access audit logs are disabled by default.

compute.regionInstanceGroupManagers.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a managed instance group using the information that you specify in the request. After the group is created, instances in the group are created using the specified instance template. This operation is marked as DONE when the group is created even if the instances in the group have not yet been created. You must separately verify the status of the individual instances with thelistmanagedinstances method. A regional managed instance group can contain up to 2000 instances.

compute.regionInstanceGroupManagers.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of managed instance groups that are contained within the specified region.

Data Access audit logs are disabled by default.

compute.regionInstanceGroupManagers.listErrors: listErrors

#
ServiceName
compute.googleapis.com

Description

Lists all errors thrown by actions on instances for a given regional managed instance group. The filter andorderBy query parameters are not supported.

Data Access audit logs are disabled by default.

compute.regionInstanceGroupManagers.listManagedInstances: listManagedInstances

#
ServiceName
compute.googleapis.com

Description

Lists the instances in the managed instance group and instances that are scheduled to be created. The list includes any current actions that the group has scheduled for its instances. The orderBy query parameter is not supported. The `pageToken` query parameter is supported only if the group's `listManagedInstancesResults` field is set to `PAGINATED`.

Data Access audit logs are disabled by default.

compute.regionInstanceGroupManagers.listPerInstanceConfigs: listPerInstanceConfigs

#
ServiceName
compute.googleapis.com

Description

Lists all of the per-instance configurations defined for the managed instance group. The orderBy query parameter is not supported.

Data Access audit logs are disabled by default.

compute.regionInstanceGroupManagers.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates a managed instance group using the information that you specify in the request. This operation is marked as DONE when the group is patched even if the instances in the group are still in the process of being patched. You must separately verify the status of the individual instances with the listmanagedinstances method. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. If you update your group to specify a new template or instance configuration, it's possible that your intended specification for each VM in the group is different from the current state of that VM. To learn how to apply an updated configuration to the VMs in a MIG, seeUpdating instances in a MIG.

compute.regionInstanceGroupManagers.patchPerInstanceConfigs: patchPerInstanceConfigs

#
ServiceName
compute.googleapis.com

Description

Inserts or patches per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.

compute.regionInstanceGroupManagers.recreateInstances: recreateInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified VM instances in the managed instance group to be immediately recreated. Each instance is recreated using the group's current configuration. This operation is marked as DONE when the flag is set even if the instances have not yet been recreated. You must separately verify the status of each instance by checking itscurrentAction field; for more information, see Checking the status of managed instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.

compute.regionInstanceGroupManagers.resize: resize

#
ServiceName
compute.googleapis.com

Description

Changes the intended size of the managed instance group. If you increase the size, the group creates new instances using the current instance template. If you decrease the size, the group deletes one or more instances. The resize operation is marked DONE if theresize request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or deleting actions with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted.

compute.regionInstanceGroupManagers.resumeInstances: resumeInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances in the managed instance group to be resumed. This method increases thetargetSize and decreases the targetSuspendedSize of the managed instance group by the number of instances that you resume. The resumeInstances operation is marked DONE if the resumeInstances request is successful. The underlying actions take additional time. You must separately verify the status of theRESUMING action with thelistmanagedinstances method. In this request, you can only specify instances that are suspended. For example, if an instance was previously suspended using the suspendInstances method, it can be resumed using the resumeInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are resumed. You can specify a maximum of 1000 instances with this method per request.

compute.regionInstanceGroupManagers.setInstanceTemplate: setInstanceTemplate

#
ServiceName
compute.googleapis.com

Description

Sets the instance template to use when creating new instances or recreating instances in this group. Existing instances are not affected.

compute.regionInstanceGroupManagers.setTargetPools: setTargetPools

#
ServiceName
compute.googleapis.com

Description

Modifies the target pools to which all new instances in this group are assigned. Existing instances in the group are not affected.

compute.regionInstanceGroupManagers.startInstances: startInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances in the managed instance group to be started. This method increases thetargetSize and decreases the targetStoppedSize of the managed instance group by the number of instances that you start. The startInstances operation is marked DONE if the startInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTARTING action with thelistmanagedinstances method. In this request, you can only specify instances that are stopped. For example, if an instance was previously stopped using the stopInstances method, it can be started using the startInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are started. You can specify a maximum of 1000 instances with this method per request.

compute.regionInstanceGroupManagers.stopInstances: stopInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances in the managed instance group to be immediately stopped. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetStoppedSize of the managed instance group by the number of instances that you stop. The stopInstances operation is marked DONE if the stopInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTOPPING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays stopping the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is stopped. Stopped instances can be started using the startInstances method. You can specify a maximum of 1000 instances with this method per request.

compute.regionInstanceGroupManagers.suspendInstances: suspendInstances

#
ServiceName
compute.googleapis.com

Description

Flags the specified instances in the managed instance group to be immediately suspended. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetSuspendedSize of the managed instance group by the number of instances that you suspend. The suspendInstances operation is marked DONE if the suspendInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSUSPENDING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays suspension of the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is suspended. Suspended instances can be resumed using the resumeInstances method. You can specify a maximum of 1000 instances with this method per request.

compute.regionInstanceGroupManagers.updatePerInstanceConfigs: updatePerInstanceConfigs

#
ServiceName
compute.googleapis.com

Description

Inserts or updates per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.

compute.regionInstanceGroups.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified instance group resource.

Data Access audit logs are disabled by default.

compute.regionInstanceGroups.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of instance group resources contained within the specified region.

Data Access audit logs are disabled by default.

compute.regionInstanceGroups.listInstances: listInstances

#
ServiceName
compute.googleapis.com

Description

Lists the instances in the specified instance group and displays information about the named ports. Depending on the specified options, this method can list all instances or only the instances that are running. The orderBy query parameter is not supported.

Data Access audit logs are disabled by default.

compute.regionInstanceGroups.setNamedPorts: setNamedPorts

#
ServiceName
compute.googleapis.com

Description

Sets the named ports for the specified regional instance group.

compute.regionInstanceGroups.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionInstanceTemplates.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified instance template. Deleting an instance template is permanent and cannot be undone.

Example Audit Log Entry #

{
  "insertId": "-saixoje3ihpg",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "fd5e53ae-2103-4dae-9c39-8c49e3756aec"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782744154740-655657811952b-29e22a4d-576c7d28",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.instanceTemplates.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/instanceTemplates/gke-dwgke-dw743447-default-pool-d20f3f37",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/instanceTemplates/gke-dwgke-dw743447-default-pool-d20f3f37",
          "service": "compute",
          "type": "compute.instanceTemplates"
        }
      }
    ],
    "methodName": "v1.compute.regionInstanceTemplates.delete",
    "request": {
      "@type": "type.googleapis.com/compute.regionInstanceTemplates.delete"
    },
    "requestMetadata": {
      "callerIp": "private",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:42:35.227819Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/instanceTemplates/gke-dwgke-dw743447-default-pool-d20f3f37",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "516115459807853236",
      "insertTime": "2026-06-29T07:42:35.175-07:00",
      "name": "operation-1782744154740-655657811952b-29e22a4d-576c7d28",
      "operationType": "delete",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782744154740-655657811952b-29e22a4d-576c7d28",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/516115459807853236",
      "startTime": "2026-06-29T07:42:35.183-07:00",
      "status": "RUNNING",
      "targetId": "5240466678091824357",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/instanceTemplates/gke-dwgke-dw743447-default-pool-d20f3f37",
      "user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:42:35.807441147Z",
  "resource": {
    "labels": {
      "instance_template_id": "5240466678091824357",
      "instance_template_name": "gke-dwgke-dw743447-default-pool-d20f3f37",
      "project_id": "example-project-id"
    },
    "type": "gce_instance_template"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:42:35.050789Z"
}

compute.regionInstanceTemplates.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified instance template.

Data Access audit logs are disabled by default.

compute.regionInstanceTemplates.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an instance template in the specified project and region using the global instance template whose URL is included in the request.

compute.regionInstanceTemplates.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of instance templates that are contained within the specified project and region.

Data Access audit logs are disabled by default.

compute.regionInstances.bulkInsert: bulkInsert

#
ServiceName
compute.googleapis.com

Description

Creates multiple instances in a given region. Count specifies the number of instances to create.

compute.regionInstantSnapshotGroups.delete: delete

#
ServiceName
compute.googleapis.com

Description

deletes a Regional InstantSnapshotGroup resource

compute.regionInstantSnapshotGroups.get: get

#
ServiceName
compute.googleapis.com

Description

returns the specified InstantSnapshotGroup resource in the specified region.

Data Access audit logs are disabled by default.

compute.regionInstantSnapshotGroups.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.regionInstantSnapshotGroups.insert: insert

#
ServiceName
compute.googleapis.com

Description

creates a Regional InstantSnapshotGroup resource

compute.regionInstantSnapshotGroups.list: list

#
ServiceName
compute.googleapis.com

Description

retrieves the list of InstantSnapshotGroup resources contained within the specified region.

Data Access audit logs are disabled by default.

compute.regionInstantSnapshotGroups.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.regionInstantSnapshotGroups.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionInstantSnapshots.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified InstantSnapshot resource. Keep in mind that deleting a single instantSnapshot might not necessarily delete all the data on that instantSnapshot. If any data on the instantSnapshot that is marked for deletion is needed for subsequent instantSnapshots, the data will be moved to the next corresponding instantSnapshot. For more information, seeDeleting instantSnapshots.

compute.regionInstantSnapshots.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified InstantSnapshot resource in the specified region.

Data Access audit logs are disabled by default.

compute.regionInstantSnapshots.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.regionInstantSnapshots.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates an instant snapshot in the specified region.

compute.regionInstantSnapshots.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of InstantSnapshot resources contained within the specified region.

Data Access audit logs are disabled by default.

compute.regionInstantSnapshots.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.regionInstantSnapshots.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a instantSnapshot in the given region. To learn more about labels, read the Labeling Resources documentation.

compute.regionInstantSnapshots.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionNetworkEndpointGroups.attachNetworkEndpoints: attachNetworkEndpoints

#
ServiceName
compute.googleapis.com

Description

Attach a list of network endpoints to the specified network endpoint group.

compute.regionNetworkEndpointGroups.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified network endpoint group. Note that the NEG cannot be deleted if it is configured as a backend of a backend service.

compute.regionNetworkEndpointGroups.detachNetworkEndpoints: detachNetworkEndpoints

#
ServiceName
compute.googleapis.com

Description

Detach the network endpoint from the specified network endpoint group.

compute.regionNetworkEndpointGroups.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified network endpoint group.

Data Access audit logs are disabled by default.

compute.regionNetworkEndpointGroups.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global API

compute.regionNetworkEndpointGroups.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of regional network endpoint groups available to the specified project in the given region.

Data Access audit logs are disabled by default.

compute.regionNetworkEndpointGroups.listNetworkEndpoints: listNetworkEndpoints

#
ServiceName
compute.googleapis.com

Description

Lists the network endpoints in the specified network endpoint group.

Data Access audit logs are disabled by default.

compute.regionNetworkFirewallPolicies.addAssociation: addAssociation

#
ServiceName
compute.googleapis.com

Description

Inserts an association for the specified network firewall policy.

compute.regionNetworkFirewallPolicies.addRule: addRule

#
ServiceName
compute.googleapis.com

Description

Inserts a rule into a network firewall policy.

compute.regionNetworkFirewallPolicies.cloneRules: cloneRules

#
ServiceName
compute.googleapis.com

Description

Copies rules to the specified network firewall policy.

compute.regionNetworkFirewallPolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified network firewall policy.

compute.regionNetworkFirewallPolicies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified network firewall policy.

Data Access audit logs are disabled by default.

compute.regionNetworkFirewallPolicies.getAssociation: getAssociation

#
ServiceName
compute.googleapis.com

Description

Gets an association with the specified name.

Data Access audit logs are disabled by default.

compute.regionNetworkFirewallPolicies.getEffectiveFirewalls: getEffectiveFirewalls

#
ServiceName
compute.googleapis.com

Description

Returns the effective firewalls on a given network.

Data Access audit logs are disabled by default.

compute.regionNetworkFirewallPolicies.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.regionNetworkFirewallPolicies.getRule: getRule

#
ServiceName
compute.googleapis.com

Description

Gets a rule of the specified priority.

Data Access audit logs are disabled by default.

compute.regionNetworkFirewallPolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new network firewall policy in the specified project and region.

compute.regionNetworkFirewallPolicies.list: list

#
ServiceName
compute.googleapis.com

Description

Lists all the network firewall policies that have been configured for the specified project in the given region.

Data Access audit logs are disabled by default.

compute.regionNetworkFirewallPolicies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified network firewall policy.

compute.regionNetworkFirewallPolicies.patchRule: patchRule

#
ServiceName
compute.googleapis.com

Description

Patches a rule of the specified priority.

compute.regionNetworkFirewallPolicies.removeAssociation: removeAssociation

#
ServiceName
compute.googleapis.com

Description

Removes an association for the specified network firewall policy.

compute.regionNetworkFirewallPolicies.removeRule: removeRule

#
ServiceName
compute.googleapis.com

Description

Deletes a rule of the specified priority.

compute.regionNetworkFirewallPolicies.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.regionNetworkFirewallPolicies.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionNotificationEndpoints.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all NotificationEndpoint resources, regional and global, available to the specified project.

Data Access audit logs are disabled by default.

compute.regionNotificationEndpoints.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified NotificationEndpoint in the given region

compute.regionNotificationEndpoints.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified NotificationEndpoint resource in the given region.

Data Access audit logs are disabled by default.

compute.regionNotificationEndpoints.insert: insert

#
ServiceName
compute.googleapis.com

Description

Create a NotificationEndpoint in the specified project in the given region using the parameters that are included in the request.

compute.regionNotificationEndpoints.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the NotificationEndpoints for a project in the given region.

Data Access audit logs are disabled by default.

compute.regionNotificationEndpoints.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionOperations.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified region-specific Operations resource.

compute.regionOperations.get: get

#
ServiceName
compute.googleapis.com

Description

Retrieves the specified region-specific Operations resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-62mxmoe15x34",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "7921d872-3eb8-4931-be27-6c5fbbd83269"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.regionOperations.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/operations/operation-1782744154740-655657811952b-29e22a4d-576c7d28",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/operations/operation-1782744154740-655657811952b-29e22a4d-576c7d28",
          "service": "compute",
          "type": "compute.regionOperations"
        }
      }
    ],
    "methodName": "v1.compute.regionOperations.get",
    "request": {
      "@type": "type.googleapis.com/compute.regionOperations.get"
    },
    "requestMetadata": {
      "callerIp": "private",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:42:37.407795Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/operations/operation-1782744154740-655657811952b-29e22a4d-576c7d28",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:42:38.217451698Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "operation_name": "operation-1782744154740-655657811952b-29e22a4d-576c7d28",
      "project_id": "example-project-id"
    },
    "type": "gce_operation"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:42:37.364461Z"
}

compute.regionOperations.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of Operation resources contained within the specified region.

Data Access audit logs are disabled by default.

compute.regionOperations.wait: wait

#
ServiceName
compute.googleapis.com

Description

Waits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method differs from the `GET` method in that it waits for no more than the default deadline (2 minutes) and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-vumiuge66pfs",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "ce27a66b-3f28-41f7-9bc0-226715ef5549"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.regionOperations.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/operations/operation-1782739223725-65564522843f2-29cb8358-813b1c25",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/operations/operation-1782739223725-65564522843f2-29cb8358-813b1c25",
          "service": "compute",
          "type": "compute.regionOperations"
        }
      }
    ],
    "methodName": "v1.compute.regionOperations.wait",
    "request": {
      "@type": "type.googleapis.com/compute.regionOperations.wait"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.create invocation-id/88997435245f4532ae2513fb4e2acb8d environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:41.931197Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/operations/operation-1782739223725-65564522843f2-29cb8358-813b1c25",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:42.746765592Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "operation_name": "operation-1782739223725-65564522843f2-29cb8358-813b1c25",
      "project_id": "example-project-id"
    },
    "type": "gce_operation"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:20:25.158695Z"
}

compute.regionSecurityPolicies.addRule: addRule

#
ServiceName
compute.googleapis.com

Description

Inserts a rule into a security policy.

compute.regionSecurityPolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified policy.

compute.regionSecurityPolicies.get: get

#
ServiceName
compute.googleapis.com

Description

List all of the ordered rules present in a single specified policy.

Data Access audit logs are disabled by default.

compute.regionSecurityPolicies.getRule: getRule

#
ServiceName
compute.googleapis.com

Description

Gets a rule at the specified priority.

Data Access audit logs are disabled by default.

compute.regionSecurityPolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new policy in the specified project using the data included in the request.

compute.regionSecurityPolicies.list: list

#
ServiceName
compute.googleapis.com

Description

List all the policies that have been configured for the specified project and region.

Data Access audit logs are disabled by default.

compute.regionSecurityPolicies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified policy with the data included in the request. To clear fields in the policy, leave the fields empty and specify them in the updateMask. This cannot be used to be update the rules in the policy. Please use the per rule methods like addRule, patchRule, and removeRule instead.

compute.regionSecurityPolicies.patchRule: patchRule

#
ServiceName
compute.googleapis.com

Description

Patches a rule at the specified priority. To clear fields in the rule, leave the fields empty and specify them in the updateMask.

compute.regionSecurityPolicies.removeRule: removeRule

#
ServiceName
compute.googleapis.com

Description

Deletes a rule at the specified priority.

compute.regionSecurityPolicies.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a security policy. To learn more about labels, read the Labeling Resources documentation.

compute.regionSnapshotSettings.get: get

#
ServiceName
compute.googleapis.com

Description

Get region snapshot settings.

Data Access audit logs are disabled by default.

compute.regionSnapshotSettings.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patch region snapshot settings.

compute.regionSnapshots.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified Snapshot resource. Keep in mind that deleting a single snapshot might not necessarily delete all the data on that snapshot. If any data on the snapshot that is marked for deletion is needed for subsequent snapshots, the data will be moved to the next corresponding snapshot. For more information, seeDeleting snapshots.

compute.regionSnapshots.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified Snapshot resource.

Data Access audit logs are disabled by default.

compute.regionSnapshots.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.regionSnapshots.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a snapshot in the specified region using the data included in the request.

compute.regionSnapshots.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of Snapshot resources contained within the specified region.

Data Access audit logs are disabled by default.

compute.regionSnapshots.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.regionSnapshots.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a regional snapshot. To learn more about labels, read the Labeling Resources documentation.

compute.regionSnapshots.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.regionSnapshots.updateKmsKey: updateKmsKey

#
ServiceName
compute.googleapis.com

Description

Rotates the customer-managed encryption key to the latest version for the specified snapshot.

compute.regionSslCertificates.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified SslCertificate resource in the region.

compute.regionSslCertificates.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified SslCertificate resource in the specified region. Get a list of available SSL certificates by making a list() request.

Data Access audit logs are disabled by default.

compute.regionSslCertificates.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a SslCertificate resource in the specified project and region using the data included in the request

compute.regionSslCertificates.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of SslCertificate resources available to the specified project in the specified region.

Data Access audit logs are disabled by default.

compute.regionSslPolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified SSL policy. The SSL policy resource can be deleted only if it is not in use by any TargetHttpsProxy or TargetSslProxy resources.

compute.regionSslPolicies.get: get

#
ServiceName
compute.googleapis.com

Description

Lists all of the ordered rules present in a single specified policy.

Data Access audit logs are disabled by default.

compute.regionSslPolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new policy in the specified project and region using the data included in the request.

compute.regionSslPolicies.list: list

#
ServiceName
compute.googleapis.com

Description

Lists all the SSL policies that have been configured for the specified project and region.

Data Access audit logs are disabled by default.

compute.regionSslPolicies.listAvailableFeatures: listAvailableFeatures

#
ServiceName
compute.googleapis.com

Description

Lists all features that can be specified in the SSL policy when using custom profile.

Data Access audit logs are disabled by default.

compute.regionSslPolicies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified SSL policy with the data included in the request.

compute.regionTargetHttpProxies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified TargetHttpProxy resource.

compute.regionTargetHttpProxies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified TargetHttpProxy resource in the specified region.

Data Access audit logs are disabled by default.

compute.regionTargetHttpProxies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a TargetHttpProxy resource in the specified project and region using the data included in the request.

compute.regionTargetHttpProxies.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of TargetHttpProxy resources available to the specified project in the specified region.

Data Access audit logs are disabled by default.

compute.regionTargetHttpProxies.setUrlMap: setUrlMap

#
ServiceName
compute.googleapis.com

Description

Changes the URL map for TargetHttpProxy.

compute.regionTargetHttpsProxies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified TargetHttpsProxy resource.

compute.regionTargetHttpsProxies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified TargetHttpsProxy resource in the specified region.

Data Access audit logs are disabled by default.

compute.regionTargetHttpsProxies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a TargetHttpsProxy resource in the specified project and region using the data included in the request.

compute.regionTargetHttpsProxies.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of TargetHttpsProxy resources available to the specified project in the specified region.

Data Access audit logs are disabled by default.

compute.regionTargetHttpsProxies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified regional TargetHttpsProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.

compute.regionTargetHttpsProxies.setSslCertificates: setSslCertificates

#
ServiceName
compute.googleapis.com

Description

Replaces SslCertificates for TargetHttpsProxy.

compute.regionTargetHttpsProxies.setUrlMap: setUrlMap

#
ServiceName
compute.googleapis.com

Description

Changes the URL map for TargetHttpsProxy.

compute.regionTargetTcpProxies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified TargetTcpProxy resource.

compute.regionTargetTcpProxies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified TargetTcpProxy resource.

Data Access audit logs are disabled by default.

compute.regionTargetTcpProxies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a TargetTcpProxy resource in the specified project and region using the data included in the request.

compute.regionTargetTcpProxies.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of TargetTcpProxy resources available to the specified project in a given region.

Data Access audit logs are disabled by default.

compute.regionUrlMaps.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified UrlMap resource.

compute.regionUrlMaps.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified UrlMap resource.

Data Access audit logs are disabled by default.

compute.regionUrlMaps.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a UrlMap resource in the specified project using the data included in the request.

compute.regionUrlMaps.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of UrlMap resources available to the specified project in the specified region.

Data Access audit logs are disabled by default.

compute.regionUrlMaps.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified UrlMap resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.

compute.regionUrlMaps.update: update

#
ServiceName
compute.googleapis.com

Description

Updates the specified UrlMap resource with the data included in the request.

compute.regionUrlMaps.validate: validate

#
ServiceName
compute.googleapis.com

Description

Runs static validation for the UrlMap. In particular, the tests of the provided UrlMap will be run. Calling this method does NOT create the UrlMap.

compute.regionZones.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of Zone resources under the specific region available to the specified project.

Data Access audit logs are disabled by default.

compute.regions.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified Region resource. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request. This method fails if the quota information is unavailable for the region and if the organization policy constraint compute.requireBasicQuotaInResponse is enforced. This constraint, when enforced, disables the fail-open behaviour when quota information (the `items.quotas` field) is unavailable for the region. It is recommended to use the default setting for the constraint unless your application requires the fail-closed behaviour for this method.

Data Access audit logs are disabled by default.

compute.regions.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of region resources available to the specified project. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `items.quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request. This method fails if the quota information is unavailable for the region and if the organization policy constraint compute.requireBasicQuotaInResponse is enforced. This constraint, when enforced, disables the fail-open behaviour when quota information (the `items.quotas` field) is unavailable for the region. It is recommended to use the default setting for the constraint unless your application requires the fail-closed behaviour for this method.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-26k7ahdd4gc",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "7d77c784-2a47-4404-9cf8-89b3bf0f35e5"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.regions.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.regions.list",
    "numResponseItems": "43",
    "request": {
      "@type": "type.googleapis.com/compute.regions.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.regions.list invocation-id/82f00dca4ca64a3bb0afd8372dd83147 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:45.082506Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/regions",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:45.327010659Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.regions.list",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:44.738824Z"
}

compute.reservationBlocks.get: get

#
ServiceName
compute.googleapis.com

Description

Retrieves information about the specified reservation block.

Data Access audit logs are disabled by default.

compute.reservationBlocks.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.reservationBlocks.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of reservation blocks under a single reservation.

Data Access audit logs are disabled by default.

compute.reservationBlocks.performMaintenance: performMaintenance

#
ServiceName
compute.googleapis.com

Description

Allows customers to perform maintenance on a reservation block

compute.reservationBlocks.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.reservationBlocks.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.reservationSlots.get: get

#
ServiceName
compute.googleapis.com

Description

Retrieves information about the specified reservation slot.

Data Access audit logs are disabled by default.

compute.reservationSlots.getVersion: getVersion

#
ServiceName
compute.googleapis.com

Description

Allows customers to get SBOM versions of a reservation slot.

Data Access audit logs are disabled by default.

compute.reservationSlots.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of reservation slots under a single reservation.

Data Access audit logs are disabled by default.

compute.reservationSlots.update: update

#
ServiceName
compute.googleapis.com

Description

Update a reservation slot in the specified sub-block.

compute.reservationSubBlocks.get: get

#
ServiceName
compute.googleapis.com

Description

Retrieves information about the specified reservation subBlock.

Data Access audit logs are disabled by default.

compute.reservationSubBlocks.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.reservationSubBlocks.getVersion: getVersion

#
ServiceName
compute.googleapis.com

Description

Allows customers to get SBOM versions of a reservation subBlock.

Data Access audit logs are disabled by default.

compute.reservationSubBlocks.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of reservation subBlocks under a single reservation.

Data Access audit logs are disabled by default.

compute.reservationSubBlocks.performMaintenance: performMaintenance

#
ServiceName
compute.googleapis.com

Description

Allows customers to perform maintenance on a reservation subBlock

compute.reservationSubBlocks.reportFaulty: reportFaulty

#
ServiceName
compute.googleapis.com

Description

Allows customers to report a faulty subBlock.

compute.reservationSubBlocks.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.reservationSubBlocks.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.reservations.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of reservations. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-t3gmqie5l23a",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "7c8fe96a-e271-427a-88ac-2cf72531d24f"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.reservations.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.reservations.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.reservations.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.reservations.list invocation-id/c681a151147e4da7af261fc0ff149b62 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:56.655375Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/reservations",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:57.274401940Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.reservations.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:56.600481Z"
}

compute.reservations.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified reservation.

Example Audit Log Entry #

{
  "insertId": "-b2s4ehe4qsom",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a9013f93-2226-4737-9e5d-33d78fe089de"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746993451-655662144e257-1d7b959c-ea96f49c",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.reservations.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
          "service": "compute",
          "type": "compute.reservations"
        }
      }
    ],
    "methodName": "v1.compute.reservations.delete",
    "request": {
      "@type": "type.googleapis.com/compute.reservations.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.reservations.delete invocation-id/afb93cfcd3ae40669c54ed717e97b352 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:29:53.568794Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "8607707594908184990",
      "insertTime": "2026-06-29T08:29:53.531-07:00",
      "name": "operation-1782746993451-655662144e257-1d7b959c-ea96f49c",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746993451-655662144e257-1d7b959c-ea96f49c",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/8607707594908184990",
      "startTime": "2026-06-29T08:29:53.538-07:00",
      "status": "RUNNING",
      "targetId": "2753888838017298537",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:29:54.048763854Z",
  "resource": {
    "labels": {
      "location": "us-central1-a",
      "method": "compute.reservations.delete",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:29:53.409862Z"
}

compute.reservations.get: get

#
ServiceName
compute.googleapis.com

Description

Retrieves information about the specified reservation.

Data Access audit logs are disabled by default.

compute.reservations.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.reservations.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new reservation. For more information, readReserving zonal resources.

Example Audit Log Entry #

{
  "insertId": "y5xxwke6gaxy",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "17918d58-c4f0-4d4f-8bf1-006fad042407"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746758491-655661343acc8-55548b2b-08e5546a",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.reservations.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
          "service": "compute",
          "type": "compute.reservations"
        }
      }
    ],
    "methodName": "v1.compute.reservations.insert",
    "request": {
      "@type": "type.googleapis.com/compute.reservations.insert",
      "name": "dwn4-dw745960",
      "specificReservation": {
        "count": "1",
        "instanceProperties": {
          "machineType": "e2-micro"
        }
      },
      "specificReservationRequired": false,
      "zone": "us-central1-a"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.reservations.create invocation-id/6afe383282904f5c99ce5fcb84f81969 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:25:58.817438Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "8517525243176104041",
      "insertTime": "2026-06-29T08:25:58.704-07:00",
      "name": "operation-1782746758491-655661343acc8-55548b2b-08e5546a",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746758491-655661343acc8-55548b2b-08e5546a",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/8517525243176104041",
      "startTime": "2026-06-29T08:25:58.710-07:00",
      "status": "RUNNING",
      "targetId": "2753888838017298537",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
      "user": "user@example.com",
      "zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:25:59.723022760Z",
  "resource": {
    "labels": {
      "location": "us-central1-a",
      "method": "compute.reservations.insert",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:25:58.459020Z"
}

compute.reservations.list: list

#
ServiceName
compute.googleapis.com

Description

A list of all the reservations that have been configured for the specified project in specified zone.

Data Access audit logs are disabled by default.

compute.reservations.performMaintenance: performMaintenance

#
ServiceName
compute.googleapis.com

Description

Perform maintenance on an extended reservation

compute.reservations.resize: resize

#
ServiceName
compute.googleapis.com

Description

Resizes the reservation (applicable to standalone reservations only). For more information, readModifying reservations.

compute.reservations.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.reservations.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.reservations.update: update

#
ServiceName
compute.googleapis.com

Description

Update share settings of the reservation.

compute.resourcePolicies.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of resource policies. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.resourcePolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified resource policy.

Example Audit Log Entry #

{
  "insertId": "by3381e67xz4",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "633e2c64-e63f-492f-b625-c9135400abe8"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782747119236-6556628c43523-71ae348f-48a21077",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.resourcePolicies.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
          "service": "compute",
          "type": "compute.resourcePolicies"
        }
      }
    ],
    "methodName": "v1.compute.resourcePolicies.delete",
    "request": {
      "@type": "type.googleapis.com/compute.resourcePolicies.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.resource-policies.delete invocation-id/b2f8933fffd144ec86b0b2912638feed environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:31:59.445513Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "254959561057710336",
      "insertTime": "2026-06-29T08:31:59.398-07:00",
      "name": "operation-1782747119236-6556628c43523-71ae348f-48a21077",
      "operationType": "delete",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782747119236-6556628c43523-71ae348f-48a21077",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/254959561057710336",
      "startTime": "2026-06-29T08:31:59.408-07:00",
      "status": "RUNNING",
      "targetId": "3948597118829015508",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:31:59.959212145Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "region": "us-central1",
      "resource_policy_id": "3948597118829015508"
    },
    "type": "gce_resource_policy"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:31:59.130981Z"
}

compute.resourcePolicies.get: get

#
ServiceName
compute.googleapis.com

Description

Retrieves all information of the specified resource policy.

Data Access audit logs are disabled by default.

compute.resourcePolicies.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.resourcePolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new resource policy.

Example Audit Log Entry #

{
  "insertId": "w32goe2unyk",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9d052125-07f7-4be1-864b-1201ec00c89d"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746939973-655661e14dfe1-a5a0ce94-2d1b0895",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.resourcePolicies.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
          "service": "compute",
          "type": "compute.resourcePolicies"
        }
      }
    ],
    "methodName": "v1.compute.resourcePolicies.insert",
    "request": {
      "@type": "type.googleapis.com/compute.resourcePolicies.insert",
      "name": "dwrp5-dw746783",
      "snapshotSchedulePolicy": {
        "retentionPolicy": {
          "maxRetentionDays": "1"
        },
        "schedule": {
          "dailySchedule": {
            "daysInCycle": "1",
            "startTime": "04:00"
          }
        }
      }
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.resource-policies.create.snapshot-schedule invocation-id/ecd05751ffae4bd4b2c2ae61d12d31fd environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:29:00.142026Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "2467155034629943763",
      "insertTime": "2026-06-29T08:29:00.087-07:00",
      "name": "operation-1782746939973-655661e14dfe1-a5a0ce94-2d1b0895",
      "operationType": "insert",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782746939973-655661e14dfe1-a5a0ce94-2d1b0895",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/2467155034629943763",
      "startTime": "2026-06-29T08:29:00.089-07:00",
      "status": "RUNNING",
      "targetId": "3948597118829015508",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:29:00.461903164Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "region": "us-central1",
      "resource_policy_id": "3948597118829015508"
    },
    "type": "gce_resource_policy"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:28:59.942229Z"
}

compute.resourcePolicies.list: list

#
ServiceName
compute.googleapis.com

Description

A list all the resource policies that have been configured for the specified project in specified region.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-yclroje8ol7a",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "6b08e2ed-6723-4219-a035-5c6d9e231121"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "110162197178770594910"
      },
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
      "principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.resourcePolicies.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "beta.compute.resourcePolicies.list",
    "request": {
      "@type": "type.googleapis.com/compute.resourcePolicies.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 cluster-autoscaler,gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:39:47.818564Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/resourcePolicies",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:39:48.183988090Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "region": "us-central1",
      "resource_policy_id": ""
    },
    "type": "gce_resource_policy"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:39:47.783707Z"
}

compute.resourcePolicies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Modify the specified resource policy.

compute.resourcePolicies.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.resourcePolicies.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.rolloutPlans.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes a RolloutPlan.

compute.rolloutPlans.get: get

#
ServiceName
compute.googleapis.com

Description

Gets details of a single project-scoped RolloutPlan.

Data Access audit logs are disabled by default.

compute.rolloutPlans.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new RolloutPlan in a given project and location.

compute.rolloutPlans.list: list

#
ServiceName
compute.googleapis.com

Description

Lists RolloutPlans in a given project and location.

Data Access audit logs are disabled by default.

compute.rollouts.advance: advance

#
ServiceName
compute.googleapis.com

Description

Advances a Rollout to the next wave, or completes it if no waves remain.

compute.rollouts.cancel: cancel

#
ServiceName
compute.googleapis.com

Description

Cancels a Rollout.

compute.rollouts.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes a Rollout.

compute.rollouts.get: get

#
ServiceName
compute.googleapis.com

Description

Gets details of a single project-scoped Rollout.

Data Access audit logs are disabled by default.

compute.rollouts.list: list

#
ServiceName
compute.googleapis.com

Description

Lists Rollouts in a given project and location.

Data Access audit logs are disabled by default.

compute.rollouts.pause: pause

#
ServiceName
compute.googleapis.com

Description

Pauses a Rollout.

compute.rollouts.resume: resume

#
ServiceName
compute.googleapis.com

Description

Resumes a Rollout.

compute.routers.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of routers. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "d1n4mrdsnkg",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "27b55eac-2a95-4f8f-b06e-79074f298552"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.routers.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.routers.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.routers.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routers.list invocation-id/ee179d0149344bb7bcd08c515368504a environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:46.499347Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/routers",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:47.088357155Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.routers.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:46.446689Z"
}

compute.routers.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified Router resource.

Example Audit Log Entry #

{
  "insertId": "w5e36e52ixs",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "1f8a70c2-da96-4902-bde3-88782abf5ec4"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750838708-655670676d831-3c4ffca5-bef06add",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.routers.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
          "service": "compute",
          "type": "compute.routers"
        }
      }
    ],
    "methodName": "v1.compute.routers.delete",
    "request": {
      "@type": "type.googleapis.com/compute.routers.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routers.delete invocation-id/8283a36d91d64fb19d24b3d644a42a93 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:33:58.832838Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "7809329013451595929",
      "insertTime": "2026-06-29T09:33:58.793-07:00",
      "name": "operation-1782750838708-655670676d831-3c4ffca5-bef06add",
      "operationType": "delete",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750838708-655670676d831-3c4ffca5-bef06add",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/7809329013451595929",
      "startTime": "2026-06-29T09:33:58.800-07:00",
      "status": "RUNNING",
      "targetId": "841057025972445937",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:33:59.535976879Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "region": "us-central1",
      "router_id": "841057025972445937"
    },
    "type": "gce_router"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:33:58.676672Z"
}

compute.routers.deleteRoutePolicy: deleteRoutePolicy

#
ServiceName
compute.googleapis.com

Description

Deletes Route Policy

compute.routers.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified Router resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "nvnltle92jjq",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "0a700996-0978-43aa-a641-b4dc7fca4fe9"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.routers.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
          "service": "compute",
          "type": "compute.routers"
        }
      }
    ],
    "methodName": "v1.compute.routers.get",
    "request": {
      "@type": "type.googleapis.com/compute.routers.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routers.create invocation-id/f69a59bf5ade4f5fb8eab3137b2e79ef environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:24:11.692522Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:24:11.929199718Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "region": "us-central1",
      "router_id": "841057025972445937"
    },
    "type": "gce_router"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:24:11.618967Z"
}

compute.routers.getNatIpInfo: getNatIpInfo

#
ServiceName
compute.googleapis.com

Description

Retrieves runtime NAT IP information.

Data Access audit logs are disabled by default.

compute.routers.getNatMappingInfo: getNatMappingInfo

#
ServiceName
compute.googleapis.com

Description

Retrieves runtime Nat mapping information of VM endpoints.

Data Access audit logs are disabled by default.

compute.routers.getRoutePolicy: getRoutePolicy

#
ServiceName
compute.googleapis.com

Description

Returns specified Route Policy

Data Access audit logs are disabled by default.

compute.routers.getRouterStatus: getRouterStatus

#
ServiceName
compute.googleapis.com

Description

Retrieves runtime information of the specified router.

Data Access audit logs are disabled by default.

compute.routers.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a Router resource in the specified project and region using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-toawhle2sp2k",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "ccc4a20f-836b-4d47-8c82-2a74f8bd7c41"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745450335-65565c54acdc5-b4f870dd-9299e4f6",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.routers.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/routers/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/routers/dwn3-dw745304",
          "service": "compute",
          "type": "compute.routers"
        }
      },
      {
        "granted": true,
        "permission": "compute.networks.updatePolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/dwn3-dw745304",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.routers.insert",
    "request": {
      "@type": "type.googleapis.com/compute.routers.insert",
      "name": "dwn3-dw745304",
      "network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn3-dw745304"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routers.create invocation-id/17b5fa44ebae489490e26180c6f6d175 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:04:10.660299Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/routers/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "4715875489907947397",
      "insertTime": "2026-06-29T08:04:10.507-07:00",
      "name": "operation-1782745450335-65565c54acdc5-b4f870dd-9299e4f6",
      "operationType": "insert",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782745450335-65565c54acdc5-b4f870dd-9299e4f6",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/4715875489907947397",
      "startTime": "2026-06-29T08:04:10.512-07:00",
      "status": "RUNNING",
      "targetId": "424833158361331589",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/routers/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:04:10.979288224Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "region": "us-central1",
      "router_id": "424833158361331589"
    },
    "type": "gce_router"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:04:10.303422Z"
}

compute.routers.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of Router resources available to the specified project.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-9ddbphe2fjhq",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "e7e15147-6dfb-4d4d-9653-f0c797d01f24"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.routers.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.routers.list",
    "request": {
      "@type": "type.googleapis.com/compute.routers.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routers.list invocation-id/7a46e704be124e3e877b31298cb6b252 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:37:32.893063Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/routers",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:37:33.073149721Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "region": "us-central1",
      "router_id": ""
    },
    "type": "gce_router"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T15:37:32.857871Z"
}

compute.routers.listBgpRoutes: listBgpRoutes

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of router bgp routes available to the specified project.

Data Access audit logs are disabled by default.

compute.routers.listRoutePolicies: listRoutePolicies

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of router route policy subresources available to the specified project.

Data Access audit logs are disabled by default.

compute.routers.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified Router resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.

compute.routers.patchRoutePolicy: patchRoutePolicy

#
ServiceName
compute.googleapis.com

Description

Patches Route Policy

compute.routers.preview: preview

#
ServiceName
compute.googleapis.com

Description

Preview fields auto-generated during router create andupdate operations. Calling this method does NOT create or update the router.

compute.routers.update: update

#
ServiceName
compute.googleapis.com

Description

Updates the specified Router resource with the data included in the request. This method conforms toPUT semantics, which requests that the state of the target resource be created or replaced with the state defined by the representation enclosed in the request message payload.

compute.routers.updateRoutePolicy: updateRoutePolicy

#
ServiceName
compute.googleapis.com

Description

Updates or creates new Route Policy

compute.routes.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified Route resource.

Example Audit Log Entry #

{
  "insertId": "-rez22tdk2vg",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a66ddecc-2d27-47f6-9691-50e671377cca"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.routes.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
          "service": "compute",
          "type": "compute.routes"
        }
      }
    ],
    "methodName": "v1.compute.routes.delete",
    "request": {
      "@type": "type.googleapis.com/compute.routes.delete"
    },
    "requestMetadata": {
      "callerIp": "private",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:41:18.384089Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "2381360902523796193",
      "insertTime": "2026-06-29T07:41:18.204-07:00",
      "name": "operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2381360902523796193",
      "startTime": "2026-06-29T07:41:18.217-07:00",
      "status": "RUNNING",
      "targetId": "6536496377037274206",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
      "user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:41:18.511695891Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "route_id": "6536496377037274206"
    },
    "type": "gce_route"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:41:18.012241Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • GCP Virtual Private Cloud Route Deletion source medium: Identifies when a Virtual Private Cloud (VPC) route is deleted in Google Cloud Platform (GCP). Google Cloud routes define the paths that network traffic takes from a virtual machine (VM) instance to other destinations. These destinations can be inside a Google VPC network or outside it. An adversary may delete a route in order to impact the flow of network traffic in their target's cloud environment.T1562, T1562.007, T1578, T1578.005

compute.routes.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified Route resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-959yd8e2juoc",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "b4004784-64a2-4fcd-b103-810b0ef71de0"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.routes.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/routes/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/routes/dwg2-dw743447",
          "service": "compute",
          "type": "compute.routes"
        }
      }
    ],
    "methodName": "v1.compute.routes.get",
    "request": {
      "@type": "type.googleapis.com/compute.routes.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routes.create invocation-id/5a489800c8ae4df380924b4f0121aab9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:39:22.778184Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/routes/dwg2-dw743447",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:39:22.816507965Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "route_id": "7445334344751594859"
    },
    "type": "gce_route"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:39:22.694766Z"
}

compute.routes.insert: Insert route

#
ServiceName
compute.googleapis.com

Description

Creates a Route resource in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "tffr86d1fnk",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9b2d50b7-c9a2-486d-979c-43961d0c2fca"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782743729162-655655eb3c992-7396fd98-36c1510c",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "110162197178770594910"
      },
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
      "principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.routes.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
          "service": "compute",
          "type": "compute.routes"
        }
      },
      {
        "granted": true,
        "permission": "compute.networks.updatePolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/default",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/default",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.routes.insert",
    "request": {
      "@type": "type.googleapis.com/compute.routes.insert",
      "description": "k8s-node-route",
      "destRange": "10.0.0.0/24",
      "name": "gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
      "network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/default",
      "nextHopInstance": "zones/us-central1-a/instances/gke-dwgke-dw743447-default-pool-d20f3f37-s2rw",
      "priority": "1000"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 Kubernetes/0.0.0 (linux amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:35:29.695230Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "7290103536500554846",
      "insertTime": "2026-06-29T07:35:29.518-07:00",
      "name": "operation-1782743729162-655655eb3c992-7396fd98-36c1510c",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782743729162-655655eb3c992-7396fd98-36c1510c",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/7290103536500554846",
      "startTime": "2026-06-29T07:35:29.532-07:00",
      "status": "RUNNING",
      "targetId": "6536496377037274206",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
      "user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:35:30.258679160Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "route_id": "6536496377037274206"
    },
    "type": "gce_route"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:35:29.207201Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • GCP Virtual Private Cloud Route Creation source low: Identifies when a virtual private cloud (VPC) route is created in Google Cloud Platform (GCP). Google Cloud routes define the paths that network traffic takes from a virtual machine (VM) instance to other destinations. These destinations can be inside a Google VPC network or outside it. An adversary may create a route in order to impact the flow of network traffic in their target's cloud environment.T1562, T1562.007, T1578, T1578.005

compute.routes.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of Route resources available to the specified project.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "kvj9q7e616q6",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9aa3f09f-c92a-4228-81f7-6484acfbc1dc"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.routes.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.routes.list",
    "numResponseItems": "43",
    "request": {
      "@type": "type.googleapis.com/compute.routes.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routes.list invocation-id/a785f0a0d1c548c9b81ad47c5cadec43 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:25.375624Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/routes",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:25.949158475Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "route_id": ""
    },
    "type": "gce_route"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:25.313652Z"
}

compute.routes.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.securityPolicies.addRule: addRule

#
ServiceName
compute.googleapis.com

Description

Inserts a rule into a security policy.

Example Audit Log Entry #

{
  "insertId": "k9c6hwd4wlc",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "0270021b-eeeb-4ca0-a167-076518679eb2"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745463188-65565c60eed14-8cae6859-612cf305",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.securityPolicies.update",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
          "service": "compute",
          "type": "compute.securityPolicies"
        }
      }
    ],
    "methodName": "v1.compute.securityPolicies.addRule",
    "request": {
      "@type": "type.googleapis.com/compute.securityPolicies.addRule",
      "action": "deny(403)",
      "match": {
        "config": {
          "srcIpRanges": [
            "192.0.2.0/24"
          ]
        },
        "versionedExpr": "SRC_IPS_V1"
      },
      "priority": "1000"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.security-policies.rules.create invocation-id/d0929ee2866a4574990367d5adbb6616 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:04:23.931061Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "3773060907793332120",
      "insertTime": "2026-06-29T08:04:23.752-07:00",
      "name": "operation-1782745463188-65565c60eed14-8cae6859-612cf305",
      "operationType": "AddRule",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745463188-65565c60eed14-8cae6859-612cf305",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/3773060907793332120",
      "startTime": "2026-06-29T08:04:23.792-07:00",
      "status": "RUNNING",
      "targetId": "2027392770551789442",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/securityPolicies/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:04:24.736114521Z",
  "resource": {
    "labels": {
      "location": "global",
      "policy_name": "dwn3-dw745304",
      "project_id": "example-project-id"
    },
    "type": "network_security_policy"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:04:23.250477Z"
}

compute.securityPolicies.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all SecurityPolicy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-8as0iee86xmk",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9216a543-466f-4836-b4a9-ec11d3b2f5c3"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.securityPolicies.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.securityPolicies.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.securityPolicies.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.security-policies.list invocation-id/ff4b428ba3274d43a53e8ef002822881 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:50.626694Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/securityPolicies",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:51.144731260Z",
  "resource": {
    "labels": {
      "location": "global",
      "policy_name": "",
      "project_id": "example-project-id"
    },
    "type": "network_security_policy"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:50.524135Z"
}

compute.securityPolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified policy.

compute.securityPolicies.get: get

#
ServiceName
compute.googleapis.com

Description

List all of the ordered rules present in a single specified policy.

Data Access audit logs are disabled by default.

compute.securityPolicies.getRule: getRule

#
ServiceName
compute.googleapis.com

Description

Gets a rule at the specified priority.

Data Access audit logs are disabled by default.

compute.securityPolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new policy in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-6nb2ted4yy6",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "0a5fc297-a38d-4926-9e16-edcc065b1f38"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745453720-65565c57e71cc-1a4dbe1b-b7986a3a",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.securityPolicies.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
          "service": "compute",
          "type": "compute.securityPolicies"
        }
      }
    ],
    "methodName": "v1.compute.securityPolicies.insert",
    "request": {
      "@type": "type.googleapis.com/compute.securityPolicies.insert",
      "description": "dw",
      "name": "dwn3-dw745304"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.security-policies.create invocation-id/86af9383123c4ee7a025dd4cd570d3bb environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:04:14.099092Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "2837914212396644226",
      "insertTime": "2026-06-29T08:04:13.982-07:00",
      "name": "operation-1782745453720-65565c57e71cc-1a4dbe1b-b7986a3a",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745453720-65565c57e71cc-1a4dbe1b-b7986a3a",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2837914212396644226",
      "startTime": "2026-06-29T08:04:13.984-07:00",
      "status": "RUNNING",
      "targetId": "2027392770551789442",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/securityPolicies/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:04:14.498801934Z",
  "resource": {
    "labels": {
      "location": "global",
      "policy_name": "dwn3-dw745304",
      "project_id": "example-project-id"
    },
    "type": "network_security_policy"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:04:13.792466Z"
}

compute.securityPolicies.list: list

#
ServiceName
compute.googleapis.com

Description

List all the policies that have been configured for the specified project.

Data Access audit logs are disabled by default.

compute.securityPolicies.listPreconfiguredExpressionSets: listPreconfiguredExpressionSets

#
ServiceName
compute.googleapis.com

Description

Gets the current list of preconfigured Web Application Firewall (WAF) expressions.

Data Access audit logs are disabled by default.

compute.securityPolicies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified policy with the data included in the request. To clear fields in the policy, leave the fields empty and specify them in the updateMask. This cannot be used to be update the rules in the policy. Please use the per rule methods like addRule, patchRule, and removeRule instead.

compute.securityPolicies.patchRule: patchRule

#
ServiceName
compute.googleapis.com

Description

Patches a rule at the specified priority. To clear fields in the rule, leave the fields empty and specify them in the updateMask.

compute.securityPolicies.removeRule: removeRule

#
ServiceName
compute.googleapis.com

Description

Deletes a rule at the specified priority.

compute.securityPolicies.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a security policy. To learn more about labels, read the Labeling Resources documentation.

compute.serviceAttachments.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all ServiceAttachment resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-eowacze5vv8g",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "68f4061c-2bf3-465c-aaf0-45ec61aea219"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.serviceAttachments.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.serviceAttachments.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.serviceAttachments.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.service-attachments.list invocation-id/6a38523f01cb4c52943bbc4719250685 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:37:20.499704Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/serviceAttachments",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:37:21.141281302Z",
  "resource": {
    "labels": {
      "method": "compute.serviceAttachments.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com"
    },
    "type": "audited_resource"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T15:37:20.396035Z"
}

compute.serviceAttachments.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified ServiceAttachment in the given scope

compute.serviceAttachments.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified ServiceAttachment resource in the given scope.

Data Access audit logs are disabled by default.

compute.serviceAttachments.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.serviceAttachments.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a ServiceAttachment in the specified project in the given scope using the parameters that are included in the request.

compute.serviceAttachments.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the ServiceAttachments for a project in the given scope.

Data Access audit logs are disabled by default.

compute.serviceAttachments.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified ServiceAttachment resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.

compute.serviceAttachments.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.serviceAttachments.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.snapshotSettings.get: get

#
ServiceName
compute.googleapis.com

Description

Get snapshot settings.

Data Access audit logs are disabled by default.

compute.snapshotSettings.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patch snapshot settings.

compute.snapshots.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified Snapshot resource. Keep in mind that deleting a single snapshot might not necessarily delete all the data on that snapshot. If any data on the snapshot that is marked for deletion is needed for subsequent snapshots, the data will be moved to the next corresponding snapshot. For more information, seeDeleting snapshots.

Example Audit Log Entry #

{
  "insertId": "-1cd1xjegxnie",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "e5652fd5-eba6-471f-b9e0-c8b717670d1b"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750219415-65566e18d304a-7361d396-ee07909b",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.snapshots.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/snapshots/dwsnap7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/snapshots/dwsnap7201353",
          "service": "compute",
          "type": "compute.snapshots"
        }
      }
    ],
    "methodName": "v1.compute.snapshots.delete",
    "request": {
      "@type": "type.googleapis.com/compute.snapshots.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.snapshots.delete invocation-id/13f58f77238d4e5297dd4559d74bbb41 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:23:39.636874Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/snapshots/dwsnap7201353",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "275427962146202340",
      "insertTime": "2026-06-29T09:23:39.515-07:00",
      "name": "operation-1782750219415-65566e18d304a-7361d396-ee07909b",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782750219415-65566e18d304a-7361d396-ee07909b",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/275427962146202340",
      "startTime": "2026-06-29T09:23:39.521-07:00",
      "status": "RUNNING",
      "targetId": "8262724568879146268",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/snapshots/dwsnap7201353",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:23:40.305965552Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "snapshot_id": "8262724568879146268"
    },
    "type": "gce_snapshot"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:23:39.382036Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
PermissionType (kusto rule field)eqADMIN_WRITE1 rulekusto
Severity (kusto rule field)eqNOTICE1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • GCP Audit Logs - Detect Bulk VM Snapshot Deletion source high: Detects bulk deletion of Google Cloud VM snapshots within a short time period, which may indicate data destruction or defense evasion activities. VM snapshots are critical for backup and disaster recovery. Bulk deletion of snapshots can prevent recovery from incidents and may indicate malicious activity such as ransomware, data destruction, or an attempt to cover tracks after a security breach. Adversaries may delete snapshots to maximize damage, prevent forensic investigation, or hinder recovery efforts. This rule triggers when multiple snapshots are deleted by the same user within a 1-minute window.T1485, T1490, T1562, T1562.001

compute.snapshots.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified Snapshot resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-gwl536e3z2ce",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a89a682d-5aac-4f83-adf0-71a3894ce7f1"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.snapshots.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/snapshots/dwg2-dw743447",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/snapshots/dwg2-dw743447",
          "service": "compute",
          "type": "compute.snapshots"
        }
      }
    ],
    "methodName": "v1.compute.snapshots.get",
    "request": {
      "@type": "type.googleapis.com/compute.snapshots.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.snapshot invocation-id/b2c31cc6aed14ec89b974a9093f05120 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:38:57.061033Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/snapshots/dwg2-dw743447",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:38:57.957501193Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "snapshot_id": "8400522908034612701"
    },
    "type": "gce_snapshot"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:38:56.916687Z"
}

compute.snapshots.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "8lny9be3wixa",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "7986d8a0-a67b-427b-9b13-6af55e283059"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.snapshots.getIamPolicy",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/global/snapshots/dwsnap7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/snapshots/dwsnap7201353",
          "service": "compute",
          "type": "compute.snapshots"
        }
      }
    ],
    "methodName": "v1.compute.snapshots.getIamPolicy",
    "request": {
      "@type": "type.googleapis.com/compute.snapshots.getIamPolicy",
      "optionsRequestedPolicyVersion": "3"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.snapshots.add-iam-policy-binding invocation-id/8e7965f200914c2791edd6a21492223f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:23:37.529028Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/snapshots/dwsnap7201353",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:23:37.549780777Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "snapshot_id": "8262724568879146268"
    },
    "type": "gce_snapshot"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:23:37.388087Z"
}

compute.snapshots.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a snapshot in the specified project using the data included in the request. For regular snapshot creation, consider using this method instead of disks.createSnapshot, as this method supports more features, such as creating snapshots in a project different from the source disk project.

Example Audit Log Entry #

{
  "insertId": "z0o37qefayw6",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "803b8483-b55b-4f9e-b9be-c6767899a3c1"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750195660-65566e022b59d-bd3b8614-a76cae00",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.snapshots.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/snapshots/dwsnap7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/snapshots/dwsnap7201353",
          "service": "compute",
          "type": "compute.snapshots"
        }
      },
      {
        "granted": true,
        "permission": "compute.disks.createSnapshot",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/zones/us-central1-a/disks/dwd7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/disks/dwd7201353",
          "service": "compute",
          "type": "compute.disks"
        }
      },
      {
        "granted": true,
        "permission": "compute.snapshots.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/snapshots/dwsnap7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/snapshots/dwsnap7201353",
          "service": "compute",
          "type": "compute.snapshots"
        }
      }
    ],
    "methodName": "v1.compute.snapshots.insert",
    "request": {
      "@type": "type.googleapis.com/compute.snapshots.insert",
      "name": "dwsnap7201353",
      "sourceDisk": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwd7201353"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.snapshots.create invocation-id/b1f8ce8d9f3f4ea0b61c037eb8938633 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:23:16.429182Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "US"
      ]
    },
    "resourceName": "projects/example-project-id/global/snapshots/dwsnap7201353",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "2456351177540838684",
      "insertTime": "2026-06-29T09:23:15.887-07:00",
      "name": "operation-1782750195660-65566e022b59d-bd3b8614-a76cae00",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782750195660-65566e022b59d-bd3b8614-a76cae00",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2456351177540838684",
      "startTime": "2026-06-29T09:23:15.889-07:00",
      "status": "RUNNING",
      "targetId": "8262724568879146268",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/snapshots/dwsnap7201353",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:23:17.168078709Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "snapshot_id": "8262724568879146268"
    },
    "type": "gce_snapshot"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:23:15.636676Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
protoPayload.response.error (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

compute.snapshots.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of Snapshot resources contained within the specified project.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-ib1ftze3opa8",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "093a1f39-40b6-4e0d-b2ce-1ecebf7ecc22"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.snapshots.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.snapshots.list",
    "request": {
      "@type": "type.googleapis.com/compute.snapshots.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.snapshots.list invocation-id/6170a5d6323645ec9f7193c9d3cd4b07 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:22.625769Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/snapshots",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:23.501243596Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "snapshot_id": ""
    },
    "type": "gce_snapshot"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:22.577253Z"
}

compute.snapshots.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

Example Audit Log Entry #

{
  "insertId": "-8k385se5yies",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9f50c0d4-cce6-4f40-b6bc-997369aea469"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.snapshots.setIamPolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/snapshots/dwsnap7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/snapshots/dwsnap7201353",
          "service": "compute",
          "type": "compute.snapshots"
        }
      }
    ],
    "methodName": "v1.compute.snapshots.setIamPolicy",
    "request": {
      "@type": "type.googleapis.com/compute.snapshots.setIamPolicy",
      "policy": {
        "bindings": [
          {
            "members": [
              "user:user@example.com"
            ],
            "role": "roles/compute.storageAdmin"
          }
        ],
        "etag": "\u0000 \u0001",
        "version": "3"
      }
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.snapshots.add-iam-policy-binding invocation-id/8e7965f200914c2791edd6a21492223f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:23:38.108648Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/snapshots/dwsnap7201353",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:23:39.093621325Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "snapshot_id": "8262724568879146268"
    },
    "type": "gce_snapshot"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:23:37.825435Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
protoPayload.response.error (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

compute.snapshots.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a snapshot. To learn more about labels, read theLabeling Resources documentation.

compute.snapshots.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.snapshots.updateKmsKey: updateKmsKey

#
ServiceName
compute.googleapis.com

Description

Rotates the customer-managed encryption key to the latest version for the specified snapshot.

compute.sslCertificates.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all SslCertificate resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-o4fnx0dmwx8",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "d33b414c-0343-4793-aa45-463c9056c1cd"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.sslCertificates.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.sslCertificates.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.sslCertificates.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.ssl-certificates.list invocation-id/aabac67204074387b77cd30fa78802ac environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:34.627407Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/sslCertificates",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:34.941426397Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "ssl_certificate_id": "",
      "ssl_certificate_name": ""
    },
    "type": "gce_ssl_certificate"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:34.534530Z"
}

compute.sslCertificates.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified SslCertificate resource.

compute.sslCertificates.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified SslCertificate resource.

Data Access audit logs are disabled by default.

compute.sslCertificates.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a SslCertificate resource in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-bdeahaehmhzw",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "60208691-711d-4fa3-bfe4-b8af41167a7f"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745447775-65565c523bd95-a351d411-d01cd85a",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.sslCertificates.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/sslCertificates/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/sslCertificates/dwn3-dw745304",
          "service": "compute",
          "type": "compute.sslCertificates"
        }
      },
      {
        "granted": true,
        "permission": "compute.sslCertificates.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/sslCertificates/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/sslCertificates/dwn3-dw745304",
          "service": "compute",
          "type": "compute.sslCertificates"
        }
      }
    ],
    "methodName": "v1.compute.sslCertificates.insert",
    "request": {
      "@type": "type.googleapis.com/compute.sslCertificates.insert",
      "name": "dwn3-dw745304"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.ssl-certificates.create invocation-id/f81212f6991b4d3ab5d96055ac907cc8 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:04:08.166313Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/sslCertificates/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "8369178116449318792",
      "insertTime": "2026-06-29T08:04:07.860-07:00",
      "name": "operation-1782745447775-65565c523bd95-a351d411-d01cd85a",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745447775-65565c523bd95-a351d411-d01cd85a",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/8369178116449318792",
      "startTime": "2026-06-29T08:04:07.865-07:00",
      "status": "RUNNING",
      "targetId": "3884773814616143752",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/sslCertificates/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:04:08.417792981Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "ssl_certificate_id": "3884773814616143752",
      "ssl_certificate_name": "dwn3-dw745304"
    },
    "type": "gce_ssl_certificate"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:04:07.749897Z"
}

compute.sslCertificates.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of SslCertificate resources available to the specified project.

Data Access audit logs are disabled by default.

compute.sslPolicies.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all SslPolicy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.sslPolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified SSL policy. The SSL policy resource can be deleted only if it is not in use by any TargetHttpsProxy or TargetSslProxy resources.

Example Audit Log Entry #

{
  "insertId": "7szi1reg2b44",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "f58ea3ac-d33a-49ba-8837-7a6ff8a5862e"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782747115931-655662891c853-7cb36233-6cda23b6",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.sslPolicies.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
          "service": "compute",
          "type": "compute.sslPolicies"
        }
      }
    ],
    "methodName": "v1.compute.sslPolicies.delete",
    "request": {
      "@type": "type.googleapis.com/compute.sslPolicies.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.ssl-policies.delete invocation-id/bb544914090b4350a4585c1415a8cc07 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:31:56.173662Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "474477542874493187",
      "insertTime": "2026-06-29T08:31:56.040-07:00",
      "name": "operation-1782747115931-655662891c853-7cb36233-6cda23b6",
      "operationType": "delete",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782747115931-655662891c853-7cb36233-6cda23b6",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/474477542874493187",
      "startTime": "2026-06-29T08:31:56.049-07:00",
      "status": "RUNNING",
      "targetId": "900054728269836753",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/sslPolicies/dwssl-dw746783",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:31:56.503154765Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.sslPolicies.delete",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:31:55.905263Z"
}

compute.sslPolicies.get: get

#
ServiceName
compute.googleapis.com

Description

Lists all of the ordered rules present in a single specified policy.

Data Access audit logs are disabled by default.

compute.sslPolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Returns the specified SSL policy resource.

Example Audit Log Entry #

{
  "insertId": "lxazskdf8ao",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "e7c35f54-2e48-4a4d-b33f-c00c7ec67e76"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782746942037-655661e345da5-7c4b5bed-a03bcb5f",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.sslPolicies.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
          "service": "compute",
          "type": "compute.sslPolicies"
        }
      }
    ],
    "methodName": "v1.compute.sslPolicies.insert",
    "request": {
      "@type": "type.googleapis.com/compute.sslPolicies.insert",
      "minTlsVersion": "TLS_1_2",
      "name": "dwssl-dw746783",
      "profile": "MODERN"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.ssl-policies.create invocation-id/16354b3dbf2742aba96ca00a2d7775a8 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:29:03.014257Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "57067654404321745",
      "insertTime": "2026-06-29T08:29:02.439-07:00",
      "name": "operation-1782746942037-655661e345da5-7c4b5bed-a03bcb5f",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782746942037-655661e345da5-7c4b5bed-a03bcb5f",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/57067654404321745",
      "startTime": "2026-06-29T08:29:02.443-07:00",
      "status": "RUNNING",
      "targetId": "900054728269836753",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/sslPolicies/dwssl-dw746783",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:29:03.792808390Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.sslPolicies.insert",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:29:01.999333Z"
}

compute.sslPolicies.list: list

#
ServiceName
compute.googleapis.com

Description

Lists all the SSL policies that have been configured for the specified project.

Data Access audit logs are disabled by default.

compute.sslPolicies.listAvailableFeatures: listAvailableFeatures

#
ServiceName
compute.googleapis.com

Description

Lists all features that can be specified in the SSL policy when using custom profile.

Data Access audit logs are disabled by default.

compute.sslPolicies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified SSL policy with the data included in the request.

compute.storagePoolTypes.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of storage pool types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.storagePoolTypes.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified storage pool type.

Data Access audit logs are disabled by default.

compute.storagePoolTypes.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of storage pool types available to the specified project.

Data Access audit logs are disabled by default.

compute.storagePools.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of storage pools. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.storagePools.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified storage pool. Deleting a storagePool removes its data permanently and is irreversible. However, deleting a storagePool does not delete any snapshots previously made from the storagePool. You must separately delete snapshots.

compute.storagePools.get: get

#
ServiceName
compute.googleapis.com

Description

Returns a specified storage pool. Gets a list of available storage pools by making a list() request.

Data Access audit logs are disabled by default.

compute.storagePools.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.storagePools.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a storage pool in the specified project using the data in the request.

compute.storagePools.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of storage pools contained within the specified zone.

Data Access audit logs are disabled by default.

compute.storagePools.listDisks: listDisks

#
ServiceName
compute.googleapis.com

Description

Lists the disks in a specified storage pool.

Data Access audit logs are disabled by default.

compute.storagePools.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

compute.storagePools.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.storagePools.update: update

#
ServiceName
compute.googleapis.com

Description

Updates the specified storagePool with the data included in the request. The update is performed only on selected fields included as part of update-mask. Only the following fields can be modified: pool_provisioned_capacity_gb, pool_provisioned_iops and pool_provisioned_throughput.

compute.subnetworks.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of subnetworks. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "gz50ghe41rho",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "9b560ff3-9cc2-4f94-8723-aa79b7406b55"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.subnetworks.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.subnetworks.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.subnetworks.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.list invocation-id/52c852ef64b74b078e971c96a308b9e9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:03.867335Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/subnetworks",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:19:04.792393124Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.subnetworks.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:19:03.635745Z"
}

compute.subnetworks.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified subnetwork.

Example Audit Log Entry #

{
  "insertId": "-eetn32e39diy",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "a3fc5605-21fa-472d-b05c-c2926bed9d28"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782747049573-65566249d3e2f-da7f6a0f-8859dd5e",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.subnetworks.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      }
    ],
    "methodName": "v1.compute.subnetworks.delete",
    "request": {
      "@type": "type.googleapis.com/compute.subnetworks.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.delete invocation-id/9f4646520ad246dcaa9e987b24d05677 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:30:50.323877Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "1292404513359999301",
      "insertTime": "2026-06-29T08:30:50.279-07:00",
      "name": "operation-1782747049573-65566249d3e2f-da7f6a0f-8859dd5e",
      "operationType": "delete",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782747049573-65566249d3e2f-da7f6a0f-8859dd5e",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/1292404513359999301",
      "startTime": "2026-06-29T08:30:50.283-07:00",
      "status": "RUNNING",
      "targetId": "8667758831208445258",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:30:50.779202137Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "subnetwork_id": "8667758831208445258",
      "subnetwork_name": "dwn4-dw745960"
    },
    "type": "gce_subnetwork"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:30:49.647324Z"
}

compute.subnetworks.expandIpCidrRange: expandIpCidrRange

#
ServiceName
compute.googleapis.com

Description

Expands the IP CIDR range of the subnetwork to a specified value.

Example Audit Log Entry #

{
  "insertId": "-arxy3ye4st1s",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "cdb7aa93-b313-44e1-b926-f28a0c104529"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745347033-65565bf228b07-42267ea4-bac5a8d2",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.subnetworks.expandIpCidrRange",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      }
    ],
    "methodName": "v1.compute.subnetworks.expandIpCidrRange",
    "request": {
      "@type": "type.googleapis.com/compute.subnetworks.expandIpCidrRange",
      "ipCidrRange": "10.11.0.0/23"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.expand-ip-range invocation-id/d996edd4176e441ea1ffdb8c6e6faf07 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:02:27.738798Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "5566941891178477548",
      "insertTime": "2026-06-29T08:02:27.691-07:00",
      "name": "operation-1782745347033-65565bf228b07-42267ea4-bac5a8d2",
      "operationType": "expandIpCidrRange",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782745347033-65565bf228b07-42267ea4-bac5a8d2",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/5566941891178477548",
      "startTime": "2026-06-29T08:02:27.701-07:00",
      "status": "RUNNING",
      "targetId": "7239462238538380809",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:02:28.191377956Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "subnetwork_id": "7239462238538380809",
      "subnetwork_name": "dwn3-dw745304"
    },
    "type": "gce_subnetwork"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:02:27.085602Z"
}

compute.subnetworks.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified subnetwork.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-susohme4rfk4",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "cf92aa5a-8867-4bf5-bd75-56624357ef2a"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.subnetworks.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      }
    ],
    "methodName": "v1.compute.subnetworks.get",
    "request": {
      "@type": "type.googleapis.com/compute.subnetworks.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.create invocation-id/88997435245f4532ae2513fb4e2acb8d environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:42.379911Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:42.595146086Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "subnetwork_id": "424051083471474679",
      "subnetwork_name": "dwgen-dw739065"
    },
    "type": "gce_subnetwork"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:20:42.286501Z"
}

compute.subnetworks.getIamPolicy: getIamPolicy

#
ServiceName
compute.googleapis.com

Description

Gets the access control policy for a resource. May be empty if no such policy or resource exists.

Data Access audit logs are disabled by default.

compute.subnetworks.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a subnetwork in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-t3mzgge2w08o",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "243f1fa6-70a4-4f42-bf19-6dfc6755f3f3"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782739223725-65564522843f2-29cb8358-813b1c25",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.subnetworks.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      },
      {
        "granted": true,
        "permission": "compute.networks.updatePolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/dwgen-dw739065",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.subnetworks.insert",
    "request": {
      "@type": "type.googleapis.com/compute.subnetworks.insert",
      "ipCidrRange": "10.8.0.0/24",
      "name": "dwgen-dw739065",
      "network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwgen-dw739065",
      "privateIpGoogleAccess": false
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.create invocation-id/88997435245f4532ae2513fb4e2acb8d environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:25.013691Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "2040419509439811575",
      "insertTime": "2026-06-29T06:20:24.953-07:00",
      "name": "operation-1782739223725-65564522843f2-29cb8358-813b1c25",
      "operationType": "insert",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782739223725-65564522843f2-29cb8358-813b1c25",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/2040419509439811575",
      "status": "PENDING",
      "targetId": "424051083471474679",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:25.608503415Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "subnetwork_id": "424051083471474679",
      "subnetwork_name": "dwgen-dw739065"
    },
    "type": "gce_subnetwork"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T13:20:23.799297Z"
}

compute.subnetworks.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of subnetworks available to the specified project.

Data Access audit logs are disabled by default.

compute.subnetworks.listUsable: listUsable

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of all usable subnetworks in the project.

Data Access audit logs are disabled by default.

compute.subnetworks.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified subnetwork with the data included in the request. Only certain fields can be updated with a patch request as indicated in the field descriptions. You must specify the current fingerprint of the subnetwork resource being patched.

Example Audit Log Entry #

{
  "insertId": "46zk7xd723s",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "4693d407-89fc-4d5e-b830-80584aa19de9"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782751427697-6556729921c7a-cd5ddbd6-bcd78d58",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.subnetworks.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      },
      {
        "granted": true,
        "permission": "compute.subnetworks.update",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      }
    ],
    "methodName": "v1.compute.subnetworks.patch",
    "request": {
      "@type": "type.googleapis.com/compute.subnetworks.patch",
      "fingerprint": "���?@�m\r",
      "secondaryIpRanges": [
        {
          "ipCidrRange": "10.47.1.0/24",
          "rangeName": "sec1"
        }
      ]
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.update invocation-id/41cccc57ae6f4bc0b9477d1c50848116 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:43:47.947430Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "905571120127532",
      "insertTime": "2026-06-29T09:43:47.911-07:00",
      "name": "operation-1782751427697-6556729921c7a-cd5ddbd6-bcd78d58",
      "operationType": "compute.subnetworks.patch",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782751427697-6556729921c7a-cd5ddbd6-bcd78d58",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/905571120127532",
      "startTime": "2026-06-29T09:43:47.917-07:00",
      "status": "RUNNING",
      "targetId": "7299916566109298265",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:43:48.796662665Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "subnetwork_id": "7299916566109298265",
      "subnetwork_name": "dwn7e126182"
    },
    "type": "gce_subnetwork"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:43:47.759356Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

compute.subnetworks.setIamPolicy: setIamPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy.

Example Audit Log Entry #

{
  "insertId": "z0ib7ce476qi",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "1ea9b3fd-4bc4-4b4e-9f18-22a226e35aff"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.subnetworks.setIamPolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      }
    ],
    "methodName": "v1.compute.subnetworks.setIamPolicy",
    "request": {
      "@type": "type.googleapis.com/compute.subnetworks.setIamPolicy",
      "policy": {
        "bindings": [
          {
            "members": [
              "user:user@example.com"
            ],
            "role": "roles/compute.networkUser"
          }
        ],
        "version": "3"
      }
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.set-iam-policy invocation-id/f1975807bc01441988a46254711c9efb environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:14:04.273751Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:14:05.110242737Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "subnetwork_id": "8667758831208445258",
      "subnetwork_name": "dwn4-dw745960"
    },
    "type": "gce_subnetwork"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:14:04.143265Z"
}

compute.subnetworks.setPrivateIpGoogleAccess: setPrivateIpGoogleAccess

#
ServiceName
compute.googleapis.com

Description

Set whether VMs in this subnet can access Google services without assigning external IP addresses through Private Google Access.

Example Audit Log Entry #

{
  "insertId": "-4fl9vpe83dq0",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "e0c5d2cf-7ff1-4b61-b750-52fb6b1a2e14"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745380423-65565c120087d-758930d8-c7d2e395",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.subnetworks.setPrivateIpGoogleAccess",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
          "service": "compute",
          "type": "compute.subnetworks"
        }
      }
    ],
    "methodName": "v1.compute.subnetworks.setPrivateIpGoogleAccess",
    "request": {
      "@type": "type.googleapis.com/compute.subnetworks.setPrivateIpGoogleAccess",
      "privateIpGoogleAccess": true
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.update invocation-id/0ff7455620ab4d81883162c36f481ac2 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:03:00.695200Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "715287601722898379",
      "insertTime": "2026-06-29T08:03:00.660-07:00",
      "name": "operation-1782745380423-65565c120087d-758930d8-c7d2e395",
      "operationType": "setPrivateIpGoogleAccess",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782745380423-65565c120087d-758930d8-c7d2e395",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/715287601722898379",
      "startTime": "2026-06-29T08:03:00.665-07:00",
      "status": "RUNNING",
      "targetId": "7239462238538380809",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:03:00.810818539Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "subnetwork_id": "7239462238538380809",
      "subnetwork_name": "dwn3-dw745304"
    },
    "type": "gce_subnetwork"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:03:00.551516Z"
}

compute.subnetworks.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.targetGrpcProxies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified TargetGrpcProxy in the given scope

compute.targetGrpcProxies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified TargetGrpcProxy resource in the given scope.

Data Access audit logs are disabled by default.

compute.targetGrpcProxies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a TargetGrpcProxy in the specified project in the given scope using the parameters that are included in the request.

compute.targetGrpcProxies.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the TargetGrpcProxies for a project in the given scope.

Data Access audit logs are disabled by default.

compute.targetGrpcProxies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified TargetGrpcProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.

compute.targetHttpProxies.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all TargetHttpProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-7pbhwme2ig8m",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "022d0ac7-2ed5-4089-8830-4acaebf3e8db"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.targetHttpProxies.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.targetHttpProxies.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.targetHttpProxies.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-http-proxies.list invocation-id/fa885c2816c04623b3c43d2bf84d9519 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:59.315733Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/targetHttpProxies",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:59.756703184Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "target_http_proxy_id": ""
    },
    "type": "gce_target_http_proxy"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:59.240439Z"
}

compute.targetHttpProxies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified TargetHttpProxy resource.

compute.targetHttpProxies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified TargetHttpProxy resource.

Data Access audit logs are disabled by default.

compute.targetHttpProxies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a TargetHttpProxy resource in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "bof91cd8jdg",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "882aea5f-b48a-4a41-a654-2edf867950f5"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745429324-65565c40a324a-19ad8652-71b5a643",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.targetHttpProxies.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
          "service": "compute",
          "type": "compute.targetHttpProxies"
        }
      },
      {
        "granted": true,
        "permission": "compute.urlMaps.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/urlMaps/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/urlMaps/dwn3-dw745304",
          "service": "compute",
          "type": "compute.urlMaps"
        }
      }
    ],
    "methodName": "v1.compute.targetHttpProxies.insert",
    "request": {
      "@type": "type.googleapis.com/compute.targetHttpProxies.insert",
      "name": "dwn3-dw745304",
      "urlMap": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/urlMaps/dwn3-dw745304"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-http-proxies.create invocation-id/7f5c5de7a99f40ffb3df0fa4e379892d environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:03:49.899777Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "2138839784539240378",
      "insertTime": "2026-06-29T08:03:49.763-07:00",
      "name": "operation-1782745429324-65565c40a324a-19ad8652-71b5a643",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745429324-65565c40a324a-19ad8652-71b5a643",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2138839784539240378",
      "startTime": "2026-06-29T08:03:49.765-07:00",
      "status": "RUNNING",
      "targetId": "1860445510560593850",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:03:49.972054496Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "target_http_proxy_id": "1860445510560593850"
    },
    "type": "gce_target_http_proxy"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:03:49.402214Z"
}

compute.targetHttpProxies.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of TargetHttpProxy resources available to the specified project.

Data Access audit logs are disabled by default.

compute.targetHttpProxies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified TargetHttpProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.

compute.targetHttpProxies.setUrlMap: setUrlMap

#
ServiceName
compute.googleapis.com

Description

Changes the URL map for TargetHttpProxy.

compute.targetHttpsProxies.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all TargetHttpsProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-o4fnx0dmx9g",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "4cf2c82f-2a6e-47af-befa-0536a5537313"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.targetHttpsProxies.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.targetHttpsProxies.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.targetHttpsProxies.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-https-proxies.list invocation-id/fb9687339f7542c4b2209bca1d37431f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:00.702467Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/targetHttpsProxies",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:19:00.973959637Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "target_https_proxy_id": ""
    },
    "type": "gce_target_https_proxy"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:19:00.617546Z"
}

compute.targetHttpsProxies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified TargetHttpsProxy resource.

compute.targetHttpsProxies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified TargetHttpsProxy resource.

Data Access audit logs are disabled by default.

compute.targetHttpsProxies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a TargetHttpsProxy resource in the specified project using the data included in the request.

compute.targetHttpsProxies.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of TargetHttpsProxy resources available to the specified project.

Data Access audit logs are disabled by default.

compute.targetHttpsProxies.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified TargetHttpsProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.

compute.targetHttpsProxies.setCertificateMap: setCertificateMap

#
ServiceName
compute.googleapis.com

Description

Changes the Certificate Map for TargetHttpsProxy.

compute.targetHttpsProxies.setQuicOverride: setQuicOverride

#
ServiceName
compute.googleapis.com

Description

Sets the QUIC override policy for TargetHttpsProxy.

compute.targetHttpsProxies.setSslCertificates: setSslCertificates

#
ServiceName
compute.googleapis.com

Description

Replaces SslCertificates for TargetHttpsProxy.

compute.targetHttpsProxies.setSslPolicy: setSslPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the SSL policy for TargetHttpsProxy. The SSL policy specifies the server-side support for SSL features. This affects connections between clients and the HTTPS proxy load balancer. They do not affect the connection between the load balancer and the backends.

compute.targetHttpsProxies.setUrlMap: setUrlMap

#
ServiceName
compute.googleapis.com

Description

Changes the URL map for TargetHttpsProxy.

compute.targetInstances.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of target instances. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.targetInstances.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified TargetInstance resource.

compute.targetInstances.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified TargetInstance resource.

Data Access audit logs are disabled by default.

compute.targetInstances.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a TargetInstance resource in the specified project and zone using the data included in the request.

compute.targetInstances.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of TargetInstance resources available to the specified project and zone.

Data Access audit logs are disabled by default.

compute.targetInstances.setSecurityPolicy: setSecurityPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the Google Cloud Armor security policy for the specified target instance. For more information, seeGoogle Cloud Armor Overview

compute.targetInstances.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.targetPools.addHealthCheck: addHealthCheck

#
ServiceName
compute.googleapis.com

Description

Adds health check URLs to a target pool.

compute.targetPools.addInstance: addInstance

#
ServiceName
compute.googleapis.com

Description

Adds an instance to a target pool.

compute.targetPools.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of target pools. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "d1n4mrdsnd8",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "765183ee-296c-4ba7-8fae-654dcfc311c7"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.targetPools.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.targetPools.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.targetPools.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-pools.list invocation-id/a3d168a0b2d54b90949100dbb28f3bf2 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:32.036448Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/targetPools",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:32.750396935Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.targetPools.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:31.976461Z"
}

compute.targetPools.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified target pool.

compute.targetPools.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified target pool.

Data Access audit logs are disabled by default.

compute.targetPools.getHealth: getHealth

#
ServiceName
compute.googleapis.com

Description

Gets the most recent health check results for each IP for the instance that is referenced by the given target pool.

Data Access audit logs are disabled by default.

compute.targetPools.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a target pool in the specified project and region using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-lbqbnje4266m",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "d76bb787-192d-4fcf-a012-8d4f83f48572"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745524113-65565c9b09055-c513e2c9-7445a58a",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.targetPools.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/targetPools/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/targetPools/dwn3-dw745304",
          "service": "compute",
          "type": "compute.targetPools"
        }
      }
    ],
    "methodName": "v1.compute.targetPools.insert",
    "request": {
      "@type": "type.googleapis.com/compute.targetPools.insert",
      "name": "dwn3-dw745304",
      "sessionAffinity": "NONE"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-pools.create invocation-id/8d40743a846749dabc01cb363f42e603 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:05:24.333221Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/targetPools/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "8053302139619850075",
      "insertTime": "2026-06-29T08:05:24.298-07:00",
      "name": "operation-1782745524113-65565c9b09055-c513e2c9-7445a58a",
      "operationType": "insert",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782745524113-65565c9b09055-c513e2c9-7445a58a",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/8053302139619850075",
      "startTime": "2026-06-29T08:05:24.301-07:00",
      "status": "RUNNING",
      "targetId": "4069930833999247195",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/targetPools/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:05:25.057201413Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "target_pool_id": "4069930833999247195",
      "zone": "us-central1"
    },
    "type": "gce_target_pool"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:05:24.174060Z"
}

compute.targetPools.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of target pools available to the specified project and region.

Data Access audit logs are disabled by default.

compute.targetPools.removeHealthCheck: removeHealthCheck

#
ServiceName
compute.googleapis.com

Description

Removes health check URL from a target pool.

compute.targetPools.removeInstance: removeInstance

#
ServiceName
compute.googleapis.com

Description

Removes instance URL from a target pool.

compute.targetPools.setBackup: setBackup

#
ServiceName
compute.googleapis.com

Description

Changes a backup target pool's configurations.

compute.targetPools.setSecurityPolicy: setSecurityPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the Google Cloud Armor security policy for the specified target pool. For more information, seeGoogle Cloud Armor Overview

compute.targetPools.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.targetSslProxies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified TargetSslProxy resource.

compute.targetSslProxies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified TargetSslProxy resource.

Data Access audit logs are disabled by default.

compute.targetSslProxies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a TargetSslProxy resource in the specified project using the data included in the request.

compute.targetSslProxies.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of TargetSslProxy resources available to the specified project.

Data Access audit logs are disabled by default.

compute.targetSslProxies.setBackendService: setBackendService

#
ServiceName
compute.googleapis.com

Description

Changes the BackendService for TargetSslProxy.

compute.targetSslProxies.setCertificateMap: setCertificateMap

#
ServiceName
compute.googleapis.com

Description

Changes the Certificate Map for TargetSslProxy.

compute.targetSslProxies.setProxyHeader: setProxyHeader

#
ServiceName
compute.googleapis.com

Description

Changes the ProxyHeaderType for TargetSslProxy.

compute.targetSslProxies.setSslCertificates: setSslCertificates

#
ServiceName
compute.googleapis.com

Description

Changes SslCertificates for TargetSslProxy.

compute.targetSslProxies.setSslPolicy: setSslPolicy

#
ServiceName
compute.googleapis.com

Description

Sets the SSL policy for TargetSslProxy. The SSL policy specifies the server-side support for SSL features. This affects connections between clients and the load balancer. They do not affect the connection between the load balancer and the backends.

compute.targetSslProxies.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.targetTcpProxies.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all TargetTcpProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.targetTcpProxies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified TargetTcpProxy resource.

compute.targetTcpProxies.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified TargetTcpProxy resource.

Data Access audit logs are disabled by default.

compute.targetTcpProxies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a TargetTcpProxy resource in the specified project using the data included in the request.

compute.targetTcpProxies.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of TargetTcpProxy resources available to the specified project.

Data Access audit logs are disabled by default.

compute.targetTcpProxies.setBackendService: setBackendService

#
ServiceName
compute.googleapis.com

Description

Changes the BackendService for TargetTcpProxy.

compute.targetTcpProxies.setProxyHeader: setProxyHeader

#
ServiceName
compute.googleapis.com

Description

Changes the ProxyHeaderType for TargetTcpProxy.

compute.targetTcpProxies.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.targetVpnGateways.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of target VPN gateways. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-l1srtzd5qdy",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "cfa4ad32-dfbf-4bab-b92b-539860650fa4"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.targetVpnGateways.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.targetVpnGateways.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.targetVpnGateways.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-vpn-gateways.list invocation-id/0ba41739ca1246208f746789acd4d806 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:49.259163Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/targetVpnGateways",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:50.182992379Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.targetVpnGateways.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:49.139697Z"
}

compute.targetVpnGateways.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified target VPN gateway.

Example Audit Log Entry #

{
  "insertId": "ftq1h3dkply",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "f7b3ea03-aeea-4f61-bb13-e8e0de91520c"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782751041762-6556712913470-2c7bc076-b63a6ff8",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.targetVpnGateways.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
          "service": "compute",
          "type": "compute.targetVpnGateways"
        }
      }
    ],
    "methodName": "v1.compute.targetVpnGateways.delete",
    "request": {
      "@type": "type.googleapis.com/compute.targetVpnGateways.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-vpn-gateways.delete invocation-id/43f96eb83b6442828edf6bc842a20fbe environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:37:21.964771Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "350832198996140462",
      "insertTime": "2026-06-29T09:37:21.885-07:00",
      "name": "operation-1782751041762-6556712913470-2c7bc076-b63a6ff8",
      "operationType": "delete",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782751041762-6556712913470-2c7bc076-b63a6ff8",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/350832198996140462",
      "startTime": "2026-06-29T09:37:21.908-07:00",
      "status": "RUNNING",
      "targetId": "5216856529901134626",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:37:22.731965164Z",
  "resource": {
    "labels": {
      "gateway_id": "5216856529901134626",
      "project_id": "example-project-id",
      "region": "us-central1"
    },
    "type": "vpn_gateway"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:37:21.725980Z"
}

compute.targetVpnGateways.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified target VPN gateway.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "4ga1idd9l0g",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "20ff4afe-09cf-4437-8238-caf40a5ccb33"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.targetVpnGateways.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
          "service": "compute",
          "type": "compute.targetVpnGateways"
        }
      }
    ],
    "methodName": "v1.compute.targetVpnGateways.get",
    "request": {
      "@type": "type.googleapis.com/compute.targetVpnGateways.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-vpn-gateways.create invocation-id/bc1305e24fe340ce9ff31686dfe4680c environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:31:11.332300Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:31:12.126907392Z",
  "resource": {
    "labels": {
      "gateway_id": "5216856529901134626",
      "project_id": "example-project-id",
      "region": "us-central1"
    },
    "type": "vpn_gateway"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:31:11.095312Z"
}

compute.targetVpnGateways.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a target VPN gateway in the specified project and region using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-4e3xu0e5a780",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "f575c4f9-9c14-4bdd-bce5-edf210eabe36"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750669910-65566fc6733cf-0c2262c8-9e703843",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.targetVpnGateways.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
          "service": "compute",
          "type": "compute.targetVpnGateways"
        }
      },
      {
        "granted": true,
        "permission": "compute.networks.updatePolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/dwn7c068744",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/dwn7c068744",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.targetVpnGateways.insert",
    "request": {
      "@type": "type.googleapis.com/compute.targetVpnGateways.insert",
      "name": "dwtgw7c068744",
      "network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn7c068744"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-vpn-gateways.create invocation-id/bc1305e24fe340ce9ff31686dfe4680c environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:31:10.158861Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "4882535682875007777",
      "insertTime": "2026-06-29T09:31:10.081-07:00",
      "name": "operation-1782750669910-65566fc6733cf-0c2262c8-9e703843",
      "operationType": "insert",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750669910-65566fc6733cf-0c2262c8-9e703843",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/4882535682875007777",
      "startTime": "2026-06-29T09:31:10.086-07:00",
      "status": "RUNNING",
      "targetId": "5216856529901134626",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:31:10.450450667Z",
  "resource": {
    "labels": {
      "gateway_id": "5216856529901134626",
      "project_id": "example-project-id",
      "region": "us-central1"
    },
    "type": "vpn_gateway"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:31:09.888202Z"
}

compute.targetVpnGateways.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of target VPN gateways available to the specified project and region.

Data Access audit logs are disabled by default.

compute.targetVpnGateways.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a TargetVpnGateway. To learn more about labels, read theLabeling Resources documentation.

compute.urlMaps.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of all UrlMap resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-1dujd6e82pew",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "940566fa-c1fb-4c52-877b-64350e12b0d8"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.urlMaps.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.urlMaps.aggregatedList",
    "numResponseItems": "176",
    "request": {
      "@type": "type.googleapis.com/compute.urlMaps.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.url-maps.list invocation-id/eb971c4e4e7b4ebebf027935b674a967 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:30.781542Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/urlMaps",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:31.010108302Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "url_map_id": ""
    },
    "type": "gce_url_map"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:30.621835Z"
}

compute.urlMaps.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified UrlMap resource.

compute.urlMaps.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified UrlMap resource.

Data Access audit logs are disabled by default.

compute.urlMaps.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a UrlMap resource in the specified project using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-r6q7ake5qmiq",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "779daba9-970c-4e1d-8896-1a1b3a7e1b3e"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782745423512-65565c3b18405-349e89e9-987d262d",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.urlMaps.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/urlMaps/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/urlMaps/dwn3-dw745304",
          "service": "compute",
          "type": "compute.urlMaps"
        }
      },
      {
        "granted": true,
        "permission": "compute.backendServices.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/backendServices/dwn3-dw745304",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/backendServices/dwn3-dw745304",
          "service": "compute",
          "type": "compute.backendServices"
        }
      }
    ],
    "methodName": "v1.compute.urlMaps.insert",
    "request": {
      "@type": "type.googleapis.com/compute.urlMaps.insert",
      "defaultService": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/backendServices/dwn3-dw745304",
      "name": "dwn3-dw745304"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.url-maps.create invocation-id/e29028d8d6b2422195ca5b958cf3b5b7 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:03:44.030673Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/urlMaps/dwn3-dw745304",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "2482222853646137248",
      "insertTime": "2026-06-29T08:03:43.723-07:00",
      "name": "operation-1782745423512-65565c3b18405-349e89e9-987d262d",
      "operationType": "insert",
      "progress": "0",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745423512-65565c3b18405-349e89e9-987d262d",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2482222853646137248",
      "startTime": "2026-06-29T08:03:43.727-07:00",
      "status": "RUNNING",
      "targetId": "2488935084370900896",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/urlMaps/dwn3-dw745304",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:03:44.880118331Z",
  "resource": {
    "labels": {
      "project_id": "example-project-id",
      "url_map_id": "2488935084370900896"
    },
    "type": "gce_url_map"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:03:43.491671Z"
}

compute.urlMaps.invalidateCache: invalidateCache

#
ServiceName
compute.googleapis.com

Description

Initiates a cache invalidation operation, invalidating the specified path, scoped to the specified UrlMap. For more information, see Invalidating cached content.

compute.urlMaps.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of UrlMap resources available to the specified project.

Data Access audit logs are disabled by default.

compute.urlMaps.patch: patch

#
ServiceName
compute.googleapis.com

Description

Patches the specified UrlMap resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.

compute.urlMaps.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.urlMaps.update: update

#
ServiceName
compute.googleapis.com

Description

Updates the specified UrlMap resource with the data included in the request.

compute.urlMaps.validate: validate

#
ServiceName
compute.googleapis.com

Description

Runs static validation for the UrlMap. In particular, the tests of the provided UrlMap will be run. Calling this method does NOT create the UrlMap.

compute.vpnGateways.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of VPN gateways. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

compute.vpnGateways.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified VPN gateway.

Example Audit Log Entry #

{
  "insertId": "1xzcwke2nvig",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "1b3c0734-e4da-4f59-b7d7-1833be579287"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750835440-655670644fc65-cfad3dc4-166caf3e",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.vpnGateways.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
          "service": "compute",
          "type": "compute.vpnGateways"
        }
      }
    ],
    "methodName": "v1.compute.vpnGateways.delete",
    "request": {
      "@type": "type.googleapis.com/compute.vpnGateways.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-gateways.delete invocation-id/69239331a76e4c81aa22e626c7dbfb5e environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:33:55.569523Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "479278259749462172",
      "insertTime": "2026-06-29T09:33:55.527-07:00",
      "name": "operation-1782750835440-655670644fc65-cfad3dc4-166caf3e",
      "operationType": "compute.vpnGateways.delete",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750835440-655670644fc65-cfad3dc4-166caf3e",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/479278259749462172",
      "startTime": "2026-06-29T09:33:55.534-07:00",
      "status": "RUNNING",
      "targetId": "1638926550725239489",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:33:56.331797686Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "method": "compute.vpnGateways.delete",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:33:55.402698Z"
}

compute.vpnGateways.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified VPN gateway.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "b45h5be7pfss",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "876f8749-2ee6-4439-a4f8-41afd1180525"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.vpnGateways.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
          "service": "compute",
          "type": "compute.vpnGateways"
        }
      }
    ],
    "methodName": "v1.compute.vpnGateways.get",
    "request": {
      "@type": "type.googleapis.com/compute.vpnGateways.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-gateways.create invocation-id/3f9c3929eae44ebfad9d61ea26ad4230 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:24:16.933317Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:24:17.256770325Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "method": "compute.vpnGateways.get",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:24:16.866812Z"
}

compute.vpnGateways.getStatus: getStatus

#
ServiceName
compute.googleapis.com

Description

Returns the status for the specified VPN gateway.

Data Access audit logs are disabled by default.

compute.vpnGateways.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a VPN gateway in the specified project and region using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "-2harb5e38zl4",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "d7231aa9-2c6c-4fce-9fb4-ee3f5d8cc3a5"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750254474-65566e3a424a6-204ec108-78927688",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.vpnGateways.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
          "service": "compute",
          "type": "compute.vpnGateways"
        }
      },
      {
        "granted": true,
        "permission": "compute.networks.updatePolicy",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/networks/dwn7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/networks/dwn7201353",
          "service": "compute",
          "type": "compute.networks"
        }
      }
    ],
    "methodName": "v1.compute.vpnGateways.insert",
    "request": {
      "@type": "type.googleapis.com/compute.vpnGateways.insert",
      "name": "dwvgw7201353",
      "network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn7201353"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-gateways.create invocation-id/3f9c3929eae44ebfad9d61ea26ad4230 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:24:14.959942Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "1110148817399784129",
      "insertTime": "2026-06-29T09:24:14.679-07:00",
      "name": "operation-1782750254474-65566e3a424a6-204ec108-78927688",
      "operationType": "compute.vpnGateways.insert",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750254474-65566e3a424a6-204ec108-78927688",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/1110148817399784129",
      "startTime": "2026-06-29T09:24:14.731-07:00",
      "status": "RUNNING",
      "targetId": "1638926550725239489",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:24:15.307627570Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "method": "compute.vpnGateways.insert",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:24:14.457224Z"
}

compute.vpnGateways.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of VPN gateways available to the specified project and region.

Data Access audit logs are disabled by default.

compute.vpnGateways.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a VpnGateway. To learn more about labels, read theLabeling Resources documentation.

compute.vpnGateways.testIamPermissions: testIamPermissions

#
ServiceName
compute.googleapis.com

Description

Returns permissions that a caller has on the specified resource.

Data Access audit logs are disabled by default.

compute.vpnTunnels.aggregatedList: aggregatedList

#
ServiceName
compute.googleapis.com

Description

Retrieves an aggregated list of VPN tunnels. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "p9bmsydws6m",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "c6ce3a2c-8f72-45e7-a510-f95ba33e4df7"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.vpnTunnels.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.vpnTunnels.aggregatedList",
    "numResponseItems": "43",
    "request": {
      "@type": "type.googleapis.com/compute.vpnTunnels.aggregatedList"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-tunnels.list invocation-id/df3e7b2f41d44dcfb422a4728d7927b6 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:47.873098Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/global/vpnTunnels",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:48.021049276Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.vpnTunnels.aggregatedList",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:47.747318Z"
}

compute.vpnTunnels.delete: Delete VPN tunnel

#
ServiceName
compute.googleapis.com

Description

Deletes the specified VPN Tunnel resource.

Example Audit Log Entry #

{
  "insertId": "-psnk3fe8f1sa",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "7d7e77b3-867b-4d77-aa37-7895ee396907"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750778591-6556702e18a79-63b26ed9-70dbd948",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.vpnTunnels.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
          "service": "compute",
          "type": "compute.vpnTunnels"
        }
      }
    ],
    "methodName": "v1.compute.vpnTunnels.delete",
    "request": {
      "@type": "type.googleapis.com/compute.vpnTunnels.delete"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-tunnels.delete invocation-id/d8a67df265bb4e8d9ca98bb962e772d0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:32:58.777772Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "3828055915319206101",
      "insertTime": "2026-06-29T09:32:58.677-07:00",
      "name": "operation-1782750778591-6556702e18a79-63b26ed9-70dbd948",
      "operationType": "delete",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750778591-6556702e18a79-63b26ed9-70dbd948",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/3828055915319206101",
      "startTime": "2026-06-29T09:32:58.692-07:00",
      "status": "RUNNING",
      "targetId": "3874875912158650568",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:32:59.669466345Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "tunnel_id": "3874875912158650568",
      "tunnel_name": "dwvt7d068744"
    },
    "type": "vpn_tunnel"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:32:58.564332Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

compute.vpnTunnels.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified VpnTunnel resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "47bxo0e4fwus",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "361a09b7-91cd-4bf6-bb3f-e52cd2c8c38f"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.vpnTunnels.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
          "service": "compute",
          "type": "compute.vpnTunnels"
        }
      }
    ],
    "methodName": "v1.compute.vpnTunnels.get",
    "request": {
      "@type": "type.googleapis.com/compute.vpnTunnels.get"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-tunnels.create invocation-id/b682445225614e4985bc3da1a77f1766 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:32:53.301945Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:32:53.982005924Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "tunnel_id": "3874875912158650568",
      "tunnel_name": "dwvt7d068744"
    },
    "type": "vpn_tunnel"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:32:53.238897Z"
}

compute.vpnTunnels.insert: Insert VPN tunnel

#
ServiceName
compute.googleapis.com

Description

Creates a VpnTunnel resource in the specified project and region using the data included in the request.

Example Audit Log Entry #

{
  "insertId": "svdnsqe8m9xc",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "097573d5-ace8-4c6b-b377-4a16bac8e003"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "operation-1782750261941-65566e4161577-f9d5e578-f1d237e3",
    "producer": "compute.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.vpnTunnels.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7201353",
          "service": "compute",
          "type": "compute.vpnTunnels"
        }
      },
      {
        "granted": true,
        "permission": "compute.routers.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
          "service": "compute",
          "type": "compute.routers"
        }
      },
      {
        "granted": true,
        "permission": "compute.vpnGateways.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
          "service": "compute",
          "type": "compute.vpnGateways"
        }
      },
      {
        "granted": true,
        "permission": "compute.externalVpnGateways.use",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
        "resourceAttributes": {
          "name": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
          "service": "compute",
          "type": "compute.externalVpnGateways"
        }
      }
    ],
    "methodName": "v1.compute.vpnTunnels.insert",
    "request": {
      "@type": "type.googleapis.com/compute.vpnTunnels.insert",
      "ikeVersion": "2",
      "name": "dwvt7201353",
      "peerExternalGateway": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/externalVpnGateways/dwegw7201353",
      "peerExternalGatewayInterface": "0",
      "router": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
      "vpnGateway": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
      "vpnGatewayInterface": "0"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-tunnels.create invocation-id/03c6b384dc7c4362a7df7f74e0b700e9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:24:22.359864Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7201353",
    "response": {
      "@type": "type.googleapis.com/operation",
      "id": "4833237373941654233",
      "insertTime": "2026-06-29T09:24:22.231-07:00",
      "name": "operation-1782750261941-65566e4161577-f9d5e578-f1d237e3",
      "operationType": "insert",
      "progress": "0",
      "region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
      "selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750261941-65566e4161577-f9d5e578-f1d237e3",
      "selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/4833237373941654233",
      "startTime": "2026-06-29T09:24:22.234-07:00",
      "status": "RUNNING",
      "targetId": "744197005117432538",
      "targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7201353",
      "user": "user@example.com"
    },
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:24:22.897923033Z",
  "resource": {
    "labels": {
      "location": "us-central1",
      "project_id": "example-project-id",
      "tunnel_id": "744197005117432538",
      "tunnel_name": "dwvt7201353"
    },
    "type": "vpn_tunnel"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:24:21.904200Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

compute.vpnTunnels.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of VpnTunnel resources contained in the specified project and region.

Data Access audit logs are disabled by default.

compute.vpnTunnels.setLabels: setLabels

#
ServiceName
compute.googleapis.com

Description

Sets the labels on a VpnTunnel. To learn more about labels, read theLabeling Resources documentation.

compute.wireGroups.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified wire group in the given scope.

compute.wireGroups.get: get

#
ServiceName
compute.googleapis.com

Description

Gets the specified wire group resource in the given scope.

Data Access audit logs are disabled by default.

compute.wireGroups.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a wire group in the specified project in the given scope using the parameters that are included in the request.

compute.wireGroups.list: list

#
ServiceName
compute.googleapis.com

Description

Lists the wire groups for a project in the given scope.

Data Access audit logs are disabled by default.

compute.wireGroups.patch: patch

#
ServiceName
compute.googleapis.com

Description

Updates the specified wire group resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.

compute.zoneOperations.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes the specified zone-specific Operations resource.

compute.zoneOperations.get: get

#
ServiceName
compute.googleapis.com

Description

Retrieves the specified zone-specific Operations resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "6o7gmee1mdn2",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "35ef1567-722d-466e-83d2-c6163002ba53"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.zoneOperations.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/zones/us-central1-a/operations/operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/operations/operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
          "service": "compute",
          "type": "compute.zoneOperations"
        }
      }
    ],
    "methodName": "v1.compute.zoneOperations.get",
    "request": {
      "@type": "type.googleapis.com/compute.zoneOperations.get"
    },
    "requestMetadata": {
      "callerIp": "private",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:42:34.621053Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/operations/operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:42:34.726139448Z",
  "resource": {
    "labels": {
      "location": "us-central1-a",
      "operation_name": "operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
      "project_id": "example-project-id"
    },
    "type": "gce_operation"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:42:34.574392Z"
}

compute.zoneOperations.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves a list of Operation resources contained within the specified zone.

Data Access audit logs are disabled by default.

compute.zoneOperations.wait: wait

#
ServiceName
compute.googleapis.com

Description

Waits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method waits for no more than the 2 minutes and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-r5ifl7e3af0a",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "c17059cf-4203-4a9d-8cb8-11889725eaf4"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.zoneOperations.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/zones/us-central1-a/operations/operation-1782739348249-65564599459f9-31ad5434-c32a2182",
        "resourceAttributes": {
          "name": "projects/example-project-id/zones/us-central1-a/operations/operation-1782739348249-65564599459f9-31ad5434-c32a2182",
          "service": "compute",
          "type": "compute.zoneOperations"
        }
      }
    ],
    "methodName": "v1.compute.zoneOperations.wait",
    "request": {
      "@type": "type.googleapis.com/compute.zoneOperations.wait"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.create invocation-id/d3a99ae5add44e01b925c5905c2c65e4 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:22:41.190270Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-a"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-a/operations/operation-1782739348249-65564599459f9-31ad5434-c32a2182",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:22:41.655811575Z",
  "resource": {
    "labels": {
      "location": "us-central1-a",
      "operation_name": "operation-1782739348249-65564599459f9-31ad5434-c32a2182",
      "project_id": "example-project-id"
    },
    "type": "gce_operation"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:22:29.468907Z"
}

compute.zoneVmExtensionPolicies.delete: delete

#
ServiceName
compute.googleapis.com

Description

Deletes a specified zone VM extension policy within a project.

compute.zoneVmExtensionPolicies.get: get

#
ServiceName
compute.googleapis.com

Description

Retrieves details of a specific zone VM extension policy within a project.

Data Access audit logs are disabled by default.

compute.zoneVmExtensionPolicies.insert: insert

#
ServiceName
compute.googleapis.com

Description

Creates a new zone-level VM extension policy within a project.

compute.zoneVmExtensionPolicies.list: list

#
ServiceName
compute.googleapis.com

Description

Lists all VM extension policies within a specific zone for a project.

Data Access audit logs are disabled by default.

compute.zoneVmExtensionPolicies.update: update

#
ServiceName
compute.googleapis.com

Description

Modifies an existing zone VM extension policy within a project.

compute.zones.get: get

#
ServiceName
compute.googleapis.com

Description

Returns the specified Zone resource.

Data Access audit logs are disabled by default.

compute.zones.list: list

#
ServiceName
compute.googleapis.com

Description

Retrieves the list of Zone resources available to the specified project.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "u9v4p4dttk4",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "090249a6-6518-4b9a-b681-82367b9d44a7"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.zones.list",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "v1.compute.zones.list",
    "numResponseItems": "130",
    "request": {
      "@type": "type.googleapis.com/compute.zones.list"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.zones.list invocation-id/567c3c40de4b4f279757afac8b8a3055 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:43.515312Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/zones",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:43.773626168Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.zones.list",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "v1"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:43.329939Z"
}

compute.reservations.listConsumableReservations: listConsumableReservations

#
ServiceName
compute.googleapis.com

Description

List the reservations a project is allowed to consume.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-s9pwize7n3ku",
  "labels": {
    "compute.googleapis.com/root_trigger_id": "56214f99-b6ff-40c2-a50c-4c86497e1ec2"
  },
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "110162197178770594910"
      },
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
      "principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "compute.reservations.listConsumableReservations",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id",
        "resourceAttributes": {
          "name": "projects/example-project-id",
          "service": "resourcemanager",
          "type": "resourcemanager.projects"
        }
      }
    ],
    "methodName": "beta.compute.reservations.listConsumableReservations",
    "request": {
      "@type": "type.googleapis.com/compute.reservations.listConsumableReservations"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 vertex-gke-integration-pipeline,gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:39:41.859947Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1-f"
      ]
    },
    "resourceName": "projects/example-project-id/zones/us-central1-f/consumableReservations",
    "serviceName": "compute.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:39:42.042643663Z",
  "resource": {
    "labels": {
      "location": "global",
      "method": "compute.reservations.listConsumableReservations",
      "project_id": "example-project-id",
      "service": "compute.googleapis.com",
      "version": "beta"
    },
    "type": "api"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:39:41.823808Z"
}