Compute Engine
| methodName | Description | Log type | Sample | Rule |
|---|---|---|---|---|
| any | Catch-all entry for compute.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation. | activity | N | Y |
| compute. | Retrieves an aggregated list of accelerator types. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Returns the specified accelerator type. | data_access | N | N |
| compute. | Retrieves a list of accelerator types that are available to the specified project. | data_access | N | N |
| compute. | Retrieves an aggregated list of addresses. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified address resource. | activity | Y | N |
| compute. | Returns the specified address resource. | data_access | Y | N |
| compute. | Creates an address resource in the specified project by using the data included in the request. | activity | Y | N |
| compute. | Retrieves a list of addresses contained within the specified region. | data_access | Y | N |
| compute. | Moves the specified address resource. | activity | N | N |
| compute. | Sets the labels on an Address. To learn more about labels, read theLabeling Resources documentation. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Advise how, where and when to create the requested amount of instances with specified accelerators, within the specified time and location limits. The method recommends creating future reservations for the requested resources. | activity | N | N |
| compute. | Retrieves an aggregated list of autoscalers. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified autoscaler. | activity | N | N |
| compute. | Returns the specified autoscaler resource. | data_access | N | N |
| compute. | Creates an autoscaler in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves a list of autoscalers contained within the specified zone. | data_access | N | N |
| compute. | Updates an autoscaler in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates an autoscaler in the specified project using the data included in the request. | activity | N | N |
| compute. | Adds a key for validating requests with signed URLs for this backend bucket. | activity | N | N |
| compute. | Retrieves the list of all BackendBucket resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified BackendBucket resource. | activity | Y | N |
| compute. | Deletes a key for validating requests with signed URLs for this backend bucket. | activity | N | N |
| compute. | Returns the specified BackendBucket resource. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a BackendBucket resource in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves the list of BackendBucket resources available to the specified project. | data_access | N | N |
| compute. | Retrieves a list of all usable backend buckets in the specified project. | data_access | N | N |
| compute. | Updates the specified BackendBucket resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Sets the edge security policy for the specified backend bucket. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates the specified BackendBucket resource with the data included in the request. | activity | N | N |
| compute. | Adds a key for validating requests with signed URLs for this backend service. | activity | N | N |
| compute. | Retrieves the list of all BackendService resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified BackendService resource. | activity | N | N |
| compute. | Deletes a key for validating requests with signed URLs for this backend service. | activity | N | N |
| compute. | Returns the specified BackendService resource. | data_access | Y | N |
| compute. | Returns effective security policies applied to this backend service. | data_access | N | N |
| compute. | Gets the most recent health check results for this BackendService. Example request body: { "group": "/zones/us-east1-b/instanceGroups/lb-backend-example" } | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a BackendService resource in the specified project using the data included in the request. For more information, see Backend services overview. | activity | Y | N |
| compute. | Retrieves the list of BackendService resources available to the specified project. | data_access | Y | N |
| compute. | Retrieves a list of all usable backend services in the specified project. | data_access | N | N |
| compute. | Patches the specified BackendService resource with the data included in the request. For more information, see Backend services overview. This method supports PATCH semantics and uses the JSON merge patch format and processing rules. | activity | N | N |
| compute. | Sets the edge security policy for the specified backend service. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Sets the Google Cloud Armor security policy for the specified backend service. For more information, seeGoogle Cloud Armor Overview | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates the specified BackendService resource with the data included in the request. For more information, seeBackend services overview. | activity | N | N |
| compute. | Deletes the specified cross-site network in the given scope. | activity | N | N |
| compute. | Returns the specified cross-site network in the given scope. | data_access | N | N |
| compute. | Creates a cross-site network in the specified project in the given scope using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the cross-site networks for a project in the given scope. | data_access | N | N |
| compute. | Updates the specified cross-site network with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Retrieves an aggregated list of disk types. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Returns the specified disk type. | data_access | N | N |
| compute. | Retrieves a list of disk types available to the specified project. | data_access | N | N |
| compute. | Adds existing resource policies to a disk. You can only add one policy which will be applied to this disk for scheduling snapshot creation. | activity | N | N |
| compute. | Retrieves an aggregated list of persistent disks. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Bulk create a set of disks. | activity | N | N |
| compute. | Sets the labels on many disks at once. To learn more about labels, read theLabeling Resources documentation. | activity | N | N |
| compute. | Creates a snapshot of a specified persistent disk. For regular snapshot creation, consider using snapshots.insert instead, as that method supports more features, such as creating snapshots in a project different from the source disk project. | activity | Y | N |
| compute. | Deletes the specified persistent disk. Deleting a disk removes its data permanently and is irreversible. However, deleting a disk does not delete any snapshots previously made from the disk. You must separatelydelete snapshots. | activity | Y | N |
| compute. | Returns the specified persistent disk. | data_access | Y | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a persistent disk in the specified project using the data in the request. You can create a disk from a source (sourceImage, sourceSnapshot, orsourceDisk) or create an empty 500 GB data disk by omitting all properties. You can also create a disk that is larger than the default size by specifying the sizeGb property. | activity | Y | N |
| compute. | Retrieves a list of persistent disks contained within the specified zone. | data_access | Y | N |
| compute. | Removes resource policies from a disk. | activity | N | N |
| compute. | Resizes the specified persistent disk. You can only increase the size of the disk. | activity | Y | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | Y | Y |
| compute. | Sets the labels on a disk. To learn more about labels, read theLabeling Resources documentation. | activity | Y | N |
| compute. | Starts asynchronous replication. Must be invoked on the primary disk. | activity | N | N |
| compute. | Stops asynchronous replication. Can be invoked either on the primary or on the secondary disk. | activity | N | N |
| compute. | Stops asynchronous replication for a consistency group of disks. Can be invoked either in the primary or secondary scope. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates the specified disk with the data included in the request. The update is performed only on selected fields included as part of update-mask. | activity | N | N |
| compute. | Rotates the customer-managed encryption key to the latest version for the specified persistent disk. | activity | N | N |
| compute. | Deletes the specified externalVpnGateway. | activity | Y | N |
| compute. | Returns the specified externalVpnGateway. Get a list of available externalVpnGateways by making a list() request. | data_access | Y | N |
| compute. | Creates a ExternalVpnGateway in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves the list of ExternalVpnGateway available to the specified project. | data_access | N | N |
| compute. | Sets the labels on an ExternalVpnGateway. To learn more about labels, read the Labeling Resources documentation. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Inserts an association for the specified firewall policy. | activity | N | N |
| compute. | Inserts a rule into a firewall policy. | activity | N | N |
| compute. | Copies rules to the specified firewall policy. | activity | N | N |
| compute. | Deletes the specified policy. | activity | N | N |
| compute. | Returns the specified firewall policy. | data_access | N | N |
| compute. | Gets an association with the specified name. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Gets a rule of the specified priority. | data_access | N | N |
| compute. | Creates a new policy in the specified project using the data included in the request. | activity | N | N |
| compute. | Lists all the policies that have been configured for the specified folder or organization. | data_access | N | N |
| compute. | Lists associations of a specified target, i.e., organization or folder. | data_access | N | N |
| compute. | Moves the specified firewall policy. | activity | N | N |
| compute. | Patches the specified policy with the data included in the request. | activity | N | N |
| compute. | Patches a rule of the specified priority. | activity | N | N |
| compute. | Removes an association for the specified firewall policy. | activity | N | N |
| compute. | Deletes a rule of the specified priority. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Deletes the specified firewall. | activity | Y | Y |
| compute. | Returns the specified firewall. | data_access | Y | N |
| compute. | Creates a firewall rule in the specified project using the data included in the request. | activity | Y | Y |
| compute. | Retrieves the list of firewall rules available to the specified project. | data_access | Y | N |
| compute. | Patches the specified firewall rule with the data included in the request. | activity | Y | Y |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates the specified firewall rule with the data included in the request. | activity | N | Y |
| compute. | Retrieves an aggregated list of forwarding rules. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified ForwardingRule resource. | activity | Y | N |
| compute. | Returns the specified ForwardingRule resource. | data_access | Y | N |
| compute. | Creates a ForwardingRule resource in the specified project and region using the data included in the request. | activity | Y | N |
| compute. | Retrieves a list of ForwardingRule resources available to the specified project and region. | data_access | N | N |
| compute. | Updates the specified forwarding rule with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. Currently, you can only patch the network_tier field. | activity | N | N |
| compute. | Sets the labels on the specified resource. To learn more about labels, read the Labeling Resources documentation. | activity | N | N |
| compute. | Changes target URL for forwarding rule. The new target should be of the same type as the old target. | activity | N | N |
| compute. | Retrieves an aggregated list of future reservations. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Cancel the specified future reservation. | activity | N | N |
| compute. | Deletes the specified future reservation. | activity | N | N |
| compute. | Retrieves information about the specified future reservation. | data_access | N | N |
| compute. | Creates a new Future Reservation. | activity | N | N |
| compute. | A list of all the future reservations that have been configured for the specified project in specified zone. | data_access | N | N |
| compute. | Updates the specified future reservation. | activity | N | N |
| compute. | Deletes the specified address resource. | activity | Y | N |
| compute. | Returns the specified address resource. | data_access | N | N |
| compute. | Creates an address resource in the specified project by using the data included in the request. | activity | Y | N |
| compute. | Retrieves a list of global addresses. | data_access | N | N |
| compute. | Moves the specified address resource from one project to another project. | activity | N | N |
| compute. | Sets the labels on a GlobalAddress. To learn more about labels, read theLabeling Resources documentation. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Deletes the specified GlobalForwardingRule resource. | activity | N | N |
| compute. | Returns the specified GlobalForwardingRule resource. Gets a list of available forwarding rules by making a list() request. | data_access | N | N |
| compute. | Creates a GlobalForwardingRule resource in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves a list of GlobalForwardingRule resources available to the specified project. | data_access | N | N |
| compute. | Updates the specified forwarding rule with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. Currently, you can only patch the network_tier field. | activity | N | N |
| compute. | Sets the labels on the specified resource. To learn more about labels, read the Labeling resources documentation. | activity | N | N |
| compute. | Changes target URL for the GlobalForwardingRule resource. The new target should be of the same type as the old target. | activity | N | N |
| compute. | Attach a network endpoint to the specified network endpoint group. | activity | N | N |
| compute. | Deletes the specified network endpoint group.Note that the NEG cannot be deleted if there are backend services referencing it. | activity | N | N |
| compute. | Detach the network endpoint from the specified network endpoint group. | activity | N | N |
| compute. | Returns the specified network endpoint group. | data_access | N | N |
| compute. | Creates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global API | activity | N | N |
| compute. | Retrieves the list of network endpoint groups that are located in the specified project. | data_access | N | N |
| compute. | Lists the network endpoints in the specified network endpoint group. | data_access | N | N |
| compute. | Retrieves an aggregated list of all operations. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified Operations resource. | activity | N | N |
| compute. | Retrieves the specified Operations resource. | data_access | Y | N |
| compute. | Retrieves a list of Operation resources contained within the specified project. | data_access | N | N |
| compute. | Waits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method differs from the `GET` method in that it waits for no more than the default deadline (2 minutes) and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`. | data_access | Y | N |
| compute. | Deletes the specified Operations resource. | activity | N | N |
| compute. | Retrieves the specified Operations resource. Gets a list of operations by making a `list()` request. | data_access | N | N |
| compute. | Retrieves a list of Operation resources contained within the specified organization. | data_access | N | N |
| compute. | Deletes the specified global PublicDelegatedPrefix. | activity | N | N |
| compute. | Returns the specified global PublicDelegatedPrefix resource. | data_access | N | N |
| compute. | Creates a global PublicDelegatedPrefix in the specified project using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the global PublicDelegatedPrefixes for a project. | data_access | N | N |
| compute. | Patches the specified global PublicDelegatedPrefix resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Retrieves the list of all VM Extension Policy resources available to the specified project. To prevent failure, it's recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Purge scoped resources (zonal policies) from a global VM extension policy, and then delete the global VM extension policy. Purge of the scoped resources is a pre-condition of the global VM extension policy deletion. The deletion of the global VM extension policy happens after the purge rollout is done, so it's not a part of the LRO. It's an automatic process that triggers in the backend. | activity | N | N |
| compute. | Gets details of a global VM extension policy. | data_access | N | N |
| compute. | Creates a new project level GlobalVmExtensionPolicy. | activity | N | N |
| compute. | Lists global VM extension policies. | data_access | N | N |
| compute. | Updates a global VM extension policy. | activity | N | N |
| compute. | Retrieves the list of all HealthCheck resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified HealthCheck resource. | activity | N | N |
| compute. | Returns the specified HealthCheck resource. | data_access | N | N |
| compute. | Creates a HealthCheck resource in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves the list of HealthCheck resources available to the specified project. | data_access | N | N |
| compute. | Updates a HealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates a HealthCheck resource in the specified project using the data included in the request. | activity | N | N |
| compute. | Deletes the specified HttpHealthCheck resource. | activity | N | N |
| compute. | Returns the specified HttpHealthCheck resource. | data_access | N | N |
| compute. | Creates a HttpHealthCheck resource in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves the list of HttpHealthCheck resources available to the specified project. | data_access | N | N |
| compute. | Updates a HttpHealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates a HttpHealthCheck resource in the specified project using the data included in the request. | activity | N | N |
| compute. | Deletes the specified HttpsHealthCheck resource. | activity | N | N |
| compute. | Returns the specified HttpsHealthCheck resource. | data_access | N | N |
| compute. | Creates a HttpsHealthCheck resource in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of HttpsHealthCheck resources available to the specified project. | data_access | N | N |
| compute. | Updates a HttpsHealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates a HttpsHealthCheck resource in the specified project using the data included in the request. | activity | N | N |
| compute. | Returns the latest image that is part of an image family, is not deprecated and is rolled out in the specified zone. | data_access | N | N |
| compute. | Deletes the specified image. | activity | Y | N |
| compute. | Sets the deprecation status of an image. If an empty request body is given, clears the deprecation status instead. | activity | N | N |
| compute. | Returns the specified image. | data_access | Y | N |
| compute. | Returns the latest image that is part of an image family and is not deprecated. For more information on image families, seePublic image families documentation. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | Y | N |
| compute. | Creates an image in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves the list of custom images available to the specified project. Custom images are images you create that belong to your project. This method does not get any images that belong to other projects, including publicly-available images, like Debian 8. If you want to get a list of publicly-available images, use this method to make a request to the respective image project, such as debian-cloud or windows-cloud. | data_access | Y | N |
| compute. | Patches the specified image with the data included in the request. Only the following fields can be modified: family, description, deprecation status. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | Y | Y |
| compute. | Sets the labels on an image. To learn more about labels, read theLabeling Resources documentation. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Cancels the specified resize request and removes it from the queue. Cancelled resize request does no longer wait for the resources to be provisioned. Cancel is only possible for requests that are accepted in the queue. | activity | N | N |
| compute. | Deletes the specified, inactive resize request. Requests that are still active cannot be deleted. Deleting request does not delete instances that were provisioned previously. | activity | N | N |
| compute. | Returns all of the details about the specified resize request. | data_access | N | N |
| compute. | Creates a new resize request that starts provisioning VMs immediately or queues VM creation. | activity | N | N |
| compute. | Retrieves a list of resize requests that are contained in the managed instance group. | data_access | N | N |
| compute. | Flags the specified instances to be removed from the managed instance group. Abandoning an instance does not delete the instance, but it does remove the instance from any target pools that are applied by the managed instance group. This method reduces thetargetSize of the managed instance group by the number of instances that you abandon. This operation is marked asDONE when the action is scheduled even if the instances have not yet been removed from the group. You must separately verify the status of the abandoning action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Retrieves the list of managed instance groups and groups them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Applies changes to selected instances on the managed instance group. This method can be used to apply new overrides and/or new versions. | activity | N | N |
| compute. | Creates instances with per-instance configurations in this managed instance group. Instances are created using the current instance template. Thecreate instances operation is marked DONE if thecreateInstances request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or actions with the listmanagedinstances method. | activity | N | N |
| compute. | Deletes the specified managed instance group and all of the instances in that group. Note that the instance group must not belong to a backend service. Read Deleting an instance group for more information. | activity | Y | N |
| compute. | Flags the specified instances in the managed instance group for immediate deletion. The instances are also removed from any target pools of which they were a member. This method reduces thetargetSize of the managed instance group by the number of instances that you delete. This operation is marked as DONE when the action is scheduled even if the instances are still being deleted. You must separately verify the status of the deleting action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Deletes selected per-instance configurations for the managed instance group. | activity | N | N |
| compute. | Returns all of the details about the specified managed instance group. | data_access | Y | N |
| compute. | Creates a managed instance group using the information that you specify in the request. After the group is created, instances in the group are created using the specified instance template. This operation is marked as DONE when the group is created even if the instances in the group have not yet been created. You must separately verify the status of the individual instances with thelistmanagedinstances method. A managed instance group can have up to 1000 VM instances per group. Please contact Cloud Support if you need an increase in this limit. | activity | Y | N |
| compute. | Retrieves a list of managed instance groups that are contained within the specified project and zone. | data_access | Y | N |
| compute. | Lists all errors thrown by actions on instances for a given managed instance group. The filter and orderBy query parameters are not supported. | data_access | N | N |
| compute. | Lists all of the instances in the managed instance group. Each instance in the list has a currentAction, which indicates the action that the managed instance group is performing on the instance. For example, if the group is still creating an instance, the currentAction is CREATING. If a previous action failed, the list displays the errors for that failed action. The orderBy query parameter is not supported. The `pageToken` query parameter is supported only if the group's `listManagedInstancesResults` field is set to `PAGINATED`. | data_access | Y | N |
| compute. | Lists all of the per-instance configurations defined for the managed instance group. The orderBy query parameter is not supported. | data_access | N | N |
| compute. | Updates a managed instance group using the information that you specify in the request. This operation is marked as DONE when the group is patched even if the instances in the group are still in the process of being patched. You must separately verify the status of the individual instances with thelistManagedInstances method. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. If you update your group to specify a new template or instance configuration, it's possible that your intended specification for each VM in the group is different from the current state of that VM. To learn how to apply an updated configuration to the VMs in a MIG, seeUpdating instances in a MIG. | activity | N | N |
| compute. | Inserts or patches per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch. | activity | N | N |
| compute. | Flags the specified VM instances in the managed instance group to be immediately recreated. Each instance is recreated using the group's current configuration. This operation is marked as DONE when the flag is set even if the instances have not yet been recreated. You must separately verify the status of each instance by checking itscurrentAction field; for more information, see Checking the status of managed instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Resizes the managed instance group. If you increase the size, the group creates new instances using the current instance template. If you decrease the size, the group deletes instances. The resize operation is markedDONE when the resize actions are scheduled even if the group has not yet added or deleted any instances. You must separately verify the status of the creating or deleting actions with thelistmanagedinstances method. When resizing down, the instance group arbitrarily chooses the order in which VMs are deleted. The group takes into account some VM attributes when making the selection including: + The status of the VM instance. + The health of the VM instance. + The instance template version the VM is based on. + For regional managed instance groups, the location of the VM instance. This list is subject to change. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. | activity | N | N |
| compute. | Flags the specified instances in the managed instance group to be resumed. This method increases thetargetSize and decreases the targetSuspendedSize of the managed instance group by the number of instances that you resume. The resumeInstances operation is marked DONE if the resumeInstances request is successful. The underlying actions take additional time. You must separately verify the status of theRESUMING action with thelistmanagedinstances method. In this request, you can only specify instances that are suspended. For example, if an instance was previously suspended using the suspendInstances method, it can be resumed using the resumeInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are resumed. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Specifies the instance template to use when creating new instances in this group. The templates for existing instances in the group do not change unless you run recreateInstances, runapplyUpdatesToInstances, or set the group'supdatePolicy.type to PROACTIVE. | activity | N | N |
| compute. | Modifies the target pools to which all instances in this managed instance group are assigned. The target pools automatically apply to all of the instances in the managed instance group. This operation is markedDONE when you make the request even if the instances have not yet been added to their target pools. The change might take some time to apply to all of the instances in the group depending on the size of the group. | activity | N | N |
| compute. | Flags the specified instances in the managed instance group to be started. This method increases thetargetSize and decreases the targetStoppedSize of the managed instance group by the number of instances that you start. The startInstances operation is marked DONE if the startInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTARTING action with thelistmanagedinstances method. In this request, you can only specify instances that are stopped. For example, if an instance was previously stopped using the stopInstances method, it can be started using the startInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are started. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Flags the specified instances in the managed instance group to be immediately stopped. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetStoppedSize of the managed instance group by the number of instances that you stop. The stopInstances operation is marked DONE if the stopInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTOPPING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays stopping the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is stopped. Stopped instances can be started using the startInstances method. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Flags the specified instances in the managed instance group to be immediately suspended. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetSuspendedSize of the managed instance group by the number of instances that you suspend. The suspendInstances operation is marked DONE if the suspendInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSUSPENDING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays suspension of the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is suspended. Suspended instances can be resumed using the resumeInstances method. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Inserts or updates per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch. | activity | N | N |
| compute. | Adds a list of instances to the specified instance group. All of the instances in the instance group must be in the same network/subnetwork. Read Adding instances for more information. | activity | N | N |
| compute. | Retrieves the list of instance groups and sorts them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified instance group. The instances in the group are not deleted. Note that instance group must not belong to a backend service. Read Deleting an instance group for more information. | activity | N | N |
| compute. | Returns the specified zonal instance group. Get a list of available zonal instance groups by making a list() request. For managed instance groups, use theinstanceGroupManagers or regionInstanceGroupManagers methods instead. | data_access | N | N |
| compute. | Creates an instance group in the specified project using the parameters that are included in the request. | activity | Y | N |
| compute. | Retrieves the list of zonal instance group resources contained within the specified zone. For managed instance groups, use theinstanceGroupManagers or regionInstanceGroupManagers methods instead. | data_access | N | N |
| compute. | Lists the instances in the specified instance group. The orderBy query parameter is not supported. The filter query parameter is supported, but only for expressions that use `eq` (equal) or `ne` (not equal) operators. | data_access | N | N |
| compute. | Removes one or more instances from the specified instance group, but does not delete those instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration before the VM instance is removed or deleted. | activity | Y | N |
| compute. | Sets the named ports for the specified instance group. | activity | Y | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Get Instance settings. | data_access | N | N |
| compute. | Patch Instance settings | activity | N | N |
| compute. | Retrieves the list of all InstanceTemplates resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified instance template. Deleting an instance template is permanent and cannot be undone. It is not possible to delete templates that are already in use by a managed instance group. | activity | N | N |
| compute. | Returns the specified instance template. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates an instance template in the specified project using the data that is included in the request. If you are creating a new template to update an existing instance group, your new instance template must use the same network or, if applicable, the same subnetwork as the original template. | activity | Y | N |
| compute. | Retrieves a list of instance templates that are contained within the specified project. | data_access | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Adds an access config to an instance's network interface. | activity | N | N |
| compute. | Adds one dynamic network interface to an active instance. | activity | N | N |
| compute. | Adds existing resource policies to an instance. You can only add one policy right now which will be applied to this instance for scheduling live migrations. | activity | N | N |
| compute. | Retrieves an aggregated list of all of the instances in your project across all regions and zones. The performance of this method degrades when a filter is specified on a project that has a very large number of instances. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Attaches an existing Disk resource to an instance. You must first create the disk before you can attach it. It is not possible to create and attach a disk at the same time. For more information, readAdding a persistent disk to your instance. | activity | Y | N |
| compute. | Creates multiple instances. Count specifies the number of instances to create. For more information, seeAbout bulk creation of VMs. | activity | N | N |
| compute. | Deletes the specified Instance resource. | activity | Y | N |
| compute. | Deletes an access config from an instance's network interface. | activity | N | N |
| compute. | Deletes one dynamic network interface from an active instance. InstancesDeleteNetworkInterfaceRequest indicates: - instance from which to delete, using project+zone+resource_id fields; - dynamic network interface to be deleted, using network_interface_name field; | activity | N | N |
| compute. | Detaches a disk from an instance. | activity | Y | N |
| compute. | Returns the specified Instance resource. | data_access | Y | N |
| compute. | Returns effective firewalls applied to an interface of the instance. | data_access | N | N |
| compute. | Returns the specified guest attributes entry. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Returns the screenshot from the specified instance. | data_access | N | N |
| compute. | Returns the last 1 MB of serial port output from the specified instance. | data_access | N | N |
| compute. | Returns the Shielded Instance Identity of an instance | data_access | N | N |
| compute. | Creates an instance resource in the specified project using the data included in the request. | activity | Y | Y |
| compute. | Retrieves the list of instances contained within the specified zone. | data_access | Y | N |
| compute. | Retrieves a list of resources that refer to the VM instance specified in the request. For example, if the VM instance is part of a managed or unmanaged instance group, the referrers list includes the instance group. For more information, readViewing referrers to VM instances. | data_access | N | N |
| compute. | Google-initiated live migration of a VM to new host hardware. Appears in system_event audit logs (cloudaudit.googleapis.com/system_event), not admin_activity. Not user-callable; emitted by GCE infrastructure. | system_event | N | N |
| compute. | Perform a manual maintenance on the instance. | activity | N | N |
| compute. | Removes resource policies from an instance. | activity | N | N |
| compute. | Mark the host as faulty and try to restart the instance on a new host. | activity | N | N |
| compute. | Performs a reset on the instance. This is a hard reset. The VM does not do a graceful shutdown. For more information, seeResetting an instance. | activity | Y | N |
| compute. | Resumes an instance that was suspended using theinstances().suspend method. | activity | N | N |
| compute. | Sends diagnostic interrupt to the instance. | activity | N | N |
| compute. | Sets deletion protection on the instance. | activity | Y | N |
| compute. | Sets the auto-delete flag for a disk attached to an instance. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Sets labels on an instance. To learn more about labels, read theLabeling Resources documentation. | activity | Y | N |
| compute. | Changes the number and/or type of accelerator for a stopped instance to the values specified in the request. | activity | N | N |
| compute. | Changes the machine type for a stopped instance to the machine type specified in the request. | activity | Y | N |
| compute. | Sets metadata for the specified instance to the data included in the request. | activity | Y | Y |
| compute. | Changes the minimum CPU platform that this instance should use. This method can only be called on a stopped instance. For more information, readSpecifying a Minimum CPU Platform. | activity | N | N |
| compute. | Sets name of an instance. | activity | N | N |
| compute. | Sets an instance's scheduling options. You can only call this method on astopped instance, that is, a VM instance that is in a `TERMINATED` state. SeeInstance Life Cycle for more information on the possible instance states. For more information about setting scheduling options for a VM, seeSet VM host maintenance policy. | activity | Y | N |
| compute. | Sets the Google Cloud Armor security policy for the specified instance. For more information, seeGoogle Cloud Armor Overview | activity | N | N |
| compute. | Sets the service account on the instance. | activity | N | N |
| compute. | Sets the Shielded Instance integrity policy for an instance. You can only use this method on a running instance. This method supports PATCH semantics and uses the JSON merge patch format and processing rules. | activity | N | N |
| compute. | Sets network tags for the specified instance to the data included in the request. | activity | Y | N |
| compute. | Simulates a host maintenance event on a VM. For more information, see Simulate a host maintenance event. | activity | Y | N |
| compute. | Starts an instance that was stopped using the stopInstance method. | activity | Y | N |
| compute. | Starts an instance that was stopped using theinstances().stop method. For more information, seeRestart an instance. | activity | N | N |
| compute. | Stops a running instance, shutting it down cleanly. | activity | Y | N |
| compute. | This method suspends a running instance, saving its state to persistent storage, and allows you to resume the instance at a later time. Suspended instances have no compute costs (cores or RAM), and incur only storage charges for the saved VM memory and localSSD data. Any charged resources the virtual machine was using, such as persistent disks and static IP addresses, will continue to be charged while the instance is suspended. For more information, see Suspending and resuming an instance. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates an instance only if the necessary resources are available. This method can update only a specific set of instance properties. See Updating a running instance for a list of updatable instance properties. | activity | N | N |
| compute. | Updates the specified access config from an instance's network interface with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Updates the Display config for a VM instance. You can only use this method on a stopped VM instance. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Updates an instance's network interface. This method can only update an interface's alias IP range and attached network. See Modifying alias IP ranges for an existing instance for instructions on changing alias IP ranges. See Migrating a VM between networks for instructions on migrating an interface. This method follows PATCH semantics. | activity | N | N |
| compute. | Updates the Shielded Instance config for an instance. You can only use this method on a stopped instance. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | Y | N |
| compute. | deletes a Zonal InstantSnapshotGroup resource | activity | N | N |
| compute. | returns the specified InstantSnapshotGroup resource in the specified zone. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | inserts a Zonal InstantSnapshotGroup resource | activity | N | N |
| compute. | retrieves the list of InstantSnapshotGroup resources contained within the specified zone. | data_access | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves an aggregated list of instantSnapshots. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified InstantSnapshot resource. Keep in mind that deleting a single instantSnapshot might not necessarily delete all the data on that instantSnapshot. If any data on the instantSnapshot that is marked for deletion is needed for subsequent instantSnapshots, the data will be moved to the next corresponding instantSnapshot. For more information, seeDeleting instantSnapshots. | activity | N | N |
| compute. | Returns the specified InstantSnapshot resource in the specified zone. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates an instant snapshot in the specified zone. | activity | N | N |
| compute. | Retrieves the list of InstantSnapshot resources contained within the specified zone. | data_access | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Sets the labels on a instantSnapshot in the given zone. To learn more about labels, read the Labeling Resources documentation. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Deletes the specified InterconnectAttachmentGroup in the given scope | activity | N | N |
| compute. | Returns the specified InterconnectAttachmentGroup resource in the given scope. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Returns the InterconnectAttachmentStatuses for the specified InterconnectAttachmentGroup resource. | data_access | N | N |
| compute. | Creates a InterconnectAttachmentGroup in the specified project in the given scope using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the InterconnectAttachmentGroups for a project in the given scope. | data_access | N | N |
| compute. | Patches the specified InterconnectAttachmentGroup resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves an aggregated list of interconnect attachments. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified interconnect attachment. | activity | N | N |
| compute. | Returns the specified interconnect attachment. | data_access | N | N |
| compute. | Creates an InterconnectAttachment in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of interconnect attachments contained within the specified region. | data_access | N | N |
| compute. | Updates the specified interconnect attachment with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Sets the labels on an InterconnectAttachment. To learn more about labels, read the Labeling Resources documentation. | activity | N | N |
| compute. | Create Interconnects with redundancy by creating them in a specified interconnect group. | activity | N | N |
| compute. | Deletes the specified InterconnectGroup in the given scope | activity | N | N |
| compute. | Returns the specified InterconnectGroup resource in the given scope. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Returns the interconnectStatuses for the specified InterconnectGroup. | data_access | N | N |
| compute. | Creates a InterconnectGroup in the specified project in the given scope using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the InterconnectGroups for a project in the given scope. | data_access | N | N |
| compute. | Patches the specified InterconnectGroup resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Returns the details for the specified interconnect location. Gets a list of available interconnect locations by making a list() request. | data_access | N | N |
| compute. | Retrieves the list of interconnect locations available to the specified project. | data_access | N | N |
| compute. | Returns the details for the specified interconnect remote location. Gets a list of available interconnect remote locations by making alist() request. | data_access | N | N |
| compute. | Retrieves the list of interconnect remote locations available to the specified project. | data_access | N | N |
| compute. | Deletes the specified Interconnect. | activity | N | N |
| compute. | Returns the specified Interconnect. Get a list of available Interconnects by making a list() request. | data_access | N | N |
| compute. | Returns the interconnectDiagnostics for the specified Interconnect. In the event of a global outage, do not use this API to make decisions about where to redirect your network traffic. Unlike a VLAN attachment, which is regional, a Cloud Interconnect connection is a global resource. A global outage can prevent this API from functioning properly. | data_access | N | N |
| compute. | Returns the interconnectMacsecConfig for the specified Interconnect. | data_access | N | N |
| compute. | Creates an Interconnect in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of Interconnects available to the specified project. | data_access | N | N |
| compute. | Updates the specified Interconnect with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Sets the labels on an Interconnect. To learn more about labels, read the Labeling Resources documentation. | activity | N | N |
| compute. | Return a specified license code. License codes are mirrored across all projects that have permissions to read the License Code. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | data_access | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | data_access | N | N |
| compute. | Deletes the specified license. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | activity | N | N |
| compute. | Returns the specified License resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | data_access | N | N |
| compute. | Create a License resource in the specified project. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | activity | N | N |
| compute. | Retrieves the list of licenses available in the specified project. This method does not get any licenses that belong to other projects, including licenses attached to publicly-available images, like Debian 9. If you want to get a list of publicly-available licenses, use this method to make a request to the respective image project, such as debian-cloud orwindows-cloud. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | data_access | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | data_access | N | N |
| compute. | Updates a License resource in the specified project. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images. | activity | N | N |
| compute. | Deletes the specified machine image. Deleting a machine image is permanent and cannot be undone. | activity | N | N |
| compute. | Returns the specified machine image. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a machine image in the specified project using the data that is included in the request. If you are creating a new machine image to update an existing instance, your new machine image should use the same network or, if applicable, the same subnetwork as the original instance. | activity | N | N |
| compute. | Retrieves a list of machine images that are contained within the specified project. | data_access | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Sets the labels on a machine image. To learn more about labels, read theLabeling Resources documentation. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves an aggregated list of machine types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Returns the specified machine type. | data_access | N | N |
| compute. | Retrieves a list of machine types available to the specified project. | data_access | N | N |
| compute. | Retrieves the list of all NetworkAttachment resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified NetworkAttachment in the given scope | activity | N | N |
| compute. | Returns the specified NetworkAttachment resource in the given scope. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a NetworkAttachment in the specified project in the given scope using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the NetworkAttachments for a project in the given scope. | data_access | N | N |
| compute. | Patches the specified NetworkAttachment resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves the list of all NetworkEdgeSecurityService resources available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified service. | activity | N | N |
| compute. | Gets a specified NetworkEdgeSecurityService. | data_access | N | N |
| compute. | Creates a new service in the specified project using the data included in the request. | activity | N | N |
| compute. | Patches the specified policy with the data included in the request. | activity | N | N |
| compute. | Retrieves the list of network endpoint groups and sorts them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Attach a list of network endpoints to the specified network endpoint group. | activity | N | N |
| compute. | Deletes the specified network endpoint group. The network endpoints in the NEG and the VM instances they belong to are not terminated when the NEG is deleted. Note that the NEG cannot be deleted if there are backend services referencing it. | activity | Y | N |
| compute. | Detach a list of network endpoints from the specified network endpoint group. | activity | N | N |
| compute. | Returns the specified network endpoint group. | data_access | N | N |
| compute. | Creates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global API | activity | Y | N |
| compute. | Retrieves the list of network endpoint groups that are located in the specified project and zone. | data_access | N | N |
| compute. | Lists the network endpoints in the specified network endpoint group. | data_access | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Inserts an association for the specified firewall policy. | activity | N | N |
| compute. | Inserts a packet mirroring rule into a firewall policy. | activity | N | N |
| compute. | Inserts a rule into a firewall policy. | activity | N | N |
| compute. | Retrieves an aggregated list of network firewall policies, listing network firewall policies from all applicable scopes (global and regional) and grouping the results per scope. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Copies rules to the specified firewall policy. | activity | N | N |
| compute. | Deletes the specified policy. | activity | N | N |
| compute. | Returns the specified network firewall policy. | data_access | N | N |
| compute. | Gets an association with the specified name. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Gets a packet mirroring rule of the specified priority. | data_access | N | N |
| compute. | Gets a rule of the specified priority. | data_access | N | N |
| compute. | Creates a new policy in the specified project using the data included in the request. | activity | N | N |
| compute. | Lists all the policies that have been configured for the specified project. | data_access | N | N |
| compute. | Patches the specified policy with the data included in the request. | activity | N | N |
| compute. | Patches a packet mirroring rule of the specified priority. | activity | N | N |
| compute. | Patches a rule of the specified priority. | activity | N | N |
| compute. | Removes an association for the specified firewall policy. | activity | N | N |
| compute. | Deletes a packet mirroring rule of the specified priority. | activity | N | N |
| compute. | Deletes a rule of the specified priority. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Returns the specified network profile. | data_access | N | N |
| compute. | Retrieves a list of network profiles available to the specified project. | data_access | N | N |
| compute. | Adds a peering to the specified network. | activity | Y | N |
| compute. | Cancel requests to remove a peering from the specified network. Applicable only for PeeringConnection with update_strategy=CONSENSUS. Cancels a request to remove a peering from the specified network. | activity | N | N |
| compute. | Deletes the specified network. | activity | Y | Y |
| compute. | Returns the specified network. | data_access | Y | N |
| compute. | Returns the effective firewalls on a given network. | data_access | N | N |
| compute. | Creates a network in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves the list of networks available to the specified project. | data_access | Y | N |
| compute. | Lists the peering routes exchanged over peering connection. | data_access | N | N |
| compute. | Patches the specified network with the data included in the request. Only routingConfig can be modified. | activity | N | N |
| compute. | Removes a peering from the specified network. | activity | Y | N |
| compute. | Requests to remove a peering from the specified network. Applicable only for PeeringConnection with update_strategy=CONSENSUS. | activity | N | N |
| compute. | Switches the network mode from auto subnet mode to custom subnet mode. | activity | N | N |
| compute. | Updates the specified network peering with the data included in the request. You can only modify the NetworkPeering.export_custom_routes field and the NetworkPeering.import_custom_routes field. | activity | N | N |
| compute. | Adds specified number of nodes to the node group. | activity | N | N |
| compute. | Retrieves an aggregated list of node groups. Note: use nodeGroups.listNodes for more details about each group. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified NodeGroup resource. | activity | N | N |
| compute. | Deletes specified nodes from the node group. | activity | N | N |
| compute. | Returns the specified NodeGroup. Get a list of available NodeGroups by making a list() request. Note: the "nodes" field should not be used. Use nodeGroups.listNodes instead. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a NodeGroup resource in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves a list of node groups available to the specified project. Note: use nodeGroups.listNodes for more details about each group. | data_access | N | N |
| compute. | Lists nodes in the node group. | data_access | N | N |
| compute. | Updates the specified node group. | activity | N | N |
| compute. | Perform maintenance on a subset of nodes in the node group. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Updates the node template of the node group. | activity | N | N |
| compute. | Simulates maintenance event on specified nodes from the node group. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves an aggregated list of node templates. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified NodeTemplate resource. | activity | N | N |
| compute. | Returns the specified node template. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a NodeTemplate resource in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves a list of node templates available to the specified project. | data_access | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves an aggregated list of node types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Returns the specified node type. | data_access | N | N |
| compute. | Retrieves a list of node types available to the specified project. | data_access | N | N |
| compute. | Inserts an association for the specified security policy. This has billing implications. Projects in the hierarchy with effective hierarchical security policies will be automatically enrolled into Cloud Armor Enterprise if not already enrolled. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.addAssociation instead. | activity | N | N |
| compute. | Inserts a rule into a security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.addRule instead. | activity | N | N |
| compute. | Copies rules to the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.cloneRules instead. | activity | N | N |
| compute. | Deletes the specified policy. Use this API to remove Cloud Armor policies. Previously, alpha and beta versions of this API were used to remove firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.delete instead. | activity | N | N |
| compute. | List all of the ordered rules present in a single specified policy. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.get instead. | data_access | N | N |
| compute. | Gets an association with the specified name. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.getAssociation instead. | data_access | N | N |
| compute. | Gets a rule at the specified priority. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.getRule instead. | data_access | N | N |
| compute. | Creates a new policy in the specified organization using the data included in the request. Use this API to add Cloud Armor policies. Previously, alpha and beta versions of this API were used to add firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.insert instead. | activity | N | N |
| compute. | List all the policies that have been configured for the specified organization. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.list instead. | data_access | N | N |
| compute. | Lists associations of a specified target, i.e., organization or folder. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.listAssociations instead. | data_access | N | N |
| compute. | Gets the current list of preconfigured Web Application Firewall (WAF) expressions. | data_access | N | N |
| compute. | Moves the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.move instead. | activity | N | N |
| compute. | Patches the specified policy with the data included in the request. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.patch instead. | activity | N | N |
| compute. | Patches a rule at the specified priority. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.patchRule instead. | activity | N | N |
| compute. | Removes an association for the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.removeAssociation instead. | activity | N | N |
| compute. | Deletes a rule at the specified priority. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.removeRule instead. | activity | N | N |
| compute. | Retrieves an aggregated list of packetMirrorings. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | Y |
| compute. | Deletes the specified PacketMirroring resource. | activity | Y | Y |
| compute. | Returns the specified PacketMirroring resource. | data_access | Y | Y |
| compute. | Creates a PacketMirroring resource in the specified project and region using the data included in the request. | activity | Y | Y |
| compute. | Retrieves a list of PacketMirroring resources available to the specified project and region. | data_access | Y | Y |
| compute. | Patches the specified PacketMirroring resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules. | activity | Y | Y |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Returns the details of the given PreviewFeature. | data_access | N | N |
| compute. | Returns the details of the given PreviewFeature. | data_access | N | N |
| compute. | Patches the given PreviewFeature. This method is used to enable or disable a PreviewFeature. | activity | N | N |
| compute. | Disable this project as a shared VPC host project. | activity | N | N |
| compute. | Disable a service resource (also known as service project) associated with this host project. | activity | N | N |
| compute. | Enable this project as a shared VPC host project. | activity | N | N |
| compute. | Enable service resource (a.k.a service project) for a host project, so that subnets in the host project can be used by instances in the service project. | activity | N | N |
| compute. | Returns the specified Project resource. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request. | data_access | Y | N |
| compute. | Gets the shared VPC host project that this project links to. May be empty if no link exists. | data_access | N | N |
| compute. | Gets service resources (a.k.a service project) associated with this host project. | data_access | N | N |
| compute. | Lists all shared VPC host projects visible to the user in an organization. | data_access | N | N |
| compute. | Moves a persistent disk from one zone to another. *Note*: The moveDisk API will be deprecated on September 29, 2026. Starting September 29, 2025, you can't use the moveDisk API on new projects. To move a disk to a different region or zone, follow the steps in Change the location of a disk. Projects that already use the moveDisk API can continue usage until September 29, 2026. Starting November 1, 2025, API responses will include a warning message in the response body about the upcoming deprecation. You can skip the message to continue using the service without interruption. | activity | N | N |
| compute. | Moves an instance and its attached persistent disks from one zone to another. *Note*: Moving VMs or disks by using this method might cause unexpected behavior. For more information, see the known issue. [Deprecated] This method is deprecated. See moving instance across zones instead. | activity | N | N |
| compute. | Sets the Cloud Armor tier of the project. To set ENTERPRISE or above the billing account of the project must be subscribed to Cloud Armor Enterprise. See Subscribing to Cloud Armor Enterprise for more information. | activity | Y | N |
| compute. | Sets metadata common to all instances within the specified project using the data included in the request. | activity | Y | Y |
| compute. | Sets the default network tier of the project. The default network tier is used when an address/forwardingRule/instance is created without specifying the network tier field. | activity | N | N |
| compute. | Enables the usage export feature and sets theusage export bucket where reports are stored. If you provide an empty request body using this method, the usage export feature will be disabled. | activity | N | N |
| compute. | Announces the specified PublicAdvertisedPrefix | activity | N | N |
| compute. | Deletes the specified PublicAdvertisedPrefix | activity | N | N |
| compute. | Returns the specified PublicAdvertisedPrefix resource. | data_access | N | N |
| compute. | Creates a PublicAdvertisedPrefix in the specified project using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the PublicAdvertisedPrefixes for a project. | data_access | N | N |
| compute. | Patches the specified Router resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Withdraws the specified PublicAdvertisedPrefix | activity | N | N |
| compute. | Lists all PublicDelegatedPrefix resources owned by the specific project across all scopes. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Announces the specified PublicDelegatedPrefix in the given region. | activity | N | N |
| compute. | Deletes the specified PublicDelegatedPrefix in the given region. | activity | N | N |
| compute. | Returns the specified PublicDelegatedPrefix resource in the given region. | data_access | N | N |
| compute. | Creates a PublicDelegatedPrefix in the specified project in the given region using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the PublicDelegatedPrefixes for a project in the given region. | data_access | N | N |
| compute. | Patches the specified PublicDelegatedPrefix resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Withdraws the specified PublicDelegatedPrefix in the given region. | activity | N | N |
| compute. | Deletes the specified autoscaler. | activity | N | N |
| compute. | Returns the specified autoscaler. | data_access | N | N |
| compute. | Creates an autoscaler in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves a list of autoscalers contained within the specified region. | data_access | N | N |
| compute. | Updates an autoscaler in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates an autoscaler in the specified project using the data included in the request. | activity | N | N |
| compute. | Deletes the specified regional BackendBucket resource. | activity | N | N |
| compute. | Returns the specified regional BackendBucket resource. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a RegionBackendBucket in the specified project in the given scope using the parameters that are included in the request. | activity | N | N |
| compute. | Retrieves the list of BackendBucket resources available to the specified project in the given region. | data_access | N | N |
| compute. | Retrieves a list of all usable backend buckets in the specified project in the given region. | data_access | N | N |
| compute. | Updates the specified BackendBucket resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Deletes the specified regional BackendService resource. | activity | Y | N |
| compute. | Returns the specified regional BackendService resource. | data_access | Y | N |
| compute. | Gets the most recent health check results for this regional BackendService. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a regional BackendService resource in the specified project using the data included in the request. For more information, see Backend services overview. | activity | Y | N |
| compute. | Retrieves the list of regional BackendService resources available to the specified project in the given region. | data_access | N | N |
| compute. | Retrieves a list of all usable backend services in the specified project in the given region. | data_access | N | N |
| compute. | Updates the specified regional BackendService resource with the data included in the request. For more information, see Understanding backend services This method supports PATCH semantics and uses the JSON merge patch format and processing rules. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Sets the Google Cloud Armor security policy for the specified backend service. For more information, seeGoogle Cloud Armor Overview | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates the specified regional BackendService resource with the data included in the request. For more information, see Backend services overview. | activity | N | N |
| compute. | Retrieves an aggregated list of commitments by region. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Returns the specified commitment resource. | data_access | N | N |
| compute. | Creates a commitment in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves a list of commitments contained within the specified region. | data_access | N | N |
| compute. | Updates the specified commitment with the data included in the request. Update is performed only on selected fields included as part of update-mask. Only the following fields can be updated: auto_renew and plan. | activity | N | N |
| compute. | Retrieves the list of all CompositeHealthCheck resources (all regional) available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified CompositeHealthCheck in the given region | activity | N | N |
| compute. | Returns the specified CompositeHealthCheck resource in the given region. | data_access | N | N |
| compute. | Gets the most recent health check results for this regional CompositeHealthCheck. | data_access | N | N |
| compute. | Create a CompositeHealthCheck in the specified project in the given region using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the CompositeHealthChecks for a project in the given region. | data_access | N | N |
| compute. | Updates the specified regional CompositeHealthCheck resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Returns the specified regional disk type. | data_access | N | N |
| compute. | Retrieves a list of regional disk types available to the specified project. | data_access | N | N |
| compute. | Adds existing resource policies to a regional disk. You can only add one policy which will be applied to this disk for scheduling snapshot creation. | activity | N | N |
| compute. | Bulk create a set of disks. | activity | N | N |
| compute. | Creates a snapshot of a specified persistent disk. For regular snapshot creation, consider using snapshots.insert instead, as that method supports more features, such as creating snapshots in a project different from the source disk project. | activity | N | N |
| compute. | Deletes the specified regional persistent disk. Deleting a regional disk removes all the replicas of its data permanently and is irreversible. However, deleting a disk does not delete anysnapshots previously made from the disk. You must separatelydelete snapshots. | activity | N | N |
| compute. | Returns a specified regional persistent disk. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a persistent regional disk in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of persistent disks contained within the specified region. | data_access | Y | N |
| compute. | Removes resource policies from a regional disk. | activity | N | N |
| compute. | Resizes the specified regional persistent disk. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Sets the labels on the target regional disk. | activity | N | N |
| compute. | Starts asynchronous replication. Must be invoked on the primary disk. | activity | N | N |
| compute. | Stops asynchronous replication. Can be invoked either on the primary or on the secondary disk. | activity | N | N |
| compute. | Stops asynchronous replication for a consistency group of disks. Can be invoked either in the primary or secondary scope. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Update the specified disk with the data included in the request. Update is performed only on selected fields included as part of update-mask. | activity | N | N |
| compute. | Rotates the customer-managed encryption key to the latest version for the specified persistent disk. | activity | N | N |
| compute. | Retrieves the list of all HealthAggregationPolicy resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified HealthAggregationPolicy in the given region. | activity | N | N |
| compute. | Returns the specified HealthAggregationPolicy resource in the given region. | data_access | N | N |
| compute. | Create a HealthAggregationPolicy in the specified project in the given region using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the HealthAggregationPolicies for a project in the given region. | data_access | N | N |
| compute. | Updates the specified regional HealthAggregationPolicy resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves the list of all HealthCheckService resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified regional HealthCheckService. | activity | N | N |
| compute. | Returns the specified regional HealthCheckService resource. | data_access | N | N |
| compute. | Creates a regional HealthCheckService resource in the specified project and region using the data included in the request. | activity | N | N |
| compute. | Lists all the HealthCheckService resources that have been configured for the specified project in the given region. | data_access | N | N |
| compute. | Updates the specified regional HealthCheckService resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Deletes the specified HealthCheck resource. | activity | Y | N |
| compute. | Returns the specified HealthCheck resource. | data_access | Y | N |
| compute. | Creates a HealthCheck resource in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves the list of HealthCheck resources available to the specified project. | data_access | N | N |
| compute. | Updates a HealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates a HealthCheck resource in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of all HealthSource resources (all regional) available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified HealthSource in the given region | activity | N | N |
| compute. | Returns the specified HealthSource resource in the given region. | data_access | N | N |
| compute. | Gets the most recent health check results for this regional HealthSource. | data_access | N | N |
| compute. | Create a HealthSource in the specified project in the given region using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the HealthSources for a project in the given region. | data_access | N | N |
| compute. | Updates the specified regional HealthSource resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Cancels the specified resize request. Cancelled resize request no longer waits for the resources to be provisioned. Cancel is only possible for requests that are in accepted state. | activity | N | N |
| compute. | Deletes the specified, inactive resize request. Requests that are still active cannot be deleted. Deleting request does not delete instances that were provisioned previously. | activity | N | N |
| compute. | Returns all of the details about the specified resize request. | data_access | N | N |
| compute. | Creates a new Resize Request that starts provisioning VMs immediately or queues VM creation. | activity | N | N |
| compute. | Retrieves a list of Resize Requests that are contained in the managed instance group. | data_access | N | N |
| compute. | Flags the specified instances to be immediately removed from the managed instance group. Abandoning an instance does not delete the instance, but it does remove the instance from any target pools that are applied by the managed instance group. This method reduces thetargetSize of the managed instance group by the number of instances that you abandon. This operation is marked asDONE when the action is scheduled even if the instances have not yet been removed from the group. You must separately verify the status of the abandoning action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Apply updates to selected instances the managed instance group. | activity | N | N |
| compute. | Creates instances with per-instance configurations in this regional managed instance group. Instances are created using the current instance template. The create instances operation is marked DONE if the createInstances request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or actions with the listmanagedinstances method. | activity | N | N |
| compute. | Deletes the specified managed instance group and all of the instances in that group. | activity | N | N |
| compute. | Flags the specified instances in the managed instance group to be immediately deleted. The instances are also removed from any target pools of which they were a member. This method reduces thetargetSize of the managed instance group by the number of instances that you delete. The deleteInstances operation is marked DONE if the deleteInstances request is successful. The underlying actions take additional time. You must separately verify the status of thedeleting action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Deletes selected per-instance configurations for the managed instance group. | activity | N | N |
| compute. | Returns all of the details about the specified managed instance group. | data_access | N | N |
| compute. | Creates a managed instance group using the information that you specify in the request. After the group is created, instances in the group are created using the specified instance template. This operation is marked as DONE when the group is created even if the instances in the group have not yet been created. You must separately verify the status of the individual instances with thelistmanagedinstances method. A regional managed instance group can contain up to 2000 instances. | activity | N | N |
| compute. | Retrieves the list of managed instance groups that are contained within the specified region. | data_access | N | N |
| compute. | Lists all errors thrown by actions on instances for a given regional managed instance group. The filter andorderBy query parameters are not supported. | data_access | N | N |
| compute. | Lists the instances in the managed instance group and instances that are scheduled to be created. The list includes any current actions that the group has scheduled for its instances. The orderBy query parameter is not supported. The `pageToken` query parameter is supported only if the group's `listManagedInstancesResults` field is set to `PAGINATED`. | data_access | N | N |
| compute. | Lists all of the per-instance configurations defined for the managed instance group. The orderBy query parameter is not supported. | data_access | N | N |
| compute. | Updates a managed instance group using the information that you specify in the request. This operation is marked as DONE when the group is patched even if the instances in the group are still in the process of being patched. You must separately verify the status of the individual instances with the listmanagedinstances method. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. If you update your group to specify a new template or instance configuration, it's possible that your intended specification for each VM in the group is different from the current state of that VM. To learn how to apply an updated configuration to the VMs in a MIG, seeUpdating instances in a MIG. | activity | N | N |
| compute. | Inserts or patches per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch. | activity | N | N |
| compute. | Flags the specified VM instances in the managed instance group to be immediately recreated. Each instance is recreated using the group's current configuration. This operation is marked as DONE when the flag is set even if the instances have not yet been recreated. You must separately verify the status of each instance by checking itscurrentAction field; for more information, see Checking the status of managed instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Changes the intended size of the managed instance group. If you increase the size, the group creates new instances using the current instance template. If you decrease the size, the group deletes one or more instances. The resize operation is marked DONE if theresize request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or deleting actions with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. | activity | N | N |
| compute. | Flags the specified instances in the managed instance group to be resumed. This method increases thetargetSize and decreases the targetSuspendedSize of the managed instance group by the number of instances that you resume. The resumeInstances operation is marked DONE if the resumeInstances request is successful. The underlying actions take additional time. You must separately verify the status of theRESUMING action with thelistmanagedinstances method. In this request, you can only specify instances that are suspended. For example, if an instance was previously suspended using the suspendInstances method, it can be resumed using the resumeInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are resumed. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Sets the instance template to use when creating new instances or recreating instances in this group. Existing instances are not affected. | activity | N | N |
| compute. | Modifies the target pools to which all new instances in this group are assigned. Existing instances in the group are not affected. | activity | N | N |
| compute. | Flags the specified instances in the managed instance group to be started. This method increases thetargetSize and decreases the targetStoppedSize of the managed instance group by the number of instances that you start. The startInstances operation is marked DONE if the startInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTARTING action with thelistmanagedinstances method. In this request, you can only specify instances that are stopped. For example, if an instance was previously stopped using the stopInstances method, it can be started using the startInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are started. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Flags the specified instances in the managed instance group to be immediately stopped. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetStoppedSize of the managed instance group by the number of instances that you stop. The stopInstances operation is marked DONE if the stopInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTOPPING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays stopping the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is stopped. Stopped instances can be started using the startInstances method. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Flags the specified instances in the managed instance group to be immediately suspended. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetSuspendedSize of the managed instance group by the number of instances that you suspend. The suspendInstances operation is marked DONE if the suspendInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSUSPENDING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays suspension of the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is suspended. Suspended instances can be resumed using the resumeInstances method. You can specify a maximum of 1000 instances with this method per request. | activity | N | N |
| compute. | Inserts or updates per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch. | activity | N | N |
| compute. | Returns the specified instance group resource. | data_access | N | N |
| compute. | Retrieves the list of instance group resources contained within the specified region. | data_access | N | N |
| compute. | Lists the instances in the specified instance group and displays information about the named ports. Depending on the specified options, this method can list all instances or only the instances that are running. The orderBy query parameter is not supported. | data_access | N | N |
| compute. | Sets the named ports for the specified regional instance group. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Deletes the specified instance template. Deleting an instance template is permanent and cannot be undone. | activity | Y | N |
| compute. | Returns the specified instance template. | data_access | N | N |
| compute. | Creates an instance template in the specified project and region using the global instance template whose URL is included in the request. | activity | N | N |
| compute. | Retrieves a list of instance templates that are contained within the specified project and region. | data_access | N | N |
| compute. | Creates multiple instances in a given region. Count specifies the number of instances to create. | activity | N | N |
| compute. | deletes a Regional InstantSnapshotGroup resource | activity | N | N |
| compute. | returns the specified InstantSnapshotGroup resource in the specified region. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | creates a Regional InstantSnapshotGroup resource | activity | N | N |
| compute. | retrieves the list of InstantSnapshotGroup resources contained within the specified region. | data_access | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Deletes the specified InstantSnapshot resource. Keep in mind that deleting a single instantSnapshot might not necessarily delete all the data on that instantSnapshot. If any data on the instantSnapshot that is marked for deletion is needed for subsequent instantSnapshots, the data will be moved to the next corresponding instantSnapshot. For more information, seeDeleting instantSnapshots. | activity | N | N |
| compute. | Returns the specified InstantSnapshot resource in the specified region. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates an instant snapshot in the specified region. | activity | N | N |
| compute. | Retrieves the list of InstantSnapshot resources contained within the specified region. | data_access | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Sets the labels on a instantSnapshot in the given region. To learn more about labels, read the Labeling Resources documentation. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Attach a list of network endpoints to the specified network endpoint group. | activity | N | N |
| compute. | Deletes the specified network endpoint group. Note that the NEG cannot be deleted if it is configured as a backend of a backend service. | activity | N | N |
| compute. | Detach the network endpoint from the specified network endpoint group. | activity | N | N |
| compute. | Returns the specified network endpoint group. | data_access | N | N |
| compute. | Creates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global API | activity | N | N |
| compute. | Retrieves the list of regional network endpoint groups available to the specified project in the given region. | data_access | N | N |
| compute. | Lists the network endpoints in the specified network endpoint group. | data_access | N | N |
| compute. | Inserts an association for the specified network firewall policy. | activity | N | N |
| compute. | Inserts a rule into a network firewall policy. | activity | N | N |
| compute. | Copies rules to the specified network firewall policy. | activity | N | N |
| compute. | Deletes the specified network firewall policy. | activity | N | N |
| compute. | Returns the specified network firewall policy. | data_access | N | N |
| compute. | Gets an association with the specified name. | data_access | N | N |
| compute. | Returns the effective firewalls on a given network. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Gets a rule of the specified priority. | data_access | N | N |
| compute. | Creates a new network firewall policy in the specified project and region. | activity | N | N |
| compute. | Lists all the network firewall policies that have been configured for the specified project in the given region. | data_access | N | N |
| compute. | Patches the specified network firewall policy. | activity | N | N |
| compute. | Patches a rule of the specified priority. | activity | N | N |
| compute. | Removes an association for the specified network firewall policy. | activity | N | N |
| compute. | Deletes a rule of the specified priority. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves the list of all NotificationEndpoint resources, regional and global, available to the specified project. | data_access | N | N |
| compute. | Deletes the specified NotificationEndpoint in the given region | activity | N | N |
| compute. | Returns the specified NotificationEndpoint resource in the given region. | data_access | N | N |
| compute. | Create a NotificationEndpoint in the specified project in the given region using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the NotificationEndpoints for a project in the given region. | data_access | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Deletes the specified region-specific Operations resource. | activity | N | N |
| compute. | Retrieves the specified region-specific Operations resource. | data_access | Y | N |
| compute. | Retrieves a list of Operation resources contained within the specified region. | data_access | N | N |
| compute. | Waits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method differs from the `GET` method in that it waits for no more than the default deadline (2 minutes) and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`. | data_access | Y | N |
| compute. | Inserts a rule into a security policy. | activity | N | N |
| compute. | Deletes the specified policy. | activity | N | N |
| compute. | List all of the ordered rules present in a single specified policy. | data_access | N | N |
| compute. | Gets a rule at the specified priority. | data_access | N | N |
| compute. | Creates a new policy in the specified project using the data included in the request. | activity | N | N |
| compute. | List all the policies that have been configured for the specified project and region. | data_access | N | N |
| compute. | Patches the specified policy with the data included in the request. To clear fields in the policy, leave the fields empty and specify them in the updateMask. This cannot be used to be update the rules in the policy. Please use the per rule methods like addRule, patchRule, and removeRule instead. | activity | N | N |
| compute. | Patches a rule at the specified priority. To clear fields in the rule, leave the fields empty and specify them in the updateMask. | activity | N | N |
| compute. | Deletes a rule at the specified priority. | activity | N | N |
| compute. | Sets the labels on a security policy. To learn more about labels, read the Labeling Resources documentation. | activity | N | N |
| compute. | Get region snapshot settings. | data_access | N | N |
| compute. | Patch region snapshot settings. | activity | N | N |
| compute. | Deletes the specified Snapshot resource. Keep in mind that deleting a single snapshot might not necessarily delete all the data on that snapshot. If any data on the snapshot that is marked for deletion is needed for subsequent snapshots, the data will be moved to the next corresponding snapshot. For more information, seeDeleting snapshots. | activity | N | N |
| compute. | Returns the specified Snapshot resource. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a snapshot in the specified region using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of Snapshot resources contained within the specified region. | data_access | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Sets the labels on a regional snapshot. To learn more about labels, read the Labeling Resources documentation. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Rotates the customer-managed encryption key to the latest version for the specified snapshot. | activity | N | N |
| compute. | Deletes the specified SslCertificate resource in the region. | activity | N | N |
| compute. | Returns the specified SslCertificate resource in the specified region. Get a list of available SSL certificates by making a list() request. | data_access | N | N |
| compute. | Creates a SslCertificate resource in the specified project and region using the data included in the request | activity | N | N |
| compute. | Retrieves the list of SslCertificate resources available to the specified project in the specified region. | data_access | N | N |
| compute. | Deletes the specified SSL policy. The SSL policy resource can be deleted only if it is not in use by any TargetHttpsProxy or TargetSslProxy resources. | activity | N | N |
| compute. | Lists all of the ordered rules present in a single specified policy. | data_access | N | N |
| compute. | Creates a new policy in the specified project and region using the data included in the request. | activity | N | N |
| compute. | Lists all the SSL policies that have been configured for the specified project and region. | data_access | N | N |
| compute. | Lists all features that can be specified in the SSL policy when using custom profile. | data_access | N | N |
| compute. | Patches the specified SSL policy with the data included in the request. | activity | N | N |
| compute. | Deletes the specified TargetHttpProxy resource. | activity | N | N |
| compute. | Returns the specified TargetHttpProxy resource in the specified region. | data_access | N | N |
| compute. | Creates a TargetHttpProxy resource in the specified project and region using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of TargetHttpProxy resources available to the specified project in the specified region. | data_access | N | N |
| compute. | Changes the URL map for TargetHttpProxy. | activity | N | N |
| compute. | Deletes the specified TargetHttpsProxy resource. | activity | N | N |
| compute. | Returns the specified TargetHttpsProxy resource in the specified region. | data_access | N | N |
| compute. | Creates a TargetHttpsProxy resource in the specified project and region using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of TargetHttpsProxy resources available to the specified project in the specified region. | data_access | N | N |
| compute. | Patches the specified regional TargetHttpsProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Replaces SslCertificates for TargetHttpsProxy. | activity | N | N |
| compute. | Changes the URL map for TargetHttpsProxy. | activity | N | N |
| compute. | Deletes the specified TargetTcpProxy resource. | activity | N | N |
| compute. | Returns the specified TargetTcpProxy resource. | data_access | N | N |
| compute. | Creates a TargetTcpProxy resource in the specified project and region using the data included in the request. | activity | N | N |
| compute. | Retrieves a list of TargetTcpProxy resources available to the specified project in a given region. | data_access | N | N |
| compute. | Deletes the specified UrlMap resource. | activity | N | N |
| compute. | Returns the specified UrlMap resource. | data_access | N | N |
| compute. | Creates a UrlMap resource in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of UrlMap resources available to the specified project in the specified region. | data_access | N | N |
| compute. | Patches the specified UrlMap resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Updates the specified UrlMap resource with the data included in the request. | activity | N | N |
| compute. | Runs static validation for the UrlMap. In particular, the tests of the provided UrlMap will be run. Calling this method does NOT create the UrlMap. | activity | N | N |
| compute. | Retrieves the list of Zone resources under the specific region available to the specified project. | data_access | N | N |
| compute. | Returns the specified Region resource. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request. This method fails if the quota information is unavailable for the region and if the organization policy constraint compute.requireBasicQuotaInResponse is enforced. This constraint, when enforced, disables the fail-open behaviour when quota information (the `items.quotas` field) is unavailable for the region. It is recommended to use the default setting for the constraint unless your application requires the fail-closed behaviour for this method. | data_access | N | N |
| compute. | Retrieves the list of region resources available to the specified project. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `items.quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request. This method fails if the quota information is unavailable for the region and if the organization policy constraint compute.requireBasicQuotaInResponse is enforced. This constraint, when enforced, disables the fail-open behaviour when quota information (the `items.quotas` field) is unavailable for the region. It is recommended to use the default setting for the constraint unless your application requires the fail-closed behaviour for this method. | data_access | Y | N |
| compute. | Retrieves information about the specified reservation block. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Retrieves a list of reservation blocks under a single reservation. | data_access | N | N |
| compute. | Allows customers to perform maintenance on a reservation block | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves information about the specified reservation slot. | data_access | N | N |
| compute. | Allows customers to get SBOM versions of a reservation slot. | data_access | N | N |
| compute. | Retrieves a list of reservation slots under a single reservation. | data_access | N | N |
| compute. | Update a reservation slot in the specified sub-block. | activity | N | N |
| compute. | Retrieves information about the specified reservation subBlock. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Allows customers to get SBOM versions of a reservation subBlock. | data_access | N | N |
| compute. | Retrieves a list of reservation subBlocks under a single reservation. | data_access | N | N |
| compute. | Allows customers to perform maintenance on a reservation subBlock | activity | N | N |
| compute. | Allows customers to report a faulty subBlock. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves an aggregated list of reservations. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified reservation. | activity | Y | N |
| compute. | Retrieves information about the specified reservation. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a new reservation. For more information, readReserving zonal resources. | activity | Y | N |
| compute. | A list of all the reservations that have been configured for the specified project in specified zone. | data_access | N | N |
| compute. | Perform maintenance on an extended reservation | activity | N | N |
| compute. | Resizes the reservation (applicable to standalone reservations only). For more information, readModifying reservations. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Update share settings of the reservation. | activity | N | N |
| compute. | Retrieves an aggregated list of resource policies. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified resource policy. | activity | Y | N |
| compute. | Retrieves all information of the specified resource policy. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a new resource policy. | activity | Y | N |
| compute. | A list all the resource policies that have been configured for the specified project in specified region. | data_access | Y | N |
| compute. | Modify the specified resource policy. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Deletes a RolloutPlan. | activity | N | N |
| compute. | Gets details of a single project-scoped RolloutPlan. | data_access | N | N |
| compute. | Creates a new RolloutPlan in a given project and location. | activity | N | N |
| compute. | Lists RolloutPlans in a given project and location. | data_access | N | N |
| compute. | Advances a Rollout to the next wave, or completes it if no waves remain. | activity | N | N |
| compute. | Cancels a Rollout. | activity | N | N |
| compute. | Deletes a Rollout. | activity | N | N |
| compute. | Gets details of a single project-scoped Rollout. | data_access | N | N |
| compute. | Lists Rollouts in a given project and location. | data_access | N | N |
| compute. | Pauses a Rollout. | activity | N | N |
| compute. | Resumes a Rollout. | activity | N | N |
| compute. | Retrieves an aggregated list of routers. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified Router resource. | activity | Y | N |
| compute. | Deletes Route Policy | activity | N | N |
| compute. | Returns the specified Router resource. | data_access | Y | N |
| compute. | Retrieves runtime NAT IP information. | data_access | N | N |
| compute. | Retrieves runtime Nat mapping information of VM endpoints. | data_access | N | N |
| compute. | Returns specified Route Policy | data_access | N | N |
| compute. | Retrieves runtime information of the specified router. | data_access | N | N |
| compute. | Creates a Router resource in the specified project and region using the data included in the request. | activity | Y | N |
| compute. | Retrieves a list of Router resources available to the specified project. | data_access | Y | N |
| compute. | Retrieves a list of router bgp routes available to the specified project. | data_access | N | N |
| compute. | Retrieves a list of router route policy subresources available to the specified project. | data_access | N | N |
| compute. | Patches the specified Router resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Patches Route Policy | activity | N | N |
| compute. | Preview fields auto-generated during router create andupdate operations. Calling this method does NOT create or update the router. | activity | N | N |
| compute. | Updates the specified Router resource with the data included in the request. This method conforms toPUT semantics, which requests that the state of the target resource be created or replaced with the state defined by the representation enclosed in the request message payload. | activity | N | N |
| compute. | Updates or creates new Route Policy | activity | N | N |
| compute. | Deletes the specified Route resource. | activity | Y | Y |
| compute. | Returns the specified Route resource. | data_access | Y | N |
| compute. | Creates a Route resource in the specified project using the data included in the request. | activity | Y | Y |
| compute. | Retrieves the list of Route resources available to the specified project. | data_access | Y | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Inserts a rule into a security policy. | activity | Y | N |
| compute. | Retrieves the list of all SecurityPolicy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified policy. | activity | N | N |
| compute. | List all of the ordered rules present in a single specified policy. | data_access | N | N |
| compute. | Gets a rule at the specified priority. | data_access | N | N |
| compute. | Creates a new policy in the specified project using the data included in the request. | activity | Y | N |
| compute. | List all the policies that have been configured for the specified project. | data_access | N | N |
| compute. | Gets the current list of preconfigured Web Application Firewall (WAF) expressions. | data_access | N | N |
| compute. | Patches the specified policy with the data included in the request. To clear fields in the policy, leave the fields empty and specify them in the updateMask. This cannot be used to be update the rules in the policy. Please use the per rule methods like addRule, patchRule, and removeRule instead. | activity | N | N |
| compute. | Patches a rule at the specified priority. To clear fields in the rule, leave the fields empty and specify them in the updateMask. | activity | N | N |
| compute. | Deletes a rule at the specified priority. | activity | N | N |
| compute. | Sets the labels on a security policy. To learn more about labels, read the Labeling Resources documentation. | activity | N | N |
| compute. | Retrieves the list of all ServiceAttachment resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified ServiceAttachment in the given scope | activity | N | N |
| compute. | Returns the specified ServiceAttachment resource in the given scope. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a ServiceAttachment in the specified project in the given scope using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the ServiceAttachments for a project in the given scope. | data_access | N | N |
| compute. | Patches the specified ServiceAttachment resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Get snapshot settings. | data_access | N | N |
| compute. | Patch snapshot settings. | activity | N | N |
| compute. | Deletes the specified Snapshot resource. Keep in mind that deleting a single snapshot might not necessarily delete all the data on that snapshot. If any data on the snapshot that is marked for deletion is needed for subsequent snapshots, the data will be moved to the next corresponding snapshot. For more information, seeDeleting snapshots. | activity | Y | Y |
| compute. | Returns the specified Snapshot resource. | data_access | Y | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | Y | N |
| compute. | Creates a snapshot in the specified project using the data included in the request. For regular snapshot creation, consider using this method instead of disks.createSnapshot, as this method supports more features, such as creating snapshots in a project different from the source disk project. | activity | Y | Y |
| compute. | Retrieves the list of Snapshot resources contained within the specified project. | data_access | Y | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | Y | Y |
| compute. | Sets the labels on a snapshot. To learn more about labels, read theLabeling Resources documentation. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Rotates the customer-managed encryption key to the latest version for the specified snapshot. | activity | N | N |
| compute. | Retrieves the list of all SslCertificate resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified SslCertificate resource. | activity | N | N |
| compute. | Returns the specified SslCertificate resource. | data_access | N | N |
| compute. | Creates a SslCertificate resource in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves the list of SslCertificate resources available to the specified project. | data_access | N | N |
| compute. | Retrieves the list of all SslPolicy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified SSL policy. The SSL policy resource can be deleted only if it is not in use by any TargetHttpsProxy or TargetSslProxy resources. | activity | Y | N |
| compute. | Lists all of the ordered rules present in a single specified policy. | data_access | N | N |
| compute. | Returns the specified SSL policy resource. | activity | Y | N |
| compute. | Lists all the SSL policies that have been configured for the specified project. | data_access | N | N |
| compute. | Lists all features that can be specified in the SSL policy when using custom profile. | data_access | N | N |
| compute. | Patches the specified SSL policy with the data included in the request. | activity | N | N |
| compute. | Retrieves an aggregated list of storage pool types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Returns the specified storage pool type. | data_access | N | N |
| compute. | Retrieves a list of storage pool types available to the specified project. | data_access | N | N |
| compute. | Retrieves an aggregated list of storage pools. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified storage pool. Deleting a storagePool removes its data permanently and is irreversible. However, deleting a storagePool does not delete any snapshots previously made from the storagePool. You must separately delete snapshots. | activity | N | N |
| compute. | Returns a specified storage pool. Gets a list of available storage pools by making a list() request. | data_access | N | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a storage pool in the specified project using the data in the request. | activity | N | N |
| compute. | Retrieves a list of storage pools contained within the specified zone. | data_access | N | N |
| compute. | Lists the disks in a specified storage pool. | data_access | N | N |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates the specified storagePool with the data included in the request. The update is performed only on selected fields included as part of update-mask. Only the following fields can be modified: pool_provisioned_capacity_gb, pool_provisioned_iops and pool_provisioned_throughput. | activity | N | N |
| compute. | Retrieves an aggregated list of subnetworks. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified subnetwork. | activity | Y | N |
| compute. | Expands the IP CIDR range of the subnetwork to a specified value. | activity | Y | N |
| compute. | Returns the specified subnetwork. | data_access | Y | N |
| compute. | Gets the access control policy for a resource. May be empty if no such policy or resource exists. | data_access | N | N |
| compute. | Creates a subnetwork in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves a list of subnetworks available to the specified project. | data_access | N | N |
| compute. | Retrieves an aggregated list of all usable subnetworks in the project. | data_access | N | N |
| compute. | Patches the specified subnetwork with the data included in the request. Only certain fields can be updated with a patch request as indicated in the field descriptions. You must specify the current fingerprint of the subnetwork resource being patched. | activity | Y | Y |
| compute. | Sets the access control policy on the specified resource. Replaces any existing policy. | activity | Y | N |
| compute. | Set whether VMs in this subnet can access Google services without assigning external IP addresses through Private Google Access. | activity | Y | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Deletes the specified TargetGrpcProxy in the given scope | activity | N | N |
| compute. | Returns the specified TargetGrpcProxy resource in the given scope. | data_access | N | N |
| compute. | Creates a TargetGrpcProxy in the specified project in the given scope using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the TargetGrpcProxies for a project in the given scope. | data_access | N | N |
| compute. | Patches the specified TargetGrpcProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Retrieves the list of all TargetHttpProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified TargetHttpProxy resource. | activity | N | N |
| compute. | Returns the specified TargetHttpProxy resource. | data_access | N | N |
| compute. | Creates a TargetHttpProxy resource in the specified project using the data included in the request. | activity | Y | N |
| compute. | Retrieves the list of TargetHttpProxy resources available to the specified project. | data_access | N | N |
| compute. | Patches the specified TargetHttpProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Changes the URL map for TargetHttpProxy. | activity | N | N |
| compute. | Retrieves the list of all TargetHttpsProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified TargetHttpsProxy resource. | activity | N | N |
| compute. | Returns the specified TargetHttpsProxy resource. | data_access | N | N |
| compute. | Creates a TargetHttpsProxy resource in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of TargetHttpsProxy resources available to the specified project. | data_access | N | N |
| compute. | Patches the specified TargetHttpsProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Changes the Certificate Map for TargetHttpsProxy. | activity | N | N |
| compute. | Sets the QUIC override policy for TargetHttpsProxy. | activity | N | N |
| compute. | Replaces SslCertificates for TargetHttpsProxy. | activity | N | N |
| compute. | Sets the SSL policy for TargetHttpsProxy. The SSL policy specifies the server-side support for SSL features. This affects connections between clients and the HTTPS proxy load balancer. They do not affect the connection between the load balancer and the backends. | activity | N | N |
| compute. | Changes the URL map for TargetHttpsProxy. | activity | N | N |
| compute. | Retrieves an aggregated list of target instances. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified TargetInstance resource. | activity | N | N |
| compute. | Returns the specified TargetInstance resource. | data_access | N | N |
| compute. | Creates a TargetInstance resource in the specified project and zone using the data included in the request. | activity | N | N |
| compute. | Retrieves a list of TargetInstance resources available to the specified project and zone. | data_access | N | N |
| compute. | Sets the Google Cloud Armor security policy for the specified target instance. For more information, seeGoogle Cloud Armor Overview | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Adds health check URLs to a target pool. | activity | N | N |
| compute. | Adds an instance to a target pool. | activity | N | N |
| compute. | Retrieves an aggregated list of target pools. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified target pool. | activity | N | N |
| compute. | Returns the specified target pool. | data_access | N | N |
| compute. | Gets the most recent health check results for each IP for the instance that is referenced by the given target pool. | data_access | N | N |
| compute. | Creates a target pool in the specified project and region using the data included in the request. | activity | Y | N |
| compute. | Retrieves a list of target pools available to the specified project and region. | data_access | N | N |
| compute. | Removes health check URL from a target pool. | activity | N | N |
| compute. | Removes instance URL from a target pool. | activity | N | N |
| compute. | Changes a backup target pool's configurations. | activity | N | N |
| compute. | Sets the Google Cloud Armor security policy for the specified target pool. For more information, seeGoogle Cloud Armor Overview | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Deletes the specified TargetSslProxy resource. | activity | N | N |
| compute. | Returns the specified TargetSslProxy resource. | data_access | N | N |
| compute. | Creates a TargetSslProxy resource in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of TargetSslProxy resources available to the specified project. | data_access | N | N |
| compute. | Changes the BackendService for TargetSslProxy. | activity | N | N |
| compute. | Changes the Certificate Map for TargetSslProxy. | activity | N | N |
| compute. | Changes the ProxyHeaderType for TargetSslProxy. | activity | N | N |
| compute. | Changes SslCertificates for TargetSslProxy. | activity | N | N |
| compute. | Sets the SSL policy for TargetSslProxy. The SSL policy specifies the server-side support for SSL features. This affects connections between clients and the load balancer. They do not affect the connection between the load balancer and the backends. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves the list of all TargetTcpProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified TargetTcpProxy resource. | activity | N | N |
| compute. | Returns the specified TargetTcpProxy resource. | data_access | N | N |
| compute. | Creates a TargetTcpProxy resource in the specified project using the data included in the request. | activity | N | N |
| compute. | Retrieves the list of TargetTcpProxy resources available to the specified project. | data_access | N | N |
| compute. | Changes the BackendService for TargetTcpProxy. | activity | N | N |
| compute. | Changes the ProxyHeaderType for TargetTcpProxy. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves an aggregated list of target VPN gateways. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified target VPN gateway. | activity | Y | N |
| compute. | Returns the specified target VPN gateway. | data_access | Y | N |
| compute. | Creates a target VPN gateway in the specified project and region using the data included in the request. | activity | Y | N |
| compute. | Retrieves a list of target VPN gateways available to the specified project and region. | data_access | N | N |
| compute. | Sets the labels on a TargetVpnGateway. To learn more about labels, read theLabeling Resources documentation. | activity | N | N |
| compute. | Retrieves the list of all UrlMap resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified UrlMap resource. | activity | N | N |
| compute. | Returns the specified UrlMap resource. | data_access | N | N |
| compute. | Creates a UrlMap resource in the specified project using the data included in the request. | activity | Y | N |
| compute. | Initiates a cache invalidation operation, invalidating the specified path, scoped to the specified UrlMap. For more information, see Invalidating cached content. | activity | N | N |
| compute. | Retrieves the list of UrlMap resources available to the specified project. | data_access | N | N |
| compute. | Patches the specified UrlMap resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Updates the specified UrlMap resource with the data included in the request. | activity | N | N |
| compute. | Runs static validation for the UrlMap. In particular, the tests of the provided UrlMap will be run. Calling this method does NOT create the UrlMap. | activity | N | N |
| compute. | Retrieves an aggregated list of VPN gateways. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | N | N |
| compute. | Deletes the specified VPN gateway. | activity | Y | N |
| compute. | Returns the specified VPN gateway. | data_access | Y | N |
| compute. | Returns the status for the specified VPN gateway. | data_access | N | N |
| compute. | Creates a VPN gateway in the specified project and region using the data included in the request. | activity | Y | N |
| compute. | Retrieves a list of VPN gateways available to the specified project and region. | data_access | N | N |
| compute. | Sets the labels on a VpnGateway. To learn more about labels, read theLabeling Resources documentation. | activity | N | N |
| compute. | Returns permissions that a caller has on the specified resource. | data_access | N | N |
| compute. | Retrieves an aggregated list of VPN tunnels. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`. | data_access | Y | N |
| compute. | Deletes the specified VPN Tunnel resource. | activity | Y | Y |
| compute. | Returns the specified VpnTunnel resource. | data_access | Y | N |
| compute. | Creates a VpnTunnel resource in the specified project and region using the data included in the request. | activity | Y | Y |
| compute. | Retrieves a list of VpnTunnel resources contained in the specified project and region. | data_access | N | N |
| compute. | Sets the labels on a VpnTunnel. To learn more about labels, read theLabeling Resources documentation. | activity | N | N |
| compute. | Deletes the specified wire group in the given scope. | activity | N | N |
| compute. | Gets the specified wire group resource in the given scope. | data_access | N | N |
| compute. | Creates a wire group in the specified project in the given scope using the parameters that are included in the request. | activity | N | N |
| compute. | Lists the wire groups for a project in the given scope. | data_access | N | N |
| compute. | Updates the specified wire group resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules. | activity | N | N |
| compute. | Deletes the specified zone-specific Operations resource. | activity | N | N |
| compute. | Retrieves the specified zone-specific Operations resource. | data_access | Y | N |
| compute. | Retrieves a list of Operation resources contained within the specified zone. | data_access | N | N |
| compute. | Waits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method waits for no more than the 2 minutes and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`. | data_access | Y | N |
| compute. | Deletes a specified zone VM extension policy within a project. | activity | N | N |
| compute. | Retrieves details of a specific zone VM extension policy within a project. | data_access | N | N |
| compute. | Creates a new zone-level VM extension policy within a project. | activity | N | N |
| compute. | Lists all VM extension policies within a specific zone for a project. | data_access | N | N |
| compute. | Modifies an existing zone VM extension policy within a project. | activity | N | N |
| compute. | Returns the specified Zone resource. | data_access | N | N |
| compute. | Retrieves the list of Zone resources available to the specified project. | data_access | Y | N |
| compute. | List the reservations a project is allowed to consume. | data_access | Y | N |
any: compute.googleapis.com (any method)
#Description
Catch-all entry for compute.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
GCPUserIp (kusto rule field) | is_not_null | | 2 rules | kusto |
GCPUserIp (kusto rule field) | ne | private | 2 rules | kusto |
VMOperation (kusto rule field) | eq | insert | 2 rules | kusto |
Severity (kusto rule field) | eq | NOTICE | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1133, T1562, T1562.001, T1562.004T1059, T1069, T1078, T1547, T1548, T1552T1078, T1106, T1526
compute.acceleratorTypes.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of accelerator types. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-qkprxdd337q",
"labels": {
"compute.googleapis.com/root_trigger_id": "f98043f4-0f0c-49a8-87cf-5a6a1aa7a659"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.acceleratorTypes.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.acceleratorTypes.aggregatedList",
"numResponseItems": "174",
"request": {
"@type": "type.googleapis.com/compute.acceleratorTypes.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.accelerator-types.list invocation-id/098c934ed73d416883a95875b984939f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:40.300776Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/acceleratorTypes",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:40.781499677Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.acceleratorTypes.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:40.113008Z"
}
compute.acceleratorTypes.get: get
#Description
Returns the specified accelerator type.
Data Access audit logs are disabled by default.
compute.acceleratorTypes.list: list
#Description
Retrieves a list of accelerator types that are available to the specified project.
Data Access audit logs are disabled by default.
compute.addresses.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of addresses. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-gx57kae1rw0u",
"labels": {
"compute.googleapis.com/root_trigger_id": "d76a696e-2d16-431e-8e4a-a62c9c340b35"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.addresses.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.addresses.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.addresses.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.list invocation-id/ea7aaee947ee44a1bfd3e44433c20c8e environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:26.755047Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/addresses",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:27.768107147Z",
"resource": {
"labels": {
"location": "global",
"project_id": "example-project-id",
"reserved_address_id": ""
},
"type": "gce_reserved_address"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:26.671109Z"
}
compute.addresses.delete: delete
#Description
Deletes the specified address resource.
Example Audit Log Entry #
{
"insertId": "-qluhtce1xekj",
"labels": {
"compute.googleapis.com/root_trigger_id": "b67cbd07-0aa5-47f0-822f-d6928729fa68"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782744130263-65565769c1864-a09711bf-0fb552de",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.addresses.deleteInternal",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"service": "compute",
"type": "compute.addresses"
}
}
],
"methodName": "v1.compute.addresses.delete",
"request": {
"@type": "type.googleapis.com/compute.addresses.delete"
},
"requestMetadata": {
"callerIp": "private",
"callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:42:11.047799Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"response": {
"@type": "type.googleapis.com/operation",
"id": "6341651908594186925",
"insertTime": "2026-06-29T07:42:10.989-07:00",
"name": "operation-1782744130263-65565769c1864-a09711bf-0fb552de",
"operationType": "delete",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782744130263-65565769c1864-a09711bf-0fb552de",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/6341651908594186925",
"startTime": "2026-06-29T07:42:11.007-07:00",
"status": "RUNNING",
"targetId": "4742281296736108351",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:42:12.036038037Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"reserved_address_id": "4742281296736108351"
},
"type": "gce_reserved_address"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:42:10.316308Z"
}
compute.addresses.get: get
#Description
Returns the specified address resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-o4q3zee3dbzy",
"labels": {
"compute.googleapis.com/root_trigger_id": "b2207c35-1025-445b-a670-e95687dfe9e5"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.addresses.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
"service": "compute",
"type": "compute.addresses"
}
}
],
"methodName": "v1.compute.addresses.get",
"request": {
"@type": "type.googleapis.com/compute.addresses.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.create invocation-id/b5afe11eca0c4cb4976cb7d45d6e5fa9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:20:57.161127Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:20:57.695646512Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"reserved_address_id": "8707194920272646109"
},
"type": "gce_reserved_address"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:20:57.079378Z"
}
compute.addresses.insert: insert
#Description
Creates an address resource in the specified project by using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-81m2fde2asfa",
"labels": {
"compute.googleapis.com/root_trigger_id": "9a227fdf-d92c-4cd1-8411-c58cdea6129e"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782739249968-6556453b8b4f2-65eb49e3-95a2a27f",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.addresses.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
"service": "compute",
"type": "compute.addresses"
}
}
],
"methodName": "v1.compute.addresses.insert",
"request": {
"@type": "type.googleapis.com/compute.addresses.insert",
"name": "dwgen-dw739065"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.create invocation-id/b5afe11eca0c4cb4976cb7d45d6e5fa9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:20:50.293376Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
"response": {
"@type": "type.googleapis.com/operation",
"id": "798636759271329757",
"insertTime": "2026-06-29T06:20:50.260-07:00",
"name": "operation-1782739249968-6556453b8b4f2-65eb49e3-95a2a27f",
"operationType": "insert",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782739249968-6556453b8b4f2-65eb49e3-95a2a27f",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/798636759271329757",
"startTime": "2026-06-29T06:20:50.265-07:00",
"status": "RUNNING",
"targetId": "8707194920272646109",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/addresses/dwgen-dw739065",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:20:50.643550018Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"reserved_address_id": "8707194920272646109"
},
"type": "gce_reserved_address"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T13:20:50.033933Z"
}
compute.addresses.list: list
#Description
Retrieves a list of addresses contained within the specified region.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-3a8dv5e7qzco",
"labels": {
"compute.googleapis.com/root_trigger_id": "ccbfbaf6-f02f-44ac-aa03-3c47241a9054"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.addresses.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.addresses.list",
"request": {
"@type": "type.googleapis.com/compute.addresses.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.list invocation-id/345a3836fc8542ae86e7e13d2e9ccb07 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:37:31.630682Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/addresses",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:37:32.610254515Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"reserved_address_id": ""
},
"type": "gce_reserved_address"
},
"severity": "INFO",
"timestamp": "2026-06-29T15:37:31.593989Z"
}
compute.addresses.move: move
#Description
Moves the specified address resource.
compute.addresses.setLabels: setLabels
#Description
Sets the labels on an Address. To learn more about labels, read theLabeling Resources documentation.
compute.addresses.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.advice.calendarMode: calendarMode
#Description
Advise how, where and when to create the requested amount of instances with specified accelerators, within the specified time and location limits. The method recommends creating future reservations for the requested resources.
compute.autoscalers.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of autoscalers. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.autoscalers.delete: delete
#Description
Deletes the specified autoscaler.
compute.autoscalers.get: get
#Description
Returns the specified autoscaler resource.
Data Access audit logs are disabled by default.
compute.autoscalers.insert: insert
#Description
Creates an autoscaler in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-j3w3ibe5nm1k",
"labels": {
"compute.googleapis.com/root_trigger_id": "a0fa2f1f-f310-4146-b966-8491ea0296bd"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745502771-65565c86ae940-e0b83d49-c6e19dc5",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.autoscalers.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/autoscalers/dwn3-dw745304-0hxp",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/autoscalers/dwn3-dw745304-0hxp",
"service": "compute",
"type": "compute.autoscalers"
}
},
{
"granted": true,
"permission": "compute.instanceGroupManagers.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
"service": "compute",
"type": "compute.instanceGroupManagers"
}
}
],
"methodName": "v1.compute.autoscalers.insert",
"request": {
"@type": "type.googleapis.com/compute.autoscalers.insert",
"autoscalingPolicy": {
"maxNumReplicas": "2",
"minNumReplicas": "0"
},
"name": "dwn3-dw745304-0hxp",
"target": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-groups.managed.set-autoscaling invocation-id/a542d70e2ac54b66a331659b7052ec43 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:05:03.018735Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/autoscalers/dwn3-dw745304-0hxp",
"response": {
"@type": "type.googleapis.com/operation",
"id": "3498777969783945073",
"insertTime": "2026-06-29T08:05:02.938-07:00",
"name": "operation-1782745502771-65565c86ae940-e0b83d49-c6e19dc5",
"operationType": "compute.autoscalers.insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782745502771-65565c86ae940-e0b83d49-c6e19dc5",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/3498777969783945073",
"startTime": "2026-06-29T08:05:02.943-07:00",
"status": "RUNNING",
"targetId": "8603239420171073393",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/autoscalers/dwn3-dw745304-0hxp",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:05:03.557547786Z",
"resource": {
"labels": {
"autoscaler_id": "8603239420171073393",
"location": "us-central1-a",
"project_id": "example-project-id"
},
"type": "gce_autoscaler"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:05:02.736149Z"
}
compute.autoscalers.list: list
#Description
Retrieves a list of autoscalers contained within the specified zone.
Data Access audit logs are disabled by default.
compute.autoscalers.patch: patch
#Description
Updates an autoscaler in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.autoscalers.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.autoscalers.update: update
#Description
Updates an autoscaler in the specified project using the data included in the request.
compute.backendBuckets.addSignedUrlKey: addSignedUrlKey
#Description
Adds a key for validating requests with signed URLs for this backend bucket.
compute.backendBuckets.aggregatedList: aggregatedList
#Description
Retrieves the list of all BackendBucket resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.backendBuckets.delete: delete
#Description
Deletes the specified BackendBucket resource.
Example Audit Log Entry #
{
"insertId": "w7o09aeg8ale",
"labels": {
"compute.googleapis.com/root_trigger_id": "f8127176-af54-448b-bafe-6edcfe5f9034"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782747082755-6556626978d23-9d277378-cc903e66",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.backendBuckets.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
"resourceAttributes": {
"name": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
"service": "compute",
"type": "compute.backendBuckets"
}
}
],
"methodName": "v1.compute.backendBuckets.delete",
"request": {
"@type": "type.googleapis.com/compute.backendBuckets.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-buckets.delete invocation-id/8b838c546bff4d7bb535c021ca3844dc environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:31:22.970845Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
"response": {
"@type": "type.googleapis.com/operation",
"id": "8247178286211215653",
"insertTime": "2026-06-29T08:31:22.852-07:00",
"name": "operation-1782747082755-6556626978d23-9d277378-cc903e66",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782747082755-6556626978d23-9d277378-cc903e66",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/8247178286211215653",
"startTime": "2026-06-29T08:31:22.857-07:00",
"status": "RUNNING",
"targetId": "9153106374927790504",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/backendBuckets/dwbb-dw746783",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:31:23.283965096Z",
"resource": {
"labels": {
"backend_bucket_id": "9153106374927790504",
"project_id": "example-project-id"
},
"type": "gce_backend_bucket"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:31:22.717372Z"
}
compute.backendBuckets.deleteSignedUrlKey: deleteSignedUrlKey
#Description
Deletes a key for validating requests with signed URLs for this backend bucket.
compute.backendBuckets.get: get
#Description
Returns the specified BackendBucket resource.
Data Access audit logs are disabled by default.
compute.backendBuckets.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.backendBuckets.insert: insert
#Description
Creates a BackendBucket resource in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "y4u4tbe7siby",
"labels": {
"compute.googleapis.com/root_trigger_id": "d4b5a414-df18-4fdc-af0d-0c1093d95e1a"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746951729-655661ec84229-b362823f-f7845f94",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.backendBuckets.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
"resourceAttributes": {
"name": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
"service": "compute",
"type": "compute.backendBuckets"
}
}
],
"methodName": "v1.compute.backendBuckets.insert",
"request": {
"@type": "type.googleapis.com/compute.backendBuckets.insert",
"bucketName": "dwbb-dw746783",
"enableCdn": false,
"name": "dwbb-dw746783"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-buckets.create invocation-id/74f8289ff9954fd3afc1ac3ea0ad9532 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:29:12.244413Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/backendBuckets/dwbb-dw746783",
"response": {
"@type": "type.googleapis.com/operation",
"id": "39143132380475816",
"insertTime": "2026-06-29T08:29:11.885-07:00",
"name": "operation-1782746951729-655661ec84229-b362823f-f7845f94",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782746951729-655661ec84229-b362823f-f7845f94",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/39143132380475816",
"startTime": "2026-06-29T08:29:11.888-07:00",
"status": "RUNNING",
"targetId": "9153106374927790504",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/backendBuckets/dwbb-dw746783",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:29:12.527683763Z",
"resource": {
"labels": {
"backend_bucket_id": "9153106374927790504",
"project_id": "example-project-id"
},
"type": "gce_backend_bucket"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:29:11.704555Z"
}
compute.backendBuckets.list: list
#Description
Retrieves the list of BackendBucket resources available to the specified project.
Data Access audit logs are disabled by default.
compute.backendBuckets.listUsable: listUsable
#Description
Retrieves a list of all usable backend buckets in the specified project.
Data Access audit logs are disabled by default.
compute.backendBuckets.patch: patch
#Description
Updates the specified BackendBucket resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.backendBuckets.setEdgeSecurityPolicy: setEdgeSecurityPolicy
#Description
Sets the edge security policy for the specified backend bucket.
compute.backendBuckets.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.backendBuckets.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.backendBuckets.update: update
#Description
Updates the specified BackendBucket resource with the data included in the request.
compute.backendServices.addSignedUrlKey: addSignedUrlKey
#Description
Adds a key for validating requests with signed URLs for this backend service.
compute.backendServices.aggregatedList: aggregatedList
#Description
Retrieves the list of all BackendService resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "vxhk4mdlumk",
"labels": {
"compute.googleapis.com/root_trigger_id": "64d85f3c-aeb6-4d59-b00d-554a789a3882"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.backendServices.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.backendServices.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.backendServices.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-services.list invocation-id/b37e14813184495399c8084e3384921a environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:29.448224Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/backendServices",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:29.752707604Z",
"resource": {
"labels": {
"backend_service_id": "",
"location": "global",
"project_id": "example-project-id"
},
"type": "gce_backend_service"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:29.335272Z"
}
compute.backendServices.delete: delete
#Description
Deletes the specified BackendService resource.
compute.backendServices.deleteSignedUrlKey: deleteSignedUrlKey
#Description
Deletes a key for validating requests with signed URLs for this backend service.
compute.backendServices.get: get
#Description
Returns the specified BackendService resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-4fkxnae12mgg",
"labels": {
"compute.googleapis.com/root_trigger_id": "e76b29b0-f855-4105-b0ab-bc93b6d4b713"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "110162197178770594910"
},
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
"principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.backendServices.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/backendServices/k8s-ingress-svc-acct-permission-check-probe",
"resourceAttributes": {
"name": "projects/example-project-id/global/backendServices/k8s-ingress-svc-acct-permission-check-probe",
"service": "compute",
"type": "compute.backendServices"
}
}
],
"methodName": "v1.compute.backendServices.get",
"request": {
"@type": "type.googleapis.com/compute.backendServices.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-api-go-client/0.5 Kubernetes/0.0.0 (linux amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:39:47.532900Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/backendServices/k8s-ingress-svc-acct-permission-check-probe",
"serviceName": "compute.googleapis.com",
"status": {
"code": 5,
"message": "The resource 'projects/example-project-id/global/backendServices/k8s-ingress-svc-acct-permission-check-probe' was not found"
}
},
"receiveTimestamp": "2026-06-29T14:39:48.378923912Z",
"resource": {
"labels": {
"backend_service_id": "0",
"location": "global",
"project_id": "example-project-id"
},
"type": "gce_backend_service"
},
"severity": "ERROR",
"timestamp": "2026-06-29T14:39:47.467641Z"
}
compute.backendServices.getEffectiveSecurityPolicies: getEffectiveSecurityPolicies
#Description
Returns effective security policies applied to this backend service.
Data Access audit logs are disabled by default.
compute.backendServices.getHealth: getHealth
#Description
Gets the most recent health check results for this BackendService. Example request body: { "group": "/zones/us-east1-b/instanceGroups/lb-backend-example" }
Data Access audit logs are disabled by default.
compute.backendServices.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.backendServices.insert: insert
#Description
Creates a BackendService resource in the specified project using the data included in the request. For more information, see Backend services overview.
Example Audit Log Entry #
{
"insertId": "kjqm4ld68m2",
"labels": {
"compute.googleapis.com/root_trigger_id": "fabab22c-7e17-4fa7-a694-78f16840dc24"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745406113-65565c2a80653-8b3a4929-a02bbfc1",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.backendServices.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/backendServices/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/backendServices/dwn3-dw745304",
"service": "compute",
"type": "compute.backendServices"
}
}
],
"methodName": "v1.compute.backendServices.insert",
"request": {
"@type": "type.googleapis.com/compute.backendServices.insert",
"healthChecks": [
"https://compute.googleapis.com/compute/v1/projects/example-project-id/global/healthChecks/dwn3-dw745304"
],
"name": "dwn3-dw745304",
"portName": "http",
"protocol": "HTTP",
"timeoutSec": "30"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-services.create invocation-id/9ee923ad72444eadb52cde40c047aeb2 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:03:26.726188Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/backendServices/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "2034658459352250321",
"insertTime": "2026-06-29T08:03:26.531-07:00",
"name": "operation-1782745406113-65565c2a80653-8b3a4929-a02bbfc1",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745406113-65565c2a80653-8b3a4929-a02bbfc1",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2034658459352250321",
"startTime": "2026-06-29T08:03:26.534-07:00",
"status": "RUNNING",
"targetId": "8155814126983002065",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/backendServices/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:03:27.644584217Z",
"resource": {
"labels": {
"backend_service_id": "8155814126983002065",
"location": "global",
"project_id": "example-project-id"
},
"type": "gce_backend_service"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:03:26.196728Z"
}
compute.backendServices.list: list
#Description
Retrieves the list of BackendService resources available to the specified project.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-q1ju39ehikl0",
"labels": {
"compute.googleapis.com/root_trigger_id": "8c13bf3d-a7b9-4b68-8a7b-8b62bb560164"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.backendServices.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.backendServices.list",
"request": {
"@type": "type.googleapis.com/compute.backendServices.list"
},
"requestMetadata": {
"callerIp": "private",
"callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:40:10.210535Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/backendServices",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:40:10.244320418Z",
"resource": {
"labels": {
"backend_service_id": "",
"location": "global",
"project_id": "example-project-id"
},
"type": "gce_backend_service"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:40:10.163141Z"
}
compute.backendServices.listUsable: listUsable
#Description
Retrieves a list of all usable backend services in the specified project.
Data Access audit logs are disabled by default.
compute.backendServices.patch: patch
#Description
Patches the specified BackendService resource with the data included in the request. For more information, see Backend services overview. This method supports PATCH semantics and uses the JSON merge patch format and processing rules.
compute.backendServices.setEdgeSecurityPolicy: setEdgeSecurityPolicy
#Description
Sets the edge security policy for the specified backend service.
compute.backendServices.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.backendServices.setSecurityPolicy: setSecurityPolicy
#Description
Sets the Google Cloud Armor security policy for the specified backend service. For more information, seeGoogle Cloud Armor Overview
compute.backendServices.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.backendServices.update: update
#Description
Updates the specified BackendService resource with the data included in the request. For more information, seeBackend services overview.
compute.crossSiteNetworks.delete: delete
#Description
Deletes the specified cross-site network in the given scope.
compute.crossSiteNetworks.get: get
#Description
Returns the specified cross-site network in the given scope.
Data Access audit logs are disabled by default.
compute.crossSiteNetworks.insert: insert
#Description
Creates a cross-site network in the specified project in the given scope using the parameters that are included in the request.
compute.crossSiteNetworks.list: list
#Description
Lists the cross-site networks for a project in the given scope.
Data Access audit logs are disabled by default.
compute.crossSiteNetworks.patch: patch
#Description
Updates the specified cross-site network with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.diskTypes.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of disk types. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-da0gcfe5lmkg",
"labels": {
"compute.googleapis.com/root_trigger_id": "157ddb05-f185-443a-a509-19332543bf9a"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.diskTypes.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.diskTypes.aggregatedList",
"numResponseItems": "174",
"request": {
"@type": "type.googleapis.com/compute.diskTypes.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disk-types.list invocation-id/e42e5d7a7bdb46fca5a7e0a737f7d0f8 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:42.066364Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/diskTypes",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:42.165744875Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.diskTypes.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:41.940959Z"
}
compute.diskTypes.get: get
#Description
Returns the specified disk type.
Data Access audit logs are disabled by default.
compute.diskTypes.list: list
#Description
Retrieves a list of disk types available to the specified project.
Data Access audit logs are disabled by default.
compute.disks.addResourcePolicies: addResourcePolicies
#Description
Adds existing resource policies to a disk. You can only add one policy which will be applied to this disk for scheduling snapshot creation.
compute.disks.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of persistent disks. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "o52fdzd3in6",
"labels": {
"compute.googleapis.com/root_trigger_id": "f70b750d-2e14-48aa-a20e-517e1cf030fc"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.disks.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.disks.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.disks.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.list invocation-id/33943f07842c4255a3521c9168fd6c6d environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:16.989490Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/disks",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:17.521503370Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.disks.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:16.918158Z"
}
compute.disks.bulkInsert: bulkInsert
#Description
Bulk create a set of disks.
compute.disks.bulkSetLabels: bulkSetLabels
#Description
Sets the labels on many disks at once. To learn more about labels, read theLabeling Resources documentation.
compute.disks.createSnapshot: createSnapshot
#Description
Creates a snapshot of a specified persistent disk. For regular snapshot creation, consider using snapshots.insert instead, as that method supports more features, such as creating snapshots in a project different from the source disk project.
Example Audit Log Entry #
{
"insertId": "-o4qyyve3d0mq",
"labels": {
"compute.googleapis.com/root_trigger_id": "6cfcd3a7-76c2-46dd-88d4-f16d893ab4d4"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782743858003-655656661c00b-5043920b-eb14d557",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.disks.createSnapshot",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"service": "compute",
"type": "compute.disks"
}
},
{
"granted": true,
"permission": "compute.snapshots.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/snapshots/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/global/snapshots/dwg2-dw743447",
"service": "compute",
"type": "compute.snapshots"
}
},
{
"granted": true,
"permission": "compute.snapshots.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/snapshots/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/global/snapshots/dwg2-dw743447",
"service": "compute",
"type": "compute.snapshots"
}
}
],
"methodName": "v1.compute.disks.createSnapshot",
"request": {
"@type": "type.googleapis.com/compute.disks.createSnapshot",
"guestFlush": false,
"name": "dwg2-dw743447"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.snapshot invocation-id/b2c31cc6aed14ec89b974a9093f05120 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:37:38.900130Z"
}
},
"resourceLocation": {
"currentLocations": [
"US"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"response": {
"@type": "type.googleapis.com/operation",
"id": "1097498485150662109",
"insertTime": "2026-06-29T07:37:38.157-07:00",
"name": "operation-1782743858003-655656661c00b-5043920b-eb14d557",
"operationType": "createSnapshot",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743858003-655656661c00b-5043920b-eb14d557",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/1097498485150662109",
"startTime": "2026-06-29T07:37:38.162-07:00",
"status": "RUNNING",
"targetId": "5595570648524995674",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:37:38.921205567Z",
"resource": {
"labels": {
"disk_id": "5595570648524995674",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_disk"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:37:37.967443Z"
}
compute.disks.delete: delete
#Description
Deletes the specified persistent disk. Deleting a disk removes its data permanently and is irreversible. However, deleting a disk does not delete any snapshots previously made from the disk. You must separatelydelete snapshots.
Example Audit Log Entry #
{
"insertId": "978wxae79vfe",
"labels": {
"compute.googleapis.com/root_trigger_id": "430978a5-67eb-437b-85b3-3d27ad63639b"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782747023637-6556623117cba-97d75530-49db3aaa",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.disks.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"service": "compute",
"type": "compute.disks"
}
}
],
"methodName": "v1.compute.disks.delete",
"request": {
"@type": "type.googleapis.com/compute.disks.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.delete invocation-id/65a8b593091342178330684dfc110ef6 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:30:23.778475Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"id": "4425269679013966176",
"insertTime": "2026-06-29T08:30:23.739-07:00",
"name": "operation-1782747023637-6556623117cba-97d75530-49db3aaa",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782747023637-6556623117cba-97d75530-49db3aaa",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/4425269679013966176",
"startTime": "2026-06-29T08:30:23.748-07:00",
"status": "RUNNING",
"targetId": "6960107639937118366",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:30:24.082630172Z",
"resource": {
"labels": {
"disk_id": "6960107639937118366",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_disk"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:30:23.609716Z"
}
compute.disks.get: get
#Description
Returns the specified persistent disk.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-315klte57gx2",
"labels": {
"compute.googleapis.com/root_trigger_id": "4e7f0b77-1b17-4f9b-9c60-3ff56f1b8617"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.disks.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwd7201353",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwd7201353",
"service": "compute",
"type": "compute.disks"
}
}
],
"methodName": "v1.compute.disks.get",
"request": {
"@type": "type.googleapis.com/compute.disks.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.create invocation-id/5814964eb3484ae9ba022179278c2614 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:21:49.889553Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwd7201353",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:21:50.155057500Z",
"resource": {
"labels": {
"disk_id": "553183922380285299",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_disk"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:21:49.823606Z"
}
compute.disks.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.disks.insert: insert
#Description
Creates a persistent disk in the specified project using the data in the request. You can create a disk from a source (sourceImage, sourceSnapshot, orsourceDisk) or create an empty 500 GB data disk by omitting all properties. You can also create a disk that is larger than the default size by specifying the sizeGb property.
Example Audit Log Entry #
{
"insertId": "3dldice3zank",
"labels": {
"compute.googleapis.com/root_trigger_id": "7a2e56b3-72e9-42e3-9b23-f0234bfcb42a"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.disks.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"service": "compute",
"type": "compute.disks"
}
}
],
"methodName": "v1.compute.disks.insert",
"request": {
"@type": "type.googleapis.com/compute.disks.insert",
"name": "dwg2-dw743447",
"sizeGb": "10"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.create invocation-id/afc1ad74d6584e5584d7b097afe66852 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:37:30.919808Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"serviceName": "compute.googleapis.com",
"status": {
"code": 6,
"message": "The resource 'projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447' already exists"
}
},
"receiveTimestamp": "2026-06-29T14:37:31.929624377Z",
"resource": {
"labels": {
"disk_id": "5595570648524995674",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_disk"
},
"severity": "ERROR",
"timestamp": "2026-06-29T14:37:30.844659Z"
}
compute.disks.list: list
#Description
Retrieves a list of persistent disks contained within the specified zone.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-bngn6reb409g",
"labels": {
"compute.googleapis.com/root_trigger_id": "1442007e-4bc9-4013-b6af-6a330ea54358"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "110162197178770594910"
},
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
"principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.disks.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.disks.list",
"request": {
"@type": "type.googleapis.com/compute.disks.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-api-go-client/0.5 GCE CSI Driver/v1.23.1-gke.14 (linux amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:39:36.147419Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-b"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-b/disks",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:39:36.364360921Z",
"resource": {
"labels": {
"disk_id": "",
"project_id": "example-project-id",
"zone": "us-central1-b"
},
"type": "gce_disk"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:39:36.087532Z"
}
compute.disks.removeResourcePolicies: removeResourcePolicies
#Description
Removes resource policies from a disk.
compute.disks.resize: resize
#Description
Resizes the specified persistent disk. You can only increase the size of the disk.
Example Audit Log Entry #
{
"insertId": "aacx1ie1oz5u",
"labels": {
"compute.googleapis.com/root_trigger_id": "64ff41fe-4667-4b4a-a757-c57bf1674388"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746739546-655661222991d-114b4c2d-1988f1ac",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.disks.resize",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"service": "compute",
"type": "compute.disks"
}
}
],
"methodName": "v1.compute.disks.resize",
"request": {
"@type": "type.googleapis.com/compute.disks.resize",
"sizeGb": "20"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.resize invocation-id/9d7667bf067649d7a7f918b834daf1ad environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:25:39.707759Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"id": "8752018324255092892",
"insertTime": "2026-06-29T08:25:39.655-07:00",
"name": "operation-1782746739546-655661222991d-114b4c2d-1988f1ac",
"operationType": "resize",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746739546-655661222991d-114b4c2d-1988f1ac",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/8752018324255092892",
"startTime": "2026-06-29T08:25:39.672-07:00",
"status": "RUNNING",
"targetId": "6960107639937118366",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:25:39.911159526Z",
"resource": {
"labels": {
"disk_id": "6960107639937118366",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_disk"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:25:39.508593Z"
}
compute.disks.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
Example Audit Log Entry #
{
"insertId": "-x8wxeqe5r63q",
"labels": {
"compute.googleapis.com/root_trigger_id": "0be16acf-81e9-4971-a0c2-33cf2a05ef3a"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.disks.setIamPolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"service": "compute",
"type": "compute.disks"
}
}
],
"methodName": "v1.compute.disks.setIamPolicy",
"request": {
"@type": "type.googleapis.com/compute.disks.setIamPolicy",
"policy": {
"bindings": [
{
"members": [
"user:user@example.com"
],
"role": "roles/compute.networkUser"
}
],
"version": "3"
}
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.set-iam-policy invocation-id/2aa31bd7faa54566990708f54615cf35 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:25:42.241052Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"response": {
"@type": "type.googleapis.com/error",
"error": {
"code": 400,
"errors": [
{
"domain": "global",
"message": "Role roles/compute.networkUser is not supported for this resource.",
"reason": "invalidIamPolicy"
}
],
"message": "Role roles/compute.networkUser is not supported for this resource."
}
},
"serviceName": "compute.googleapis.com",
"status": {
"code": 3,
"message": "Role roles/compute.networkUser is not supported for this resource."
}
},
"receiveTimestamp": "2026-06-29T15:25:43.018418271Z",
"resource": {
"labels": {
"disk_id": "6960107639937118366",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_disk"
},
"severity": "ERROR",
"timestamp": "2026-06-29T15:25:42.174914Z"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
protoPayload.response.error (panther rule field) | is_null | | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
compute.disks.setLabels: setLabels
#Description
Sets the labels on a disk. To learn more about labels, read theLabeling Resources documentation.
Example Audit Log Entry #
{
"insertId": "xbaoc8e6bk7u",
"labels": {
"compute.googleapis.com/root_trigger_id": "2c010051-83ef-42ec-93a2-c22466e0e791"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746743778-6556612632c8d-6b7809c2-b0b409a6",
"last": true,
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.disks.setLabels",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"service": "compute",
"type": "compute.disks"
}
}
],
"methodName": "v1.compute.disks.setLabels",
"request": {
"@type": "type.googleapis.com/compute.disks.setLabels",
"labelFingerprint": "�e�J�|�#",
"labels": [
{
"key": "env",
"value": "dw"
}
]
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.add-labels invocation-id/7aab7c7b1ada40a2a2607bd7755dc902 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:25:43.878129Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"endTime": "2026-06-29T08:25:43.845-07:00",
"id": "2121917952695414936",
"insertTime": "2026-06-29T08:25:43.836-07:00",
"name": "operation-1782746743778-6556612632c8d-6b7809c2-b0b409a6",
"operationType": "setLabels",
"progress": "100",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746743778-6556612632c8d-6b7809c2-b0b409a6",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/2121917952695414936",
"startTime": "2026-06-29T08:25:43.843-07:00",
"status": "DONE",
"targetId": "6960107639937118366",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwdisk4-dw745960",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:25:44.766679415Z",
"resource": {
"labels": {
"disk_id": "6960107639937118366",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_disk"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:25:43.748731Z"
}
compute.disks.startAsyncReplication: startAsyncReplication
#Description
Starts asynchronous replication. Must be invoked on the primary disk.
compute.disks.stopAsyncReplication: stopAsyncReplication
#Description
Stops asynchronous replication. Can be invoked either on the primary or on the secondary disk.
compute.disks.stopGroupAsyncReplication: stopGroupAsyncReplication
#Description
Stops asynchronous replication for a consistency group of disks. Can be invoked either in the primary or secondary scope.
compute.disks.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.disks.update: update
#Description
Updates the specified disk with the data included in the request. The update is performed only on selected fields included as part of update-mask.
compute.disks.updateKmsKey: updateKmsKey
#Description
Rotates the customer-managed encryption key to the latest version for the specified persistent disk.
compute.externalVpnGateways.delete: delete
#Description
Deletes the specified externalVpnGateway.
Example Audit Log Entry #
{
"insertId": "d36kkbdvefi",
"labels": {
"compute.googleapis.com/root_trigger_id": "9c179ed8-7fb8-455f-9e64-62ce1f1d8ea5"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750832555-655670618f7c5-39544f00-581d1630",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.externalVpnGateways.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"service": "compute",
"type": "compute.externalVpnGateways"
}
}
],
"methodName": "v1.compute.externalVpnGateways.delete",
"request": {
"@type": "type.googleapis.com/compute.externalVpnGateways.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.external-vpn-gateways.delete invocation-id/53a6affa988d47b089acf386ddb40195 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:33:52.773531Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"response": {
"@type": "type.googleapis.com/operation",
"id": "3634290948251263135",
"insertTime": "2026-06-29T09:33:52.647-07:00",
"name": "operation-1782750832555-655670618f7c5-39544f00-581d1630",
"operationType": "compute.externalVpnGateways.delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782750832555-655670618f7c5-39544f00-581d1630",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/3634290948251263135",
"startTime": "2026-06-29T09:33:52.659-07:00",
"status": "RUNNING",
"targetId": "4449701621952094941",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:33:52.860279240Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.externalVpnGateways.delete",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:33:52.493736Z"
}
compute.externalVpnGateways.get: get
#Description
Returns the specified externalVpnGateway. Get a list of available externalVpnGateways by making a list() request.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "gxkp3dee7eqs",
"labels": {
"compute.googleapis.com/root_trigger_id": "b9c2013e-fefb-4c6e-a25c-be4fa65ca949"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.externalVpnGateways.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"service": "compute",
"type": "compute.externalVpnGateways"
}
}
],
"methodName": "v1.compute.externalVpnGateways.get",
"request": {
"@type": "type.googleapis.com/compute.externalVpnGateways.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.external-vpn-gateways.create invocation-id/74c392d77ec7477a81dd10cf8ac4dfb9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:24:20.327802Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:24:20.916907948Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.externalVpnGateways.get",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:24:20.218759Z"
}
compute.externalVpnGateways.insert: insert
#Description
Creates a ExternalVpnGateway in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-xuk6f8e5bhvc",
"labels": {
"compute.googleapis.com/root_trigger_id": "d41f2c1c-a6b9-4eec-9c92-b28d9f6669ea"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750258265-65566e3ddfbe8-024b9f1a-3b1bab39",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.externalVpnGateways.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"service": "compute",
"type": "compute.externalVpnGateways"
}
}
],
"methodName": "v1.compute.externalVpnGateways.insert",
"request": {
"@type": "type.googleapis.com/compute.externalVpnGateways.insert",
"interfaces": [
{
"id": "0",
"ipAddress": "203.0.113.5"
}
],
"name": "dwegw7201353",
"redundancyType": "SINGLE_IP_INTERNALLY_REDUNDANT"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.external-vpn-gateways.create invocation-id/74c392d77ec7477a81dd10cf8ac4dfb9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:24:18.659973Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"response": {
"@type": "type.googleapis.com/operation",
"id": "1121347094220579549",
"insertTime": "2026-06-29T09:24:18.388-07:00",
"name": "operation-1782750258265-65566e3ddfbe8-024b9f1a-3b1bab39",
"operationType": "compute.externalVpnGateways.insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782750258265-65566e3ddfbe8-024b9f1a-3b1bab39",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/1121347094220579549",
"startTime": "2026-06-29T09:24:18.393-07:00",
"status": "RUNNING",
"targetId": "4449701621952094941",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:24:18.785123581Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.externalVpnGateways.insert",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:24:18.241953Z"
}
compute.externalVpnGateways.list: list
#Description
Retrieves the list of ExternalVpnGateway available to the specified project.
Data Access audit logs are disabled by default.
compute.externalVpnGateways.setLabels: setLabels
#Description
Sets the labels on an ExternalVpnGateway. To learn more about labels, read the Labeling Resources documentation.
compute.externalVpnGateways.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.firewallPolicies.addAssociation: addAssociation
#Description
Inserts an association for the specified firewall policy.
compute.firewallPolicies.addRule: addRule
#Description
Inserts a rule into a firewall policy.
compute.firewallPolicies.cloneRules: cloneRules
#Description
Copies rules to the specified firewall policy.
compute.firewallPolicies.delete: delete
#Description
Deletes the specified policy.
compute.firewallPolicies.get: get
#Description
Returns the specified firewall policy.
Data Access audit logs are disabled by default.
compute.firewallPolicies.getAssociation: getAssociation
#Description
Gets an association with the specified name.
Data Access audit logs are disabled by default.
compute.firewallPolicies.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.firewallPolicies.getRule: getRule
#Description
Gets a rule of the specified priority.
Data Access audit logs are disabled by default.
compute.firewallPolicies.insert: insert
#Description
Creates a new policy in the specified project using the data included in the request.
compute.firewallPolicies.list: list
#Description
Lists all the policies that have been configured for the specified folder or organization.
Data Access audit logs are disabled by default.
compute.firewallPolicies.listAssociations: listAssociations
#Description
Lists associations of a specified target, i.e., organization or folder.
Data Access audit logs are disabled by default.
compute.firewallPolicies.move: move
#Description
Moves the specified firewall policy.
compute.firewallPolicies.patch: patch
#Description
Patches the specified policy with the data included in the request.
compute.firewallPolicies.patchRule: patchRule
#Description
Patches a rule of the specified priority.
compute.firewallPolicies.removeAssociation: removeAssociation
#Description
Removes an association for the specified firewall policy.
compute.firewallPolicies.removeRule: removeRule
#Description
Deletes a rule of the specified priority.
compute.firewallPolicies.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.firewallPolicies.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.firewalls.delete: Delete firewall rule
#Description
Deletes the specified firewall.
Example Audit Log Entry #
{
"insertId": "p1bbz6dddqk",
"labels": {
"compute.googleapis.com/root_trigger_id": "3bb2eb19-ede2-4eae-baec-c0cb62ee443f"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782744010897-655656f7eb789-1b8b5be4-2b778aac",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.firewalls.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/firewalls/gke-dwgke-dw743447-265a84d2-exkubelet",
"resourceAttributes": {
"name": "projects/example-project-id/global/firewalls/gke-dwgke-dw743447-265a84d2-exkubelet",
"service": "compute",
"type": "compute.firewalls"
}
},
{
"granted": true,
"permission": "compute.networks.updatePolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/default",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/default",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.firewalls.delete",
"request": {
"@type": "type.googleapis.com/compute.firewalls.delete"
},
"requestMetadata": {
"callerIp": "private",
"callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:40:11.429940Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/firewalls/gke-dwgke-dw743447-265a84d2-exkubelet",
"resourceOriginalState": {
"@type": "compute.googleapis.com/delete.state",
"creationTimestamp": "2026-06-29T07:32:38.631-07:00",
"denieds": [
{
"IPProtocol": "tcp",
"ports": [
"10255"
]
}
],
"description": "",
"direction": "INGRESS",
"disabled": false,
"enableLogging": false,
"id": "8682464889424264425",
"logConfig": {
"enable": false
},
"name": "gke-dwgke-dw743447-265a84d2-exkubelet",
"network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/default",
"priority": "1000",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/gke-dwgke-dw743447-265a84d2-exkubelet",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/8682464889424264425",
"sourceRanges": [
"0.0.0.0/0"
],
"targetTags": [
"gke-dwgke-dw743447-265a84d2-node"
]
},
"response": {
"@type": "type.googleapis.com/operation",
"id": "2020390200037817636",
"insertTime": "2026-06-29T07:40:11.205-07:00",
"name": "operation-1782744010897-655656f7eb789-1b8b5be4-2b778aac",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782744010897-655656f7eb789-1b8b5be4-2b778aac",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2020390200037817636",
"startTime": "2026-06-29T07:40:11.244-07:00",
"status": "RUNNING",
"targetId": "8682464889424264425",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/gke-dwgke-dw743447-265a84d2-exkubelet",
"user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:40:12.336833330Z",
"resource": {
"labels": {
"firewall_rule_id": "8682464889424264425",
"project_id": "example-project-id"
},
"type": "gce_firewall_rule"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:40:10.983424Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1685↳ also matches compute.firewalls.insert: Insert firewall rule, compute.firewalls.patch: Patch firewall rule, compute.firewalls.update: Update firewall rule Elastic #
T1562, T1562.007Panther #
compute.firewalls.get: get
#Description
Returns the specified firewall.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-8k385se5oc70",
"labels": {
"compute.googleapis.com/root_trigger_id": "b9dd475b-3460-4330-9197-900b4861ffae"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.firewalls.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/firewalls/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/global/firewalls/dwgen-dw739065",
"service": "compute",
"type": "compute.firewalls"
}
}
],
"methodName": "v1.compute.firewalls.get",
"request": {
"@type": "type.googleapis.com/compute.firewalls.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.firewall-rules.create invocation-id/b9c37dbd896c42b985609ea1a5ff0e1b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:20:48.675128Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/firewalls/dwgen-dw739065",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:20:49.568658753Z",
"resource": {
"labels": {
"firewall_rule_id": "6445511313097478084",
"project_id": "example-project-id"
},
"type": "gce_firewall_rule"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:20:48.576484Z"
}
compute.firewalls.insert: Insert firewall rule
#Description
Creates a firewall rule in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-4xmq76d4xjy",
"labels": {
"compute.googleapis.com/root_trigger_id": "86947610-9c75-40af-9fc2-8c813fe0efac"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782739243566-655645357054d-883f888e-284c2eb9",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.firewalls.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/firewalls/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/global/firewalls/dwgen-dw739065",
"service": "compute",
"type": "compute.firewalls"
}
},
{
"granted": true,
"permission": "compute.networks.updatePolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/dwgen-dw739065",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.firewalls.insert",
"request": {
"@type": "type.googleapis.com/compute.firewalls.insert",
"alloweds": [
{
"IPProtocol": "tcp",
"ports": [
"22"
]
}
],
"direction": "INGRESS",
"name": "dwgen-dw739065",
"network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwgen-dw739065",
"sourceRanges": [
"10.8.0.0/24"
]
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.firewall-rules.create invocation-id/b9c37dbd896c42b985609ea1a5ff0e1b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:20:44.100557Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/firewalls/dwgen-dw739065",
"response": {
"@type": "type.googleapis.com/operation",
"id": "8277527470017597380",
"insertTime": "2026-06-29T06:20:43.899-07:00",
"name": "operation-1782739243566-655645357054d-883f888e-284c2eb9",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782739243566-655645357054d-883f888e-284c2eb9",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/8277527470017597380",
"startTime": "2026-06-29T06:20:43.936-07:00",
"status": "RUNNING",
"targetId": "6445511313097478084",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/dwgen-dw739065",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:20:44.665409680Z",
"resource": {
"labels": {
"firewall_rule_id": "6445511313097478084",
"project_id": "example-project-id"
},
"type": "gce_firewall_rule"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T13:20:43.646289Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1685↳ also matches compute.firewalls.delete: Delete firewall rule, compute.firewalls.patch: Patch firewall rule, compute.firewalls.update: Update firewall rule Elastic #
T1562, T1562.007YARA-L #
T1562Panther #
compute.firewalls.list: list
#Description
Retrieves the list of firewall rules available to the specified project.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-ksf4xoe4cf6g",
"labels": {
"compute.googleapis.com/root_trigger_id": "7a71e88b-ef10-44f5-8b2b-4f34ff99a525"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.firewalls.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.firewalls.list",
"numResponseItems": "4",
"request": {
"@type": "type.googleapis.com/compute.firewalls.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.firewall-rules.list invocation-id/c1cb0a3178ae4efcae5c1e333f60955b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:57.986196Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/firewalls",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:58.439463135Z",
"resource": {
"labels": {
"firewall_rule_id": "",
"project_id": "example-project-id"
},
"type": "gce_firewall_rule"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:57.921053Z"
}
compute.firewalls.patch: Patch firewall rule
#Description
Patches the specified firewall rule with the data included in the request.
Example Audit Log Entry #
{
"insertId": "-hgwc5ud8wg8",
"labels": {
"compute.googleapis.com/root_trigger_id": "6c752747-7957-4722-a964-94488f2ef76c"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782743724697-655655e6fa6f8-8263b121-cf8db9a8",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.firewalls.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/firewalls/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/global/firewalls/dwg2-dw743447",
"service": "compute",
"type": "compute.firewalls"
}
},
{
"granted": true,
"permission": "compute.firewalls.update",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/firewalls/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/global/firewalls/dwg2-dw743447",
"service": "compute",
"type": "compute.firewalls"
}
},
{
"granted": true,
"permission": "compute.networks.updatePolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/dwg2-dw743447",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.firewalls.patch",
"request": {
"@type": "type.googleapis.com/compute.firewalls.patch",
"alloweds": [
{
"IPProtocol": "tcp",
"ports": [
"22"
]
},
{
"IPProtocol": "tcp",
"ports": [
"80"
]
}
],
"description": "",
"direction": "INGRESS",
"logConfig": {
"enable": false
},
"name": "dwg2-dw743447",
"network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwg2-dw743447",
"priority": "1000",
"sourceRanges": [
"10.9.0.0/24"
]
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.firewall-rules.update invocation-id/c6323f0a21bc4e17b01224f54083ed54 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:35:25.517822Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/firewalls/dwg2-dw743447",
"resourceOriginalState": {
"@type": "compute.googleapis.com/patch.state",
"alloweds": [
{
"IPProtocol": "tcp",
"ports": [
"22"
]
}
],
"creationTimestamp": "2026-06-29T07:35:18.445-07:00",
"description": "",
"direction": "INGRESS",
"disabled": false,
"enableLogging": false,
"id": "854235574774479945",
"logConfig": {
"enable": false
},
"name": "dwg2-dw743447",
"network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwg2-dw743447",
"priority": "1000",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/dwg2-dw743447",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/854235574774479945",
"sourceRanges": [
"10.9.0.0/24"
]
},
"response": {
"@type": "type.googleapis.com/operation",
"id": "5435957740976421954",
"insertTime": "2026-06-29T07:35:25.319-07:00",
"name": "operation-1782743724697-655655e6fa6f8-8263b121-cf8db9a8",
"operationType": "patch",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782743724697-655655e6fa6f8-8263b121-cf8db9a8",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/5435957740976421954",
"startTime": "2026-06-29T07:35:25.322-07:00",
"status": "RUNNING",
"targetId": "854235574774479945",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/firewalls/dwg2-dw743447",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:35:25.722373560Z",
"resource": {
"labels": {
"firewall_rule_id": "854235574774479945",
"project_id": "example-project-id"
},
"type": "gce_firewall_rule"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:35:24.782058Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1685↳ also matches compute.firewalls.delete: Delete firewall rule, compute.firewalls.insert: Insert firewall rule, compute.firewalls.update: Update firewall rule Elastic #
T1562, T1562.007Panther #
compute.firewalls.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.firewalls.update: Update firewall rule
#Description
Updates the specified firewall rule with the data included in the request.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1685↳ also matches compute.firewalls.delete: Delete firewall rule, compute.firewalls.insert: Insert firewall rule, compute.firewalls.patch: Patch firewall rule Panther #
compute.forwardingRules.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of forwarding rules. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "a9yp7pe18gqc",
"labels": {
"compute.googleapis.com/root_trigger_id": "c96b243a-60e0-47b9-871e-30049ac69bbe"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.forwardingRules.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.forwardingRules.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.forwardingRules.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.forwarding-rules.list invocation-id/813f468e67674e3e8ea4ef0693c358ba environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:28.081489Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/forwardingRules",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:28.169535752Z",
"resource": {
"labels": {
"forwarding_rule_id": "",
"project_id": "example-project-id",
"region": "global"
},
"type": "gce_forwarding_rule"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:27.976490Z"
}
compute.forwardingRules.delete: delete
#Description
Deletes the specified ForwardingRule resource.
Example Audit Log Entry #
{
"insertId": "-wpoyi8dpcg4",
"labels": {
"compute.googleapis.com/root_trigger_id": "8790bfb0-75ff-4f05-89b7-1375fc7748c3"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782744101494-6556574e52036-0867aad4-85a6a0c5",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.forwardingRules.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"service": "compute",
"type": "compute.forwardingRules"
}
},
{
"granted": true,
"permission": "compute.forwardingRules.pscDelete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"service": "compute",
"type": "compute.forwardingRules"
}
}
],
"methodName": "v1.compute.forwardingRules.delete",
"request": {
"@type": "type.googleapis.com/compute.forwardingRules.delete"
},
"requestMetadata": {
"callerIp": "private",
"callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:41:41.818793Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"response": {
"@type": "type.googleapis.com/operation",
"id": "8233641262258797258",
"insertTime": "2026-06-29T07:41:41.738-07:00",
"name": "operation-1782744101494-6556574e52036-0867aad4-85a6a0c5",
"operationType": "deleteRegionPscForwardingRule",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782744101494-6556574e52036-0867aad4-85a6a0c5",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/8233641262258797258",
"startTime": "2026-06-29T07:41:41.759-07:00",
"status": "RUNNING",
"targetId": "2318136879392701578",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:41:41.960562757Z",
"resource": {
"labels": {
"forwarding_rule_id": "2318136879392701578",
"project_id": "example-project-id",
"region": "us-central1"
},
"type": "gce_forwarding_rule"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:41:41.561642Z"
}
compute.forwardingRules.get: get
#Description
Returns the specified ForwardingRule resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-l2krt0e2keqi",
"labels": {
"compute.googleapis.com/root_trigger_id": "42fe0927-16d1-462d-b8cf-0cd7073633e2"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.forwardingRules.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"service": "compute",
"type": "compute.forwardingRules"
}
}
],
"methodName": "v1.compute.forwardingRules.get",
"request": {
"@type": "type.googleapis.com/compute.forwardingRules.get"
},
"requestMetadata": {
"callerIp": "private",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:41:41.487818Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:41:42.068440975Z",
"resource": {
"labels": {
"forwarding_rule_id": "2318136879392701578",
"project_id": "example-project-id",
"region": "us-central1"
},
"type": "gce_forwarding_rule"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:41:41.420268Z"
}
compute.forwardingRules.insert: insert
#Description
Creates a ForwardingRule resource in the specified project and region using the data included in the request.
Example Audit Log Entry #
{
"insertId": "821c3se5nvu6",
"labels": {
"compute.googleapis.com/root_trigger_id": "beede198-5d50-4249-a668-a64688d02026"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782743653528-655655a31b48d-832c548a-8736b7c2",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.forwardingRules.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"service": "compute",
"type": "compute.forwardingRules"
}
},
{
"granted": true,
"permission": "compute.forwardingRules.pscCreate",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"service": "compute",
"type": "compute.forwardingRules"
}
},
{
"granted": true,
"permission": "compute.networks.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/default",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/default",
"service": "compute",
"type": "compute.networks"
}
},
{
"granted": true,
"permission": "compute.addresses.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"service": "compute",
"type": "compute.addresses"
}
}
],
"methodName": "v1.compute.forwardingRules.insert",
"request": {
"@type": "type.googleapis.com/compute.forwardingRules.insert",
"IPAddress": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/addresses/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"name": "gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/default",
"target": "projects/c085ef9d0ad1ab7fep-tp/regions/us-central1/serviceAttachments/gke-265a84d2523e48fa99a3-4293-c798-sa"
},
"requestMetadata": {
"callerIp": "private",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:34:14.060757Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"response": {
"@type": "type.googleapis.com/operation",
"id": "347555886273608842",
"insertTime": "2026-06-29T07:34:13.969-07:00",
"name": "operation-1782743653528-655655a31b48d-832c548a-8736b7c2",
"operationType": "createRegionPscForwardingRule",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782743653528-655655a31b48d-832c548a-8736b7c2",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/347555886273608842",
"startTime": "2026-06-29T07:34:13.981-07:00",
"status": "RUNNING",
"targetId": "2318136879392701578",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/forwardingRules/gk3-dwgke-dw743447-265a84d2-a3281bcc-pe",
"user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:34:14.121798391Z",
"resource": {
"labels": {
"forwarding_rule_id": "2318136879392701578",
"project_id": "example-project-id",
"region": "us-central1"
},
"type": "gce_forwarding_rule"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:34:13.571434Z"
}
compute.forwardingRules.list: list
#Description
Retrieves a list of ForwardingRule resources available to the specified project and region.
Data Access audit logs are disabled by default.
compute.forwardingRules.patch: patch
#Description
Updates the specified forwarding rule with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. Currently, you can only patch the network_tier field.
compute.forwardingRules.setLabels: setLabels
#Description
Sets the labels on the specified resource. To learn more about labels, read the Labeling Resources documentation.
compute.forwardingRules.setTarget: setTarget
#Description
Changes target URL for forwarding rule. The new target should be of the same type as the old target.
compute.futureReservations.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of future reservations. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.futureReservations.cancel: cancel
#Description
Cancel the specified future reservation.
compute.futureReservations.delete: delete
#Description
Deletes the specified future reservation.
compute.futureReservations.get: get
#Description
Retrieves information about the specified future reservation.
Data Access audit logs are disabled by default.
compute.futureReservations.insert: insert
#Description
Creates a new Future Reservation.
compute.futureReservations.list: list
#Description
A list of all the future reservations that have been configured for the specified project in specified zone.
Data Access audit logs are disabled by default.
compute.futureReservations.update: update
#Description
Updates the specified future reservation.
compute.globalAddresses.delete: delete
#Description
Deletes the specified address resource.
Example Audit Log Entry #
{
"insertId": "96k0rtd68jo",
"labels": {
"compute.googleapis.com/root_trigger_id": "03a75f4c-bad8-49ba-8fb2-5d2cad651775"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782747111155-655662848e8da-f3a4b041-6e552434",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.globalAddresses.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/addresses/dwga-dw746783",
"resourceAttributes": {
"name": "projects/example-project-id/global/addresses/dwga-dw746783",
"service": "compute",
"type": "compute.globalAddresses"
}
}
],
"methodName": "v1.compute.globalAddresses.delete",
"request": {
"@type": "type.googleapis.com/compute.globalAddresses.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.delete invocation-id/fb9ce2157370463eb3ec7c88bb17adca environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:31:51.639256Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/addresses/dwga-dw746783",
"response": {
"@type": "type.googleapis.com/operation",
"id": "2827387436532707592",
"insertTime": "2026-06-29T08:31:51.481-07:00",
"name": "operation-1782747111155-655662848e8da-f3a4b041-6e552434",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782747111155-655662848e8da-f3a4b041-6e552434",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2827387436532707592",
"startTime": "2026-06-29T08:31:51.484-07:00",
"status": "RUNNING",
"targetId": "8192489518443475373",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/addresses/dwga-dw746783",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:31:52.531334684Z",
"resource": {
"labels": {
"location": "global",
"project_id": "example-project-id",
"reserved_address_id": "8192489518443475373"
},
"type": "gce_reserved_address"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:31:51.235080Z"
}
compute.globalAddresses.get: get
#Description
Returns the specified address resource.
Data Access audit logs are disabled by default.
compute.globalAddresses.insert: insert
#Description
Creates an address resource in the specified project by using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-hg6sg6d1z3e",
"labels": {
"compute.googleapis.com/root_trigger_id": "b64abb06-286f-42e9-b5ae-d29de7f3ab8c"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746945875-655661e6eef15-3faa63fd-4ea2c377",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.globalAddresses.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/addresses/dwga-dw746783",
"resourceAttributes": {
"name": "projects/example-project-id/global/addresses/dwga-dw746783",
"service": "compute",
"type": "compute.globalAddresses"
}
}
],
"methodName": "v1.compute.globalAddresses.insert",
"request": {
"@type": "type.googleapis.com/compute.globalAddresses.insert",
"ipVersion": "IPV4",
"name": "dwga-dw746783"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.addresses.create invocation-id/c6c3ed5f52a54859aa14194fad3447d5 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:29:06.313137Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/addresses/dwga-dw746783",
"response": {
"@type": "type.googleapis.com/operation",
"id": "5453971430816297389",
"insertTime": "2026-06-29T08:29:06.165-07:00",
"name": "operation-1782746945875-655661e6eef15-3faa63fd-4ea2c377",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782746945875-655661e6eef15-3faa63fd-4ea2c377",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/5453971430816297389",
"startTime": "2026-06-29T08:29:06.168-07:00",
"status": "RUNNING",
"targetId": "8192489518443475373",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/addresses/dwga-dw746783",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:29:06.622173103Z",
"resource": {
"labels": {
"location": "global",
"project_id": "example-project-id",
"reserved_address_id": "8192489518443475373"
},
"type": "gce_reserved_address"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:29:05.940202Z"
}
compute.globalAddresses.list: list
#Description
Retrieves a list of global addresses.
Data Access audit logs are disabled by default.
compute.globalAddresses.move: move
#Description
Moves the specified address resource from one project to another project.
compute.globalAddresses.setLabels: setLabels
#Description
Sets the labels on a GlobalAddress. To learn more about labels, read theLabeling Resources documentation.
compute.globalAddresses.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.globalForwardingRules.delete: delete
#Description
Deletes the specified GlobalForwardingRule resource.
compute.globalForwardingRules.get: get
#Description
Returns the specified GlobalForwardingRule resource. Gets a list of available forwarding rules by making a list() request.
Data Access audit logs are disabled by default.
compute.globalForwardingRules.insert: insert
#Description
Creates a GlobalForwardingRule resource in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "jhh08md5qq8",
"labels": {
"compute.googleapis.com/root_trigger_id": "92cd3eec-692f-4ace-9350-5dd6a4e712fd"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745432588-65565c43c0008-c0038248-b2d064de",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.targetHttpProxies.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
"service": "compute",
"type": "compute.targetHttpProxies"
}
},
{
"granted": true,
"permission": "compute.globalForwardingRules.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/forwardingRules/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/forwardingRules/dwn3-dw745304",
"service": "compute",
"type": "compute.globalForwardingRules"
}
}
],
"methodName": "v1.compute.globalForwardingRules.insert",
"request": {
"@type": "type.googleapis.com/compute.globalForwardingRules.insert",
"loadBalancingScheme": "EXTERNAL",
"name": "dwn3-dw745304",
"portRange": "80",
"target": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/targetHttpProxies/dwn3-dw745304"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.forwarding-rules.create invocation-id/07e1ea7331be49ff857dd4b77bf0a35a environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:03:53.254217Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/forwardingRules/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "822885693652940727",
"insertTime": "2026-06-29T08:03:53.027-07:00",
"name": "operation-1782745432588-65565c43c0008-c0038248-b2d064de",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745432588-65565c43c0008-c0038248-b2d064de",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/822885693652940727",
"startTime": "2026-06-29T08:03:53.029-07:00",
"status": "RUNNING",
"targetId": "3603505146659551159",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/forwardingRules/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:03:54.052964535Z",
"resource": {
"labels": {
"forwarding_rule_id": "3603505146659551159",
"project_id": "example-project-id",
"region": "global"
},
"type": "gce_forwarding_rule"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:03:52.652167Z"
}
compute.globalForwardingRules.list: list
#Description
Retrieves a list of GlobalForwardingRule resources available to the specified project.
Data Access audit logs are disabled by default.
compute.globalForwardingRules.patch: patch
#Description
Updates the specified forwarding rule with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. Currently, you can only patch the network_tier field.
compute.globalForwardingRules.setLabels: setLabels
#Description
Sets the labels on the specified resource. To learn more about labels, read the Labeling resources documentation.
compute.globalForwardingRules.setTarget: setTarget
#Description
Changes target URL for the GlobalForwardingRule resource. The new target should be of the same type as the old target.
compute.globalNetworkEndpointGroups.attachNetworkEndpoints: attachNetworkEndpoints
#Description
Attach a network endpoint to the specified network endpoint group.
compute.globalNetworkEndpointGroups.delete: delete
#Description
Deletes the specified network endpoint group.Note that the NEG cannot be deleted if there are backend services referencing it.
compute.globalNetworkEndpointGroups.detachNetworkEndpoints: detachNetworkEndpoints
#Description
Detach the network endpoint from the specified network endpoint group.
compute.globalNetworkEndpointGroups.get: get
#Description
Returns the specified network endpoint group.
Data Access audit logs are disabled by default.
compute.globalNetworkEndpointGroups.insert: insert
#Description
Creates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global API
compute.globalNetworkEndpointGroups.list: list
#Description
Retrieves the list of network endpoint groups that are located in the specified project.
Data Access audit logs are disabled by default.
compute.globalNetworkEndpointGroups.listNetworkEndpoints: listNetworkEndpoints
#Description
Lists the network endpoints in the specified network endpoint group.
Data Access audit logs are disabled by default.
compute.globalOperations.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of all operations. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-pscaw9dlcvk",
"labels": {
"compute.googleapis.com/root_trigger_id": "a46e66ad-db46-4e57-923d-c06a758f225f"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.globalOperations.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.globalOperations.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.globalOperations.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.operations.list invocation-id/5af3ea2d9a0446e0ab60c469c3afe543 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:19:02.255613Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/operations",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:19:03.254248297Z",
"resource": {
"labels": {
"location": "global",
"operation_name": "",
"project_id": "example-project-id"
},
"type": "gce_operation"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:19:01.999629Z"
}
compute.globalOperations.delete: delete
#Description
Deletes the specified Operations resource.
compute.globalOperations.get: get
#Description
Retrieves the specified Operations resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "w7dymie13thm",
"labels": {
"compute.googleapis.com/root_trigger_id": "3cf5fc26-08cb-4539-b650-c614ce9a3a0a"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.globalOperations.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/operations/operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
"resourceAttributes": {
"name": "projects/example-project-id/global/operations/operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
"service": "compute",
"type": "compute.globalOperations"
}
}
],
"methodName": "v1.compute.globalOperations.get",
"request": {
"@type": "type.googleapis.com/compute.globalOperations.get"
},
"requestMetadata": {
"callerIp": "private",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:41:25.194129Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/operations/operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:41:25.679317511Z",
"resource": {
"labels": {
"location": "global",
"operation_name": "operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
"project_id": "example-project-id"
},
"type": "gce_operation"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:41:25.125679Z"
}
compute.globalOperations.list: list
#Description
Retrieves a list of Operation resources contained within the specified project.
Data Access audit logs are disabled by default.
compute.globalOperations.wait: wait
#Description
Waits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method differs from the `GET` method in that it waits for no more than the default deadline (2 minutes) and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "o78ts4d6l8m",
"labels": {
"compute.googleapis.com/root_trigger_id": "d3b76fcd-4990-46dc-a6ed-3ad1e199cab8"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.globalOperations.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/operations/operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
"resourceAttributes": {
"name": "projects/example-project-id/global/operations/operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
"service": "compute",
"type": "compute.globalOperations"
}
}
],
"methodName": "v1.compute.globalOperations.wait",
"request": {
"@type": "type.googleapis.com/compute.globalOperations.wait"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.create invocation-id/4ffe3c8ff74e4802bb2de389b3abfd97 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:20:22.192191Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/operations/operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:20:22.866504633Z",
"resource": {
"labels": {
"location": "global",
"operation_name": "operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
"project_id": "example-project-id"
},
"type": "gce_operation"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:20:12.257154Z"
}
compute.globalOrganizationOperations.delete: delete
#Description
Deletes the specified Operations resource.
compute.globalOrganizationOperations.get: get
#Description
Retrieves the specified Operations resource. Gets a list of operations by making a `list()` request.
Data Access audit logs are disabled by default.
compute.globalOrganizationOperations.list: list
#Description
Retrieves a list of Operation resources contained within the specified organization.
Data Access audit logs are disabled by default.
compute.globalPublicDelegatedPrefixes.delete: delete
#Description
Deletes the specified global PublicDelegatedPrefix.
compute.globalPublicDelegatedPrefixes.get: get
#Description
Returns the specified global PublicDelegatedPrefix resource.
Data Access audit logs are disabled by default.
compute.globalPublicDelegatedPrefixes.insert: insert
#Description
Creates a global PublicDelegatedPrefix in the specified project using the parameters that are included in the request.
compute.globalPublicDelegatedPrefixes.list: list
#Description
Lists the global PublicDelegatedPrefixes for a project.
Data Access audit logs are disabled by default.
compute.globalPublicDelegatedPrefixes.patch: patch
#Description
Patches the specified global PublicDelegatedPrefix resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.
compute.globalVmExtensionPolicies.aggregatedList: aggregatedList
#Description
Retrieves the list of all VM Extension Policy resources available to the specified project. To prevent failure, it's recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.globalVmExtensionPolicies.delete: delete
#Description
Purge scoped resources (zonal policies) from a global VM extension policy, and then delete the global VM extension policy. Purge of the scoped resources is a pre-condition of the global VM extension policy deletion. The deletion of the global VM extension policy happens after the purge rollout is done, so it's not a part of the LRO. It's an automatic process that triggers in the backend.
compute.globalVmExtensionPolicies.get: get
#Description
Gets details of a global VM extension policy.
Data Access audit logs are disabled by default.
compute.globalVmExtensionPolicies.insert: insert
#Description
Creates a new project level GlobalVmExtensionPolicy.
compute.globalVmExtensionPolicies.list: list
#Description
Lists global VM extension policies.
Data Access audit logs are disabled by default.
compute.globalVmExtensionPolicies.update: update
#Description
Updates a global VM extension policy.
compute.healthChecks.aggregatedList: aggregatedList
#Description
Retrieves the list of all HealthCheck resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-il53hbd3wk6",
"labels": {
"compute.googleapis.com/root_trigger_id": "f3ab90fd-cc16-4621-b6be-9f125cd32e15"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.healthChecks.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.healthChecks.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.healthChecks.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.health-checks.list invocation-id/650fe4e282de442897f5d3bfa317d1a6 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:33.313676Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/healthChecks",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:33.926492711Z",
"resource": {
"labels": {
"health_check_id": "",
"project_id": "example-project-id"
},
"type": "gce_health_check"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:33.226446Z"
}
compute.healthChecks.delete: delete
#Description
Deletes the specified HealthCheck resource.
compute.healthChecks.get: get
#Description
Returns the specified HealthCheck resource.
Data Access audit logs are disabled by default.
compute.healthChecks.insert: insert
#Description
Creates a HealthCheck resource in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-n0vxgoddaio",
"labels": {
"compute.googleapis.com/root_trigger_id": "32891bf4-dd38-43e0-a3da-991f4e9362c4"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745398248-65565c230032b-915006d0-31077acb",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.healthChecks.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/healthChecks/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/healthChecks/dwn3-dw745304",
"service": "compute",
"type": "compute.healthChecks"
}
}
],
"methodName": "v1.compute.healthChecks.insert",
"request": {
"@type": "type.googleapis.com/compute.healthChecks.insert",
"checkIntervalSec": "5",
"healthyThreshold": "2",
"httpHealthCheck": {
"port": "80",
"portSpecification": "USE_FIXED_PORT",
"proxyHeader": "NONE",
"requestPath": "/"
},
"name": "dwn3-dw745304",
"timeoutSec": "5",
"type": "HTTP",
"unhealthyThreshold": "2"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.health-checks.create.http invocation-id/d889e6716d484701b62e8d354aa5fe41 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:03:19.026016Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/healthChecks/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "3358878850454861785",
"insertTime": "2026-06-29T08:03:18.350-07:00",
"name": "operation-1782745398248-65565c230032b-915006d0-31077acb",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745398248-65565c230032b-915006d0-31077acb",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/3358878850454861785",
"startTime": "2026-06-29T08:03:18.357-07:00",
"status": "RUNNING",
"targetId": "681147439262939097",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/healthChecks/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:03:19.568052887Z",
"resource": {
"labels": {
"health_check_id": "681147439262939097",
"project_id": "example-project-id"
},
"type": "gce_health_check"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:03:18.218406Z"
}
compute.healthChecks.list: list
#Description
Retrieves the list of HealthCheck resources available to the specified project.
Data Access audit logs are disabled by default.
compute.healthChecks.patch: patch
#Description
Updates a HealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.healthChecks.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.healthChecks.update: update
#Description
Updates a HealthCheck resource in the specified project using the data included in the request.
compute.httpHealthChecks.delete: delete
#Description
Deletes the specified HttpHealthCheck resource.
compute.httpHealthChecks.get: get
#Description
Returns the specified HttpHealthCheck resource.
Data Access audit logs are disabled by default.
compute.httpHealthChecks.insert: insert
#Description
Creates a HttpHealthCheck resource in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "auy5a7dtna6",
"labels": {
"compute.googleapis.com/root_trigger_id": "c1bb1f98-df6c-4497-acf7-f28680eb62bf"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745402243-65565c26cf804-50cf965c-8cd92d35",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.httpHealthChecks.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/httpHealthChecks/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/httpHealthChecks/dwn3-dw745304",
"service": "compute",
"type": "compute.httpHealthChecks"
}
}
],
"methodName": "v1.compute.httpHealthChecks.insert",
"request": {
"@type": "type.googleapis.com/compute.httpHealthChecks.insert",
"checkIntervalSec": "5",
"healthyThreshold": "2",
"name": "dwn3-dw745304",
"port": "80",
"requestPath": "/",
"timeoutSec": "5",
"unhealthyThreshold": "2"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.http-health-checks.create invocation-id/09c964e472444e928fb91e6a4769da24 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:03:22.696997Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/httpHealthChecks/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "7193487255039588309",
"insertTime": "2026-06-29T08:03:22.313-07:00",
"name": "operation-1782745402243-65565c26cf804-50cf965c-8cd92d35",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745402243-65565c26cf804-50cf965c-8cd92d35",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/7193487255039588309",
"startTime": "2026-06-29T08:03:22.324-07:00",
"status": "RUNNING",
"targetId": "2584761422561884117",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/httpHealthChecks/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:03:23.596022795Z",
"resource": {
"labels": {
"health_check_id": "2584761422561884117",
"project_id": "example-project-id"
},
"type": "gce_health_check"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:03:22.203815Z"
}
compute.httpHealthChecks.list: list
#Description
Retrieves the list of HttpHealthCheck resources available to the specified project.
Data Access audit logs are disabled by default.
compute.httpHealthChecks.patch: patch
#Description
Updates a HttpHealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.httpHealthChecks.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.httpHealthChecks.update: update
#Description
Updates a HttpHealthCheck resource in the specified project using the data included in the request.
compute.httpsHealthChecks.delete: delete
#Description
Deletes the specified HttpsHealthCheck resource.
compute.httpsHealthChecks.get: get
#Description
Returns the specified HttpsHealthCheck resource.
Data Access audit logs are disabled by default.
compute.httpsHealthChecks.insert: insert
#Description
Creates a HttpsHealthCheck resource in the specified project using the data included in the request.
compute.httpsHealthChecks.list: list
#Description
Retrieves the list of HttpsHealthCheck resources available to the specified project.
Data Access audit logs are disabled by default.
compute.httpsHealthChecks.patch: patch
#Description
Updates a HttpsHealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.httpsHealthChecks.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.httpsHealthChecks.update: update
#Description
Updates a HttpsHealthCheck resource in the specified project using the data included in the request.
compute.imageFamilyViews.get: get
#Description
Returns the latest image that is part of an image family, is not deprecated and is rolled out in the specified zone.
Data Access audit logs are disabled by default.
compute.images.delete: delete
#Description
Deletes the specified image.
Example Audit Log Entry #
{
"insertId": "-1nmsk4dfg1a",
"labels": {
"compute.googleapis.com/root_trigger_id": "a9b7796b-da46-484e-b643-5c2d6152ce44"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750893821-6556709bfcdf2-8f369141-1b5de419",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.images.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/images/dwimg7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/images/dwimg7201353",
"service": "compute",
"type": "compute.images"
}
}
],
"methodName": "v1.compute.images.delete",
"request": {
"@type": "type.googleapis.com/compute.images.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.delete invocation-id/8e6fca578ae744948398be0ec867ddbb environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:34:54.107342Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/images/dwimg7201353",
"response": {
"@type": "type.googleapis.com/operation",
"id": "7375611902957658178",
"insertTime": "2026-06-29T09:34:53.971-07:00",
"name": "operation-1782750893821-6556709bfcdf2-8f369141-1b5de419",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782750893821-6556709bfcdf2-8f369141-1b5de419",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/7375611902957658178",
"startTime": "2026-06-29T09:34:53.979-07:00",
"status": "RUNNING",
"targetId": "2102812314665166192",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/images/dwimg7201353",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:34:54.333277595Z",
"resource": {
"labels": {
"image_id": "2102812314665166192",
"project_id": "example-project-id"
},
"type": "gce_image"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:34:53.779678Z"
}
compute.images.deprecate: deprecate
#Description
Sets the deprecation status of an image. If an empty request body is given, clears the deprecation status instead.
compute.images.get: get
#Description
Returns the specified image.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "imv94de8g2vm",
"labels": {
"compute.googleapis.com/root_trigger_id": "9b8a44f5-73e3-4471-824e-7dc1d48b7bcc"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.images.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/images/dwimg7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/images/dwimg7201353",
"service": "compute",
"type": "compute.images"
}
}
],
"methodName": "v1.compute.images.get",
"request": {
"@type": "type.googleapis.com/compute.images.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.create invocation-id/db552a7c776f4859b55b88660d0dfece environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:22:10.941139Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/images/dwimg7201353",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:22:11.193215424Z",
"resource": {
"labels": {
"image_id": "2102812314665166192",
"project_id": "example-project-id"
},
"type": "gce_image"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:22:10.100037Z"
}
compute.images.getFromFamily: getFromFamily
#Description
Returns the latest image that is part of an image family and is not deprecated. For more information on image families, seePublic image families documentation.
Data Access audit logs are disabled by default.
compute.images.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-xigftje294r0",
"labels": {
"compute.googleapis.com/root_trigger_id": "4ab44c8c-e1bc-4b53-97b8-5a23f02c0f69"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.images.getIamPolicy",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/images/dwimg7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/images/dwimg7201353",
"service": "compute",
"type": "compute.images"
}
}
],
"methodName": "v1.compute.images.getIamPolicy",
"request": {
"@type": "type.googleapis.com/compute.images.getIamPolicy",
"optionsRequestedPolicyVersion": "3"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.add-iam-policy-binding invocation-id/4e1305315d774dd7956df13292bf3847 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:22:12.540172Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/images/dwimg7201353",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:22:13.194244811Z",
"resource": {
"labels": {
"image_id": "2102812314665166192",
"project_id": "example-project-id"
},
"type": "gce_image"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:22:12.379689Z"
}
compute.images.insert: insert
#Description
Creates an image in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "vd2ljid4fl0",
"labels": {
"compute.googleapis.com/root_trigger_id": "46d726b1-bffc-49a9-a0a6-b84dfc29faa0"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.images.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/images/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/global/images/dwg2-dw743447",
"service": "compute",
"type": "compute.images"
}
},
{
"granted": true,
"permission": "compute.disks.useReadOnly",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"service": "compute",
"type": "compute.disks"
}
}
],
"methodName": "v1.compute.images.insert",
"request": {
"@type": "type.googleapis.com/compute.images.insert",
"name": "dwg2-dw743447",
"sourceDisk": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"sourceType": "RAW"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.create invocation-id/7369f3ed5f84474abd89b1c4ccd0b473 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:38:58.652253Z"
}
},
"resourceLocation": {
"currentLocations": [
"us"
]
},
"resourceName": "projects/example-project-id/global/images/dwg2-dw743447",
"serviceName": "compute.googleapis.com",
"status": {
"code": 3,
"message": "com.google.apps.framework.request.StatusException: <eye3 title='INVALID_ARGUMENT'/> generic::INVALID_ARGUMENT: The disk resource 'projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447' is already being used by 'projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447'"
}
},
"receiveTimestamp": "2026-06-29T14:38:58.893529541Z",
"resource": {
"labels": {
"image_id": "",
"project_id": "example-project-id"
},
"type": "gce_image"
},
"severity": "ERROR",
"timestamp": "2026-06-29T14:38:58.359563Z"
}
compute.images.list: list
#Description
Retrieves the list of custom images available to the specified project. Custom images are images you create that belong to your project. This method does not get any images that belong to other projects, including publicly-available images, like Debian 8. If you want to get a list of publicly-available images, use this method to make a request to the respective image project, such as debian-cloud or windows-cloud.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "i1lqyze2hmce",
"labels": {
"compute.googleapis.com/root_trigger_id": "550f4e25-9496-4d5f-9dd7-dbc26e0ce168"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.images.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.images.list",
"request": {
"@type": "type.googleapis.com/compute.images.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.list invocation-id/4edabe620cd94f8dbf8c0704ba22df76 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:18.598416Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/images",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:19.144001039Z",
"resource": {
"labels": {
"image_id": "",
"project_id": "example-project-id"
},
"type": "gce_image"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:18.527169Z"
}
compute.images.patch: patch
#Description
Patches the specified image with the data included in the request. Only the following fields can be modified: family, description, deprecation status.
compute.images.setIamPolicy: Set image IAM policy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
Example Audit Log Entry #
{
"insertId": "-nualo9e7gz96",
"labels": {
"compute.googleapis.com/root_trigger_id": "a84c4564-f203-4820-8834-ef43f4bee33a"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.images.setIamPolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/images/dwimg7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/images/dwimg7201353",
"service": "compute",
"type": "compute.images"
}
}
],
"methodName": "v1.compute.images.setIamPolicy",
"request": {
"@type": "type.googleapis.com/compute.images.setIamPolicy",
"policy": {
"bindings": [
{
"members": [
"user:user@example.com"
],
"role": "roles/compute.imageUser"
}
],
"etag": "\u0000 \u0001",
"version": "3"
}
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.images.add-iam-policy-binding invocation-id/4e1305315d774dd7956df13292bf3847 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:22:13.126852Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/images/dwimg7201353",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:22:13.729414065Z",
"resource": {
"labels": {
"image_id": "2102812314665166192",
"project_id": "example-project-id"
},
"type": "gce_image"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:22:12.879476Z"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
protoPayload.response.error (panther rule field) | is_null | | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1537Panther #
compute.images.setLabels: setLabels
#Description
Sets the labels on an image. To learn more about labels, read theLabeling Resources documentation.
compute.images.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.instanceGroupManagerResizeRequests.cancel: cancel
#Description
Cancels the specified resize request and removes it from the queue. Cancelled resize request does no longer wait for the resources to be provisioned. Cancel is only possible for requests that are accepted in the queue.
compute.instanceGroupManagerResizeRequests.delete: delete
#Description
Deletes the specified, inactive resize request. Requests that are still active cannot be deleted. Deleting request does not delete instances that were provisioned previously.
compute.instanceGroupManagerResizeRequests.get: get
#Description
Returns all of the details about the specified resize request.
Data Access audit logs are disabled by default.
compute.instanceGroupManagerResizeRequests.insert: insert
#Description
Creates a new resize request that starts provisioning VMs immediately or queues VM creation.
compute.instanceGroupManagerResizeRequests.list: list
#Description
Retrieves a list of resize requests that are contained in the managed instance group.
Data Access audit logs are disabled by default.
compute.instanceGroupManagers.abandonInstances: abandonInstances
#Description
Flags the specified instances to be removed from the managed instance group. Abandoning an instance does not delete the instance, but it does remove the instance from any target pools that are applied by the managed instance group. This method reduces thetargetSize of the managed instance group by the number of instances that you abandon. This operation is marked asDONE when the action is scheduled even if the instances have not yet been removed from the group. You must separately verify the status of the abandoning action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.
compute.instanceGroupManagers.aggregatedList: aggregatedList
#Description
Retrieves the list of managed instance groups and groups them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.instanceGroupManagers.applyUpdatesToInstances: applyUpdatesToInstances
#Description
Applies changes to selected instances on the managed instance group. This method can be used to apply new overrides and/or new versions.
compute.instanceGroupManagers.createInstances: createInstances
#Description
Creates instances with per-instance configurations in this managed instance group. Instances are created using the current instance template. Thecreate instances operation is marked DONE if thecreateInstances request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or actions with the listmanagedinstances method.
compute.instanceGroupManagers.delete: delete
#Description
Deletes the specified managed instance group and all of the instances in that group. Note that the instance group must not belong to a backend service. Read Deleting an instance group for more information.
Example Audit Log Entry #
{
"insertId": "1p6mmle2hwia",
"labels": {
"compute.googleapis.com/root_trigger_id": "62a07eaf-a7d8-4e79-bffe-60b4c74da171"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceGroupManagers.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"service": "compute",
"type": "compute.instanceGroupManagers"
}
},
{
"granted": true,
"permission": "compute.instanceGroups.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"service": "compute",
"type": "compute.instanceGroups"
}
}
],
"methodName": "v1.compute.instanceGroupManagers.delete",
"request": {
"@type": "type.googleapis.com/compute.instanceGroupManagers.delete"
},
"requestMetadata": {
"callerIp": "private",
"callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:40:11.651369Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"response": {
"@type": "type.googleapis.com/operation",
"id": "4956059394064203044",
"insertTime": "2026-06-29T07:40:11.614-07:00",
"name": "operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
"operationType": "compute.instanceGroupManagers.delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/4956059394064203044",
"startTime": "2026-06-29T07:40:11.618-07:00",
"status": "RUNNING",
"targetId": "1685950597165956322",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:40:11.784159677Z",
"resource": {
"labels": {
"instance_group_manager_id": "1685950597165956322",
"instance_group_manager_name": "gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"location": "us-central1-a",
"project_id": "example-project-id"
},
"type": "gce_instance_group_manager"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:40:11.539378Z"
}
compute.instanceGroupManagers.deleteInstances: deleteInstances
#Description
Flags the specified instances in the managed instance group for immediate deletion. The instances are also removed from any target pools of which they were a member. This method reduces thetargetSize of the managed instance group by the number of instances that you delete. This operation is marked as DONE when the action is scheduled even if the instances are still being deleted. You must separately verify the status of the deleting action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.
compute.instanceGroupManagers.deletePerInstanceConfigs: deletePerInstanceConfigs
#Description
Deletes selected per-instance configurations for the managed instance group.
compute.instanceGroupManagers.get: get
#Description
Returns all of the details about the specified managed instance group.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "tpalqwe77ipw",
"labels": {
"compute.googleapis.com/root_trigger_id": "90e13af1-8556-441b-8b89-b624c3f7df00"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceGroupManagers.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"service": "compute",
"type": "compute.instanceGroupManagers"
}
}
],
"methodName": "v1.compute.instanceGroupManagers.get",
"request": {
"@type": "type.googleapis.com/compute.instanceGroupManagers.get"
},
"requestMetadata": {
"callerIp": "private",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:45:16.554263Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"serviceName": "compute.googleapis.com",
"status": {
"code": 5,
"message": "The resource 'projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp' was not found"
}
},
"receiveTimestamp": "2026-06-29T14:45:16.693762735Z",
"resource": {
"labels": {
"instance_group_manager_id": "0",
"instance_group_manager_name": "gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"location": "us-central1-a",
"project_id": "example-project-id"
},
"type": "gce_instance_group_manager"
},
"severity": "ERROR",
"timestamp": "2026-06-29T14:45:16.501910Z"
}
compute.instanceGroupManagers.insert: insert
#Description
Creates a managed instance group using the information that you specify in the request. After the group is created, instances in the group are created using the specified instance template. This operation is marked as DONE when the group is created even if the instances in the group have not yet been created. You must separately verify the status of the individual instances with thelistmanagedinstances method. A managed instance group can have up to 1000 VM instances per group. Please contact Cloud Support if you need an increase in this limit.
Example Audit Log Entry #
{
"insertId": "-8tusg9e9vddc",
"labels": {
"compute.googleapis.com/root_trigger_id": "a53cde13-994a-425a-a98b-19e47439782b"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745481589-65565c727b46b-74638acf-0963a398",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceGroupManagers.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
"service": "compute",
"type": "compute.instanceGroupManagers"
}
},
{
"granted": true,
"permission": "compute.instances.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwn3-dw745304-0000",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwn3-dw745304-0000",
"service": "compute",
"type": "compute.instances"
}
},
{
"granted": true,
"permission": "compute.disks.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwn3-dw745304-0000",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwn3-dw745304-0000",
"service": "compute",
"type": "compute.disks"
}
},
{
"granted": true,
"permission": "compute.subnetworks.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
"service": "compute",
"type": "compute.subnetworks"
}
},
{
"granted": true,
"permission": "compute.instances.setMetadata",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwn3-dw745304-0000",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwn3-dw745304-0000",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instanceGroupManagers.insert",
"request": {
"@type": "type.googleapis.com/compute.instanceGroupManagers.insert",
"instanceTemplate": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/instanceTemplates/dwn3-dw745304",
"name": "dwn3-dw745304",
"targetSize": "0"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-groups.managed.create invocation-id/7e67413d65f54759bfafd552a4d923d4 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:04:43.235256Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "6067619727955408740",
"insertTime": "2026-06-29T08:04:43.182-07:00",
"name": "operation-1782745481589-65565c727b46b-74638acf-0963a398",
"operationType": "compute.instanceGroupManagers.insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782745481589-65565c727b46b-74638acf-0963a398",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/6067619727955408740",
"startTime": "2026-06-29T08:04:43.186-07:00",
"status": "RUNNING",
"targetId": "345848323240834916",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:04:43.693330607Z",
"resource": {
"labels": {
"instance_group_manager_id": "345848323240834916",
"instance_group_manager_name": "dwn3-dw745304",
"location": "us-central1-a",
"project_id": "example-project-id"
},
"type": "gce_instance_group_manager"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:04:41.655635Z"
}
compute.instanceGroupManagers.list: list
#Description
Retrieves a list of managed instance groups that are contained within the specified project and zone.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "w7t0nwe4yf04",
"labels": {
"compute.googleapis.com/root_trigger_id": "a61b2872-e37a-4b5f-9e2e-de55f324c314"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceGroupManagers.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.instanceGroupManagers.list",
"request": {
"@type": "type.googleapis.com/compute.instanceGroupManagers.list"
},
"requestMetadata": {
"callerIp": "private",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:45:18.719038Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:45:19.409278616Z",
"resource": {
"labels": {
"instance_group_manager_id": "",
"instance_group_manager_name": "",
"location": "us-central1-a",
"project_id": "example-project-id"
},
"type": "gce_instance_group_manager"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:45:18.685570Z"
}
compute.instanceGroupManagers.listErrors: listErrors
#Description
Lists all errors thrown by actions on instances for a given managed instance group. The filter and orderBy query parameters are not supported.
Data Access audit logs are disabled by default.
compute.instanceGroupManagers.listManagedInstances: listManagedInstances
#Description
Lists all of the instances in the managed instance group. Each instance in the list has a currentAction, which indicates the action that the managed instance group is performing on the instance. For example, if the group is still creating an instance, the currentAction is CREATING. If a previous action failed, the list displays the errors for that failed action. The orderBy query parameter is not supported. The `pageToken` query parameter is supported only if the group's `listManagedInstancesResults` field is set to `PAGINATED`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-3vex0udzg1u",
"labels": {
"compute.googleapis.com/root_trigger_id": "09a44e07-6edf-4a1d-8800-e08c22147835"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceGroupManagers.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"service": "compute",
"type": "compute.instanceGroupManagers"
}
}
],
"methodName": "v1.compute.instanceGroupManagers.listManagedInstances",
"request": {
"@type": "type.googleapis.com/compute.instanceGroupManagers.listManagedInstances"
},
"requestMetadata": {
"callerIp": "private",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:42:00.570559Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:42:01.028859167Z",
"resource": {
"labels": {
"instance_group_manager_id": "1685950597165956322",
"instance_group_manager_name": "gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"location": "us-central1-a",
"project_id": "example-project-id"
},
"type": "gce_instance_group_manager"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:42:00.502057Z"
}
compute.instanceGroupManagers.listPerInstanceConfigs: listPerInstanceConfigs
#Description
Lists all of the per-instance configurations defined for the managed instance group. The orderBy query parameter is not supported.
Data Access audit logs are disabled by default.
compute.instanceGroupManagers.patch: patch
#Description
Updates a managed instance group using the information that you specify in the request. This operation is marked as DONE when the group is patched even if the instances in the group are still in the process of being patched. You must separately verify the status of the individual instances with thelistManagedInstances method. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. If you update your group to specify a new template or instance configuration, it's possible that your intended specification for each VM in the group is different from the current state of that VM. To learn how to apply an updated configuration to the VMs in a MIG, seeUpdating instances in a MIG.
compute.instanceGroupManagers.patchPerInstanceConfigs: patchPerInstanceConfigs
#Description
Inserts or patches per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.
compute.instanceGroupManagers.recreateInstances: recreateInstances
#Description
Flags the specified VM instances in the managed instance group to be immediately recreated. Each instance is recreated using the group's current configuration. This operation is marked as DONE when the flag is set even if the instances have not yet been recreated. You must separately verify the status of each instance by checking itscurrentAction field; for more information, see Checking the status of managed instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.
compute.instanceGroupManagers.resize: resize
#Description
Resizes the managed instance group. If you increase the size, the group creates new instances using the current instance template. If you decrease the size, the group deletes instances. The resize operation is markedDONE when the resize actions are scheduled even if the group has not yet added or deleted any instances. You must separately verify the status of the creating or deleting actions with thelistmanagedinstances method. When resizing down, the instance group arbitrarily chooses the order in which VMs are deleted. The group takes into account some VM attributes when making the selection including: + The status of the VM instance. + The health of the VM instance. + The instance template version the VM is based on. + For regional managed instance groups, the location of the VM instance. This list is subject to change. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted.
compute.instanceGroupManagers.resumeInstances: resumeInstances
#Description
Flags the specified instances in the managed instance group to be resumed. This method increases thetargetSize and decreases the targetSuspendedSize of the managed instance group by the number of instances that you resume. The resumeInstances operation is marked DONE if the resumeInstances request is successful. The underlying actions take additional time. You must separately verify the status of theRESUMING action with thelistmanagedinstances method. In this request, you can only specify instances that are suspended. For example, if an instance was previously suspended using the suspendInstances method, it can be resumed using the resumeInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are resumed. You can specify a maximum of 1000 instances with this method per request.
compute.instanceGroupManagers.setInstanceTemplate: setInstanceTemplate
#Description
Specifies the instance template to use when creating new instances in this group. The templates for existing instances in the group do not change unless you run recreateInstances, runapplyUpdatesToInstances, or set the group'supdatePolicy.type to PROACTIVE.
compute.instanceGroupManagers.setTargetPools: setTargetPools
#Description
Modifies the target pools to which all instances in this managed instance group are assigned. The target pools automatically apply to all of the instances in the managed instance group. This operation is markedDONE when you make the request even if the instances have not yet been added to their target pools. The change might take some time to apply to all of the instances in the group depending on the size of the group.
compute.instanceGroupManagers.startInstances: startInstances
#Description
Flags the specified instances in the managed instance group to be started. This method increases thetargetSize and decreases the targetStoppedSize of the managed instance group by the number of instances that you start. The startInstances operation is marked DONE if the startInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTARTING action with thelistmanagedinstances method. In this request, you can only specify instances that are stopped. For example, if an instance was previously stopped using the stopInstances method, it can be started using the startInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are started. You can specify a maximum of 1000 instances with this method per request.
compute.instanceGroupManagers.stopInstances: stopInstances
#Description
Flags the specified instances in the managed instance group to be immediately stopped. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetStoppedSize of the managed instance group by the number of instances that you stop. The stopInstances operation is marked DONE if the stopInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTOPPING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays stopping the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is stopped. Stopped instances can be started using the startInstances method. You can specify a maximum of 1000 instances with this method per request.
compute.instanceGroupManagers.suspendInstances: suspendInstances
#Description
Flags the specified instances in the managed instance group to be immediately suspended. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetSuspendedSize of the managed instance group by the number of instances that you suspend. The suspendInstances operation is marked DONE if the suspendInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSUSPENDING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays suspension of the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is suspended. Suspended instances can be resumed using the resumeInstances method. You can specify a maximum of 1000 instances with this method per request.
compute.instanceGroupManagers.updatePerInstanceConfigs: updatePerInstanceConfigs
#Description
Inserts or updates per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.
compute.instanceGroups.addInstances: addInstances
#Description
Adds a list of instances to the specified instance group. All of the instances in the instance group must be in the same network/subnetwork. Read Adding instances for more information.
compute.instanceGroups.aggregatedList: aggregatedList
#Description
Retrieves the list of instance groups and sorts them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "cspgjwe6akq6",
"labels": {
"compute.googleapis.com/root_trigger_id": "6ffaf0d4-0a5a-4a13-9d00-f4a5eb8998d3"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceGroups.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.instanceGroups.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.instanceGroups.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-groups.list invocation-id/3713116eaa63429aa5926242b2f6e5b0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:35.912021Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/instanceGroups",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:36.925169374Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.instanceGroups.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:35.851309Z"
}
compute.instanceGroups.delete: delete
#Description
Deletes the specified instance group. The instances in the group are not deleted. Note that instance group must not belong to a backend service. Read Deleting an instance group for more information.
compute.instanceGroups.get: get
#Description
Returns the specified zonal instance group. Get a list of available zonal instance groups by making a list() request. For managed instance groups, use theinstanceGroupManagers or regionInstanceGroupManagers methods instead.
Data Access audit logs are disabled by default.
compute.instanceGroups.insert: insert
#Description
Creates an instance group in the specified project using the parameters that are included in the request.
Example Audit Log Entry #
{
"insertId": "50063md3cli",
"labels": {
"compute.googleapis.com/root_trigger_id": "a53cde13-994a-425a-a98b-19e47439782b"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745485069-65565c75ccb7b-75b04204-44600cd1",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceGroups.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
"service": "compute",
"type": "compute.instanceGroups"
}
}
],
"methodName": "v1.compute.instanceGroups.insert",
"request": {
"@type": "type.googleapis.com/compute.instanceGroups.insert",
"description": "This instance group is controlled by Instance Group Manager 'dwn3-dw745304'. To modify instances in this group, use the Instance Group Manager API: https://cloud.google.com/compute/docs/reference/latest/instanceGroupManagers",
"name": "dwn3-dw745304",
"network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn3-dw745304",
"requestId": "a85c428f-5380-3ba8-846f-54d37e249e43"
},
"requestMetadata": {
"callerSuppliedUserAgent": "GCE Managed Instance Group",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:04:46.246015Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/000000000000/zones/us-central1-a/instanceGroups/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"clientOperationId": "a85c428f-5380-3ba8-846f-54d37e249e43",
"id": "3853369069582366561",
"insertTime": "2026-06-29T08:04:46.207-07:00",
"name": "operation-1782745485069-65565c75ccb7b-75b04204-44600cd1",
"operationType": "compute.instanceGroups.insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782745485069-65565c75ccb7b-75b04204-44600cd1",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/3853369069582366561",
"startTime": "2026-06-29T08:04:46.211-07:00",
"status": "RUNNING",
"targetId": "577154529996257121",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:04:46.839546323Z",
"resource": {
"labels": {
"instance_group_id": "577154529996257121",
"instance_group_name": "dwn3-dw745304",
"location": "us-central1-a",
"project_id": "example-project-id"
},
"type": "gce_instance_group"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:04:45.037214Z"
}
compute.instanceGroups.list: list
#Description
Retrieves the list of zonal instance group resources contained within the specified zone. For managed instance groups, use theinstanceGroupManagers or regionInstanceGroupManagers methods instead.
Data Access audit logs are disabled by default.
compute.instanceGroups.listInstances: listInstances
#Description
Lists the instances in the specified instance group. The orderBy query parameter is not supported. The filter query parameter is supported, but only for expressions that use `eq` (equal) or `ne` (not equal) operators.
Data Access audit logs are disabled by default.
compute.instanceGroups.removeInstances: removeInstances
#Description
Removes one or more instances from the specified instance group, but does not delete those instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration before the VM instance is removed or deleted.
Example Audit Log Entry #
{
"insertId": "-jnmjked85oi",
"labels": {
"compute.googleapis.com/root_trigger_id": "62a07eaf-a7d8-4e79-bffe-60b4c74da171"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782744012776-655656f9b6533-39a8caae-8d2370f8",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
"principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceGroups.update",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"service": "compute",
"type": "compute.instanceGroups"
}
}
],
"methodName": "v1.compute.instanceGroups.removeInstances",
"request": {
"@type": "type.googleapis.com/compute.instanceGroups.removeInstances",
"instances": [
{
"instance": "https://www.googleapis.com/compute/v1/projects/000000000000/zones/us-central1-a/instances/gke-dwgke-dw743447-default-pool-d20f3f37-s2rw"
}
],
"requestId": "74ba3e1c-b051-4234-89e1-238de676d9ff"
},
"requestMetadata": {
"callerSuppliedUserAgent": "GCE Managed Instance Group for GKE",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:40:12.869962Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/000000000000/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"response": {
"@type": "type.googleapis.com/operation",
"clientOperationId": "74ba3e1c-b051-4234-89e1-238de676d9ff",
"id": "2725981313053965603",
"insertTime": "2026-06-29T07:40:12.842-07:00",
"name": "operation-1782744012776-655656f9b6533-39a8caae-8d2370f8",
"operationType": "compute.instanceGroups.removeInstances",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782744012776-655656f9b6533-39a8caae-8d2370f8",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/2725981313053965603",
"startTime": "2026-06-29T07:40:12.846-07:00",
"status": "RUNNING",
"targetId": "7820809400904269055",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroups/gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:40:13.837104183Z",
"resource": {
"labels": {
"instance_group_id": "7820809400904269055",
"instance_group_name": "gke-dwgke-dw743447-default-pool-d20f3f37-grp",
"location": "us-central1-a",
"project_id": "example-project-id"
},
"type": "gce_instance_group"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:40:12.749902Z"
}
compute.instanceGroups.setNamedPorts: setNamedPorts
#Description
Sets the named ports for the specified instance group.
Example Audit Log Entry #
{
"insertId": "ve9s30dxc9g",
"labels": {
"compute.googleapis.com/root_trigger_id": "44c3d8a8-fe67-462c-9e24-47442927b3fa"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745505522-65565c894e1cc-6ebd8cf7-5ac43db4",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceGroups.update",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
"service": "compute",
"type": "compute.instanceGroups"
}
},
{
"granted": true,
"permission": "compute.instanceGroupManagers.update",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instanceGroupManagers/dwn3-dw745304",
"service": "compute",
"type": "compute.instanceGroupManagers"
}
}
],
"methodName": "v1.compute.instanceGroups.setNamedPorts",
"request": {
"@type": "type.googleapis.com/compute.instanceGroups.setNamedPorts",
"fingerprint": "�e�J�|�#",
"namedPorts": [
{
"name": "http",
"port": "80"
}
]
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-groups.managed.set-named-ports invocation-id/a3f63a4e9b654fd1911ec959188c8e04 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:05:05.823823Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "2091809115258959694",
"insertTime": "2026-06-29T08:05:05.734-07:00",
"name": "operation-1782745505522-65565c894e1cc-6ebd8cf7-5ac43db4",
"operationType": "compute.instanceGroups.setNamedPorts",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782745505522-65565c894e1cc-6ebd8cf7-5ac43db4",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/2091809115258959694",
"startTime": "2026-06-29T08:05:05.759-07:00",
"status": "RUNNING",
"targetId": "577154529996257121",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instanceGroups/dwn3-dw745304",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:05:06.783285141Z",
"resource": {
"labels": {
"instance_group_id": "577154529996257121",
"instance_group_name": "dwn3-dw745304",
"location": "us-central1-a",
"project_id": "example-project-id"
},
"type": "gce_instance_group"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:05:05.577760Z"
}
compute.instanceGroups.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.instanceSettings.get: get
#Description
Get Instance settings.
Data Access audit logs are disabled by default.
compute.instanceSettings.patch: patch
#Description
Patch Instance settings
compute.instanceTemplates.aggregatedList: aggregatedList
#Description
Retrieves the list of all InstanceTemplates resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-cfdl6ee5e9oc",
"labels": {
"compute.googleapis.com/root_trigger_id": "b78e21bb-bc45-472e-a767-328ec82eb72d"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceTemplates.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.instanceTemplates.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.instanceTemplates.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-templates.list invocation-id/930603099a79484eb82778f47acf32b0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:37.254012Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/instanceTemplates",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:37.342101398Z",
"resource": {
"labels": {
"instance_template_id": "",
"instance_template_name": "",
"project_id": "example-project-id"
},
"type": "gce_instance_template"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:37.087908Z"
}
compute.instanceTemplates.delete: delete
#Description
Deletes the specified instance template. Deleting an instance template is permanent and cannot be undone. It is not possible to delete templates that are already in use by a managed instance group.
compute.instanceTemplates.get: get
#Description
Returns the specified instance template.
Data Access audit logs are disabled by default.
compute.instanceTemplates.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.instanceTemplates.insert: insert
#Description
Creates an instance template in the specified project using the data that is included in the request. If you are creating a new template to update an existing instance group, your new instance template must use the same network or, if applicable, the same subnetwork as the original template.
Example Audit Log Entry #
{
"insertId": "-skhss4e1vyny",
"labels": {
"compute.googleapis.com/root_trigger_id": "a4c6ada8-3b32-4b38-a891-79839d619128"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745477457-65565c6e8a700-e695b3c6-bb88279a",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceTemplates.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/instanceTemplates/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/instanceTemplates/dwn3-dw745304",
"service": "compute",
"type": "compute.instanceTemplates"
}
}
],
"methodName": "v1.compute.instanceTemplates.insert",
"request": {
"@type": "type.googleapis.com/compute.instanceTemplates.insert",
"name": "dwn3-dw745304",
"properties": {
"canIpForward": false,
"disks": [
{
"autoDelete": true,
"boot": true,
"initializeParams": {
"sourceImage": "https://compute.googleapis.com/compute/v1/projects/debian-cloud/global/images/family/debian-12"
},
"mode": "READ_WRITE",
"type": "PERSISTENT"
}
],
"machineType": "e2-micro",
"networkInterfaces": [
{
"network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn3-dw745304",
"subnetwork": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304"
}
],
"scheduling": {
"automaticRestart": true
},
"serviceAccounts": [
{
"email": "default",
"scopes": [
"https://www.googleapis.com/auth/devstorage.read_only",
"https://www.googleapis.com/auth/logging.write",
"https://www.googleapis.com/auth/monitoring.write",
"https://www.googleapis.com/auth/pubsub",
"https://www.googleapis.com/auth/service.management.readonly",
"https://www.googleapis.com/auth/servicecontrol",
"https://www.googleapis.com/auth/trace.append"
]
}
]
}
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instance-templates.create invocation-id/5a3d91579d004ed39da655a0fe8e7d5c environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:04:38.617699Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/instanceTemplates/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "5920604410457569130",
"insertTime": "2026-06-29T08:04:38.013-07:00",
"name": "operation-1782745477457-65565c6e8a700-e695b3c6-bb88279a",
"operationType": "compute.instanceTemplates.insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745477457-65565c6e8a700-e695b3c6-bb88279a",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/5920604410457569130",
"startTime": "2026-06-29T08:04:38.021-07:00",
"status": "RUNNING",
"targetId": "8340466719637059434",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/instanceTemplates/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:04:38.922494070Z",
"resource": {
"labels": {
"instance_template_id": "8340466719637059434",
"instance_template_name": "dwn3-dw745304",
"project_id": "example-project-id"
},
"type": "gce_instance_template"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:04:37.443345Z"
}
compute.instanceTemplates.list: list
#Description
Retrieves a list of instance templates that are contained within the specified project.
Data Access audit logs are disabled by default.
compute.instanceTemplates.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.instanceTemplates.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.instances.addAccessConfig: addAccessConfig
#Description
Adds an access config to an instance's network interface.
compute.instances.addNetworkInterface: addNetworkInterface
#Description
Adds one dynamic network interface to an active instance.
compute.instances.addResourcePolicies: addResourcePolicies
#Description
Adds existing resource policies to an instance. You can only add one policy right now which will be applied to this instance for scheduling live migrations.
compute.instances.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of all of the instances in your project across all regions and zones. The performance of this method degrades when a filter is specified on a project that has a very large number of instances. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-itsf8hd9oq6",
"labels": {
"compute.googleapis.com/root_trigger_id": "859732ab-aaf8-4568-b210-a38c8c8be283"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.instances.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.instances.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.list invocation-id/2d3139518284463aa5b59952a1f85319 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:15.606661Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/instances",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:16.566105439Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.instances.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:15.505076Z"
}
compute.instances.attachDisk: attachDisk
#Description
Attaches an existing Disk resource to an instance. You must first create the disk before you can attach it. It is not possible to create and attach a disk at the same time. For more information, readAdding a persistent disk to your instance.
Example Audit Log Entry #
{
"insertId": "-e55srie5utqm",
"labels": {
"compute.googleapis.com/root_trigger_id": "dce0bcf8-17be-4032-87b0-984b3e642e4b"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782743852172-655656608c53d-43528019-ebf883b6",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.attachDisk",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"service": "compute",
"type": "compute.instances"
}
},
{
"granted": true,
"permission": "compute.instances.attachDisk",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"service": "compute",
"type": "compute.instances"
}
},
{
"granted": true,
"permission": "compute.disks.use",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"service": "compute",
"type": "compute.disks"
}
}
],
"metadata": {
"newlyAttachedDisks": [
"https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447"
]
},
"methodName": "v1.compute.instances.attachDisk",
"request": {
"@type": "type.googleapis.com/compute.instances.attachDisk",
"mode": "READ_WRITE",
"source": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwg2-dw743447",
"type": "PERSISTENT"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.attach-disk invocation-id/831f1871873b4bf89423683252cbf706 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:37:32.444925Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"response": {
"@type": "type.googleapis.com/operation",
"id": "5682035452659318211",
"insertTime": "2026-06-29T07:37:32.400-07:00",
"name": "operation-1782743852172-655656608c53d-43528019-ebf883b6",
"operationType": "attachDisk",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743852172-655656608c53d-43528019-ebf883b6",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/5682035452659318211",
"startTime": "2026-06-29T07:37:32.413-07:00",
"status": "RUNNING",
"targetId": "8625152016897752154",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:37:33.403599438Z",
"resource": {
"labels": {
"instance_id": "8625152016897752154",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:37:32.138847Z"
}
compute.instances.bulkInsert: bulkInsert
#Description
Creates multiple instances. Count specifies the number of instances to create. For more information, seeAbout bulk creation of VMs.
compute.instances.delete: Delete instance
#Description
Deletes the specified Instance resource.
Example Audit Log Entry #
{
"insertId": "-rf4oqfe3rqoi",
"labels": {
"compute.googleapis.com/root_trigger_id": "3f730e65-c1fb-4c1a-924e-30eb647dfb04"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782739364482-655645a8c0d32-75bbae64-ac155e53",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.delete",
"request": {
"@type": "type.googleapis.com/compute.instances.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.delete invocation-id/0212d0008d6c48538b97a407d580cc5f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:22:44.702678Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"response": {
"@type": "type.googleapis.com/operation",
"id": "257884863283056459",
"insertTime": "2026-06-29T06:22:44.643-07:00",
"name": "operation-1782739364482-655645a8c0d32-75bbae64-ac155e53",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782739364482-655645a8c0d32-75bbae64-ac155e53",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/257884863283056459",
"startTime": "2026-06-29T06:22:44.659-07:00",
"status": "RUNNING",
"targetId": "6832792478432612219",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:22:44.944124935Z",
"resource": {
"labels": {
"instance_id": "6832792478432612219",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T13:22:44.528790Z"
}
compute.instances.deleteAccessConfig: deleteAccessConfig
#Description
Deletes an access config from an instance's network interface.
compute.instances.deleteNetworkInterface: deleteNetworkInterface
#Description
Deletes one dynamic network interface from an active instance. InstancesDeleteNetworkInterfaceRequest indicates: - instance from which to delete, using project+zone+resource_id fields; - dynamic network interface to be deleted, using network_interface_name field;
compute.instances.detachDisk: detachDisk
#Description
Detaches a disk from an instance.
Example Audit Log Entry #
{
"insertId": "-s8ztz9e5x406",
"labels": {
"compute.googleapis.com/root_trigger_id": "3e52829c-95a6-4be8-a27c-9d8ce576ed1e"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.detachDisk",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"service": "compute",
"type": "compute.instances"
}
},
{
"granted": true,
"permission": "compute.instances.detachDisk",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.detachDisk",
"request": {
"@type": "type.googleapis.com/compute.instances.detachDisk",
"deviceName": "persistent-disk-0"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.detach-disk invocation-id/600a917e325b4964a9d4a28e12a56bac environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:37:36.746066Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"serviceName": "compute.googleapis.com",
"status": {
"code": 3,
"message": "com.google.apps.framework.request.StatusException: <eye3 title='INVALID_ARGUMENT'/> generic::INVALID_ARGUMENT: To detach the boot disk, the instance must be in TERMINATED state."
}
},
"receiveTimestamp": "2026-06-29T14:37:37.103650910Z",
"resource": {
"labels": {
"instance_id": "8625152016897752154",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "ERROR",
"timestamp": "2026-06-29T14:37:36.643490Z"
}
compute.instances.get: get
#Description
Returns the specified Instance resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-2zon9ze5iuae",
"labels": {
"compute.googleapis.com/root_trigger_id": "adf2b608-1267-45a6-81e0-adb137dd4652"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.get",
"request": {
"@type": "type.googleapis.com/compute.instances.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.create invocation-id/d3a99ae5add44e01b925c5905c2c65e4 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:22:41.441586Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:22:42.106687928Z",
"resource": {
"labels": {
"instance_id": "6832792478432612219",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:22:41.347029Z"
}
compute.instances.getEffectiveFirewalls: getEffectiveFirewalls
#Description
Returns effective firewalls applied to an interface of the instance.
Data Access audit logs are disabled by default.
compute.instances.getGuestAttributes: getGuestAttributes
#Description
Returns the specified guest attributes entry.
Data Access audit logs are disabled by default.
compute.instances.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.instances.getScreenshot: getScreenshot
#Description
Returns the screenshot from the specified instance.
Data Access audit logs are disabled by default.
compute.instances.getSerialPortOutput: getSerialPortOutput
#Description
Returns the last 1 MB of serial port output from the specified instance.
Data Access audit logs are disabled by default.
compute.instances.getShieldedInstanceIdentity: getShieldedInstanceIdentity
#Description
Returns the Shielded Instance Identity of an instance
Data Access audit logs are disabled by default.
compute.instances.insert: Insert instance
#Description
Creates an instance resource in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-e3f928e3ga12",
"labels": {
"compute.googleapis.com/root_trigger_id": "9f284959-8561-48b5-8d51-a7b1f59fbc11"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782739348249-65564599459f9-31ad5434-c32a2182",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"service": "compute",
"type": "compute.instances"
}
},
{
"granted": true,
"permission": "compute.disks.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwgen-dw739065",
"service": "compute",
"type": "compute.disks"
}
},
{
"granted": true,
"permission": "compute.subnetworks.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
"service": "compute",
"type": "compute.subnetworks"
}
},
{
"granted": true,
"permission": "compute.instances.setServiceAccount",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"service": "compute",
"type": "compute.instances"
}
}
],
"metadata": {
"usedResources": {
"attachedDisks": [
{
"isBootDisk": true,
"sourceImage": "https://www.googleapis.com/compute/v1/projects/707281592825/global/images/debian-12-bookworm-v20260609",
"sourceImageId": "1449487925682397051"
}
]
}
},
"methodName": "v1.compute.instances.insert",
"request": {
"@type": "type.googleapis.com/compute.instances.insert",
"canIpForward": false,
"deletionProtection": false,
"disks": [
{
"autoDelete": true,
"boot": true,
"initializeParams": {
"sourceImage": "https://compute.googleapis.com/compute/v1/projects/debian-cloud/zones/-/imageFamilyViews/debian-12"
},
"mode": "READ_WRITE",
"type": "PERSISTENT"
}
],
"machineType": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/machineTypes/e2-micro",
"name": "dwgen-dw739065",
"networkInterfaces": [
{
"network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwgen-dw739065",
"subnetwork": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065"
}
],
"scheduling": {
"automaticRestart": true
},
"serviceAccounts": [
{
"email": "default",
"scopes": [
"https://www.googleapis.com/auth/devstorage.read_only",
"https://www.googleapis.com/auth/logging.write",
"https://www.googleapis.com/auth/monitoring.write",
"https://www.googleapis.com/auth/pubsub",
"https://www.googleapis.com/auth/service.management.readonly",
"https://www.googleapis.com/auth/servicecontrol",
"https://www.googleapis.com/auth/trace.append"
]
}
]
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.create invocation-id/d3a99ae5add44e01b925c5905c2c65e4 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:22:29.317225Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"response": {
"@type": "type.googleapis.com/operation",
"id": "1827009396319702906",
"insertTime": "2026-06-29T06:22:29.259-07:00",
"name": "operation-1782739348249-65564599459f9-31ad5434-c32a2182",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782739348249-65564599459f9-31ad5434-c32a2182",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/1827009396319702906",
"startTime": "2026-06-29T06:22:29.260-07:00",
"status": "RUNNING",
"targetId": "6832792478432612219",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwgen-dw739065",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:22:29.474987645Z",
"resource": {
"labels": {
"instance_id": "6832792478432612219",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T13:22:28.317183Z"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
protoPayload.response.error (panther rule field) | is_null | | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1548
compute.instances.list: list
#Description
Retrieves the list of instances contained within the specified zone.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-gvpyildz3ls",
"labels": {
"compute.googleapis.com/root_trigger_id": "38ee7910-9033-4434-b350-841b56b9358b"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.instances.list",
"request": {
"@type": "type.googleapis.com/compute.instances.list"
},
"requestMetadata": {
"callerIp": "private",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:45:18.566574Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:45:19.179629259Z",
"resource": {
"labels": {
"instance_id": "",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:45:18.485852Z"
}
compute.instances.listReferrers: listReferrers
#Description
Retrieves a list of resources that refer to the VM instance specified in the request. For example, if the VM instance is part of a managed or unmanaged instance group, the referrers list includes the instance group. For more information, readViewing referrers to VM instances.
Data Access audit logs are disabled by default.
compute.instances.migrateOnHostMaintenance: migrateOnHostMaintenance
#Description
Google-initiated live migration of a VM to new host hardware. Appears in system_event audit logs (cloudaudit.googleapis.com/system_event), not admin_activity. Not user-callable; emitted by GCE infrastructure.
compute.instances.performMaintenance: performMaintenance
#Description
Perform a manual maintenance on the instance.
compute.instances.removeResourcePolicies: removeResourcePolicies
#Description
Removes resource policies from an instance.
compute.instances.reportHostAsFaulty: reportHostAsFaulty
#Description
Mark the host as faulty and try to restart the instance on a new host.
compute.instances.reset: reset
#Description
Performs a reset on the instance. This is a hard reset. The VM does not do a graceful shutdown. For more information, seeResetting an instance.
Example Audit Log Entry #
{
"insertId": "l40d5ke7szkk",
"labels": {
"compute.googleapis.com/root_trigger_id": "27ce5016-a489-4df2-bb6a-e29b4fc953f2"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782743814685-6556563ccc280-2a348516-04852af5",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.reset",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.reset",
"request": {
"@type": "type.googleapis.com/compute.instances.reset"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.reset invocation-id/846fad68d9444087a2964f89190bc7f0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:36:54.808986Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"response": {
"@type": "type.googleapis.com/operation",
"id": "5195633674857430505",
"insertTime": "2026-06-29T07:36:54.764-07:00",
"name": "operation-1782743814685-6556563ccc280-2a348516-04852af5",
"operationType": "reset",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743814685-6556563ccc280-2a348516-04852af5",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/5195633674857430505",
"startTime": "2026-06-29T07:36:54.778-07:00",
"status": "RUNNING",
"targetId": "8625152016897752154",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:36:55.215287288Z",
"resource": {
"labels": {
"instance_id": "8625152016897752154",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:36:54.660973Z"
}
compute.instances.resume: resume
#Description
Resumes an instance that was suspended using theinstances().suspend method.
compute.instances.sendDiagnosticInterrupt: sendDiagnosticInterrupt
#Description
Sends diagnostic interrupt to the instance.
compute.instances.setDeletionProtection: setDeletionProtection
#Description
Sets deletion protection on the instance.
Example Audit Log Entry #
{
"insertId": "wqya8he2pwsu",
"labels": {
"compute.googleapis.com/root_trigger_id": "9be27c43-5b44-464d-9f14-ba4a1947ef7e"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746089523-65565eb6407bc-2c494aae-d0a8b144",
"last": true,
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.setDeletionProtection",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.setDeletionProtection",
"request": {
"@type": "type.googleapis.com/compute.instances.setDeletionProtection",
"deletionProtection": false
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.update invocation-id/76794def4fba4ae68d9cfb0a68b7d6ac environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:14:49.807226Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"endTime": "2026-06-29T08:14:49.757-07:00",
"id": "7526662050172318982",
"insertTime": "2026-06-29T08:14:49.729-07:00",
"name": "operation-1782746089523-65565eb6407bc-2c494aae-d0a8b144",
"operationType": "setDeletionProtection",
"progress": "100",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746089523-65565eb6407bc-2c494aae-d0a8b144",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/7526662050172318982",
"startTime": "2026-06-29T08:14:49.757-07:00",
"status": "DONE",
"targetId": "7874721179023389984",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:14:49.831220538Z",
"resource": {
"labels": {
"instance_id": "7874721179023389984",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:14:49.578034Z"
}
compute.instances.setDiskAutoDelete: setDiskAutoDelete
#Description
Sets the auto-delete flag for a disk attached to an instance.
compute.instances.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.instances.setLabels: setLabels
#Description
Sets labels on an instance. To learn more about labels, read theLabeling Resources documentation.
Example Audit Log Entry #
{
"insertId": "-lcuq8zd933y",
"labels": {
"compute.googleapis.com/root_trigger_id": "028556a2-d06b-4dcd-ba01-47b86211366d"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782743746550-655655fbd1c6c-8fd2de16-7bbeb6e0",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.setLabels",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.setLabels",
"request": {
"@type": "type.googleapis.com/compute.instances.setLabels",
"labelFingerprint": "�e�J�|�#",
"labels": [
{
"key": "env",
"value": "dw"
}
]
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.add-labels invocation-id/fa92fcadcb2a4b7da8498f1dd16d1e1b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:35:46.797701Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"response": {
"@type": "type.googleapis.com/operation",
"id": "1403337265143299117",
"insertTime": "2026-06-29T07:35:46.758-07:00",
"name": "operation-1782743746550-655655fbd1c6c-8fd2de16-7bbeb6e0",
"operationType": "compute.instance.setLabels",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743746550-655655fbd1c6c-8fd2de16-7bbeb6e0",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/1403337265143299117",
"startTime": "2026-06-29T07:35:46.760-07:00",
"status": "RUNNING",
"targetId": "8625152016897752154",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:35:47.295194898Z",
"resource": {
"labels": {
"instance_id": "8625152016897752154",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:35:46.610646Z"
}
compute.instances.setMachineResources: setMachineResources
#Description
Changes the number and/or type of accelerator for a stopped instance to the values specified in the request.
compute.instances.setMachineType: setMachineType
#Description
Changes the machine type for a stopped instance to the machine type specified in the request.
Example Audit Log Entry #
{
"insertId": "-u6xl5ed8jjy",
"labels": {
"compute.googleapis.com/root_trigger_id": "b930cfd9-d215-451b-82d1-9d045c89a3c1"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782743789380-65565624aa52c-6470aa91-b8bbe025",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.setMachineType",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.setMachineType",
"request": {
"@type": "type.googleapis.com/compute.instances.setMachineType",
"machineType": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/machineTypes/e2-small"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.set-machine-type invocation-id/dec895b1fd3c40a192d642b6bb70e151 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:36:29.675048Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"response": {
"@type": "type.googleapis.com/operation",
"id": "3980272502637018114",
"insertTime": "2026-06-29T07:36:29.600-07:00",
"name": "operation-1782743789380-65565624aa52c-6470aa91-b8bbe025",
"operationType": "setMachineType",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743789380-65565624aa52c-6470aa91-b8bbe025",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/3980272502637018114",
"startTime": "2026-06-29T07:36:29.626-07:00",
"status": "RUNNING",
"targetId": "8625152016897752154",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:36:29.762500589Z",
"resource": {
"labels": {
"instance_id": "8625152016897752154",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:36:29.428814Z"
}
References #
compute.instances.setMetadata: Set instance metadata
#Description
Sets metadata for the specified instance to the data included in the request.
Example Audit Log Entry #
{
"insertId": "v3xocbdko2q",
"labels": {
"compute.googleapis.com/root_trigger_id": "add18352-440d-4301-9bb2-7c703dbc5231"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782743755029-65565603e7d81-43af4565-66dabc0c",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.setMetadata",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"service": "compute",
"type": "compute.instances"
}
}
],
"metadata": {
"@type": "type.googleapis.com/google.cloud.audit.GceInstanceAuditMetadata",
"instanceMetadataDelta": {
"addedMetadataKeys": [
"dwk"
]
}
},
"methodName": "v1.compute.instances.setMetadata",
"request": {
"@type": "type.googleapis.com/compute.instances.setMetadata"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.add-metadata invocation-id/c5e59ff0ab5149719ead1164a3d0ca53 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:35:55.259710Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"response": {
"@type": "type.googleapis.com/operation",
"id": "4541556348049898532",
"insertTime": "2026-06-29T07:35:55.205-07:00",
"name": "operation-1782743755029-65565603e7d81-43af4565-66dabc0c",
"operationType": "setMetadata",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743755029-65565603e7d81-43af4565-66dabc0c",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/4541556348049898532",
"startTime": "2026-06-29T07:35:55.214-07:00",
"status": "RUNNING",
"targetId": "8625152016897752154",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:35:56.149233070Z",
"resource": {
"labels": {
"instance_id": "8625152016897752154",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:35:55.092178Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
compute.instances.setMinCpuPlatform: setMinCpuPlatform
#Description
Changes the minimum CPU platform that this instance should use. This method can only be called on a stopped instance. For more information, readSpecifying a Minimum CPU Platform.
compute.instances.setName: setName
#Description
Sets name of an instance.
compute.instances.setScheduling: setScheduling
#Description
Sets an instance's scheduling options. You can only call this method on astopped instance, that is, a VM instance that is in a `TERMINATED` state. SeeInstance Life Cycle for more information on the possible instance states. For more information about setting scheduling options for a VM, seeSet VM host maintenance policy.
Example Audit Log Entry #
{
"insertId": "-yobzz1dg1k8",
"labels": {
"compute.googleapis.com/root_trigger_id": "dfae2500-e9bc-4b48-9889-834b6d47cde0"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746078001-65565eab43945-b2fdba3b-d72a3c55",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.setScheduling",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.setScheduling",
"request": {
"@type": "type.googleapis.com/compute.instances.setScheduling",
"automaticRestart": true
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.set-scheduling invocation-id/9491c7d6868d4eeca76313a62a5e6010 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:14:38.450531Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"id": "8390035611510060337",
"insertTime": "2026-06-29T08:14:38.393-07:00",
"name": "operation-1782746078001-65565eab43945-b2fdba3b-d72a3c55",
"operationType": "setScheduling",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746078001-65565eab43945-b2fdba3b-d72a3c55",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/8390035611510060337",
"startTime": "2026-06-29T08:14:38.416-07:00",
"status": "RUNNING",
"targetId": "7874721179023389984",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:14:38.989371228Z",
"resource": {
"labels": {
"instance_id": "7874721179023389984",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:14:38.075339Z"
}
compute.instances.setSecurityPolicy: setSecurityPolicy
#Description
Sets the Google Cloud Armor security policy for the specified instance. For more information, seeGoogle Cloud Armor Overview
compute.instances.setServiceAccount: Set instance service account
#Description
Sets the service account on the instance.
compute.instances.setShieldedInstanceIntegrityPolicy: setShieldedInstanceIntegrityPolicy
#Description
Sets the Shielded Instance integrity policy for an instance. You can only use this method on a running instance. This method supports PATCH semantics and uses the JSON merge patch format and processing rules.
compute.instances.simulateMaintenanceEvent: simulateMaintenanceEvent
#Description
Simulates a host maintenance event on a VM. For more information, see Simulate a host maintenance event.
Example Audit Log Entry #
{
"insertId": "-mfuitke6wqfu",
"labels": {
"compute.googleapis.com/root_trigger_id": "b689ee1a-2822-4d19-b1f4-889316b3ccd2"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746083973-65565eb0f584c-fcd3ee82-102d6c30",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.simulateMaintenanceEvent",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.simulateMaintenanceEvent",
"request": {
"@type": "type.googleapis.com/compute.instances.simulateMaintenanceEvent"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.simulate-maintenance-event invocation-id/6f7b69a6c77e4acbac88dff56630ff87 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:14:44.138929Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"id": "3890946893801272587",
"insertTime": "2026-06-29T08:14:44.082-07:00",
"name": "operation-1782746083973-65565eb0f584c-fcd3ee82-102d6c30",
"operationType": "simulateMaintenanceEvent",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746083973-65565eb0f584c-fcd3ee82-102d6c30",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/3890946893801272587",
"startTime": "2026-06-29T08:14:44.099-07:00",
"status": "RUNNING",
"targetId": "7874721179023389984",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:14:44.348259732Z",
"resource": {
"labels": {
"instance_id": "7874721179023389984",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:14:43.925899Z"
}
compute.instances.start: Start instance
#Description
Starts an instance that was stopped using the stopInstance method.
Example Audit Log Entry #
{
"insertId": "78c42xdhomk",
"labels": {
"compute.googleapis.com/root_trigger_id": "b5a50223-9d8c-4f85-a753-17c05932cdd1"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782743791870-655656270a277-ee9a6bea-898081d8",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.start",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.start",
"request": {
"@type": "type.googleapis.com/compute.instances.start"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.start invocation-id/9e228f59439a4eb0a073ae5d07220c1c environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:36:32.318324Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"response": {
"@type": "type.googleapis.com/operation",
"id": "5697850376941681695",
"insertTime": "2026-06-29T07:36:32.236-07:00",
"name": "operation-1782743791870-655656270a277-ee9a6bea-898081d8",
"operationType": "start",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743791870-655656270a277-ee9a6bea-898081d8",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/5697850376941681695",
"startTime": "2026-06-29T07:36:32.266-07:00",
"status": "RUNNING",
"targetId": "8625152016897752154",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:36:32.880013442Z",
"resource": {
"labels": {
"instance_id": "8625152016897752154",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:36:31.920398Z"
}
compute.instances.startWithEncryptionKey: startWithEncryptionKey
#Description
Starts an instance that was stopped using theinstances().stop method. For more information, seeRestart an instance.
compute.instances.stop: Stop instance
#Description
Stops a running instance, shutting it down cleanly.
Example Audit Log Entry #
{
"insertId": "-4ov19xe6aqh6",
"labels": {
"compute.googleapis.com/root_trigger_id": "20cc77ee-276e-46a3-81f1-f750a8fea0cc"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782743758948-65565607a499a-6b0c45b8-83cea4ed",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.stop",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.stop",
"request": {
"@type": "type.googleapis.com/compute.instances.stop"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.stop invocation-id/ddebc192be3d4544a6e587e4cd020eca environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:35:59.096605Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"response": {
"@type": "type.googleapis.com/operation",
"id": "7917026563939318816",
"insertTime": "2026-06-29T07:35:59.059-07:00",
"name": "operation-1782743758948-65565607a499a-6b0c45b8-83cea4ed",
"operationType": "stop",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782743758948-65565607a499a-6b0c45b8-83cea4ed",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/7917026563939318816",
"startTime": "2026-06-29T07:35:59.067-07:00",
"status": "RUNNING",
"targetId": "8625152016897752154",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/instances/dwg2-dw743447",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:35:59.365101356Z",
"resource": {
"labels": {
"instance_id": "8625152016897752154",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:35:58.917057Z"
}
compute.instances.suspend: suspend
#Description
This method suspends a running instance, saving its state to persistent storage, and allows you to resume the instance at a later time. Suspended instances have no compute costs (cores or RAM), and incur only storage charges for the saved VM memory and localSSD data. Any charged resources the virtual machine was using, such as persistent disks and static IP addresses, will continue to be charged while the instance is suspended. For more information, see Suspending and resuming an instance.
compute.instances.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.instances.update: update
#Description
Updates an instance only if the necessary resources are available. This method can update only a specific set of instance properties. See Updating a running instance for a list of updatable instance properties.
compute.instances.updateAccessConfig: updateAccessConfig
#Description
Updates the specified access config from an instance's network interface with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.instances.updateDisplayDevice: updateDisplayDevice
#Description
Updates the Display config for a VM instance. You can only use this method on a stopped VM instance. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.instances.updateNetworkInterface: updateNetworkInterface
#Description
Updates an instance's network interface. This method can only update an interface's alias IP range and attached network. See Modifying alias IP ranges for an existing instance for instructions on changing alias IP ranges. See Migrating a VM between networks for instructions on migrating an interface. This method follows PATCH semantics.
compute.instances.updateShieldedInstanceConfig: updateShieldedInstanceConfig
#Description
Updates the Shielded Instance config for an instance. You can only use this method on a stopped instance. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
Example Audit Log Entry #
{
"insertId": "205zaye7f7vg",
"labels": {
"compute.googleapis.com/root_trigger_id": "d945faca-066d-45fa-a95d-5f460f8e9bdd"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instances.updateShieldedInstanceConfig",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"service": "compute",
"type": "compute.instances"
}
}
],
"methodName": "v1.compute.instances.updateShieldedInstanceConfig",
"request": {
"@type": "type.googleapis.com/compute.instances.updateShieldedInstanceConfig",
"enableSecureBoot": true
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.update invocation-id/7e4cb1bff7b64c91a0a114dcd73a7db1 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:14:42.614675Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/instances/dwn4-dw745960",
"serviceName": "compute.googleapis.com",
"status": {
"code": 3,
"message": "com.google.apps.framework.request.StatusException: <eye3 title='INVALID_ARGUMENT'/> generic::INVALID_ARGUMENT: Instance should be in the STOPPED state."
}
},
"receiveTimestamp": "2026-06-29T15:14:42.770550186Z",
"resource": {
"labels": {
"instance_id": "7874721179023389984",
"project_id": "example-project-id",
"zone": "us-central1-a"
},
"type": "gce_instance"
},
"severity": "ERROR",
"timestamp": "2026-06-29T15:14:42.506739Z"
}
compute.instantSnapshotGroups.delete: delete
#Description
deletes a Zonal InstantSnapshotGroup resource
compute.instantSnapshotGroups.get: get
#Description
returns the specified InstantSnapshotGroup resource in the specified zone.
Data Access audit logs are disabled by default.
compute.instantSnapshotGroups.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.instantSnapshotGroups.insert: insert
#Description
inserts a Zonal InstantSnapshotGroup resource
compute.instantSnapshotGroups.list: list
#Description
retrieves the list of InstantSnapshotGroup resources contained within the specified zone.
Data Access audit logs are disabled by default.
compute.instantSnapshotGroups.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.instantSnapshotGroups.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.instantSnapshots.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of instantSnapshots. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.instantSnapshots.delete: delete
#Description
Deletes the specified InstantSnapshot resource. Keep in mind that deleting a single instantSnapshot might not necessarily delete all the data on that instantSnapshot. If any data on the instantSnapshot that is marked for deletion is needed for subsequent instantSnapshots, the data will be moved to the next corresponding instantSnapshot. For more information, seeDeleting instantSnapshots.
compute.instantSnapshots.get: get
#Description
Returns the specified InstantSnapshot resource in the specified zone.
Data Access audit logs are disabled by default.
compute.instantSnapshots.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.instantSnapshots.insert: insert
#Description
Creates an instant snapshot in the specified zone.
compute.instantSnapshots.list: list
#Description
Retrieves the list of InstantSnapshot resources contained within the specified zone.
Data Access audit logs are disabled by default.
compute.instantSnapshots.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.instantSnapshots.setLabels: setLabels
#Description
Sets the labels on a instantSnapshot in the given zone. To learn more about labels, read the Labeling Resources documentation.
compute.instantSnapshots.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.interconnectAttachmentGroups.delete: delete
#Description
Deletes the specified InterconnectAttachmentGroup in the given scope
compute.interconnectAttachmentGroups.get: get
#Description
Returns the specified InterconnectAttachmentGroup resource in the given scope.
Data Access audit logs are disabled by default.
compute.interconnectAttachmentGroups.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.interconnectAttachmentGroups.getOperationalStatus: getOperationalStatus
#Description
Returns the InterconnectAttachmentStatuses for the specified InterconnectAttachmentGroup resource.
Data Access audit logs are disabled by default.
compute.interconnectAttachmentGroups.insert: insert
#Description
Creates a InterconnectAttachmentGroup in the specified project in the given scope using the parameters that are included in the request.
compute.interconnectAttachmentGroups.list: list
#Description
Lists the InterconnectAttachmentGroups for a project in the given scope.
Data Access audit logs are disabled by default.
compute.interconnectAttachmentGroups.patch: patch
#Description
Patches the specified InterconnectAttachmentGroup resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.
compute.interconnectAttachmentGroups.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.interconnectAttachmentGroups.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.interconnectAttachments.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of interconnect attachments. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.interconnectAttachments.delete: delete
#Description
Deletes the specified interconnect attachment.
compute.interconnectAttachments.get: get
#Description
Returns the specified interconnect attachment.
Data Access audit logs are disabled by default.
compute.interconnectAttachments.insert: insert
#Description
Creates an InterconnectAttachment in the specified project using the data included in the request.
compute.interconnectAttachments.list: list
#Description
Retrieves the list of interconnect attachments contained within the specified region.
Data Access audit logs are disabled by default.
compute.interconnectAttachments.patch: patch
#Description
Updates the specified interconnect attachment with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.interconnectAttachments.setLabels: setLabels
#Description
Sets the labels on an InterconnectAttachment. To learn more about labels, read the Labeling Resources documentation.
compute.interconnectGroups.createMembers: createMembers
#Description
Create Interconnects with redundancy by creating them in a specified interconnect group.
compute.interconnectGroups.delete: delete
#Description
Deletes the specified InterconnectGroup in the given scope
compute.interconnectGroups.get: get
#Description
Returns the specified InterconnectGroup resource in the given scope.
Data Access audit logs are disabled by default.
compute.interconnectGroups.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.interconnectGroups.getOperationalStatus: getOperationalStatus
#Description
Returns the interconnectStatuses for the specified InterconnectGroup.
Data Access audit logs are disabled by default.
compute.interconnectGroups.insert: insert
#Description
Creates a InterconnectGroup in the specified project in the given scope using the parameters that are included in the request.
compute.interconnectGroups.list: list
#Description
Lists the InterconnectGroups for a project in the given scope.
Data Access audit logs are disabled by default.
compute.interconnectGroups.patch: patch
#Description
Patches the specified InterconnectGroup resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.
compute.interconnectGroups.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.interconnectGroups.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.interconnectLocations.get: get
#Description
Returns the details for the specified interconnect location. Gets a list of available interconnect locations by making a list() request.
Data Access audit logs are disabled by default.
compute.interconnectLocations.list: list
#Description
Retrieves the list of interconnect locations available to the specified project.
Data Access audit logs are disabled by default.
compute.interconnectRemoteLocations.get: get
#Description
Returns the details for the specified interconnect remote location. Gets a list of available interconnect remote locations by making alist() request.
Data Access audit logs are disabled by default.
compute.interconnectRemoteLocations.list: list
#Description
Retrieves the list of interconnect remote locations available to the specified project.
Data Access audit logs are disabled by default.
compute.interconnects.delete: delete
#Description
Deletes the specified Interconnect.
compute.interconnects.get: get
#Description
Returns the specified Interconnect. Get a list of available Interconnects by making a list() request.
Data Access audit logs are disabled by default.
compute.interconnects.getDiagnostics: getDiagnostics
#Description
Returns the interconnectDiagnostics for the specified Interconnect. In the event of a global outage, do not use this API to make decisions about where to redirect your network traffic. Unlike a VLAN attachment, which is regional, a Cloud Interconnect connection is a global resource. A global outage can prevent this API from functioning properly.
Data Access audit logs are disabled by default.
compute.interconnects.getMacsecConfig: getMacsecConfig
#Description
Returns the interconnectMacsecConfig for the specified Interconnect.
Data Access audit logs are disabled by default.
compute.interconnects.insert: insert
#Description
Creates an Interconnect in the specified project using the data included in the request.
compute.interconnects.list: list
#Description
Retrieves the list of Interconnects available to the specified project.
Data Access audit logs are disabled by default.
compute.interconnects.patch: patch
#Description
Updates the specified Interconnect with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.interconnects.setLabels: setLabels
#Description
Sets the labels on an Interconnect. To learn more about labels, read the Labeling Resources documentation.
compute.licenseCodes.get: get
#Description
Return a specified license code. License codes are mirrored across all projects that have permissions to read the License Code. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
Data Access audit logs are disabled by default.
compute.licenseCodes.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
Data Access audit logs are disabled by default.
compute.licenseCodes.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
compute.licenseCodes.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
Data Access audit logs are disabled by default.
compute.licenses.delete: delete
#Description
Deletes the specified license. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
compute.licenses.get: get
#Description
Returns the specified License resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
Data Access audit logs are disabled by default.
compute.licenses.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
Data Access audit logs are disabled by default.
compute.licenses.insert: insert
#Description
Create a License resource in the specified project. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
compute.licenses.list: list
#Description
Retrieves the list of licenses available in the specified project. This method does not get any licenses that belong to other projects, including licenses attached to publicly-available images, like Debian 9. If you want to get a list of publicly-available licenses, use this method to make a request to the respective image project, such as debian-cloud orwindows-cloud. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
Data Access audit logs are disabled by default.
compute.licenses.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
compute.licenses.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
Data Access audit logs are disabled by default.
compute.licenses.update: update
#Description
Updates a License resource in the specified project. *Caution* This resource is intended for use only by third-party partners who are creatingCloud Marketplace images.
compute.machineImages.delete: delete
#Description
Deletes the specified machine image. Deleting a machine image is permanent and cannot be undone.
compute.machineImages.get: get
#Description
Returns the specified machine image.
Data Access audit logs are disabled by default.
compute.machineImages.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.machineImages.insert: insert
#Description
Creates a machine image in the specified project using the data that is included in the request. If you are creating a new machine image to update an existing instance, your new machine image should use the same network or, if applicable, the same subnetwork as the original instance.
compute.machineImages.list: list
#Description
Retrieves a list of machine images that are contained within the specified project.
Data Access audit logs are disabled by default.
compute.machineImages.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.machineImages.setLabels: setLabels
#Description
Sets the labels on a machine image. To learn more about labels, read theLabeling Resources documentation.
compute.machineImages.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.machineTypes.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of machine types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-1dujd6e82pik",
"labels": {
"compute.googleapis.com/root_trigger_id": "4fccf947-da17-489c-942a-ee9c28f393a7"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.machineTypes.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.machineTypes.aggregatedList",
"numResponseItems": "174",
"request": {
"@type": "type.googleapis.com/compute.machineTypes.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.machine-types.list invocation-id/e886be2aae2c4fd093fbe0707c3bfc99 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:38.745828Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/machineTypes",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:39.007032476Z",
"resource": {
"labels": {
"method": "compute.machineTypes.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com"
},
"type": "audited_resource"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:38.489101Z"
}
compute.machineTypes.get: get
#Description
Returns the specified machine type.
Data Access audit logs are disabled by default.
compute.machineTypes.list: list
#Description
Retrieves a list of machine types available to the specified project.
Data Access audit logs are disabled by default.
compute.networkAttachments.aggregatedList: aggregatedList
#Description
Retrieves the list of all NetworkAttachment resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "jg2adgdeaxe",
"labels": {
"compute.googleapis.com/root_trigger_id": "f112729a-b4f8-49c1-b95e-830a686d0cc2"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.networkAttachments.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.networkAttachments.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.networkAttachments.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.network-attachments.list invocation-id/5f8a323239a245f8bd650dc406fecc7f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:37:21.932350Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/networkAttachments",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:37:22.783706353Z",
"resource": {
"labels": {
"method": "compute.networkAttachments.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com"
},
"type": "audited_resource"
},
"severity": "INFO",
"timestamp": "2026-06-29T15:37:21.764309Z"
}
compute.networkAttachments.delete: delete
#Description
Deletes the specified NetworkAttachment in the given scope
compute.networkAttachments.get: get
#Description
Returns the specified NetworkAttachment resource in the given scope.
Data Access audit logs are disabled by default.
compute.networkAttachments.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.networkAttachments.insert: insert
#Description
Creates a NetworkAttachment in the specified project in the given scope using the parameters that are included in the request.
compute.networkAttachments.list: list
#Description
Lists the NetworkAttachments for a project in the given scope.
Data Access audit logs are disabled by default.
compute.networkAttachments.patch: patch
#Description
Patches the specified NetworkAttachment resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.
compute.networkAttachments.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.networkAttachments.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.networkEdgeSecurityServices.aggregatedList: aggregatedList
#Description
Retrieves the list of all NetworkEdgeSecurityService resources available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.networkEdgeSecurityServices.delete: delete
#Description
Deletes the specified service.
compute.networkEdgeSecurityServices.get: get
#Description
Gets a specified NetworkEdgeSecurityService.
Data Access audit logs are disabled by default.
compute.networkEdgeSecurityServices.insert: insert
#Description
Creates a new service in the specified project using the data included in the request.
compute.networkEdgeSecurityServices.patch: patch
#Description
Patches the specified policy with the data included in the request.
compute.networkEndpointGroups.aggregatedList: aggregatedList
#Description
Retrieves the list of network endpoint groups and sorts them by zone. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-k7y0nbe548ny",
"labels": {
"compute.googleapis.com/root_trigger_id": "9e04a39a-16f1-44ff-a78c-6752232ea4e5"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.networkEndpointGroups.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.networkEndpointGroups.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.networkEndpointGroups.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.network-endpoint-groups.list invocation-id/6e13d01c96994bc4afa24167a350e74a environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:51.977958Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/networkEndpointGroups",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:52.400218554Z",
"resource": {
"labels": {
"network_id": "",
"project_id": "example-project-id"
},
"type": "gce_network"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:51.895857Z"
}
compute.networkEndpointGroups.attachNetworkEndpoints: attachNetworkEndpoints
#Description
Attach a list of network endpoints to the specified network endpoint group.
compute.networkEndpointGroups.delete: delete
#Description
Deletes the specified network endpoint group. The network endpoints in the NEG and the VM instances they belong to are not terminated when the NEG is deleted. Note that the NEG cannot be deleted if there are backend services referencing it.
Example Audit Log Entry #
{
"insertId": "-xi95u4dngjq",
"labels": {
"compute.googleapis.com/root_trigger_id": "8c5d3f0e-47db-413a-8de4-8d57f45fd9de"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782747011019-655662250f4d6-5cc50f10-1982011f",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.networkEndpointGroups.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
"service": "compute",
"type": "compute.networkEndpointGroups"
}
}
],
"methodName": "v1.compute.networkEndpointGroups.delete",
"request": {
"@type": "type.googleapis.com/compute.networkEndpointGroups.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.network-endpoint-groups.delete invocation-id/51e420b32ad64f02a666a5938e138619 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:30:11.273389Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"id": "4338565224294461804",
"insertTime": "2026-06-29T08:30:11.231-07:00",
"name": "operation-1782747011019-655662250f4d6-5cc50f10-1982011f",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782747011019-655662250f4d6-5cc50f10-1982011f",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/4338565224294461804",
"startTime": "2026-06-29T08:30:11.234-07:00",
"status": "RUNNING",
"targetId": "7803364244475293840",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:30:12.109634471Z",
"resource": {
"labels": {
"network_id": "7803364244475293840",
"project_id": "example-project-id"
},
"type": "gce_network"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:30:11.092254Z"
}
compute.networkEndpointGroups.detachNetworkEndpoints: detachNetworkEndpoints
#Description
Detach a list of network endpoints from the specified network endpoint group.
compute.networkEndpointGroups.get: get
#Description
Returns the specified network endpoint group.
Data Access audit logs are disabled by default.
compute.networkEndpointGroups.insert: insert
#Description
Creates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global API
Example Audit Log Entry #
{
"insertId": "64bq3re1qiis",
"labels": {
"compute.googleapis.com/root_trigger_id": "bb8fa697-4d82-4999-bd56-690f3a3327df"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746750858-6556612cf33b9-6c2eb5eb-743b7c3c",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.networkEndpointGroups.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
"service": "compute",
"type": "compute.networkEndpointGroups"
}
},
{
"granted": true,
"permission": "compute.subnetworks.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
"service": "compute",
"type": "compute.subnetworks"
}
}
],
"methodName": "v1.compute.networkEndpointGroups.insert",
"request": {
"@type": "type.googleapis.com/compute.networkEndpointGroups.insert",
"name": "dwn4-dw745960",
"network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn4-dw745960",
"networkEndpointType": "GCE_VM_IP_PORT",
"subnetwork": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.network-endpoint-groups.create invocation-id/828354231b78464fb10d8b7394a916cc environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:25:51.399857Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"id": "7407171911059189904",
"insertTime": "2026-06-29T08:25:51.365-07:00",
"name": "operation-1782746750858-6556612cf33b9-6c2eb5eb-743b7c3c",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746750858-6556612cf33b9-6c2eb5eb-743b7c3c",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/7407171911059189904",
"startTime": "2026-06-29T08:25:51.369-07:00",
"status": "RUNNING",
"targetId": "7803364244475293840",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/networkEndpointGroups/dwn4-dw745960",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:25:51.678512110Z",
"resource": {
"labels": {
"network_id": "7803364244475293840",
"project_id": "example-project-id"
},
"type": "gce_network"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:25:50.910626Z"
}
compute.networkEndpointGroups.list: list
#Description
Retrieves the list of network endpoint groups that are located in the specified project and zone.
Data Access audit logs are disabled by default.
compute.networkEndpointGroups.listNetworkEndpoints: listNetworkEndpoints
#Description
Lists the network endpoints in the specified network endpoint group.
Data Access audit logs are disabled by default.
compute.networkEndpointGroups.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.networkFirewallPolicies.addAssociation: addAssociation
#Description
Inserts an association for the specified firewall policy.
compute.networkFirewallPolicies.addPacketMirroringRule: addPacketMirroringRule
#Description
Inserts a packet mirroring rule into a firewall policy.
compute.networkFirewallPolicies.addRule: addRule
#Description
Inserts a rule into a firewall policy.
compute.networkFirewallPolicies.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of network firewall policies, listing network firewall policies from all applicable scopes (global and regional) and grouping the results per scope. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.networkFirewallPolicies.cloneRules: cloneRules
#Description
Copies rules to the specified firewall policy.
compute.networkFirewallPolicies.delete: delete
#Description
Deletes the specified policy.
compute.networkFirewallPolicies.get: get
#Description
Returns the specified network firewall policy.
Data Access audit logs are disabled by default.
compute.networkFirewallPolicies.getAssociation: getAssociation
#Description
Gets an association with the specified name.
Data Access audit logs are disabled by default.
compute.networkFirewallPolicies.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.networkFirewallPolicies.getPacketMirroringRule: getPacketMirroringRule
#Description
Gets a packet mirroring rule of the specified priority.
Data Access audit logs are disabled by default.
compute.networkFirewallPolicies.getRule: getRule
#Description
Gets a rule of the specified priority.
Data Access audit logs are disabled by default.
compute.networkFirewallPolicies.insert: insert
#Description
Creates a new policy in the specified project using the data included in the request.
compute.networkFirewallPolicies.list: list
#Description
Lists all the policies that have been configured for the specified project.
Data Access audit logs are disabled by default.
compute.networkFirewallPolicies.patch: patch
#Description
Patches the specified policy with the data included in the request.
compute.networkFirewallPolicies.patchPacketMirroringRule: patchPacketMirroringRule
#Description
Patches a packet mirroring rule of the specified priority.
compute.networkFirewallPolicies.patchRule: patchRule
#Description
Patches a rule of the specified priority.
compute.networkFirewallPolicies.removeAssociation: removeAssociation
#Description
Removes an association for the specified firewall policy.
compute.networkFirewallPolicies.removePacketMirroringRule: removePacketMirroringRule
#Description
Deletes a packet mirroring rule of the specified priority.
compute.networkFirewallPolicies.removeRule: removeRule
#Description
Deletes a rule of the specified priority.
compute.networkFirewallPolicies.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.networkFirewallPolicies.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.networkProfiles.get: get
#Description
Returns the specified network profile.
Data Access audit logs are disabled by default.
compute.networkProfiles.list: list
#Description
Retrieves a list of network profiles available to the specified project.
Data Access audit logs are disabled by default.
compute.networks.addPeering: addPeering
#Description
Adds a peering to the specified network.
Example Audit Log Entry #
{
"insertId": "swl1e8do8be",
"labels": {
"compute.googleapis.com/root_trigger_id": "57ee88c9-d544-45be-99c8-588c6fd6abe4"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746058046-65565e983bbe0-bfbc59ed-46cbb925",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.networks.addPeering",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/dwn4-dw745960",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.networks.addPeering",
"request": {
"@type": "type.googleapis.com/compute.networks.addPeering",
"networkPeering": {
"exchangeSubnetRoutes": true,
"name": "dwpeer-dw745960",
"network": "projects/example-project-id/global/networks/dwn4-dw745960b"
}
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.peerings.create invocation-id/6f98affa682140c5b259b9c06bdd7231 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:14:18.622865Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/networks/dwn4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"id": "1873623054340273445",
"insertTime": "2026-06-29T08:14:18.506-07:00",
"name": "operation-1782746058046-65565e983bbe0-bfbc59ed-46cbb925",
"operationType": "addPeering",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782746058046-65565e983bbe0-bfbc59ed-46cbb925",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/1873623054340273445",
"startTime": "2026-06-29T08:14:18.512-07:00",
"status": "RUNNING",
"targetId": "5998021114363590006",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn4-dw745960",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:14:19.321410593Z",
"resource": {
"labels": {
"network_id": "5998021114363590006",
"project_id": "example-project-id"
},
"type": "gce_network"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:14:18.133068Z"
}
compute.networks.cancelRequestRemovePeering: cancelRequestRemovePeering
#Description
Cancel requests to remove a peering from the specified network. Applicable only for PeeringConnection with update_strategy=CONSENSUS. Cancels a request to remove a peering from the specified network.
compute.networks.delete: Delete network
#Description
Deletes the specified network.
Example Audit Log Entry #
{
"insertId": "-nagnkyd7u2c",
"labels": {
"compute.googleapis.com/root_trigger_id": "bbc34177-c63e-4b25-b5cb-6b1f6ced00bb"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782747031605-65566238b0fc0-1b4af7a4-1abf6c3c",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.networks.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/dwn4-dw745960b",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/dwn4-dw745960b",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.networks.delete",
"request": {
"@type": "type.googleapis.com/compute.networks.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.delete invocation-id/299cef3c715d4158a4219838ef2b2401 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:30:32.042641Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/networks/dwn4-dw745960b",
"response": {
"@type": "type.googleapis.com/operation",
"id": "1851171834354938232",
"insertTime": "2026-06-29T08:30:31.874-07:00",
"name": "operation-1782747031605-65566238b0fc0-1b4af7a4-1abf6c3c",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782747031605-65566238b0fc0-1b4af7a4-1abf6c3c",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/1851171834354938232",
"startTime": "2026-06-29T08:30:31.879-07:00",
"status": "RUNNING",
"targetId": "7566947103947044178",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn4-dw745960b",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:30:32.626677364Z",
"resource": {
"labels": {
"network_id": "7566947103947044178",
"project_id": "example-project-id"
},
"type": "gce_network"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:30:31.655236Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485, T1562, T1562.007
compute.networks.get: get
#Description
Returns the specified network.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-e4v3uue6k7h4",
"labels": {
"compute.googleapis.com/root_trigger_id": "3e10409f-6f55-402d-8756-9275f9c6e9b6"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.networks.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/networks/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/dwgen-dw739065",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.networks.get",
"request": {
"@type": "type.googleapis.com/compute.networks.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.create invocation-id/4ffe3c8ff74e4802bb2de389b3abfd97 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:20:22.443917Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/networks/dwgen-dw739065",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:20:23.016580549Z",
"resource": {
"labels": {
"network_id": "7671908098842284004",
"project_id": "example-project-id"
},
"type": "gce_network"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:20:22.333850Z"
}
compute.networks.getEffectiveFirewalls: getEffectiveFirewalls
#Description
Returns the effective firewalls on a given network.
Data Access audit logs are disabled by default.
compute.networks.insert: Insert network
#Description
Creates a network in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-fr5a60dbv3a",
"labels": {
"compute.googleapis.com/root_trigger_id": "566f4e3e-4778-4185-b608-f9cc91a81118"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.networks.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/dwgen-dw739065",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.networks.insert",
"request": {
"@type": "type.googleapis.com/compute.networks.insert",
"autoCreateSubnetworks": false,
"name": "dwgen-dw739065",
"routingConfig": {
"routingMode": "REGIONAL"
}
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.create invocation-id/4ffe3c8ff74e4802bb2de389b3abfd97 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:20:12.125945Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/networks/dwgen-dw739065",
"response": {
"@type": "type.googleapis.com/operation",
"id": "6594312761464836068",
"insertTime": "2026-06-29T06:20:11.961-07:00",
"name": "operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782739211644-65564516feeec-39a0e6d7-d5a9bca6",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/6594312761464836068",
"startTime": "2026-06-29T06:20:11.965-07:00",
"status": "RUNNING",
"targetId": "7671908098842284004",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwgen-dw739065",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:20:12.928400261Z",
"resource": {
"labels": {
"network_id": "7671908098842284004",
"project_id": "example-project-id"
},
"type": "gce_network"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T13:20:11.709111Z"
}
compute.networks.list: list
#Description
Retrieves the list of networks available to the specified project.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-gm52fddl6t8",
"labels": {
"compute.googleapis.com/root_trigger_id": "855573e7-3d5c-48eb-b3ba-dc5081dd99a3"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.networks.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.networks.list",
"numResponseItems": "1",
"request": {
"@type": "type.googleapis.com/compute.networks.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.list invocation-id/bf953e2e98db48dbbb5a5a2e83bc37c8 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:24.064659Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/networks",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:24.920445819Z",
"resource": {
"labels": {
"network_id": "",
"project_id": "example-project-id"
},
"type": "gce_network"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:23.877108Z"
}
compute.networks.listPeeringRoutes: listPeeringRoutes
#Description
Lists the peering routes exchanged over peering connection.
Data Access audit logs are disabled by default.
compute.networks.patch: patch
#Description
Patches the specified network with the data included in the request. Only routingConfig can be modified.
compute.networks.removePeering: removePeering
#Description
Removes a peering from the specified network.
Example Audit Log Entry #
{
"insertId": "-4ocutgdnh8u",
"labels": {
"compute.googleapis.com/root_trigger_id": "cd9572bf-faef-4718-9442-86c762e7479e"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746987347-6556620e7bc5c-2a4d935a-4d1f9c95",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.networks.removePeering",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/dwn4-dw745960",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.networks.removePeering",
"request": {
"@type": "type.googleapis.com/compute.networks.removePeering",
"name": "dwpeer-dw745960"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.peerings.delete invocation-id/d8698bae2b5c4336a93609946ee302df environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:29:47.850685Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/networks/dwn4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"id": "4418389987514331524",
"insertTime": "2026-06-29T08:29:47.682-07:00",
"name": "operation-1782746987347-6556620e7bc5c-2a4d935a-4d1f9c95",
"operationType": "removePeering",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782746987347-6556620e7bc5c-2a4d935a-4d1f9c95",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/4418389987514331524",
"startTime": "2026-06-29T08:29:47.685-07:00",
"status": "RUNNING",
"targetId": "5998021114363590006",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn4-dw745960",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:29:48.515057058Z",
"resource": {
"labels": {
"network_id": "5998021114363590006",
"project_id": "example-project-id"
},
"type": "gce_network"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:29:47.453854Z"
}
compute.networks.requestRemovePeering: requestRemovePeering
#Description
Requests to remove a peering from the specified network. Applicable only for PeeringConnection with update_strategy=CONSENSUS.
compute.networks.switchToCustomMode: switchToCustomMode
#Description
Switches the network mode from auto subnet mode to custom subnet mode.
compute.networks.updatePeering: updatePeering
#Description
Updates the specified network peering with the data included in the request. You can only modify the NetworkPeering.export_custom_routes field and the NetworkPeering.import_custom_routes field.
compute.nodeGroups.addNodes: addNodes
#Description
Adds specified number of nodes to the node group.
compute.nodeGroups.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of node groups. Note: use nodeGroups.listNodes for more details about each group. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.nodeGroups.delete: delete
#Description
Deletes the specified NodeGroup resource.
compute.nodeGroups.deleteNodes: deleteNodes
#Description
Deletes specified nodes from the node group.
compute.nodeGroups.get: get
#Description
Returns the specified NodeGroup. Get a list of available NodeGroups by making a list() request. Note: the "nodes" field should not be used. Use nodeGroups.listNodes instead.
Data Access audit logs are disabled by default.
compute.nodeGroups.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.nodeGroups.insert: insert
#Description
Creates a NodeGroup resource in the specified project using the data included in the request.
compute.nodeGroups.list: list
#Description
Retrieves a list of node groups available to the specified project. Note: use nodeGroups.listNodes for more details about each group.
Data Access audit logs are disabled by default.
compute.nodeGroups.listNodes: listNodes
#Description
Lists nodes in the node group.
Data Access audit logs are disabled by default.
compute.nodeGroups.patch: patch
#Description
Updates the specified node group.
compute.nodeGroups.performMaintenance: performMaintenance
#Description
Perform maintenance on a subset of nodes in the node group.
compute.nodeGroups.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.nodeGroups.setNodeTemplate: setNodeTemplate
#Description
Updates the node template of the node group.
compute.nodeGroups.simulateMaintenanceEvent: simulateMaintenanceEvent
#Description
Simulates maintenance event on specified nodes from the node group.
compute.nodeGroups.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.nodeTemplates.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of node templates. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.nodeTemplates.delete: delete
#Description
Deletes the specified NodeTemplate resource.
compute.nodeTemplates.get: get
#Description
Returns the specified node template.
Data Access audit logs are disabled by default.
compute.nodeTemplates.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.nodeTemplates.insert: insert
#Description
Creates a NodeTemplate resource in the specified project using the data included in the request.
compute.nodeTemplates.list: list
#Description
Retrieves a list of node templates available to the specified project.
Data Access audit logs are disabled by default.
compute.nodeTemplates.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.nodeTemplates.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.nodeTypes.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of node types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.nodeTypes.get: get
#Description
Returns the specified node type.
Data Access audit logs are disabled by default.
compute.nodeTypes.list: list
#Description
Retrieves a list of node types available to the specified project.
Data Access audit logs are disabled by default.
compute.organizationSecurityPolicies.addAssociation: addAssociation
#Description
Inserts an association for the specified security policy. This has billing implications. Projects in the hierarchy with effective hierarchical security policies will be automatically enrolled into Cloud Armor Enterprise if not already enrolled. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.addAssociation instead.
compute.organizationSecurityPolicies.addRule: addRule
#Description
Inserts a rule into a security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.addRule instead.
compute.organizationSecurityPolicies.copyRules: copyRules
#Description
Copies rules to the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.cloneRules instead.
compute.organizationSecurityPolicies.delete: delete
#Description
Deletes the specified policy. Use this API to remove Cloud Armor policies. Previously, alpha and beta versions of this API were used to remove firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.delete instead.
compute.organizationSecurityPolicies.get: get
#Description
List all of the ordered rules present in a single specified policy. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.get instead.
Data Access audit logs are disabled by default.
compute.organizationSecurityPolicies.getAssociation: getAssociation
#Description
Gets an association with the specified name. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.getAssociation instead.
Data Access audit logs are disabled by default.
compute.organizationSecurityPolicies.getRule: getRule
#Description
Gets a rule at the specified priority. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.getRule instead.
Data Access audit logs are disabled by default.
compute.organizationSecurityPolicies.insert: insert
#Description
Creates a new policy in the specified organization using the data included in the request. Use this API to add Cloud Armor policies. Previously, alpha and beta versions of this API were used to add firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.insert instead.
compute.organizationSecurityPolicies.list: list
#Description
List all the policies that have been configured for the specified organization. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.list instead.
Data Access audit logs are disabled by default.
compute.organizationSecurityPolicies.listAssociations: listAssociations
#Description
Lists associations of a specified target, i.e., organization or folder. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.listAssociations instead.
Data Access audit logs are disabled by default.
compute.organizationSecurityPolicies.listPreconfiguredExpressionSets: listPreconfiguredExpressionSets
#Description
Gets the current list of preconfigured Web Application Firewall (WAF) expressions.
Data Access audit logs are disabled by default.
compute.organizationSecurityPolicies.move: move
#Description
Moves the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.move instead.
compute.organizationSecurityPolicies.patch: patch
#Description
Patches the specified policy with the data included in the request. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.patch instead.
compute.organizationSecurityPolicies.patchRule: patchRule
#Description
Patches a rule at the specified priority. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.patchRule instead.
compute.organizationSecurityPolicies.removeAssociation: removeAssociation
#Description
Removes an association for the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.removeAssociation instead.
compute.organizationSecurityPolicies.removeRule: removeRule
#Description
Deletes a rule at the specified priority. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.removeRule instead.
compute.packetMirrorings.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of packetMirrorings. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"insertId": "9pwzume1ynmy",
"labels": {
"compute.googleapis.com/root_trigger_id": "ee17f931-057e-4a18-bb35-5b76758edef9"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.packetMirrorings.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.packetMirrorings.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.packetMirrorings.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.list invocation-id/12a11e65a9734e288f42ced4ac87959f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:37:23.884617Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/packetMirrorings",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:37:24.601686865Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.packetMirrorings.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T15:37:23.786228Z"
}
Detection Rules #
Sigma #
T1074↳ also matches compute.packetMirrorings.delete: delete, compute.packetMirrorings.get: get, compute.packetMirrorings.insert: insert, compute.packetMirrorings.list: list, compute.packetMirrorings.patch: patch
compute.packetMirrorings.delete: delete
#Description
Deletes the specified PacketMirroring resource.
Example Audit Log Entry #
{
"insertId": "6fkv3oe8ix0q",
"labels": {
"compute.googleapis.com/root_trigger_id": "721c42a7-3d22-4d7d-9aab-2f830c6d7e1d"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750573622-65566f6a9f549-542a1129-6e0b02dc",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.packetMirrorings.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"service": "compute",
"type": "compute.packetMirrorings"
}
}
],
"methodName": "v1.compute.packetMirrorings.delete",
"request": {
"@type": "type.googleapis.com/compute.packetMirrorings.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.delete invocation-id/648641e189024ef68ee97594d0066733 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:29:33.796222Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"response": {
"@type": "type.googleapis.com/operation",
"id": "7757216706370413442",
"insertTime": "2026-06-29T09:29:33.742-07:00",
"name": "operation-1782750573622-65566f6a9f549-542a1129-6e0b02dc",
"operationType": "delete",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750573622-65566f6a9f549-542a1129-6e0b02dc",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/7757216706370413442",
"startTime": "2026-06-29T09:29:33.754-07:00",
"status": "RUNNING",
"targetId": "5883760359926342587",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:29:33.918274137Z",
"resource": {
"labels": {
"packet_mirroring_id": "5883760359926342587",
"project_id": "example-project-id",
"region": "us-central1"
},
"type": "gce_packet_mirroring"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:29:33.585710Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1074↳ also matches compute.packetMirrorings.aggregatedList: aggregatedList, compute.packetMirrorings.get: get, compute.packetMirrorings.insert: insert, compute.packetMirrorings.list: list, compute.packetMirrorings.patch: patch
compute.packetMirrorings.get: get
#Description
Returns the specified PacketMirroring resource.
Data Access audit logs are disabled by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"insertId": "-6n8gzve2y5xo",
"labels": {
"compute.googleapis.com/root_trigger_id": "a3476c5e-deb3-4197-946a-7a9c08ffbe05"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.packetMirrorings.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"service": "compute",
"type": "compute.packetMirrorings"
}
}
],
"methodName": "v1.compute.packetMirrorings.get",
"request": {
"@type": "type.googleapis.com/compute.packetMirrorings.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.update invocation-id/909c1465c63c451aa5009abeb4a6ee3b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:29:32.263379Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:29:32.414511169Z",
"resource": {
"labels": {
"packet_mirroring_id": "5883760359926342587",
"project_id": "example-project-id",
"region": "us-central1"
},
"type": "gce_packet_mirroring"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:29:32.207427Z"
}
Detection Rules #
Sigma #
T1074↳ also matches compute.packetMirrorings.aggregatedList: aggregatedList, compute.packetMirrorings.delete: delete, compute.packetMirrorings.insert: insert, compute.packetMirrorings.list: list, compute.packetMirrorings.patch: patch
compute.packetMirrorings.insert: insert
#Description
Creates a PacketMirroring resource in the specified project and region using the data included in the request.
Example Audit Log Entry #
{
"insertId": "p91rdme7do96",
"labels": {
"compute.googleapis.com/root_trigger_id": "00b92107-2c5f-40b1-82c6-23dbfc0c2df3"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750548249-65566f526ca8c-4ad47fd8-d63cd051",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.packetMirrorings.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"service": "compute",
"type": "compute.packetMirrorings"
}
},
{
"granted": true,
"permission": "compute.forwardingRules.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061",
"service": "compute",
"type": "compute.forwardingRules"
}
},
{
"granted": true,
"permission": "compute.subnetworks.mirror",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061",
"service": "compute",
"type": "compute.subnetworks"
}
}
],
"methodName": "v1.compute.packetMirrorings.insert",
"request": {
"@type": "type.googleapis.com/compute.packetMirrorings.insert",
"collectorIlb": {
"url": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061"
},
"enable": "TRUE",
"mirroredResources": {
"subnetworks": [
{
"url": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061"
}
]
},
"name": "dwpm7b671061",
"network": {
"url": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn7b671061"
}
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.create invocation-id/b20d4da1176b48d4973146e22e4c4fa6 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:29:08.563964Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"response": {
"@type": "type.googleapis.com/operation",
"id": "6865284541681968059",
"insertTime": "2026-06-29T09:29:08.421-07:00",
"name": "operation-1782750548249-65566f526ca8c-4ad47fd8-d63cd051",
"operationType": "insert",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750548249-65566f526ca8c-4ad47fd8-d63cd051",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/6865284541681968059",
"startTime": "2026-06-29T09:29:08.425-07:00",
"status": "RUNNING",
"targetId": "5883760359926342587",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:29:08.665374197Z",
"resource": {
"labels": {
"packet_mirroring_id": "5883760359926342587",
"project_id": "example-project-id",
"region": "us-central1"
},
"type": "gce_packet_mirroring"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:29:08.217873Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1074↳ also matches compute.packetMirrorings.aggregatedList: aggregatedList, compute.packetMirrorings.delete: delete, compute.packetMirrorings.get: get, compute.packetMirrorings.list: list, compute.packetMirrorings.patch: patch
compute.packetMirrorings.list: list
#Description
Retrieves a list of PacketMirroring resources available to the specified project and region.
Data Access audit logs are disabled by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example Audit Log Entry #
{
"insertId": "-wgflnle2gvf0",
"labels": {
"compute.googleapis.com/root_trigger_id": "2d39a0f6-15fe-424f-8df7-fac0980c12bf"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.packetMirrorings.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.packetMirrorings.list",
"numResponseItems": "1",
"request": {
"@type": "type.googleapis.com/compute.packetMirrorings.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.list invocation-id/42567f1762b5484798b4f5f11663e269 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:29:22.645628Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/packetMirrorings",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:29:23.175555774Z",
"resource": {
"labels": {
"packet_mirroring_id": "",
"project_id": "example-project-id",
"region": "us-central1"
},
"type": "gce_packet_mirroring"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:29:22.578243Z"
}
Detection Rules #
Sigma #
T1074↳ also matches compute.packetMirrorings.aggregatedList: aggregatedList, compute.packetMirrorings.delete: delete, compute.packetMirrorings.get: get, compute.packetMirrorings.insert: insert, compute.packetMirrorings.patch: patch
compute.packetMirrorings.patch: patch
#Description
Patches the specified PacketMirroring resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.
Example Audit Log Entry #
{
"insertId": "1g9dnwe50pay",
"labels": {
"compute.googleapis.com/root_trigger_id": "fb2682a3-c230-46ff-9ae0-c92e95b46f2a"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750564824-65566f623b6c9-4a5ccf5f-22efac3c",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.packetMirrorings.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"service": "compute",
"type": "compute.packetMirrorings"
}
},
{
"granted": true,
"permission": "compute.packetMirrorings.update",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"service": "compute",
"type": "compute.packetMirrorings"
}
},
{
"granted": true,
"permission": "compute.forwardingRules.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061",
"service": "compute",
"type": "compute.forwardingRules"
}
},
{
"granted": true,
"permission": "compute.subnetworks.mirror",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061",
"service": "compute",
"type": "compute.subnetworks"
}
}
],
"methodName": "v1.compute.packetMirrorings.patch",
"request": {
"@type": "type.googleapis.com/compute.packetMirrorings.patch",
"collectorIlb": {
"url": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/forwardingRules/dwfr7b671061"
},
"enable": "FALSE",
"filter": {
"direction": "BOTH"
},
"mirroredResources": {
"subnetworks": [
{
"url": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn7b671061"
}
]
},
"name": "dwpm7b671061",
"network": {
"url": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn7b671061"
},
"priority": "1000",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.packet-mirrorings.update invocation-id/909c1465c63c451aa5009abeb4a6ee3b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:29:25.272499Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"response": {
"@type": "type.googleapis.com/operation",
"id": "7232922343376364426",
"insertTime": "2026-06-29T09:29:25.096-07:00",
"name": "operation-1782750564824-65566f623b6c9-4a5ccf5f-22efac3c",
"operationType": "patch",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750564824-65566f623b6c9-4a5ccf5f-22efac3c",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/7232922343376364426",
"startTime": "2026-06-29T09:29:25.113-07:00",
"status": "RUNNING",
"targetId": "5883760359926342587",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/packetMirrorings/dwpm7b671061",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:29:25.572437637Z",
"resource": {
"labels": {
"packet_mirroring_id": "5883760359926342587",
"project_id": "example-project-id",
"region": "us-central1"
},
"type": "gce_packet_mirroring"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:29:24.786248Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1074↳ also matches compute.packetMirrorings.aggregatedList: aggregatedList, compute.packetMirrorings.delete: delete, compute.packetMirrorings.get: get, compute.packetMirrorings.insert: insert, compute.packetMirrorings.list: list
compute.packetMirrorings.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.previewFeatures.get: get
#Description
Returns the details of the given PreviewFeature.
Data Access audit logs are disabled by default.
compute.previewFeatures.list: list
#Description
Returns the details of the given PreviewFeature.
Data Access audit logs are disabled by default.
compute.previewFeatures.update: update
#Description
Patches the given PreviewFeature. This method is used to enable or disable a PreviewFeature.
compute.projects.disableXpnHost: disableXpnHost
#Description
Disable this project as a shared VPC host project.
compute.projects.disableXpnResource: disableXpnResource
#Description
Disable a service resource (also known as service project) associated with this host project.
compute.projects.enableXpnHost: enableXpnHost
#Description
Enable this project as a shared VPC host project.
compute.projects.enableXpnResource: enableXpnResource
#Description
Enable service resource (a.k.a service project) for a host project, so that subnets in the host project can be used by instances in the service project.
compute.projects.get: get
#Description
Returns the specified Project resource. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-7h2u9de25o6a",
"labels": {
"compute.googleapis.com/root_trigger_id": "4b7d3ecc-01de-43f1-a0fb-cd317550139e"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.projects.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "compute",
"type": "compute.projects"
}
}
],
"methodName": "v1.compute.projects.get",
"request": {
"@type": "type.googleapis.com/compute.projects.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.project-info.describe invocation-id/be8c61d7c6b24697a507bc7327b66878 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:19:05.918295Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:19:06.055587708Z",
"resource": {
"labels": {
"project_id": "000000000000"
},
"type": "gce_project"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:19:05.720255Z"
}
compute.projects.getXpnHost: getXpnHost
#Description
Gets the shared VPC host project that this project links to. May be empty if no link exists.
Data Access audit logs are disabled by default.
compute.projects.getXpnResources: getXpnResources
#Description
Gets service resources (a.k.a service project) associated with this host project.
Data Access audit logs are disabled by default.
compute.projects.listXpnHosts: listXpnHosts
#Description
Lists all shared VPC host projects visible to the user in an organization.
Data Access audit logs are disabled by default.
compute.projects.moveDisk: moveDisk
#Description
Moves a persistent disk from one zone to another. *Note*: The moveDisk API will be deprecated on September 29, 2026. Starting September 29, 2025, you can't use the moveDisk API on new projects. To move a disk to a different region or zone, follow the steps in Change the location of a disk. Projects that already use the moveDisk API can continue usage until September 29, 2026. Starting November 1, 2025, API responses will include a warning message in the response body about the upcoming deprecation. You can skip the message to continue using the service without interruption.
compute.projects.moveInstance: moveInstance
#Description
Moves an instance and its attached persistent disks from one zone to another. *Note*: Moving VMs or disks by using this method might cause unexpected behavior. For more information, see the known issue. [Deprecated] This method is deprecated. See moving instance across zones instead.
compute.projects.setCloudArmorTier: setCloudArmorTier
#Description
Sets the Cloud Armor tier of the project. To set ENTERPRISE or above the billing account of the project must be subscribed to Cloud Armor Enterprise. See Subscribing to Cloud Armor Enterprise for more information.
Example Audit Log Entry #
{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "user@domain.com"
},
"requestMetadata": {
"callerIp": "8.8.8.8",
"callerSuppliedUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.36,gzip(gfe),gzip(gfe)",
"requestAttributes": {
"time": "2021-09-13T02:52:16.762326Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "compute.googleapis.com",
"methodName": "v1.compute.projects.setCommonInstanceMetadata",
"authorizationInfo": [
{
"permission": "compute.projects.setCommonInstanceMetadata",
"granted": true,
"resourceAttributes": {
"service": "compute",
"name": "projects/gsec-monitoring-prod",
"type": "compute.projects"
}
},
{
"permission": "iam.serviceAccounts.actAs",
"granted": true,
"resourceAttributes": {
"service": "compute",
"name": "projects/gsec-monitoring-prod",
"type": "compute.projects"
}
}
],
"resourceName": "projects/gsec-monitoring-prod",
"request": {
"@type": "type.googleapis.com/compute.projects.setCommonInstanceMetadata"
},
"response": {
"progress": "0",
"@type": "type.googleapis.com/operation",
"targetLink": "https://www.googleapis.com/compute/v1/projects/gsec-monitoring-prod",
"startTime": "2021-09-12T19:52:16.415-07:00",
"selfLink": "https://www.googleapis.com/compute/v1/projects/gsec-monitoring-prod/global/operations/operation-1631501536060-5cbd78d81e54a-d0e05d0c-dc9f8e1f",
"user": "user@domain.com",
"name": "operation-1631501536060-5cbd78d81e54a-d0e05d0c-dc9f8e1f",
"targetId": "598897393088",
"operationType": "compute.projects.setCommonInstanceMetadata",
"id": "967174441535734287",
"insertTime": "2021-09-12T19:52:16.411-07:00",
"status": "RUNNING",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/gsec-monitoring-prod/global/operations/967174441535734287"
},
"resourceLocation": {
"currentLocations": [
"global"
]
}
},
"insertId": "-9pd595e2pu3i",
"resource": {
"type": "gce_project",
"labels": {
"project_id": "598897393088"
}
},
"timestamp": "2021-09-13T02:52:16.113032Z",
"severity": "NOTICE",
"logName": "projects/gsec-monitoring-prod/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"id": "operation-1631501536060-5cbd78d81e54a-d0e05d0c-dc9f8e1f",
"producer": "compute.googleapis.com",
"first": true
},
"receiveTimestamp": "2021-09-13T02:52:16.847984195Z"
}
References #
compute.projects.setCommonInstanceMetadata: setCommonInstanceMetadata
#Description
Sets metadata common to all instances within the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "9gjtmcd3swk",
"labels": {
"compute.googleapis.com/root_trigger_id": "3c66288a-c958-49d1-8109-6e95aeb0a051"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782744266581-655657ebc247a-96caa119-ba492a3e",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.projects.setCommonInstanceMetadata",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "compute",
"type": "compute.projects"
}
},
{
"granted": true,
"permission": "iam.serviceAccounts.actAs",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "compute",
"type": "compute.projects"
}
}
],
"methodName": "v1.compute.projects.setCommonInstanceMetadata",
"request": {
"@type": "type.googleapis.com/compute.projects.setCommonInstanceMetadata"
},
"requestMetadata": {
"callerIp": "private",
"callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:44:27.030039Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id",
"response": {
"@type": "type.googleapis.com/operation",
"id": "4061165445698239013",
"insertTime": "2026-06-29T07:44:26.851-07:00",
"name": "operation-1782744266581-655657ebc247a-96caa119-ba492a3e",
"operationType": "compute.projects.setCommonInstanceMetadata",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782744266581-655657ebc247a-96caa119-ba492a3e",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/4061165445698239013",
"setCommonInstanceMetadataOperationMetadata": {
"clientOperationId": "operation-1782744266581-655657ebc247a-96caa119-ba492a3e"
},
"startTime": "2026-06-29T07:44:26.855-07:00",
"status": "RUNNING",
"targetId": "000000000000",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id",
"user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:44:27.750031191Z",
"resource": {
"labels": {
"project_id": "000000000000"
},
"type": "gce_project"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:44:26.636187Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
compute.projects.setDefaultNetworkTier: setDefaultNetworkTier
#Description
Sets the default network tier of the project. The default network tier is used when an address/forwardingRule/instance is created without specifying the network tier field.
compute.projects.setUsageExportBucket: setUsageExportBucket
#Description
Enables the usage export feature and sets theusage export bucket where reports are stored. If you provide an empty request body using this method, the usage export feature will be disabled.
compute.publicAdvertisedPrefixes.announce: announce
#Description
Announces the specified PublicAdvertisedPrefix
compute.publicAdvertisedPrefixes.delete: delete
#Description
Deletes the specified PublicAdvertisedPrefix
compute.publicAdvertisedPrefixes.get: get
#Description
Returns the specified PublicAdvertisedPrefix resource.
Data Access audit logs are disabled by default.
compute.publicAdvertisedPrefixes.insert: insert
#Description
Creates a PublicAdvertisedPrefix in the specified project using the parameters that are included in the request.
compute.publicAdvertisedPrefixes.list: list
#Description
Lists the PublicAdvertisedPrefixes for a project.
Data Access audit logs are disabled by default.
compute.publicAdvertisedPrefixes.patch: patch
#Description
Patches the specified Router resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.
compute.publicAdvertisedPrefixes.withdraw: withdraw
#Description
Withdraws the specified PublicAdvertisedPrefix
compute.publicDelegatedPrefixes.aggregatedList: aggregatedList
#Description
Lists all PublicDelegatedPrefix resources owned by the specific project across all scopes. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.publicDelegatedPrefixes.announce: announce
#Description
Announces the specified PublicDelegatedPrefix in the given region.
compute.publicDelegatedPrefixes.delete: delete
#Description
Deletes the specified PublicDelegatedPrefix in the given region.
compute.publicDelegatedPrefixes.get: get
#Description
Returns the specified PublicDelegatedPrefix resource in the given region.
Data Access audit logs are disabled by default.
compute.publicDelegatedPrefixes.insert: insert
#Description
Creates a PublicDelegatedPrefix in the specified project in the given region using the parameters that are included in the request.
compute.publicDelegatedPrefixes.list: list
#Description
Lists the PublicDelegatedPrefixes for a project in the given region.
Data Access audit logs are disabled by default.
compute.publicDelegatedPrefixes.patch: patch
#Description
Patches the specified PublicDelegatedPrefix resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.
compute.publicDelegatedPrefixes.withdraw: withdraw
#Description
Withdraws the specified PublicDelegatedPrefix in the given region.
compute.regionAutoscalers.delete: delete
#Description
Deletes the specified autoscaler.
compute.regionAutoscalers.get: get
#Description
Returns the specified autoscaler.
Data Access audit logs are disabled by default.
compute.regionAutoscalers.insert: insert
#Description
Creates an autoscaler in the specified project using the data included in the request.
compute.regionAutoscalers.list: list
#Description
Retrieves a list of autoscalers contained within the specified region.
Data Access audit logs are disabled by default.
compute.regionAutoscalers.patch: patch
#Description
Updates an autoscaler in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.regionAutoscalers.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionAutoscalers.update: update
#Description
Updates an autoscaler in the specified project using the data included in the request.
compute.regionBackendBuckets.delete: delete
#Description
Deletes the specified regional BackendBucket resource.
compute.regionBackendBuckets.get: get
#Description
Returns the specified regional BackendBucket resource.
Data Access audit logs are disabled by default.
compute.regionBackendBuckets.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.regionBackendBuckets.insert: insert
#Description
Creates a RegionBackendBucket in the specified project in the given scope using the parameters that are included in the request.
compute.regionBackendBuckets.list: list
#Description
Retrieves the list of BackendBucket resources available to the specified project in the given region.
Data Access audit logs are disabled by default.
compute.regionBackendBuckets.listUsable: listUsable
#Description
Retrieves a list of all usable backend buckets in the specified project in the given region.
Data Access audit logs are disabled by default.
compute.regionBackendBuckets.patch: patch
#Description
Updates the specified BackendBucket resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.regionBackendBuckets.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.regionBackendBuckets.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionBackendServices.delete: delete
#Description
Deletes the specified regional BackendService resource.
Example Audit Log Entry #
{
"insertId": "-gmgbhse440aq",
"labels": {
"compute.googleapis.com/root_trigger_id": "f89756da-e103-41e0-adaa-deb39aec5e4e"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.regionBackendServices.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
"service": "compute",
"type": "compute.regionBackendServices"
}
}
],
"methodName": "v1.compute.regionBackendServices.delete",
"request": {
"@type": "type.googleapis.com/compute.regionBackendServices.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-services.delete invocation-id/542ea518361d48c19be1d86f122bafc0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:30:18.136903Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
"response": {
"@type": "type.googleapis.com/error",
"error": {
"code": 404,
"errors": [
{
"domain": "global",
"message": "The resource 'projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r' was not found",
"reason": "notFound"
}
],
"message": "The resource 'projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r' was not found"
}
},
"serviceName": "compute.googleapis.com",
"status": {
"code": 5,
"message": "The resource 'projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r' was not found"
}
},
"receiveTimestamp": "2026-06-29T15:30:18.982324522Z",
"resource": {
"labels": {
"backend_service_id": "",
"location": "us-central1",
"project_id": "example-project-id"
},
"type": "gce_backend_service"
},
"severity": "ERROR",
"timestamp": "2026-06-29T15:30:18.038557Z"
}
compute.regionBackendServices.get: get
#Description
Returns the specified regional BackendService resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "dxe0bve2r1b4",
"labels": {
"compute.googleapis.com/root_trigger_id": "ac4a014f-8254-46d1-9582-0241e35cfe75"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.regionBackendServices.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/backendServices/dwbs7b671061",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/backendServices/dwbs7b671061",
"service": "compute",
"type": "compute.regionBackendServices"
}
}
],
"methodName": "v1.compute.regionBackendServices.get",
"request": {
"@type": "type.googleapis.com/compute.regionBackendServices.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-services.create invocation-id/70b5567d41044d699a0a24b9098c09c9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:28:49.222772Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/backendServices/dwbs7b671061",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:28:49.990748802Z",
"resource": {
"labels": {
"backend_service_id": "4206856783692506070",
"location": "us-central1",
"project_id": "example-project-id"
},
"type": "gce_backend_service"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:28:49.172962Z"
}
compute.regionBackendServices.getHealth: getHealth
#Description
Gets the most recent health check results for this regional BackendService.
Data Access audit logs are disabled by default.
compute.regionBackendServices.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.regionBackendServices.insert: insert
#Description
Creates a regional BackendService resource in the specified project using the data included in the request. For more information, see Backend services overview.
Example Audit Log Entry #
{
"insertId": "-xspuxae19ouy",
"labels": {
"compute.googleapis.com/root_trigger_id": "47606930-1b30-4796-9931-df79c4bd098f"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.regionBackendServices.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
"service": "compute",
"type": "compute.regionBackendServices"
}
}
],
"methodName": "v1.compute.regionBackendServices.insert",
"request": {
"@type": "type.googleapis.com/compute.regionBackendServices.insert",
"healthChecks": [
"https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r"
],
"loadBalancingScheme": "INTERNAL",
"name": "dwn4-dw745960r",
"protocol": "HTTP",
"timeoutSec": "30"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.backend-services.create invocation-id/5916b03dff864ccaa7adfd152174c783 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:25:49.483938Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/backendServices/dwn4-dw745960r",
"response": {
"@type": "type.googleapis.com/error",
"error": {
"code": 400,
"errors": [
{
"domain": "global",
"message": "Invalid value for field 'resource.protocol': 'HTTP'. Protocol for an INTERNAL backend service must be one of TCP/UDP/UNSPECIFIED.",
"reason": "invalid"
}
],
"message": "Invalid value for field 'resource.protocol': 'HTTP'. Protocol for an INTERNAL backend service must be one of TCP/UDP/UNSPECIFIED."
}
},
"serviceName": "compute.googleapis.com",
"status": {
"code": 3,
"message": "Invalid value for field 'resource.protocol': 'HTTP'. Protocol for an INTERNAL backend service must be one of TCP/UDP/UNSPECIFIED."
}
},
"receiveTimestamp": "2026-06-29T15:25:49.557679184Z",
"resource": {
"labels": {
"backend_service_id": "",
"location": "us-central1",
"project_id": "example-project-id"
},
"type": "gce_backend_service"
},
"severity": "ERROR",
"timestamp": "2026-06-29T15:25:49.427767Z"
}
compute.regionBackendServices.list: list
#Description
Retrieves the list of regional BackendService resources available to the specified project in the given region.
Data Access audit logs are disabled by default.
compute.regionBackendServices.listUsable: listUsable
#Description
Retrieves a list of all usable backend services in the specified project in the given region.
Data Access audit logs are disabled by default.
compute.regionBackendServices.patch: patch
#Description
Updates the specified regional BackendService resource with the data included in the request. For more information, see Understanding backend services This method supports PATCH semantics and uses the JSON merge patch format and processing rules.
compute.regionBackendServices.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.regionBackendServices.setSecurityPolicy: setSecurityPolicy
#Description
Sets the Google Cloud Armor security policy for the specified backend service. For more information, seeGoogle Cloud Armor Overview
compute.regionBackendServices.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionBackendServices.update: update
#Description
Updates the specified regional BackendService resource with the data included in the request. For more information, see Backend services overview.
compute.regionCommitments.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of commitments by region. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.regionCommitments.get: get
#Description
Returns the specified commitment resource.
Data Access audit logs are disabled by default.
compute.regionCommitments.insert: insert
#Description
Creates a commitment in the specified project using the data included in the request.
compute.regionCommitments.list: list
#Description
Retrieves a list of commitments contained within the specified region.
Data Access audit logs are disabled by default.
compute.regionCommitments.update: update
#Description
Updates the specified commitment with the data included in the request. Update is performed only on selected fields included as part of update-mask. Only the following fields can be updated: auto_renew and plan.
compute.regionCompositeHealthChecks.aggregatedList: aggregatedList
#Description
Retrieves the list of all CompositeHealthCheck resources (all regional) available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.regionCompositeHealthChecks.delete: delete
#Description
Deletes the specified CompositeHealthCheck in the given region
compute.regionCompositeHealthChecks.get: get
#Description
Returns the specified CompositeHealthCheck resource in the given region.
Data Access audit logs are disabled by default.
compute.regionCompositeHealthChecks.getHealth: getHealth
#Description
Gets the most recent health check results for this regional CompositeHealthCheck.
Data Access audit logs are disabled by default.
compute.regionCompositeHealthChecks.insert: insert
#Description
Create a CompositeHealthCheck in the specified project in the given region using the parameters that are included in the request.
compute.regionCompositeHealthChecks.list: list
#Description
Lists the CompositeHealthChecks for a project in the given region.
Data Access audit logs are disabled by default.
compute.regionCompositeHealthChecks.patch: patch
#Description
Updates the specified regional CompositeHealthCheck resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.regionCompositeHealthChecks.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionDiskTypes.get: get
#Description
Returns the specified regional disk type.
Data Access audit logs are disabled by default.
compute.regionDiskTypes.list: list
#Description
Retrieves a list of regional disk types available to the specified project.
Data Access audit logs are disabled by default.
compute.regionDisks.addResourcePolicies: addResourcePolicies
#Description
Adds existing resource policies to a regional disk. You can only add one policy which will be applied to this disk for scheduling snapshot creation.
compute.regionDisks.bulkInsert: bulkInsert
#Description
Bulk create a set of disks.
compute.regionDisks.createSnapshot: createSnapshot
#Description
Creates a snapshot of a specified persistent disk. For regular snapshot creation, consider using snapshots.insert instead, as that method supports more features, such as creating snapshots in a project different from the source disk project.
compute.regionDisks.delete: delete
#Description
Deletes the specified regional persistent disk. Deleting a regional disk removes all the replicas of its data permanently and is irreversible. However, deleting a disk does not delete anysnapshots previously made from the disk. You must separatelydelete snapshots.
compute.regionDisks.get: get
#Description
Returns a specified regional persistent disk.
Data Access audit logs are disabled by default.
compute.regionDisks.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.regionDisks.insert: insert
#Description
Creates a persistent regional disk in the specified project using the data included in the request.
compute.regionDisks.list: list
#Description
Retrieves the list of persistent disks contained within the specified region.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "8mqwiye83i5o",
"labels": {
"compute.googleapis.com/root_trigger_id": "b4ffd947-dd16-4980-aa8c-47a98f06cc15"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "110162197178770594910"
},
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
"principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.disks.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.regionDisks.list",
"request": {
"@type": "type.googleapis.com/compute.regionDisks.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-api-go-client/0.5 GCE CSI Driver/v1.23.1-gke.14 (linux amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:39:35.631396Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/disks",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:39:36.367158866Z",
"resource": {
"labels": {
"location": "us-central1",
"method": "compute.regionDisks.list",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:39:35.585884Z"
}
compute.regionDisks.removeResourcePolicies: removeResourcePolicies
#Description
Removes resource policies from a regional disk.
compute.regionDisks.resize: resize
#Description
Resizes the specified regional persistent disk.
compute.regionDisks.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.regionDisks.setLabels: setLabels
#Description
Sets the labels on the target regional disk.
compute.regionDisks.startAsyncReplication: startAsyncReplication
#Description
Starts asynchronous replication. Must be invoked on the primary disk.
compute.regionDisks.stopAsyncReplication: stopAsyncReplication
#Description
Stops asynchronous replication. Can be invoked either on the primary or on the secondary disk.
compute.regionDisks.stopGroupAsyncReplication: stopGroupAsyncReplication
#Description
Stops asynchronous replication for a consistency group of disks. Can be invoked either in the primary or secondary scope.
compute.regionDisks.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionDisks.update: update
#Description
Update the specified disk with the data included in the request. Update is performed only on selected fields included as part of update-mask.
compute.regionDisks.updateKmsKey: updateKmsKey
#Description
Rotates the customer-managed encryption key to the latest version for the specified persistent disk.
compute.regionHealthAggregationPolicies.aggregatedList: aggregatedList
#Description
Retrieves the list of all HealthAggregationPolicy resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.regionHealthAggregationPolicies.delete: delete
#Description
Deletes the specified HealthAggregationPolicy in the given region.
compute.regionHealthAggregationPolicies.get: get
#Description
Returns the specified HealthAggregationPolicy resource in the given region.
Data Access audit logs are disabled by default.
compute.regionHealthAggregationPolicies.insert: insert
#Description
Create a HealthAggregationPolicy in the specified project in the given region using the parameters that are included in the request.
compute.regionHealthAggregationPolicies.list: list
#Description
Lists the HealthAggregationPolicies for a project in the given region.
Data Access audit logs are disabled by default.
compute.regionHealthAggregationPolicies.patch: patch
#Description
Updates the specified regional HealthAggregationPolicy resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.regionHealthAggregationPolicies.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionHealthCheckServices.aggregatedList: aggregatedList
#Description
Retrieves the list of all HealthCheckService resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.regionHealthCheckServices.delete: delete
#Description
Deletes the specified regional HealthCheckService.
compute.regionHealthCheckServices.get: get
#Description
Returns the specified regional HealthCheckService resource.
Data Access audit logs are disabled by default.
compute.regionHealthCheckServices.insert: insert
#Description
Creates a regional HealthCheckService resource in the specified project and region using the data included in the request.
compute.regionHealthCheckServices.list: list
#Description
Lists all the HealthCheckService resources that have been configured for the specified project in the given region.
Data Access audit logs are disabled by default.
compute.regionHealthCheckServices.patch: patch
#Description
Updates the specified regional HealthCheckService resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.regionHealthCheckServices.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionHealthChecks.delete: delete
#Description
Deletes the specified HealthCheck resource.
Example Audit Log Entry #
{
"insertId": "9psldie31d62",
"labels": {
"compute.googleapis.com/root_trigger_id": "733e5ee6-f45a-4e1c-8de9-dc855f3475b2"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782747019471-6556622d1ea45-96290638-25c420aa",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.regionHealthChecks.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
"service": "compute",
"type": "compute.regionHealthChecks"
}
}
],
"methodName": "v1.compute.regionHealthChecks.delete",
"request": {
"@type": "type.googleapis.com/compute.regionHealthChecks.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.health-checks.delete invocation-id/48dd6eabe8eb42ba9fed59ddcb96e08f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:30:19.616034Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
"response": {
"@type": "type.googleapis.com/operation",
"id": "6148536400710938980",
"insertTime": "2026-06-29T08:30:19.569-07:00",
"name": "operation-1782747019471-6556622d1ea45-96290638-25c420aa",
"operationType": "delete",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782747019471-6556622d1ea45-96290638-25c420aa",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/6148536400710938980",
"startTime": "2026-06-29T08:30:19.580-07:00",
"status": "RUNNING",
"targetId": "1848293291438583956",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:30:19.855510334Z",
"resource": {
"labels": {
"location": "us-central1",
"method": "compute.regionHealthChecks.delete",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:30:19.418402Z"
}
compute.regionHealthChecks.get: get
#Description
Returns the specified HealthCheck resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-4flto5e1ajqg",
"labels": {
"compute.googleapis.com/root_trigger_id": "18942c9c-a039-4d95-807c-fb0ecf38fff6"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.regionHealthChecks.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/healthChecks/dwhc7b671061",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/healthChecks/dwhc7b671061",
"service": "compute",
"type": "compute.regionHealthChecks"
}
}
],
"methodName": "v1.compute.regionHealthChecks.get",
"request": {
"@type": "type.googleapis.com/compute.regionHealthChecks.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.health-checks.create.tcp invocation-id/d5316bd401884f0bacd838ecc172493b environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:28:40.040373Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/healthChecks/dwhc7b671061",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:28:40.637204026Z",
"resource": {
"labels": {
"location": "us-central1",
"method": "compute.regionHealthChecks.get",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:28:39.972550Z"
}
compute.regionHealthChecks.insert: insert
#Description
Creates a HealthCheck resource in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-rpyzoeair46",
"labels": {
"compute.googleapis.com/root_trigger_id": "fef368a9-1767-40d3-ae46-814187126032"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746746998-6556612944df9-9b059968-7274b096",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.regionHealthChecks.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
"service": "compute",
"type": "compute.regionHealthChecks"
}
}
],
"methodName": "v1.compute.regionHealthChecks.insert",
"request": {
"@type": "type.googleapis.com/compute.regionHealthChecks.insert",
"checkIntervalSec": "5",
"healthyThreshold": "2",
"httpHealthCheck": {
"port": "80",
"portSpecification": "USE_FIXED_PORT",
"proxyHeader": "NONE",
"requestPath": "/"
},
"name": "dwn4-dw745960r",
"timeoutSec": "5",
"type": "HTTP",
"unhealthyThreshold": "2"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.health-checks.create.http invocation-id/0c651f5221d74899a6ee7a5c994186ed environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:25:47.163857Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
"response": {
"@type": "type.googleapis.com/operation",
"id": "718011800694501524",
"insertTime": "2026-06-29T08:25:47.097-07:00",
"name": "operation-1782746746998-6556612944df9-9b059968-7274b096",
"operationType": "insert",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782746746998-6556612944df9-9b059968-7274b096",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/718011800694501524",
"startTime": "2026-06-29T08:25:47.104-07:00",
"status": "RUNNING",
"targetId": "1848293291438583956",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/healthChecks/dwn4-dw745960r",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:25:47.643191790Z",
"resource": {
"labels": {
"location": "us-central1",
"method": "compute.regionHealthChecks.insert",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:25:46.975047Z"
}
compute.regionHealthChecks.list: list
#Description
Retrieves the list of HealthCheck resources available to the specified project.
Data Access audit logs are disabled by default.
compute.regionHealthChecks.patch: patch
#Description
Updates a HealthCheck resource in the specified project using the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.regionHealthChecks.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionHealthChecks.update: update
#Description
Updates a HealthCheck resource in the specified project using the data included in the request.
compute.regionHealthSources.aggregatedList: aggregatedList
#Description
Retrieves the list of all HealthSource resources (all regional) available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.regionHealthSources.delete: delete
#Description
Deletes the specified HealthSource in the given region
compute.regionHealthSources.get: get
#Description
Returns the specified HealthSource resource in the given region.
Data Access audit logs are disabled by default.
compute.regionHealthSources.getHealth: getHealth
#Description
Gets the most recent health check results for this regional HealthSource.
Data Access audit logs are disabled by default.
compute.regionHealthSources.insert: insert
#Description
Create a HealthSource in the specified project in the given region using the parameters that are included in the request.
compute.regionHealthSources.list: list
#Description
Lists the HealthSources for a project in the given region.
Data Access audit logs are disabled by default.
compute.regionHealthSources.patch: patch
#Description
Updates the specified regional HealthSource resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.regionHealthSources.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionInstanceGroupManagerResizeRequests.cancel: cancel
#Description
Cancels the specified resize request. Cancelled resize request no longer waits for the resources to be provisioned. Cancel is only possible for requests that are in accepted state.
compute.regionInstanceGroupManagerResizeRequests.delete: delete
#Description
Deletes the specified, inactive resize request. Requests that are still active cannot be deleted. Deleting request does not delete instances that were provisioned previously.
compute.regionInstanceGroupManagerResizeRequests.get: get
#Description
Returns all of the details about the specified resize request.
Data Access audit logs are disabled by default.
compute.regionInstanceGroupManagerResizeRequests.insert: insert
#Description
Creates a new Resize Request that starts provisioning VMs immediately or queues VM creation.
compute.regionInstanceGroupManagerResizeRequests.list: list
#Description
Retrieves a list of Resize Requests that are contained in the managed instance group.
Data Access audit logs are disabled by default.
compute.regionInstanceGroupManagers.abandonInstances: abandonInstances
#Description
Flags the specified instances to be immediately removed from the managed instance group. Abandoning an instance does not delete the instance, but it does remove the instance from any target pools that are applied by the managed instance group. This method reduces thetargetSize of the managed instance group by the number of instances that you abandon. This operation is marked asDONE when the action is scheduled even if the instances have not yet been removed from the group. You must separately verify the status of the abandoning action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.
compute.regionInstanceGroupManagers.applyUpdatesToInstances: applyUpdatesToInstances
#Description
Apply updates to selected instances the managed instance group.
compute.regionInstanceGroupManagers.createInstances: createInstances
#Description
Creates instances with per-instance configurations in this regional managed instance group. Instances are created using the current instance template. The create instances operation is marked DONE if the createInstances request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or actions with the listmanagedinstances method.
compute.regionInstanceGroupManagers.delete: delete
#Description
Deletes the specified managed instance group and all of the instances in that group.
compute.regionInstanceGroupManagers.deleteInstances: deleteInstances
#Description
Flags the specified instances in the managed instance group to be immediately deleted. The instances are also removed from any target pools of which they were a member. This method reduces thetargetSize of the managed instance group by the number of instances that you delete. The deleteInstances operation is marked DONE if the deleteInstances request is successful. The underlying actions take additional time. You must separately verify the status of thedeleting action with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.
compute.regionInstanceGroupManagers.deletePerInstanceConfigs: deletePerInstanceConfigs
#Description
Deletes selected per-instance configurations for the managed instance group.
compute.regionInstanceGroupManagers.get: get
#Description
Returns all of the details about the specified managed instance group.
Data Access audit logs are disabled by default.
compute.regionInstanceGroupManagers.insert: insert
#Description
Creates a managed instance group using the information that you specify in the request. After the group is created, instances in the group are created using the specified instance template. This operation is marked as DONE when the group is created even if the instances in the group have not yet been created. You must separately verify the status of the individual instances with thelistmanagedinstances method. A regional managed instance group can contain up to 2000 instances.
compute.regionInstanceGroupManagers.list: list
#Description
Retrieves the list of managed instance groups that are contained within the specified region.
Data Access audit logs are disabled by default.
compute.regionInstanceGroupManagers.listErrors: listErrors
#Description
Lists all errors thrown by actions on instances for a given regional managed instance group. The filter andorderBy query parameters are not supported.
Data Access audit logs are disabled by default.
compute.regionInstanceGroupManagers.listManagedInstances: listManagedInstances
#Description
Lists the instances in the managed instance group and instances that are scheduled to be created. The list includes any current actions that the group has scheduled for its instances. The orderBy query parameter is not supported. The `pageToken` query parameter is supported only if the group's `listManagedInstancesResults` field is set to `PAGINATED`.
Data Access audit logs are disabled by default.
compute.regionInstanceGroupManagers.listPerInstanceConfigs: listPerInstanceConfigs
#Description
Lists all of the per-instance configurations defined for the managed instance group. The orderBy query parameter is not supported.
Data Access audit logs are disabled by default.
compute.regionInstanceGroupManagers.patch: patch
#Description
Updates a managed instance group using the information that you specify in the request. This operation is marked as DONE when the group is patched even if the instances in the group are still in the process of being patched. You must separately verify the status of the individual instances with the listmanagedinstances method. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules. If you update your group to specify a new template or instance configuration, it's possible that your intended specification for each VM in the group is different from the current state of that VM. To learn how to apply an updated configuration to the VMs in a MIG, seeUpdating instances in a MIG.
compute.regionInstanceGroupManagers.patchPerInstanceConfigs: patchPerInstanceConfigs
#Description
Inserts or patches per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.
compute.regionInstanceGroupManagers.recreateInstances: recreateInstances
#Description
Flags the specified VM instances in the managed instance group to be immediately recreated. Each instance is recreated using the group's current configuration. This operation is marked as DONE when the flag is set even if the instances have not yet been recreated. You must separately verify the status of each instance by checking itscurrentAction field; for more information, see Checking the status of managed instances. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted. You can specify a maximum of 1000 instances with this method per request.
compute.regionInstanceGroupManagers.resize: resize
#Description
Changes the intended size of the managed instance group. If you increase the size, the group creates new instances using the current instance template. If you decrease the size, the group deletes one or more instances. The resize operation is marked DONE if theresize request is successful. The underlying actions take additional time. You must separately verify the status of thecreating or deleting actions with thelistmanagedinstances method. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is removed or deleted.
compute.regionInstanceGroupManagers.resumeInstances: resumeInstances
#Description
Flags the specified instances in the managed instance group to be resumed. This method increases thetargetSize and decreases the targetSuspendedSize of the managed instance group by the number of instances that you resume. The resumeInstances operation is marked DONE if the resumeInstances request is successful. The underlying actions take additional time. You must separately verify the status of theRESUMING action with thelistmanagedinstances method. In this request, you can only specify instances that are suspended. For example, if an instance was previously suspended using the suspendInstances method, it can be resumed using the resumeInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are resumed. You can specify a maximum of 1000 instances with this method per request.
compute.regionInstanceGroupManagers.setInstanceTemplate: setInstanceTemplate
#Description
Sets the instance template to use when creating new instances or recreating instances in this group. Existing instances are not affected.
compute.regionInstanceGroupManagers.setTargetPools: setTargetPools
#Description
Modifies the target pools to which all new instances in this group are assigned. Existing instances in the group are not affected.
compute.regionInstanceGroupManagers.startInstances: startInstances
#Description
Flags the specified instances in the managed instance group to be started. This method increases thetargetSize and decreases the targetStoppedSize of the managed instance group by the number of instances that you start. The startInstances operation is marked DONE if the startInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTARTING action with thelistmanagedinstances method. In this request, you can only specify instances that are stopped. For example, if an instance was previously stopped using the stopInstances method, it can be started using the startInstances method. If a health check is attached to the managed instance group, the specified instances will be verified as healthy after they are started. You can specify a maximum of 1000 instances with this method per request.
compute.regionInstanceGroupManagers.stopInstances: stopInstances
#Description
Flags the specified instances in the managed instance group to be immediately stopped. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetStoppedSize of the managed instance group by the number of instances that you stop. The stopInstances operation is marked DONE if the stopInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSTOPPING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays stopping the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is stopped. Stopped instances can be started using the startInstances method. You can specify a maximum of 1000 instances with this method per request.
compute.regionInstanceGroupManagers.suspendInstances: suspendInstances
#Description
Flags the specified instances in the managed instance group to be immediately suspended. You can only specify instances that are running in this request. This method reduces thetargetSize and increases the targetSuspendedSize of the managed instance group by the number of instances that you suspend. The suspendInstances operation is marked DONE if the suspendInstances request is successful. The underlying actions take additional time. You must separately verify the status of theSUSPENDING action with thelistmanagedinstances method. If the standbyPolicy.initialDelaySec field is set, the group delays suspension of the instances until initialDelaySec have passed from instance.creationTimestamp (that is, when the instance was created). This delay gives your application time to set itself up and initialize on the instance. If more thaninitialDelaySec seconds have passed sinceinstance.creationTimestamp when this method is called, there will be zero delay. If the group is part of a backend service that has enabled connection draining, it can take up to 60 seconds after the connection draining duration has elapsed before the VM instance is suspended. Suspended instances can be resumed using the resumeInstances method. You can specify a maximum of 1000 instances with this method per request.
compute.regionInstanceGroupManagers.updatePerInstanceConfigs: updatePerInstanceConfigs
#Description
Inserts or updates per-instance configurations for the managed instance group. perInstanceConfig.name serves as a key used to distinguish whether to perform insert or patch.
compute.regionInstanceGroups.get: get
#Description
Returns the specified instance group resource.
Data Access audit logs are disabled by default.
compute.regionInstanceGroups.list: list
#Description
Retrieves the list of instance group resources contained within the specified region.
Data Access audit logs are disabled by default.
compute.regionInstanceGroups.listInstances: listInstances
#Description
Lists the instances in the specified instance group and displays information about the named ports. Depending on the specified options, this method can list all instances or only the instances that are running. The orderBy query parameter is not supported.
Data Access audit logs are disabled by default.
compute.regionInstanceGroups.setNamedPorts: setNamedPorts
#Description
Sets the named ports for the specified regional instance group.
compute.regionInstanceGroups.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionInstanceTemplates.delete: delete
#Description
Deletes the specified instance template. Deleting an instance template is permanent and cannot be undone.
Example Audit Log Entry #
{
"insertId": "-saixoje3ihpg",
"labels": {
"compute.googleapis.com/root_trigger_id": "fd5e53ae-2103-4dae-9c39-8c49e3756aec"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782744154740-655657811952b-29e22a4d-576c7d28",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.instanceTemplates.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/instanceTemplates/gke-dwgke-dw743447-default-pool-d20f3f37",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/instanceTemplates/gke-dwgke-dw743447-default-pool-d20f3f37",
"service": "compute",
"type": "compute.instanceTemplates"
}
}
],
"methodName": "v1.compute.regionInstanceTemplates.delete",
"request": {
"@type": "type.googleapis.com/compute.regionInstanceTemplates.delete"
},
"requestMetadata": {
"callerIp": "private",
"callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:42:35.227819Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/instanceTemplates/gke-dwgke-dw743447-default-pool-d20f3f37",
"response": {
"@type": "type.googleapis.com/operation",
"id": "516115459807853236",
"insertTime": "2026-06-29T07:42:35.175-07:00",
"name": "operation-1782744154740-655657811952b-29e22a4d-576c7d28",
"operationType": "delete",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782744154740-655657811952b-29e22a4d-576c7d28",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/516115459807853236",
"startTime": "2026-06-29T07:42:35.183-07:00",
"status": "RUNNING",
"targetId": "5240466678091824357",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/instanceTemplates/gke-dwgke-dw743447-default-pool-d20f3f37",
"user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:42:35.807441147Z",
"resource": {
"labels": {
"instance_template_id": "5240466678091824357",
"instance_template_name": "gke-dwgke-dw743447-default-pool-d20f3f37",
"project_id": "example-project-id"
},
"type": "gce_instance_template"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:42:35.050789Z"
}
compute.regionInstanceTemplates.get: get
#Description
Returns the specified instance template.
Data Access audit logs are disabled by default.
compute.regionInstanceTemplates.insert: insert
#Description
Creates an instance template in the specified project and region using the global instance template whose URL is included in the request.
compute.regionInstanceTemplates.list: list
#Description
Retrieves a list of instance templates that are contained within the specified project and region.
Data Access audit logs are disabled by default.
compute.regionInstances.bulkInsert: bulkInsert
#Description
Creates multiple instances in a given region. Count specifies the number of instances to create.
compute.regionInstantSnapshotGroups.delete: delete
#Description
deletes a Regional InstantSnapshotGroup resource
compute.regionInstantSnapshotGroups.get: get
#Description
returns the specified InstantSnapshotGroup resource in the specified region.
Data Access audit logs are disabled by default.
compute.regionInstantSnapshotGroups.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.regionInstantSnapshotGroups.insert: insert
#Description
creates a Regional InstantSnapshotGroup resource
compute.regionInstantSnapshotGroups.list: list
#Description
retrieves the list of InstantSnapshotGroup resources contained within the specified region.
Data Access audit logs are disabled by default.
compute.regionInstantSnapshotGroups.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.regionInstantSnapshotGroups.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionInstantSnapshots.delete: delete
#Description
Deletes the specified InstantSnapshot resource. Keep in mind that deleting a single instantSnapshot might not necessarily delete all the data on that instantSnapshot. If any data on the instantSnapshot that is marked for deletion is needed for subsequent instantSnapshots, the data will be moved to the next corresponding instantSnapshot. For more information, seeDeleting instantSnapshots.
compute.regionInstantSnapshots.get: get
#Description
Returns the specified InstantSnapshot resource in the specified region.
Data Access audit logs are disabled by default.
compute.regionInstantSnapshots.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.regionInstantSnapshots.insert: insert
#Description
Creates an instant snapshot in the specified region.
compute.regionInstantSnapshots.list: list
#Description
Retrieves the list of InstantSnapshot resources contained within the specified region.
Data Access audit logs are disabled by default.
compute.regionInstantSnapshots.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.regionInstantSnapshots.setLabels: setLabels
#Description
Sets the labels on a instantSnapshot in the given region. To learn more about labels, read the Labeling Resources documentation.
compute.regionInstantSnapshots.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionNetworkEndpointGroups.attachNetworkEndpoints: attachNetworkEndpoints
#Description
Attach a list of network endpoints to the specified network endpoint group.
compute.regionNetworkEndpointGroups.delete: delete
#Description
Deletes the specified network endpoint group. Note that the NEG cannot be deleted if it is configured as a backend of a backend service.
compute.regionNetworkEndpointGroups.detachNetworkEndpoints: detachNetworkEndpoints
#Description
Detach the network endpoint from the specified network endpoint group.
compute.regionNetworkEndpointGroups.get: get
#Description
Returns the specified network endpoint group.
Data Access audit logs are disabled by default.
compute.regionNetworkEndpointGroups.insert: insert
#Description
Creates a network endpoint group in the specified project using the parameters that are included in the request. Note: Use the following APIs to manage network endpoint groups: - To manage NEGs with zonal scope (such as zonal NEGs, hybrid connectivity NEGs): zonal API - To manage NEGs with regional scope (such as regional internet NEGs, serverless NEGs, Private Service Connect NEGs): regional API - To manage NEGs with global scope (such as global internet NEGs):global API
compute.regionNetworkEndpointGroups.list: list
#Description
Retrieves the list of regional network endpoint groups available to the specified project in the given region.
Data Access audit logs are disabled by default.
compute.regionNetworkEndpointGroups.listNetworkEndpoints: listNetworkEndpoints
#Description
Lists the network endpoints in the specified network endpoint group.
Data Access audit logs are disabled by default.
compute.regionNetworkFirewallPolicies.addAssociation: addAssociation
#Description
Inserts an association for the specified network firewall policy.
compute.regionNetworkFirewallPolicies.addRule: addRule
#Description
Inserts a rule into a network firewall policy.
compute.regionNetworkFirewallPolicies.cloneRules: cloneRules
#Description
Copies rules to the specified network firewall policy.
compute.regionNetworkFirewallPolicies.delete: delete
#Description
Deletes the specified network firewall policy.
compute.regionNetworkFirewallPolicies.get: get
#Description
Returns the specified network firewall policy.
Data Access audit logs are disabled by default.
compute.regionNetworkFirewallPolicies.getAssociation: getAssociation
#Description
Gets an association with the specified name.
Data Access audit logs are disabled by default.
compute.regionNetworkFirewallPolicies.getEffectiveFirewalls: getEffectiveFirewalls
#Description
Returns the effective firewalls on a given network.
Data Access audit logs are disabled by default.
compute.regionNetworkFirewallPolicies.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.regionNetworkFirewallPolicies.getRule: getRule
#Description
Gets a rule of the specified priority.
Data Access audit logs are disabled by default.
compute.regionNetworkFirewallPolicies.insert: insert
#Description
Creates a new network firewall policy in the specified project and region.
compute.regionNetworkFirewallPolicies.list: list
#Description
Lists all the network firewall policies that have been configured for the specified project in the given region.
Data Access audit logs are disabled by default.
compute.regionNetworkFirewallPolicies.patch: patch
#Description
Patches the specified network firewall policy.
compute.regionNetworkFirewallPolicies.patchRule: patchRule
#Description
Patches a rule of the specified priority.
compute.regionNetworkFirewallPolicies.removeAssociation: removeAssociation
#Description
Removes an association for the specified network firewall policy.
compute.regionNetworkFirewallPolicies.removeRule: removeRule
#Description
Deletes a rule of the specified priority.
compute.regionNetworkFirewallPolicies.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.regionNetworkFirewallPolicies.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionNotificationEndpoints.aggregatedList: aggregatedList
#Description
Retrieves the list of all NotificationEndpoint resources, regional and global, available to the specified project.
Data Access audit logs are disabled by default.
compute.regionNotificationEndpoints.delete: delete
#Description
Deletes the specified NotificationEndpoint in the given region
compute.regionNotificationEndpoints.get: get
#Description
Returns the specified NotificationEndpoint resource in the given region.
Data Access audit logs are disabled by default.
compute.regionNotificationEndpoints.insert: insert
#Description
Create a NotificationEndpoint in the specified project in the given region using the parameters that are included in the request.
compute.regionNotificationEndpoints.list: list
#Description
Lists the NotificationEndpoints for a project in the given region.
Data Access audit logs are disabled by default.
compute.regionNotificationEndpoints.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionOperations.delete: delete
#Description
Deletes the specified region-specific Operations resource.
compute.regionOperations.get: get
#Description
Retrieves the specified region-specific Operations resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-62mxmoe15x34",
"labels": {
"compute.googleapis.com/root_trigger_id": "7921d872-3eb8-4931-be27-6c5fbbd83269"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.regionOperations.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/operations/operation-1782744154740-655657811952b-29e22a4d-576c7d28",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/operations/operation-1782744154740-655657811952b-29e22a4d-576c7d28",
"service": "compute",
"type": "compute.regionOperations"
}
}
],
"methodName": "v1.compute.regionOperations.get",
"request": {
"@type": "type.googleapis.com/compute.regionOperations.get"
},
"requestMetadata": {
"callerIp": "private",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:42:37.407795Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/operations/operation-1782744154740-655657811952b-29e22a4d-576c7d28",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:42:38.217451698Z",
"resource": {
"labels": {
"location": "us-central1",
"operation_name": "operation-1782744154740-655657811952b-29e22a4d-576c7d28",
"project_id": "example-project-id"
},
"type": "gce_operation"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:42:37.364461Z"
}
compute.regionOperations.list: list
#Description
Retrieves a list of Operation resources contained within the specified region.
Data Access audit logs are disabled by default.
compute.regionOperations.wait: wait
#Description
Waits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method differs from the `GET` method in that it waits for no more than the default deadline (2 minutes) and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-vumiuge66pfs",
"labels": {
"compute.googleapis.com/root_trigger_id": "ce27a66b-3f28-41f7-9bc0-226715ef5549"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.regionOperations.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/operations/operation-1782739223725-65564522843f2-29cb8358-813b1c25",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/operations/operation-1782739223725-65564522843f2-29cb8358-813b1c25",
"service": "compute",
"type": "compute.regionOperations"
}
}
],
"methodName": "v1.compute.regionOperations.wait",
"request": {
"@type": "type.googleapis.com/compute.regionOperations.wait"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.create invocation-id/88997435245f4532ae2513fb4e2acb8d environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:20:41.931197Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/operations/operation-1782739223725-65564522843f2-29cb8358-813b1c25",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:20:42.746765592Z",
"resource": {
"labels": {
"location": "us-central1",
"operation_name": "operation-1782739223725-65564522843f2-29cb8358-813b1c25",
"project_id": "example-project-id"
},
"type": "gce_operation"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:20:25.158695Z"
}
compute.regionSecurityPolicies.addRule: addRule
#Description
Inserts a rule into a security policy.
compute.regionSecurityPolicies.delete: delete
#Description
Deletes the specified policy.
compute.regionSecurityPolicies.get: get
#Description
List all of the ordered rules present in a single specified policy.
Data Access audit logs are disabled by default.
compute.regionSecurityPolicies.getRule: getRule
#Description
Gets a rule at the specified priority.
Data Access audit logs are disabled by default.
compute.regionSecurityPolicies.insert: insert
#Description
Creates a new policy in the specified project using the data included in the request.
compute.regionSecurityPolicies.list: list
#Description
List all the policies that have been configured for the specified project and region.
Data Access audit logs are disabled by default.
compute.regionSecurityPolicies.patch: patch
#Description
Patches the specified policy with the data included in the request. To clear fields in the policy, leave the fields empty and specify them in the updateMask. This cannot be used to be update the rules in the policy. Please use the per rule methods like addRule, patchRule, and removeRule instead.
compute.regionSecurityPolicies.patchRule: patchRule
#Description
Patches a rule at the specified priority. To clear fields in the rule, leave the fields empty and specify them in the updateMask.
compute.regionSecurityPolicies.removeRule: removeRule
#Description
Deletes a rule at the specified priority.
compute.regionSecurityPolicies.setLabels: setLabels
#Description
Sets the labels on a security policy. To learn more about labels, read the Labeling Resources documentation.
compute.regionSnapshotSettings.get: get
#Description
Get region snapshot settings.
Data Access audit logs are disabled by default.
compute.regionSnapshotSettings.patch: patch
#Description
Patch region snapshot settings.
compute.regionSnapshots.delete: delete
#Description
Deletes the specified Snapshot resource. Keep in mind that deleting a single snapshot might not necessarily delete all the data on that snapshot. If any data on the snapshot that is marked for deletion is needed for subsequent snapshots, the data will be moved to the next corresponding snapshot. For more information, seeDeleting snapshots.
compute.regionSnapshots.get: get
#Description
Returns the specified Snapshot resource.
Data Access audit logs are disabled by default.
compute.regionSnapshots.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.regionSnapshots.insert: insert
#Description
Creates a snapshot in the specified region using the data included in the request.
compute.regionSnapshots.list: list
#Description
Retrieves the list of Snapshot resources contained within the specified region.
Data Access audit logs are disabled by default.
compute.regionSnapshots.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.regionSnapshots.setLabels: setLabels
#Description
Sets the labels on a regional snapshot. To learn more about labels, read the Labeling Resources documentation.
compute.regionSnapshots.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.regionSnapshots.updateKmsKey: updateKmsKey
#Description
Rotates the customer-managed encryption key to the latest version for the specified snapshot.
compute.regionSslCertificates.delete: delete
#Description
Deletes the specified SslCertificate resource in the region.
compute.regionSslCertificates.get: get
#Description
Returns the specified SslCertificate resource in the specified region. Get a list of available SSL certificates by making a list() request.
Data Access audit logs are disabled by default.
compute.regionSslCertificates.insert: insert
#Description
Creates a SslCertificate resource in the specified project and region using the data included in the request
compute.regionSslCertificates.list: list
#Description
Retrieves the list of SslCertificate resources available to the specified project in the specified region.
Data Access audit logs are disabled by default.
compute.regionSslPolicies.delete: delete
#Description
Deletes the specified SSL policy. The SSL policy resource can be deleted only if it is not in use by any TargetHttpsProxy or TargetSslProxy resources.
compute.regionSslPolicies.get: get
#Description
Lists all of the ordered rules present in a single specified policy.
Data Access audit logs are disabled by default.
compute.regionSslPolicies.insert: insert
#Description
Creates a new policy in the specified project and region using the data included in the request.
compute.regionSslPolicies.list: list
#Description
Lists all the SSL policies that have been configured for the specified project and region.
Data Access audit logs are disabled by default.
compute.regionSslPolicies.listAvailableFeatures: listAvailableFeatures
#Description
Lists all features that can be specified in the SSL policy when using custom profile.
Data Access audit logs are disabled by default.
compute.regionSslPolicies.patch: patch
#Description
Patches the specified SSL policy with the data included in the request.
compute.regionTargetHttpProxies.delete: delete
#Description
Deletes the specified TargetHttpProxy resource.
compute.regionTargetHttpProxies.get: get
#Description
Returns the specified TargetHttpProxy resource in the specified region.
Data Access audit logs are disabled by default.
compute.regionTargetHttpProxies.insert: insert
#Description
Creates a TargetHttpProxy resource in the specified project and region using the data included in the request.
compute.regionTargetHttpProxies.list: list
#Description
Retrieves the list of TargetHttpProxy resources available to the specified project in the specified region.
Data Access audit logs are disabled by default.
compute.regionTargetHttpProxies.setUrlMap: setUrlMap
#Description
Changes the URL map for TargetHttpProxy.
compute.regionTargetHttpsProxies.delete: delete
#Description
Deletes the specified TargetHttpsProxy resource.
compute.regionTargetHttpsProxies.get: get
#Description
Returns the specified TargetHttpsProxy resource in the specified region.
Data Access audit logs are disabled by default.
compute.regionTargetHttpsProxies.insert: insert
#Description
Creates a TargetHttpsProxy resource in the specified project and region using the data included in the request.
compute.regionTargetHttpsProxies.list: list
#Description
Retrieves the list of TargetHttpsProxy resources available to the specified project in the specified region.
Data Access audit logs are disabled by default.
compute.regionTargetHttpsProxies.patch: patch
#Description
Patches the specified regional TargetHttpsProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.
compute.regionTargetHttpsProxies.setSslCertificates: setSslCertificates
#Description
Replaces SslCertificates for TargetHttpsProxy.
compute.regionTargetHttpsProxies.setUrlMap: setUrlMap
#Description
Changes the URL map for TargetHttpsProxy.
compute.regionTargetTcpProxies.delete: delete
#Description
Deletes the specified TargetTcpProxy resource.
compute.regionTargetTcpProxies.get: get
#Description
Returns the specified TargetTcpProxy resource.
Data Access audit logs are disabled by default.
compute.regionTargetTcpProxies.insert: insert
#Description
Creates a TargetTcpProxy resource in the specified project and region using the data included in the request.
compute.regionTargetTcpProxies.list: list
#Description
Retrieves a list of TargetTcpProxy resources available to the specified project in a given region.
Data Access audit logs are disabled by default.
compute.regionUrlMaps.delete: delete
#Description
Deletes the specified UrlMap resource.
compute.regionUrlMaps.get: get
#Description
Returns the specified UrlMap resource.
Data Access audit logs are disabled by default.
compute.regionUrlMaps.insert: insert
#Description
Creates a UrlMap resource in the specified project using the data included in the request.
compute.regionUrlMaps.list: list
#Description
Retrieves the list of UrlMap resources available to the specified project in the specified region.
Data Access audit logs are disabled by default.
compute.regionUrlMaps.patch: patch
#Description
Patches the specified UrlMap resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.
compute.regionUrlMaps.update: update
#Description
Updates the specified UrlMap resource with the data included in the request.
compute.regionUrlMaps.validate: validate
#Description
Runs static validation for the UrlMap. In particular, the tests of the provided UrlMap will be run. Calling this method does NOT create the UrlMap.
compute.regionZones.list: list
#Description
Retrieves the list of Zone resources under the specific region available to the specified project.
Data Access audit logs are disabled by default.
compute.regions.get: get
#Description
Returns the specified Region resource. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request. This method fails if the quota information is unavailable for the region and if the organization policy constraint compute.requireBasicQuotaInResponse is enforced. This constraint, when enforced, disables the fail-open behaviour when quota information (the `items.quotas` field) is unavailable for the region. It is recommended to use the default setting for the constraint unless your application requires the fail-closed behaviour for this method.
Data Access audit logs are disabled by default.
compute.regions.list: list
#Description
Retrieves the list of region resources available to the specified project. To decrease latency for this method, you can optionally omit any unneeded information from the response by using a field mask. This practice is especially recommended for unused quota information (the `items.quotas` field). To exclude one or more fields, set your request's `fields` query parameter to only include the fields you need. For example, to only include the `id` and `selfLink` fields, add the query parameter `?fields=id,selfLink` to your request. This method fails if the quota information is unavailable for the region and if the organization policy constraint compute.requireBasicQuotaInResponse is enforced. This constraint, when enforced, disables the fail-open behaviour when quota information (the `items.quotas` field) is unavailable for the region. It is recommended to use the default setting for the constraint unless your application requires the fail-closed behaviour for this method.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-26k7ahdd4gc",
"labels": {
"compute.googleapis.com/root_trigger_id": "7d77c784-2a47-4404-9cf8-89b3bf0f35e5"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.regions.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.regions.list",
"numResponseItems": "43",
"request": {
"@type": "type.googleapis.com/compute.regions.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.regions.list invocation-id/82f00dca4ca64a3bb0afd8372dd83147 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:45.082506Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/regions",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:45.327010659Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.regions.list",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:44.738824Z"
}
compute.reservationBlocks.get: get
#Description
Retrieves information about the specified reservation block.
Data Access audit logs are disabled by default.
compute.reservationBlocks.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.reservationBlocks.list: list
#Description
Retrieves a list of reservation blocks under a single reservation.
Data Access audit logs are disabled by default.
compute.reservationBlocks.performMaintenance: performMaintenance
#Description
Allows customers to perform maintenance on a reservation block
compute.reservationBlocks.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.reservationBlocks.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.reservationSlots.get: get
#Description
Retrieves information about the specified reservation slot.
Data Access audit logs are disabled by default.
compute.reservationSlots.getVersion: getVersion
#Description
Allows customers to get SBOM versions of a reservation slot.
Data Access audit logs are disabled by default.
compute.reservationSlots.list: list
#Description
Retrieves a list of reservation slots under a single reservation.
Data Access audit logs are disabled by default.
compute.reservationSlots.update: update
#Description
Update a reservation slot in the specified sub-block.
compute.reservationSubBlocks.get: get
#Description
Retrieves information about the specified reservation subBlock.
Data Access audit logs are disabled by default.
compute.reservationSubBlocks.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.reservationSubBlocks.getVersion: getVersion
#Description
Allows customers to get SBOM versions of a reservation subBlock.
Data Access audit logs are disabled by default.
compute.reservationSubBlocks.list: list
#Description
Retrieves a list of reservation subBlocks under a single reservation.
Data Access audit logs are disabled by default.
compute.reservationSubBlocks.performMaintenance: performMaintenance
#Description
Allows customers to perform maintenance on a reservation subBlock
compute.reservationSubBlocks.reportFaulty: reportFaulty
#Description
Allows customers to report a faulty subBlock.
compute.reservationSubBlocks.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.reservationSubBlocks.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.reservations.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of reservations. To prevent failure, it is recommended that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-t3gmqie5l23a",
"labels": {
"compute.googleapis.com/root_trigger_id": "7c8fe96a-e271-427a-88ac-2cf72531d24f"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.reservations.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.reservations.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.reservations.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.reservations.list invocation-id/c681a151147e4da7af261fc0ff149b62 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:56.655375Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/reservations",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:57.274401940Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.reservations.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:56.600481Z"
}
compute.reservations.delete: delete
#Description
Deletes the specified reservation.
Example Audit Log Entry #
{
"insertId": "-b2s4ehe4qsom",
"labels": {
"compute.googleapis.com/root_trigger_id": "a9013f93-2226-4737-9e5d-33d78fe089de"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746993451-655662144e257-1d7b959c-ea96f49c",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.reservations.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
"service": "compute",
"type": "compute.reservations"
}
}
],
"methodName": "v1.compute.reservations.delete",
"request": {
"@type": "type.googleapis.com/compute.reservations.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.reservations.delete invocation-id/afb93cfcd3ae40669c54ed717e97b352 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:29:53.568794Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"id": "8607707594908184990",
"insertTime": "2026-06-29T08:29:53.531-07:00",
"name": "operation-1782746993451-655662144e257-1d7b959c-ea96f49c",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746993451-655662144e257-1d7b959c-ea96f49c",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/8607707594908184990",
"startTime": "2026-06-29T08:29:53.538-07:00",
"status": "RUNNING",
"targetId": "2753888838017298537",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:29:54.048763854Z",
"resource": {
"labels": {
"location": "us-central1-a",
"method": "compute.reservations.delete",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:29:53.409862Z"
}
compute.reservations.get: get
#Description
Retrieves information about the specified reservation.
Data Access audit logs are disabled by default.
compute.reservations.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.reservations.insert: insert
#Description
Creates a new reservation. For more information, readReserving zonal resources.
Example Audit Log Entry #
{
"insertId": "y5xxwke6gaxy",
"labels": {
"compute.googleapis.com/root_trigger_id": "17918d58-c4f0-4d4f-8bf1-006fad042407"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746758491-655661343acc8-55548b2b-08e5546a",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.reservations.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
"service": "compute",
"type": "compute.reservations"
}
}
],
"methodName": "v1.compute.reservations.insert",
"request": {
"@type": "type.googleapis.com/compute.reservations.insert",
"name": "dwn4-dw745960",
"specificReservation": {
"count": "1",
"instanceProperties": {
"machineType": "e2-micro"
}
},
"specificReservationRequired": false,
"zone": "us-central1-a"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.reservations.create invocation-id/6afe383282904f5c99ce5fcb84f81969 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:25:58.817438Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"id": "8517525243176104041",
"insertTime": "2026-06-29T08:25:58.704-07:00",
"name": "operation-1782746758491-655661343acc8-55548b2b-08e5546a",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/operation-1782746758491-655661343acc8-55548b2b-08e5546a",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/operations/8517525243176104041",
"startTime": "2026-06-29T08:25:58.710-07:00",
"status": "RUNNING",
"targetId": "2753888838017298537",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/reservations/dwn4-dw745960",
"user": "user@example.com",
"zone": "https://www.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:25:59.723022760Z",
"resource": {
"labels": {
"location": "us-central1-a",
"method": "compute.reservations.insert",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:25:58.459020Z"
}
compute.reservations.list: list
#Description
A list of all the reservations that have been configured for the specified project in specified zone.
Data Access audit logs are disabled by default.
compute.reservations.performMaintenance: performMaintenance
#Description
Perform maintenance on an extended reservation
compute.reservations.resize: resize
#Description
Resizes the reservation (applicable to standalone reservations only). For more information, readModifying reservations.
compute.reservations.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.reservations.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.reservations.update: update
#Description
Update share settings of the reservation.
compute.resourcePolicies.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of resource policies. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.resourcePolicies.delete: delete
#Description
Deletes the specified resource policy.
Example Audit Log Entry #
{
"insertId": "by3381e67xz4",
"labels": {
"compute.googleapis.com/root_trigger_id": "633e2c64-e63f-492f-b625-c9135400abe8"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782747119236-6556628c43523-71ae348f-48a21077",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.resourcePolicies.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
"service": "compute",
"type": "compute.resourcePolicies"
}
}
],
"methodName": "v1.compute.resourcePolicies.delete",
"request": {
"@type": "type.googleapis.com/compute.resourcePolicies.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.resource-policies.delete invocation-id/b2f8933fffd144ec86b0b2912638feed environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:31:59.445513Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
"response": {
"@type": "type.googleapis.com/operation",
"id": "254959561057710336",
"insertTime": "2026-06-29T08:31:59.398-07:00",
"name": "operation-1782747119236-6556628c43523-71ae348f-48a21077",
"operationType": "delete",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782747119236-6556628c43523-71ae348f-48a21077",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/254959561057710336",
"startTime": "2026-06-29T08:31:59.408-07:00",
"status": "RUNNING",
"targetId": "3948597118829015508",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:31:59.959212145Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"region": "us-central1",
"resource_policy_id": "3948597118829015508"
},
"type": "gce_resource_policy"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:31:59.130981Z"
}
compute.resourcePolicies.get: get
#Description
Retrieves all information of the specified resource policy.
Data Access audit logs are disabled by default.
compute.resourcePolicies.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.resourcePolicies.insert: insert
#Description
Creates a new resource policy.
Example Audit Log Entry #
{
"insertId": "w32goe2unyk",
"labels": {
"compute.googleapis.com/root_trigger_id": "9d052125-07f7-4be1-864b-1201ec00c89d"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746939973-655661e14dfe1-a5a0ce94-2d1b0895",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.resourcePolicies.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
"service": "compute",
"type": "compute.resourcePolicies"
}
}
],
"methodName": "v1.compute.resourcePolicies.insert",
"request": {
"@type": "type.googleapis.com/compute.resourcePolicies.insert",
"name": "dwrp5-dw746783",
"snapshotSchedulePolicy": {
"retentionPolicy": {
"maxRetentionDays": "1"
},
"schedule": {
"dailySchedule": {
"daysInCycle": "1",
"startTime": "04:00"
}
}
}
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.resource-policies.create.snapshot-schedule invocation-id/ecd05751ffae4bd4b2c2ae61d12d31fd environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:29:00.142026Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
"response": {
"@type": "type.googleapis.com/operation",
"id": "2467155034629943763",
"insertTime": "2026-06-29T08:29:00.087-07:00",
"name": "operation-1782746939973-655661e14dfe1-a5a0ce94-2d1b0895",
"operationType": "insert",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782746939973-655661e14dfe1-a5a0ce94-2d1b0895",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/2467155034629943763",
"startTime": "2026-06-29T08:29:00.089-07:00",
"status": "RUNNING",
"targetId": "3948597118829015508",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/resourcePolicies/dwrp5-dw746783",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:29:00.461903164Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"region": "us-central1",
"resource_policy_id": "3948597118829015508"
},
"type": "gce_resource_policy"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:28:59.942229Z"
}
compute.resourcePolicies.list: list
#Description
A list all the resource policies that have been configured for the specified project in specified region.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-yclroje8ol7a",
"labels": {
"compute.googleapis.com/root_trigger_id": "6b08e2ed-6723-4219-a035-5c6d9e231121"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "110162197178770594910"
},
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
"principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.resourcePolicies.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "beta.compute.resourcePolicies.list",
"request": {
"@type": "type.googleapis.com/compute.resourcePolicies.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-api-go-client/0.5 cluster-autoscaler,gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:39:47.818564Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/resourcePolicies",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:39:48.183988090Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"region": "us-central1",
"resource_policy_id": ""
},
"type": "gce_resource_policy"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:39:47.783707Z"
}
compute.resourcePolicies.patch: patch
#Description
Modify the specified resource policy.
compute.resourcePolicies.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.resourcePolicies.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.rolloutPlans.delete: delete
#Description
Deletes a RolloutPlan.
compute.rolloutPlans.get: get
#Description
Gets details of a single project-scoped RolloutPlan.
Data Access audit logs are disabled by default.
compute.rolloutPlans.insert: insert
#Description
Creates a new RolloutPlan in a given project and location.
compute.rolloutPlans.list: list
#Description
Lists RolloutPlans in a given project and location.
Data Access audit logs are disabled by default.
compute.rollouts.advance: advance
#Description
Advances a Rollout to the next wave, or completes it if no waves remain.
compute.rollouts.cancel: cancel
#Description
Cancels a Rollout.
compute.rollouts.delete: delete
#Description
Deletes a Rollout.
compute.rollouts.get: get
#Description
Gets details of a single project-scoped Rollout.
Data Access audit logs are disabled by default.
compute.rollouts.list: list
#Description
Lists Rollouts in a given project and location.
Data Access audit logs are disabled by default.
compute.rollouts.pause: pause
#Description
Pauses a Rollout.
compute.rollouts.resume: resume
#Description
Resumes a Rollout.
compute.routers.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of routers. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "d1n4mrdsnkg",
"labels": {
"compute.googleapis.com/root_trigger_id": "27b55eac-2a95-4f8f-b06e-79074f298552"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.routers.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.routers.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.routers.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routers.list invocation-id/ee179d0149344bb7bcd08c515368504a environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:46.499347Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/routers",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:47.088357155Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.routers.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:46.446689Z"
}
compute.routers.delete: delete
#Description
Deletes the specified Router resource.
Example Audit Log Entry #
{
"insertId": "w5e36e52ixs",
"labels": {
"compute.googleapis.com/root_trigger_id": "1f8a70c2-da96-4902-bde3-88782abf5ec4"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750838708-655670676d831-3c4ffca5-bef06add",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.routers.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
"service": "compute",
"type": "compute.routers"
}
}
],
"methodName": "v1.compute.routers.delete",
"request": {
"@type": "type.googleapis.com/compute.routers.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routers.delete invocation-id/8283a36d91d64fb19d24b3d644a42a93 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:33:58.832838Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
"response": {
"@type": "type.googleapis.com/operation",
"id": "7809329013451595929",
"insertTime": "2026-06-29T09:33:58.793-07:00",
"name": "operation-1782750838708-655670676d831-3c4ffca5-bef06add",
"operationType": "delete",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750838708-655670676d831-3c4ffca5-bef06add",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/7809329013451595929",
"startTime": "2026-06-29T09:33:58.800-07:00",
"status": "RUNNING",
"targetId": "841057025972445937",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:33:59.535976879Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"region": "us-central1",
"router_id": "841057025972445937"
},
"type": "gce_router"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:33:58.676672Z"
}
compute.routers.deleteRoutePolicy: deleteRoutePolicy
#Description
Deletes Route Policy
compute.routers.get: get
#Description
Returns the specified Router resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "nvnltle92jjq",
"labels": {
"compute.googleapis.com/root_trigger_id": "0a700996-0978-43aa-a641-b4dc7fca4fe9"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.routers.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
"service": "compute",
"type": "compute.routers"
}
}
],
"methodName": "v1.compute.routers.get",
"request": {
"@type": "type.googleapis.com/compute.routers.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routers.create invocation-id/f69a59bf5ade4f5fb8eab3137b2e79ef environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:24:11.692522Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:24:11.929199718Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"region": "us-central1",
"router_id": "841057025972445937"
},
"type": "gce_router"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:24:11.618967Z"
}
compute.routers.getNatIpInfo: getNatIpInfo
#Description
Retrieves runtime NAT IP information.
Data Access audit logs are disabled by default.
compute.routers.getNatMappingInfo: getNatMappingInfo
#Description
Retrieves runtime Nat mapping information of VM endpoints.
Data Access audit logs are disabled by default.
compute.routers.getRoutePolicy: getRoutePolicy
#Description
Returns specified Route Policy
Data Access audit logs are disabled by default.
compute.routers.getRouterStatus: getRouterStatus
#Description
Retrieves runtime information of the specified router.
Data Access audit logs are disabled by default.
compute.routers.insert: insert
#Description
Creates a Router resource in the specified project and region using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-toawhle2sp2k",
"labels": {
"compute.googleapis.com/root_trigger_id": "ccc4a20f-836b-4d47-8c82-2a74f8bd7c41"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745450335-65565c54acdc5-b4f870dd-9299e4f6",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.routers.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/routers/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/routers/dwn3-dw745304",
"service": "compute",
"type": "compute.routers"
}
},
{
"granted": true,
"permission": "compute.networks.updatePolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/dwn3-dw745304",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.routers.insert",
"request": {
"@type": "type.googleapis.com/compute.routers.insert",
"name": "dwn3-dw745304",
"network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn3-dw745304"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routers.create invocation-id/17b5fa44ebae489490e26180c6f6d175 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:04:10.660299Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/routers/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "4715875489907947397",
"insertTime": "2026-06-29T08:04:10.507-07:00",
"name": "operation-1782745450335-65565c54acdc5-b4f870dd-9299e4f6",
"operationType": "insert",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782745450335-65565c54acdc5-b4f870dd-9299e4f6",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/4715875489907947397",
"startTime": "2026-06-29T08:04:10.512-07:00",
"status": "RUNNING",
"targetId": "424833158361331589",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/routers/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:04:10.979288224Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"region": "us-central1",
"router_id": "424833158361331589"
},
"type": "gce_router"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:04:10.303422Z"
}
compute.routers.list: list
#Description
Retrieves a list of Router resources available to the specified project.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-9ddbphe2fjhq",
"labels": {
"compute.googleapis.com/root_trigger_id": "e7e15147-6dfb-4d4d-9653-f0c797d01f24"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.routers.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.routers.list",
"request": {
"@type": "type.googleapis.com/compute.routers.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routers.list invocation-id/7a46e704be124e3e877b31298cb6b252 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:37:32.893063Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/routers",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:37:33.073149721Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"region": "us-central1",
"router_id": ""
},
"type": "gce_router"
},
"severity": "INFO",
"timestamp": "2026-06-29T15:37:32.857871Z"
}
compute.routers.listBgpRoutes: listBgpRoutes
#Description
Retrieves a list of router bgp routes available to the specified project.
Data Access audit logs are disabled by default.
compute.routers.listRoutePolicies: listRoutePolicies
#Description
Retrieves a list of router route policy subresources available to the specified project.
Data Access audit logs are disabled by default.
compute.routers.patch: patch
#Description
Patches the specified Router resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.
compute.routers.patchRoutePolicy: patchRoutePolicy
#Description
Patches Route Policy
compute.routers.preview: preview
#Description
Preview fields auto-generated during router create andupdate operations. Calling this method does NOT create or update the router.
compute.routers.update: update
#Description
Updates the specified Router resource with the data included in the request. This method conforms toPUT semantics, which requests that the state of the target resource be created or replaced with the state defined by the representation enclosed in the request message payload.
compute.routers.updateRoutePolicy: updateRoutePolicy
#Description
Updates or creates new Route Policy
compute.routes.delete: delete
#Description
Deletes the specified Route resource.
Example Audit Log Entry #
{
"insertId": "-rez22tdk2vg",
"labels": {
"compute.googleapis.com/root_trigger_id": "a66ddecc-2d27-47f6-9691-50e671377cca"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.routes.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
"resourceAttributes": {
"name": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
"service": "compute",
"type": "compute.routes"
}
}
],
"methodName": "v1.compute.routes.delete",
"request": {
"@type": "type.googleapis.com/compute.routes.delete"
},
"requestMetadata": {
"callerIp": "private",
"callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:41:18.384089Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
"response": {
"@type": "type.googleapis.com/operation",
"id": "2381360902523796193",
"insertTime": "2026-06-29T07:41:18.204-07:00",
"name": "operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782744077943-65565737dc1cd-ae72f47c-90cbe729",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2381360902523796193",
"startTime": "2026-06-29T07:41:18.217-07:00",
"status": "RUNNING",
"targetId": "6536496377037274206",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
"user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:41:18.511695891Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"route_id": "6536496377037274206"
},
"type": "gce_route"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:41:18.012241Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1562, T1562.007, T1578, T1578.005
compute.routes.get: get
#Description
Returns the specified Route resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-959yd8e2juoc",
"labels": {
"compute.googleapis.com/root_trigger_id": "b4004784-64a2-4fcd-b103-810b0ef71de0"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.routes.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/routes/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/global/routes/dwg2-dw743447",
"service": "compute",
"type": "compute.routes"
}
}
],
"methodName": "v1.compute.routes.get",
"request": {
"@type": "type.googleapis.com/compute.routes.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routes.create invocation-id/5a489800c8ae4df380924b4f0121aab9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:39:22.778184Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/routes/dwg2-dw743447",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:39:22.816507965Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"route_id": "7445334344751594859"
},
"type": "gce_route"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:39:22.694766Z"
}
compute.routes.insert: Insert route
#Description
Creates a Route resource in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "tffr86d1fnk",
"labels": {
"compute.googleapis.com/root_trigger_id": "9b2d50b7-c9a2-486d-979c-43961d0c2fca"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782743729162-655655eb3c992-7396fd98-36c1510c",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "110162197178770594910"
},
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
"principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.routes.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
"resourceAttributes": {
"name": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
"service": "compute",
"type": "compute.routes"
}
},
{
"granted": true,
"permission": "compute.networks.updatePolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/default",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/default",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.routes.insert",
"request": {
"@type": "type.googleapis.com/compute.routes.insert",
"description": "k8s-node-route",
"destRange": "10.0.0.0/24",
"name": "gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
"network": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/networks/default",
"nextHopInstance": "zones/us-central1-a/instances/gke-dwgke-dw743447-default-pool-d20f3f37-s2rw",
"priority": "1000"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-api-go-client/0.5 Kubernetes/0.0.0 (linux amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:35:29.695230Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
"response": {
"@type": "type.googleapis.com/operation",
"id": "7290103536500554846",
"insertTime": "2026-06-29T07:35:29.518-07:00",
"name": "operation-1782743729162-655655eb3c992-7396fd98-36c1510c",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782743729162-655655eb3c992-7396fd98-36c1510c",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/7290103536500554846",
"startTime": "2026-06-29T07:35:29.532-07:00",
"status": "RUNNING",
"targetId": "6536496377037274206",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/routes/gke-dwgke-dw743447-265a84d-2262f2af-c950-489d-9081-714304de8057",
"user": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:35:30.258679160Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"route_id": "6536496377037274206"
},
"type": "gce_route"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:35:29.207201Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1562, T1562.007, T1578, T1578.005
compute.routes.list: list
#Description
Retrieves the list of Route resources available to the specified project.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "kvj9q7e616q6",
"labels": {
"compute.googleapis.com/root_trigger_id": "9aa3f09f-c92a-4228-81f7-6484acfbc1dc"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.routes.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.routes.list",
"numResponseItems": "43",
"request": {
"@type": "type.googleapis.com/compute.routes.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.routes.list invocation-id/a785f0a0d1c548c9b81ad47c5cadec43 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:25.375624Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/routes",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:25.949158475Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"route_id": ""
},
"type": "gce_route"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:25.313652Z"
}
compute.routes.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.securityPolicies.addRule: addRule
#Description
Inserts a rule into a security policy.
Example Audit Log Entry #
{
"insertId": "k9c6hwd4wlc",
"labels": {
"compute.googleapis.com/root_trigger_id": "0270021b-eeeb-4ca0-a167-076518679eb2"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745463188-65565c60eed14-8cae6859-612cf305",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.securityPolicies.update",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
"service": "compute",
"type": "compute.securityPolicies"
}
}
],
"methodName": "v1.compute.securityPolicies.addRule",
"request": {
"@type": "type.googleapis.com/compute.securityPolicies.addRule",
"action": "deny(403)",
"match": {
"config": {
"srcIpRanges": [
"192.0.2.0/24"
]
},
"versionedExpr": "SRC_IPS_V1"
},
"priority": "1000"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.security-policies.rules.create invocation-id/d0929ee2866a4574990367d5adbb6616 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:04:23.931061Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "3773060907793332120",
"insertTime": "2026-06-29T08:04:23.752-07:00",
"name": "operation-1782745463188-65565c60eed14-8cae6859-612cf305",
"operationType": "AddRule",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745463188-65565c60eed14-8cae6859-612cf305",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/3773060907793332120",
"startTime": "2026-06-29T08:04:23.792-07:00",
"status": "RUNNING",
"targetId": "2027392770551789442",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/securityPolicies/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:04:24.736114521Z",
"resource": {
"labels": {
"location": "global",
"policy_name": "dwn3-dw745304",
"project_id": "example-project-id"
},
"type": "network_security_policy"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:04:23.250477Z"
}
compute.securityPolicies.aggregatedList: aggregatedList
#Description
Retrieves the list of all SecurityPolicy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-8as0iee86xmk",
"labels": {
"compute.googleapis.com/root_trigger_id": "9216a543-466f-4836-b4a9-ec11d3b2f5c3"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.securityPolicies.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.securityPolicies.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.securityPolicies.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.security-policies.list invocation-id/ff4b428ba3274d43a53e8ef002822881 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:50.626694Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/securityPolicies",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:51.144731260Z",
"resource": {
"labels": {
"location": "global",
"policy_name": "",
"project_id": "example-project-id"
},
"type": "network_security_policy"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:50.524135Z"
}
compute.securityPolicies.delete: delete
#Description
Deletes the specified policy.
compute.securityPolicies.get: get
#Description
List all of the ordered rules present in a single specified policy.
Data Access audit logs are disabled by default.
compute.securityPolicies.getRule: getRule
#Description
Gets a rule at the specified priority.
Data Access audit logs are disabled by default.
compute.securityPolicies.insert: insert
#Description
Creates a new policy in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-6nb2ted4yy6",
"labels": {
"compute.googleapis.com/root_trigger_id": "0a5fc297-a38d-4926-9e16-edcc065b1f38"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745453720-65565c57e71cc-1a4dbe1b-b7986a3a",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.securityPolicies.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
"service": "compute",
"type": "compute.securityPolicies"
}
}
],
"methodName": "v1.compute.securityPolicies.insert",
"request": {
"@type": "type.googleapis.com/compute.securityPolicies.insert",
"description": "dw",
"name": "dwn3-dw745304"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.security-policies.create invocation-id/86af9383123c4ee7a025dd4cd570d3bb environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:04:14.099092Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/securityPolicies/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "2837914212396644226",
"insertTime": "2026-06-29T08:04:13.982-07:00",
"name": "operation-1782745453720-65565c57e71cc-1a4dbe1b-b7986a3a",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745453720-65565c57e71cc-1a4dbe1b-b7986a3a",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2837914212396644226",
"startTime": "2026-06-29T08:04:13.984-07:00",
"status": "RUNNING",
"targetId": "2027392770551789442",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/securityPolicies/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:04:14.498801934Z",
"resource": {
"labels": {
"location": "global",
"policy_name": "dwn3-dw745304",
"project_id": "example-project-id"
},
"type": "network_security_policy"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:04:13.792466Z"
}
compute.securityPolicies.list: list
#Description
List all the policies that have been configured for the specified project.
Data Access audit logs are disabled by default.
compute.securityPolicies.listPreconfiguredExpressionSets: listPreconfiguredExpressionSets
#Description
Gets the current list of preconfigured Web Application Firewall (WAF) expressions.
Data Access audit logs are disabled by default.
compute.securityPolicies.patch: patch
#Description
Patches the specified policy with the data included in the request. To clear fields in the policy, leave the fields empty and specify them in the updateMask. This cannot be used to be update the rules in the policy. Please use the per rule methods like addRule, patchRule, and removeRule instead.
compute.securityPolicies.patchRule: patchRule
#Description
Patches a rule at the specified priority. To clear fields in the rule, leave the fields empty and specify them in the updateMask.
compute.securityPolicies.removeRule: removeRule
#Description
Deletes a rule at the specified priority.
compute.securityPolicies.setLabels: setLabels
#Description
Sets the labels on a security policy. To learn more about labels, read the Labeling Resources documentation.
compute.serviceAttachments.aggregatedList: aggregatedList
#Description
Retrieves the list of all ServiceAttachment resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-eowacze5vv8g",
"labels": {
"compute.googleapis.com/root_trigger_id": "68f4061c-2bf3-465c-aaf0-45ec61aea219"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.serviceAttachments.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.serviceAttachments.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.serviceAttachments.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.service-attachments.list invocation-id/6a38523f01cb4c52943bbc4719250685 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:37:20.499704Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/serviceAttachments",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:37:21.141281302Z",
"resource": {
"labels": {
"method": "compute.serviceAttachments.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com"
},
"type": "audited_resource"
},
"severity": "INFO",
"timestamp": "2026-06-29T15:37:20.396035Z"
}
compute.serviceAttachments.delete: delete
#Description
Deletes the specified ServiceAttachment in the given scope
compute.serviceAttachments.get: get
#Description
Returns the specified ServiceAttachment resource in the given scope.
Data Access audit logs are disabled by default.
compute.serviceAttachments.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.serviceAttachments.insert: insert
#Description
Creates a ServiceAttachment in the specified project in the given scope using the parameters that are included in the request.
compute.serviceAttachments.list: list
#Description
Lists the ServiceAttachments for a project in the given scope.
Data Access audit logs are disabled by default.
compute.serviceAttachments.patch: patch
#Description
Patches the specified ServiceAttachment resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.
compute.serviceAttachments.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.serviceAttachments.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.snapshotSettings.get: get
#Description
Get snapshot settings.
Data Access audit logs are disabled by default.
compute.snapshotSettings.patch: patch
#Description
Patch snapshot settings.
compute.snapshots.delete: delete
#Description
Deletes the specified Snapshot resource. Keep in mind that deleting a single snapshot might not necessarily delete all the data on that snapshot. If any data on the snapshot that is marked for deletion is needed for subsequent snapshots, the data will be moved to the next corresponding snapshot. For more information, seeDeleting snapshots.
Example Audit Log Entry #
{
"insertId": "-1cd1xjegxnie",
"labels": {
"compute.googleapis.com/root_trigger_id": "e5652fd5-eba6-471f-b9e0-c8b717670d1b"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750219415-65566e18d304a-7361d396-ee07909b",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.snapshots.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/snapshots/dwsnap7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/snapshots/dwsnap7201353",
"service": "compute",
"type": "compute.snapshots"
}
}
],
"methodName": "v1.compute.snapshots.delete",
"request": {
"@type": "type.googleapis.com/compute.snapshots.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.snapshots.delete invocation-id/13f58f77238d4e5297dd4559d74bbb41 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:23:39.636874Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/snapshots/dwsnap7201353",
"response": {
"@type": "type.googleapis.com/operation",
"id": "275427962146202340",
"insertTime": "2026-06-29T09:23:39.515-07:00",
"name": "operation-1782750219415-65566e18d304a-7361d396-ee07909b",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782750219415-65566e18d304a-7361d396-ee07909b",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/275427962146202340",
"startTime": "2026-06-29T09:23:39.521-07:00",
"status": "RUNNING",
"targetId": "8262724568879146268",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/snapshots/dwsnap7201353",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:23:40.305965552Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"snapshot_id": "8262724568879146268"
},
"type": "gce_snapshot"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:23:39.382036Z"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
PermissionType (kusto rule field) | eq | ADMIN_WRITE | 1 rule | kusto |
Severity (kusto rule field) | eq | NOTICE | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1485, T1490, T1562, T1562.001
compute.snapshots.get: get
#Description
Returns the specified Snapshot resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-gwl536e3z2ce",
"labels": {
"compute.googleapis.com/root_trigger_id": "a89a682d-5aac-4f83-adf0-71a3894ce7f1"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.snapshots.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/snapshots/dwg2-dw743447",
"resourceAttributes": {
"name": "projects/example-project-id/global/snapshots/dwg2-dw743447",
"service": "compute",
"type": "compute.snapshots"
}
}
],
"methodName": "v1.compute.snapshots.get",
"request": {
"@type": "type.googleapis.com/compute.snapshots.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.disks.snapshot invocation-id/b2c31cc6aed14ec89b974a9093f05120 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:38:57.061033Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/snapshots/dwg2-dw743447",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:38:57.957501193Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"snapshot_id": "8400522908034612701"
},
"type": "gce_snapshot"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:38:56.916687Z"
}
compute.snapshots.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "8lny9be3wixa",
"labels": {
"compute.googleapis.com/root_trigger_id": "7986d8a0-a67b-427b-9b13-6af55e283059"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.snapshots.getIamPolicy",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/global/snapshots/dwsnap7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/snapshots/dwsnap7201353",
"service": "compute",
"type": "compute.snapshots"
}
}
],
"methodName": "v1.compute.snapshots.getIamPolicy",
"request": {
"@type": "type.googleapis.com/compute.snapshots.getIamPolicy",
"optionsRequestedPolicyVersion": "3"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.snapshots.add-iam-policy-binding invocation-id/8e7965f200914c2791edd6a21492223f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:23:37.529028Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/snapshots/dwsnap7201353",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:23:37.549780777Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"snapshot_id": "8262724568879146268"
},
"type": "gce_snapshot"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:23:37.388087Z"
}
compute.snapshots.insert: insert
#Description
Creates a snapshot in the specified project using the data included in the request. For regular snapshot creation, consider using this method instead of disks.createSnapshot, as this method supports more features, such as creating snapshots in a project different from the source disk project.
Example Audit Log Entry #
{
"insertId": "z0o37qefayw6",
"labels": {
"compute.googleapis.com/root_trigger_id": "803b8483-b55b-4f9e-b9be-c6767899a3c1"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750195660-65566e022b59d-bd3b8614-a76cae00",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.snapshots.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/snapshots/dwsnap7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/snapshots/dwsnap7201353",
"service": "compute",
"type": "compute.snapshots"
}
},
{
"granted": true,
"permission": "compute.disks.createSnapshot",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/zones/us-central1-a/disks/dwd7201353",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/disks/dwd7201353",
"service": "compute",
"type": "compute.disks"
}
},
{
"granted": true,
"permission": "compute.snapshots.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/snapshots/dwsnap7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/snapshots/dwsnap7201353",
"service": "compute",
"type": "compute.snapshots"
}
}
],
"methodName": "v1.compute.snapshots.insert",
"request": {
"@type": "type.googleapis.com/compute.snapshots.insert",
"name": "dwsnap7201353",
"sourceDisk": "https://compute.googleapis.com/compute/v1/projects/example-project-id/zones/us-central1-a/disks/dwd7201353"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.snapshots.create invocation-id/b1f8ce8d9f3f4ea0b61c037eb8938633 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:23:16.429182Z"
}
},
"resourceLocation": {
"currentLocations": [
"US"
]
},
"resourceName": "projects/example-project-id/global/snapshots/dwsnap7201353",
"response": {
"@type": "type.googleapis.com/operation",
"id": "2456351177540838684",
"insertTime": "2026-06-29T09:23:15.887-07:00",
"name": "operation-1782750195660-65566e022b59d-bd3b8614-a76cae00",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782750195660-65566e022b59d-bd3b8614-a76cae00",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2456351177540838684",
"startTime": "2026-06-29T09:23:15.889-07:00",
"status": "RUNNING",
"targetId": "8262724568879146268",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/snapshots/dwsnap7201353",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:23:17.168078709Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"snapshot_id": "8262724568879146268"
},
"type": "gce_snapshot"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:23:15.636676Z"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
protoPayload.response.error (panther rule field) | is_null | | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
compute.snapshots.list: list
#Description
Retrieves the list of Snapshot resources contained within the specified project.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-ib1ftze3opa8",
"labels": {
"compute.googleapis.com/root_trigger_id": "093a1f39-40b6-4e0d-b2ce-1ecebf7ecc22"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.snapshots.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.snapshots.list",
"request": {
"@type": "type.googleapis.com/compute.snapshots.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.snapshots.list invocation-id/6170a5d6323645ec9f7193c9d3cd4b07 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:22.625769Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/snapshots",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:23.501243596Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"snapshot_id": ""
},
"type": "gce_snapshot"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:22.577253Z"
}
compute.snapshots.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
Example Audit Log Entry #
{
"insertId": "-8k385se5yies",
"labels": {
"compute.googleapis.com/root_trigger_id": "9f50c0d4-cce6-4f40-b6bc-997369aea469"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.snapshots.setIamPolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/snapshots/dwsnap7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/snapshots/dwsnap7201353",
"service": "compute",
"type": "compute.snapshots"
}
}
],
"methodName": "v1.compute.snapshots.setIamPolicy",
"request": {
"@type": "type.googleapis.com/compute.snapshots.setIamPolicy",
"policy": {
"bindings": [
{
"members": [
"user:user@example.com"
],
"role": "roles/compute.storageAdmin"
}
],
"etag": "\u0000 \u0001",
"version": "3"
}
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.snapshots.add-iam-policy-binding invocation-id/8e7965f200914c2791edd6a21492223f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:23:38.108648Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/snapshots/dwsnap7201353",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:23:39.093621325Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"snapshot_id": "8262724568879146268"
},
"type": "gce_snapshot"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:23:37.825435Z"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
protoPayload.response.error (panther rule field) | is_null | | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
compute.snapshots.setLabels: setLabels
#Description
Sets the labels on a snapshot. To learn more about labels, read theLabeling Resources documentation.
compute.snapshots.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.snapshots.updateKmsKey: updateKmsKey
#Description
Rotates the customer-managed encryption key to the latest version for the specified snapshot.
compute.sslCertificates.aggregatedList: aggregatedList
#Description
Retrieves the list of all SslCertificate resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-o4fnx0dmwx8",
"labels": {
"compute.googleapis.com/root_trigger_id": "d33b414c-0343-4793-aa45-463c9056c1cd"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.sslCertificates.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.sslCertificates.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.sslCertificates.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.ssl-certificates.list invocation-id/aabac67204074387b77cd30fa78802ac environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:34.627407Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/sslCertificates",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:34.941426397Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"ssl_certificate_id": "",
"ssl_certificate_name": ""
},
"type": "gce_ssl_certificate"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:34.534530Z"
}
compute.sslCertificates.delete: delete
#Description
Deletes the specified SslCertificate resource.
compute.sslCertificates.get: get
#Description
Returns the specified SslCertificate resource.
Data Access audit logs are disabled by default.
compute.sslCertificates.insert: insert
#Description
Creates a SslCertificate resource in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-bdeahaehmhzw",
"labels": {
"compute.googleapis.com/root_trigger_id": "60208691-711d-4fa3-bfe4-b8af41167a7f"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745447775-65565c523bd95-a351d411-d01cd85a",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.sslCertificates.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/sslCertificates/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/sslCertificates/dwn3-dw745304",
"service": "compute",
"type": "compute.sslCertificates"
}
},
{
"granted": true,
"permission": "compute.sslCertificates.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/sslCertificates/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/sslCertificates/dwn3-dw745304",
"service": "compute",
"type": "compute.sslCertificates"
}
}
],
"methodName": "v1.compute.sslCertificates.insert",
"request": {
"@type": "type.googleapis.com/compute.sslCertificates.insert",
"name": "dwn3-dw745304"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.ssl-certificates.create invocation-id/f81212f6991b4d3ab5d96055ac907cc8 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:04:08.166313Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/sslCertificates/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "8369178116449318792",
"insertTime": "2026-06-29T08:04:07.860-07:00",
"name": "operation-1782745447775-65565c523bd95-a351d411-d01cd85a",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745447775-65565c523bd95-a351d411-d01cd85a",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/8369178116449318792",
"startTime": "2026-06-29T08:04:07.865-07:00",
"status": "RUNNING",
"targetId": "3884773814616143752",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/sslCertificates/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:04:08.417792981Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"ssl_certificate_id": "3884773814616143752",
"ssl_certificate_name": "dwn3-dw745304"
},
"type": "gce_ssl_certificate"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:04:07.749897Z"
}
compute.sslCertificates.list: list
#Description
Retrieves the list of SslCertificate resources available to the specified project.
Data Access audit logs are disabled by default.
compute.sslPolicies.aggregatedList: aggregatedList
#Description
Retrieves the list of all SslPolicy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.sslPolicies.delete: delete
#Description
Deletes the specified SSL policy. The SSL policy resource can be deleted only if it is not in use by any TargetHttpsProxy or TargetSslProxy resources.
Example Audit Log Entry #
{
"insertId": "7szi1reg2b44",
"labels": {
"compute.googleapis.com/root_trigger_id": "f58ea3ac-d33a-49ba-8837-7a6ff8a5862e"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782747115931-655662891c853-7cb36233-6cda23b6",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.sslPolicies.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
"resourceAttributes": {
"name": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
"service": "compute",
"type": "compute.sslPolicies"
}
}
],
"methodName": "v1.compute.sslPolicies.delete",
"request": {
"@type": "type.googleapis.com/compute.sslPolicies.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.ssl-policies.delete invocation-id/bb544914090b4350a4585c1415a8cc07 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:31:56.173662Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
"response": {
"@type": "type.googleapis.com/operation",
"id": "474477542874493187",
"insertTime": "2026-06-29T08:31:56.040-07:00",
"name": "operation-1782747115931-655662891c853-7cb36233-6cda23b6",
"operationType": "delete",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782747115931-655662891c853-7cb36233-6cda23b6",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/474477542874493187",
"startTime": "2026-06-29T08:31:56.049-07:00",
"status": "RUNNING",
"targetId": "900054728269836753",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/sslPolicies/dwssl-dw746783",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:31:56.503154765Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.sslPolicies.delete",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:31:55.905263Z"
}
compute.sslPolicies.get: get
#Description
Lists all of the ordered rules present in a single specified policy.
Data Access audit logs are disabled by default.
compute.sslPolicies.insert: insert
#Description
Returns the specified SSL policy resource.
Example Audit Log Entry #
{
"insertId": "lxazskdf8ao",
"labels": {
"compute.googleapis.com/root_trigger_id": "e7c35f54-2e48-4a4d-b33f-c00c7ec67e76"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782746942037-655661e345da5-7c4b5bed-a03bcb5f",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.sslPolicies.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
"resourceAttributes": {
"name": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
"service": "compute",
"type": "compute.sslPolicies"
}
}
],
"methodName": "v1.compute.sslPolicies.insert",
"request": {
"@type": "type.googleapis.com/compute.sslPolicies.insert",
"minTlsVersion": "TLS_1_2",
"name": "dwssl-dw746783",
"profile": "MODERN"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.ssl-policies.create invocation-id/16354b3dbf2742aba96ca00a2d7775a8 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:29:03.014257Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/sslPolicies/dwssl-dw746783",
"response": {
"@type": "type.googleapis.com/operation",
"id": "57067654404321745",
"insertTime": "2026-06-29T08:29:02.439-07:00",
"name": "operation-1782746942037-655661e345da5-7c4b5bed-a03bcb5f",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782746942037-655661e345da5-7c4b5bed-a03bcb5f",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/57067654404321745",
"startTime": "2026-06-29T08:29:02.443-07:00",
"status": "RUNNING",
"targetId": "900054728269836753",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/sslPolicies/dwssl-dw746783",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:29:03.792808390Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.sslPolicies.insert",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:29:01.999333Z"
}
compute.sslPolicies.list: list
#Description
Lists all the SSL policies that have been configured for the specified project.
Data Access audit logs are disabled by default.
compute.sslPolicies.listAvailableFeatures: listAvailableFeatures
#Description
Lists all features that can be specified in the SSL policy when using custom profile.
Data Access audit logs are disabled by default.
compute.sslPolicies.patch: patch
#Description
Patches the specified SSL policy with the data included in the request.
compute.storagePoolTypes.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of storage pool types. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.storagePoolTypes.get: get
#Description
Returns the specified storage pool type.
Data Access audit logs are disabled by default.
compute.storagePoolTypes.list: list
#Description
Retrieves a list of storage pool types available to the specified project.
Data Access audit logs are disabled by default.
compute.storagePools.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of storage pools. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.storagePools.delete: delete
#Description
Deletes the specified storage pool. Deleting a storagePool removes its data permanently and is irreversible. However, deleting a storagePool does not delete any snapshots previously made from the storagePool. You must separately delete snapshots.
compute.storagePools.get: get
#Description
Returns a specified storage pool. Gets a list of available storage pools by making a list() request.
Data Access audit logs are disabled by default.
compute.storagePools.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.storagePools.insert: insert
#Description
Creates a storage pool in the specified project using the data in the request.
compute.storagePools.list: list
#Description
Retrieves a list of storage pools contained within the specified zone.
Data Access audit logs are disabled by default.
compute.storagePools.listDisks: listDisks
#Description
Lists the disks in a specified storage pool.
Data Access audit logs are disabled by default.
compute.storagePools.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
compute.storagePools.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.storagePools.update: update
#Description
Updates the specified storagePool with the data included in the request. The update is performed only on selected fields included as part of update-mask. Only the following fields can be modified: pool_provisioned_capacity_gb, pool_provisioned_iops and pool_provisioned_throughput.
compute.subnetworks.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of subnetworks. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "gz50ghe41rho",
"labels": {
"compute.googleapis.com/root_trigger_id": "9b560ff3-9cc2-4f94-8723-aa79b7406b55"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.subnetworks.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.subnetworks.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.subnetworks.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.list invocation-id/52c852ef64b74b078e971c96a308b9e9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:19:03.867335Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/subnetworks",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:19:04.792393124Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.subnetworks.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:19:03.635745Z"
}
compute.subnetworks.delete: delete
#Description
Deletes the specified subnetwork.
Example Audit Log Entry #
{
"insertId": "-eetn32e39diy",
"labels": {
"compute.googleapis.com/root_trigger_id": "a3fc5605-21fa-472d-b05c-c2926bed9d28"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782747049573-65566249d3e2f-da7f6a0f-8859dd5e",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.subnetworks.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
"service": "compute",
"type": "compute.subnetworks"
}
}
],
"methodName": "v1.compute.subnetworks.delete",
"request": {
"@type": "type.googleapis.com/compute.subnetworks.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.delete invocation-id/9f4646520ad246dcaa9e987b24d05677 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:30:50.323877Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
"response": {
"@type": "type.googleapis.com/operation",
"id": "1292404513359999301",
"insertTime": "2026-06-29T08:30:50.279-07:00",
"name": "operation-1782747049573-65566249d3e2f-da7f6a0f-8859dd5e",
"operationType": "delete",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782747049573-65566249d3e2f-da7f6a0f-8859dd5e",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/1292404513359999301",
"startTime": "2026-06-29T08:30:50.283-07:00",
"status": "RUNNING",
"targetId": "8667758831208445258",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:30:50.779202137Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"subnetwork_id": "8667758831208445258",
"subnetwork_name": "dwn4-dw745960"
},
"type": "gce_subnetwork"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:30:49.647324Z"
}
compute.subnetworks.expandIpCidrRange: expandIpCidrRange
#Description
Expands the IP CIDR range of the subnetwork to a specified value.
Example Audit Log Entry #
{
"insertId": "-arxy3ye4st1s",
"labels": {
"compute.googleapis.com/root_trigger_id": "cdb7aa93-b313-44e1-b926-f28a0c104529"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745347033-65565bf228b07-42267ea4-bac5a8d2",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.subnetworks.expandIpCidrRange",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
"service": "compute",
"type": "compute.subnetworks"
}
}
],
"methodName": "v1.compute.subnetworks.expandIpCidrRange",
"request": {
"@type": "type.googleapis.com/compute.subnetworks.expandIpCidrRange",
"ipCidrRange": "10.11.0.0/23"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.expand-ip-range invocation-id/d996edd4176e441ea1ffdb8c6e6faf07 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:02:27.738798Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "5566941891178477548",
"insertTime": "2026-06-29T08:02:27.691-07:00",
"name": "operation-1782745347033-65565bf228b07-42267ea4-bac5a8d2",
"operationType": "expandIpCidrRange",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782745347033-65565bf228b07-42267ea4-bac5a8d2",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/5566941891178477548",
"startTime": "2026-06-29T08:02:27.701-07:00",
"status": "RUNNING",
"targetId": "7239462238538380809",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:02:28.191377956Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"subnetwork_id": "7239462238538380809",
"subnetwork_name": "dwn3-dw745304"
},
"type": "gce_subnetwork"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:02:27.085602Z"
}
compute.subnetworks.get: get
#Description
Returns the specified subnetwork.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-susohme4rfk4",
"labels": {
"compute.googleapis.com/root_trigger_id": "cf92aa5a-8867-4bf5-bd75-56624357ef2a"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.subnetworks.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
"service": "compute",
"type": "compute.subnetworks"
}
}
],
"methodName": "v1.compute.subnetworks.get",
"request": {
"@type": "type.googleapis.com/compute.subnetworks.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.create invocation-id/88997435245f4532ae2513fb4e2acb8d environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:20:42.379911Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:20:42.595146086Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"subnetwork_id": "424051083471474679",
"subnetwork_name": "dwgen-dw739065"
},
"type": "gce_subnetwork"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:20:42.286501Z"
}
compute.subnetworks.getIamPolicy: getIamPolicy
#Description
Gets the access control policy for a resource. May be empty if no such policy or resource exists.
Data Access audit logs are disabled by default.
compute.subnetworks.insert: insert
#Description
Creates a subnetwork in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-t3mzgge2w08o",
"labels": {
"compute.googleapis.com/root_trigger_id": "243f1fa6-70a4-4f42-bf19-6dfc6755f3f3"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782739223725-65564522843f2-29cb8358-813b1c25",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.subnetworks.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
"service": "compute",
"type": "compute.subnetworks"
}
},
{
"granted": true,
"permission": "compute.networks.updatePolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/dwgen-dw739065",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/dwgen-dw739065",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.subnetworks.insert",
"request": {
"@type": "type.googleapis.com/compute.subnetworks.insert",
"ipCidrRange": "10.8.0.0/24",
"name": "dwgen-dw739065",
"network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwgen-dw739065",
"privateIpGoogleAccess": false
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.create invocation-id/88997435245f4532ae2513fb4e2acb8d environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:20:25.013691Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
"response": {
"@type": "type.googleapis.com/operation",
"id": "2040419509439811575",
"insertTime": "2026-06-29T06:20:24.953-07:00",
"name": "operation-1782739223725-65564522843f2-29cb8358-813b1c25",
"operationType": "insert",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782739223725-65564522843f2-29cb8358-813b1c25",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/2040419509439811575",
"status": "PENDING",
"targetId": "424051083471474679",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwgen-dw739065",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:20:25.608503415Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"subnetwork_id": "424051083471474679",
"subnetwork_name": "dwgen-dw739065"
},
"type": "gce_subnetwork"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T13:20:23.799297Z"
}
compute.subnetworks.list: list
#Description
Retrieves a list of subnetworks available to the specified project.
Data Access audit logs are disabled by default.
compute.subnetworks.listUsable: listUsable
#Description
Retrieves an aggregated list of all usable subnetworks in the project.
Data Access audit logs are disabled by default.
compute.subnetworks.patch: patch
#Description
Patches the specified subnetwork with the data included in the request. Only certain fields can be updated with a patch request as indicated in the field descriptions. You must specify the current fingerprint of the subnetwork resource being patched.
Example Audit Log Entry #
{
"insertId": "46zk7xd723s",
"labels": {
"compute.googleapis.com/root_trigger_id": "4693d407-89fc-4d5e-b830-80584aa19de9"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782751427697-6556729921c7a-cd5ddbd6-bcd78d58",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.subnetworks.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
"service": "compute",
"type": "compute.subnetworks"
}
},
{
"granted": true,
"permission": "compute.subnetworks.update",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
"service": "compute",
"type": "compute.subnetworks"
}
}
],
"methodName": "v1.compute.subnetworks.patch",
"request": {
"@type": "type.googleapis.com/compute.subnetworks.patch",
"fingerprint": "���?@�m\r",
"secondaryIpRanges": [
{
"ipCidrRange": "10.47.1.0/24",
"rangeName": "sec1"
}
]
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.update invocation-id/41cccc57ae6f4bc0b9477d1c50848116 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:43:47.947430Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
"response": {
"@type": "type.googleapis.com/operation",
"id": "905571120127532",
"insertTime": "2026-06-29T09:43:47.911-07:00",
"name": "operation-1782751427697-6556729921c7a-cd5ddbd6-bcd78d58",
"operationType": "compute.subnetworks.patch",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782751427697-6556729921c7a-cd5ddbd6-bcd78d58",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/905571120127532",
"startTime": "2026-06-29T09:43:47.917-07:00",
"status": "RUNNING",
"targetId": "7299916566109298265",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn7e126182",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:43:48.796662665Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"subnetwork_id": "7299916566109298265",
"subnetwork_name": "dwn7e126182"
},
"type": "gce_subnetwork"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:43:47.759356Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
compute.subnetworks.setIamPolicy: setIamPolicy
#Description
Sets the access control policy on the specified resource. Replaces any existing policy.
Example Audit Log Entry #
{
"insertId": "z0ib7ce476qi",
"labels": {
"compute.googleapis.com/root_trigger_id": "1ea9b3fd-4bc4-4b4e-9f18-22a226e35aff"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.subnetworks.setIamPolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
"service": "compute",
"type": "compute.subnetworks"
}
}
],
"methodName": "v1.compute.subnetworks.setIamPolicy",
"request": {
"@type": "type.googleapis.com/compute.subnetworks.setIamPolicy",
"policy": {
"bindings": [
{
"members": [
"user:user@example.com"
],
"role": "roles/compute.networkUser"
}
],
"version": "3"
}
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.set-iam-policy invocation-id/f1975807bc01441988a46254711c9efb environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:14:04.273751Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwn4-dw745960",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:14:05.110242737Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"subnetwork_id": "8667758831208445258",
"subnetwork_name": "dwn4-dw745960"
},
"type": "gce_subnetwork"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:14:04.143265Z"
}
compute.subnetworks.setPrivateIpGoogleAccess: setPrivateIpGoogleAccess
#Description
Set whether VMs in this subnet can access Google services without assigning external IP addresses through Private Google Access.
Example Audit Log Entry #
{
"insertId": "-4fl9vpe83dq0",
"labels": {
"compute.googleapis.com/root_trigger_id": "e0c5d2cf-7ff1-4b61-b750-52fb6b1a2e14"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745380423-65565c120087d-758930d8-c7d2e395",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.subnetworks.setPrivateIpGoogleAccess",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
"service": "compute",
"type": "compute.subnetworks"
}
}
],
"methodName": "v1.compute.subnetworks.setPrivateIpGoogleAccess",
"request": {
"@type": "type.googleapis.com/compute.subnetworks.setPrivateIpGoogleAccess",
"privateIpGoogleAccess": true
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.networks.subnets.update invocation-id/0ff7455620ab4d81883162c36f481ac2 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:03:00.695200Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "715287601722898379",
"insertTime": "2026-06-29T08:03:00.660-07:00",
"name": "operation-1782745380423-65565c120087d-758930d8-c7d2e395",
"operationType": "setPrivateIpGoogleAccess",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782745380423-65565c120087d-758930d8-c7d2e395",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/715287601722898379",
"startTime": "2026-06-29T08:03:00.665-07:00",
"status": "RUNNING",
"targetId": "7239462238538380809",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/subnetworks/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:03:00.810818539Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"subnetwork_id": "7239462238538380809",
"subnetwork_name": "dwn3-dw745304"
},
"type": "gce_subnetwork"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:03:00.551516Z"
}
compute.subnetworks.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.targetGrpcProxies.delete: delete
#Description
Deletes the specified TargetGrpcProxy in the given scope
compute.targetGrpcProxies.get: get
#Description
Returns the specified TargetGrpcProxy resource in the given scope.
Data Access audit logs are disabled by default.
compute.targetGrpcProxies.insert: insert
#Description
Creates a TargetGrpcProxy in the specified project in the given scope using the parameters that are included in the request.
compute.targetGrpcProxies.list: list
#Description
Lists the TargetGrpcProxies for a project in the given scope.
Data Access audit logs are disabled by default.
compute.targetGrpcProxies.patch: patch
#Description
Patches the specified TargetGrpcProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.
compute.targetHttpProxies.aggregatedList: aggregatedList
#Description
Retrieves the list of all TargetHttpProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-7pbhwme2ig8m",
"labels": {
"compute.googleapis.com/root_trigger_id": "022d0ac7-2ed5-4089-8830-4acaebf3e8db"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.targetHttpProxies.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.targetHttpProxies.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.targetHttpProxies.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-http-proxies.list invocation-id/fa885c2816c04623b3c43d2bf84d9519 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:59.315733Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/targetHttpProxies",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:59.756703184Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"target_http_proxy_id": ""
},
"type": "gce_target_http_proxy"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:59.240439Z"
}
compute.targetHttpProxies.delete: delete
#Description
Deletes the specified TargetHttpProxy resource.
compute.targetHttpProxies.get: get
#Description
Returns the specified TargetHttpProxy resource.
Data Access audit logs are disabled by default.
compute.targetHttpProxies.insert: insert
#Description
Creates a TargetHttpProxy resource in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "bof91cd8jdg",
"labels": {
"compute.googleapis.com/root_trigger_id": "882aea5f-b48a-4a41-a654-2edf867950f5"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745429324-65565c40a324a-19ad8652-71b5a643",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.targetHttpProxies.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
"service": "compute",
"type": "compute.targetHttpProxies"
}
},
{
"granted": true,
"permission": "compute.urlMaps.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/urlMaps/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/urlMaps/dwn3-dw745304",
"service": "compute",
"type": "compute.urlMaps"
}
}
],
"methodName": "v1.compute.targetHttpProxies.insert",
"request": {
"@type": "type.googleapis.com/compute.targetHttpProxies.insert",
"name": "dwn3-dw745304",
"urlMap": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/urlMaps/dwn3-dw745304"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-http-proxies.create invocation-id/7f5c5de7a99f40ffb3df0fa4e379892d environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:03:49.899777Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "2138839784539240378",
"insertTime": "2026-06-29T08:03:49.763-07:00",
"name": "operation-1782745429324-65565c40a324a-19ad8652-71b5a643",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745429324-65565c40a324a-19ad8652-71b5a643",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2138839784539240378",
"startTime": "2026-06-29T08:03:49.765-07:00",
"status": "RUNNING",
"targetId": "1860445510560593850",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/targetHttpProxies/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:03:49.972054496Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"target_http_proxy_id": "1860445510560593850"
},
"type": "gce_target_http_proxy"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:03:49.402214Z"
}
compute.targetHttpProxies.list: list
#Description
Retrieves the list of TargetHttpProxy resources available to the specified project.
Data Access audit logs are disabled by default.
compute.targetHttpProxies.patch: patch
#Description
Patches the specified TargetHttpProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.
compute.targetHttpProxies.setUrlMap: setUrlMap
#Description
Changes the URL map for TargetHttpProxy.
compute.targetHttpsProxies.aggregatedList: aggregatedList
#Description
Retrieves the list of all TargetHttpsProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-o4fnx0dmx9g",
"labels": {
"compute.googleapis.com/root_trigger_id": "4cf2c82f-2a6e-47af-befa-0536a5537313"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.targetHttpsProxies.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.targetHttpsProxies.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.targetHttpsProxies.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-https-proxies.list invocation-id/fb9687339f7542c4b2209bca1d37431f environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:19:00.702467Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/targetHttpsProxies",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:19:00.973959637Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"target_https_proxy_id": ""
},
"type": "gce_target_https_proxy"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:19:00.617546Z"
}
compute.targetHttpsProxies.delete: delete
#Description
Deletes the specified TargetHttpsProxy resource.
compute.targetHttpsProxies.get: get
#Description
Returns the specified TargetHttpsProxy resource.
Data Access audit logs are disabled by default.
compute.targetHttpsProxies.insert: insert
#Description
Creates a TargetHttpsProxy resource in the specified project using the data included in the request.
compute.targetHttpsProxies.list: list
#Description
Retrieves the list of TargetHttpsProxy resources available to the specified project.
Data Access audit logs are disabled by default.
compute.targetHttpsProxies.patch: patch
#Description
Patches the specified TargetHttpsProxy resource with the data included in the request. This method supports PATCH semantics and usesJSON merge patch format and processing rules.
compute.targetHttpsProxies.setCertificateMap: setCertificateMap
#Description
Changes the Certificate Map for TargetHttpsProxy.
compute.targetHttpsProxies.setQuicOverride: setQuicOverride
#Description
Sets the QUIC override policy for TargetHttpsProxy.
compute.targetHttpsProxies.setSslCertificates: setSslCertificates
#Description
Replaces SslCertificates for TargetHttpsProxy.
compute.targetHttpsProxies.setSslPolicy: setSslPolicy
#Description
Sets the SSL policy for TargetHttpsProxy. The SSL policy specifies the server-side support for SSL features. This affects connections between clients and the HTTPS proxy load balancer. They do not affect the connection between the load balancer and the backends.
compute.targetHttpsProxies.setUrlMap: setUrlMap
#Description
Changes the URL map for TargetHttpsProxy.
compute.targetInstances.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of target instances. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.targetInstances.delete: delete
#Description
Deletes the specified TargetInstance resource.
compute.targetInstances.get: get
#Description
Returns the specified TargetInstance resource.
Data Access audit logs are disabled by default.
compute.targetInstances.insert: insert
#Description
Creates a TargetInstance resource in the specified project and zone using the data included in the request.
compute.targetInstances.list: list
#Description
Retrieves a list of TargetInstance resources available to the specified project and zone.
Data Access audit logs are disabled by default.
compute.targetInstances.setSecurityPolicy: setSecurityPolicy
#Description
Sets the Google Cloud Armor security policy for the specified target instance. For more information, seeGoogle Cloud Armor Overview
compute.targetInstances.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.targetPools.addHealthCheck: addHealthCheck
#Description
Adds health check URLs to a target pool.
compute.targetPools.addInstance: addInstance
#Description
Adds an instance to a target pool.
compute.targetPools.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of target pools. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "d1n4mrdsnd8",
"labels": {
"compute.googleapis.com/root_trigger_id": "765183ee-296c-4ba7-8fae-654dcfc311c7"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.targetPools.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.targetPools.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.targetPools.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-pools.list invocation-id/a3d168a0b2d54b90949100dbb28f3bf2 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:32.036448Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/targetPools",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:32.750396935Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.targetPools.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:31.976461Z"
}
compute.targetPools.delete: delete
#Description
Deletes the specified target pool.
compute.targetPools.get: get
#Description
Returns the specified target pool.
Data Access audit logs are disabled by default.
compute.targetPools.getHealth: getHealth
#Description
Gets the most recent health check results for each IP for the instance that is referenced by the given target pool.
Data Access audit logs are disabled by default.
compute.targetPools.insert: insert
#Description
Creates a target pool in the specified project and region using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-lbqbnje4266m",
"labels": {
"compute.googleapis.com/root_trigger_id": "d76bb787-192d-4fcf-a012-8d4f83f48572"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745524113-65565c9b09055-c513e2c9-7445a58a",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.targetPools.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/targetPools/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/targetPools/dwn3-dw745304",
"service": "compute",
"type": "compute.targetPools"
}
}
],
"methodName": "v1.compute.targetPools.insert",
"request": {
"@type": "type.googleapis.com/compute.targetPools.insert",
"name": "dwn3-dw745304",
"sessionAffinity": "NONE"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-pools.create invocation-id/8d40743a846749dabc01cb363f42e603 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:05:24.333221Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/targetPools/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "8053302139619850075",
"insertTime": "2026-06-29T08:05:24.298-07:00",
"name": "operation-1782745524113-65565c9b09055-c513e2c9-7445a58a",
"operationType": "insert",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782745524113-65565c9b09055-c513e2c9-7445a58a",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/8053302139619850075",
"startTime": "2026-06-29T08:05:24.301-07:00",
"status": "RUNNING",
"targetId": "4069930833999247195",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/targetPools/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:05:25.057201413Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"target_pool_id": "4069930833999247195",
"zone": "us-central1"
},
"type": "gce_target_pool"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:05:24.174060Z"
}
compute.targetPools.list: list
#Description
Retrieves a list of target pools available to the specified project and region.
Data Access audit logs are disabled by default.
compute.targetPools.removeHealthCheck: removeHealthCheck
#Description
Removes health check URL from a target pool.
compute.targetPools.removeInstance: removeInstance
#Description
Removes instance URL from a target pool.
compute.targetPools.setBackup: setBackup
#Description
Changes a backup target pool's configurations.
compute.targetPools.setSecurityPolicy: setSecurityPolicy
#Description
Sets the Google Cloud Armor security policy for the specified target pool. For more information, seeGoogle Cloud Armor Overview
compute.targetPools.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.targetSslProxies.delete: delete
#Description
Deletes the specified TargetSslProxy resource.
compute.targetSslProxies.get: get
#Description
Returns the specified TargetSslProxy resource.
Data Access audit logs are disabled by default.
compute.targetSslProxies.insert: insert
#Description
Creates a TargetSslProxy resource in the specified project using the data included in the request.
compute.targetSslProxies.list: list
#Description
Retrieves the list of TargetSslProxy resources available to the specified project.
Data Access audit logs are disabled by default.
compute.targetSslProxies.setBackendService: setBackendService
#Description
Changes the BackendService for TargetSslProxy.
compute.targetSslProxies.setCertificateMap: setCertificateMap
#Description
Changes the Certificate Map for TargetSslProxy.
compute.targetSslProxies.setProxyHeader: setProxyHeader
#Description
Changes the ProxyHeaderType for TargetSslProxy.
compute.targetSslProxies.setSslCertificates: setSslCertificates
#Description
Changes SslCertificates for TargetSslProxy.
compute.targetSslProxies.setSslPolicy: setSslPolicy
#Description
Sets the SSL policy for TargetSslProxy. The SSL policy specifies the server-side support for SSL features. This affects connections between clients and the load balancer. They do not affect the connection between the load balancer and the backends.
compute.targetSslProxies.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.targetTcpProxies.aggregatedList: aggregatedList
#Description
Retrieves the list of all TargetTcpProxy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.targetTcpProxies.delete: delete
#Description
Deletes the specified TargetTcpProxy resource.
compute.targetTcpProxies.get: get
#Description
Returns the specified TargetTcpProxy resource.
Data Access audit logs are disabled by default.
compute.targetTcpProxies.insert: insert
#Description
Creates a TargetTcpProxy resource in the specified project using the data included in the request.
compute.targetTcpProxies.list: list
#Description
Retrieves the list of TargetTcpProxy resources available to the specified project.
Data Access audit logs are disabled by default.
compute.targetTcpProxies.setBackendService: setBackendService
#Description
Changes the BackendService for TargetTcpProxy.
compute.targetTcpProxies.setProxyHeader: setProxyHeader
#Description
Changes the ProxyHeaderType for TargetTcpProxy.
compute.targetTcpProxies.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.targetVpnGateways.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of target VPN gateways. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-l1srtzd5qdy",
"labels": {
"compute.googleapis.com/root_trigger_id": "cfa4ad32-dfbf-4bab-b92b-539860650fa4"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.targetVpnGateways.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.targetVpnGateways.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.targetVpnGateways.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-vpn-gateways.list invocation-id/0ba41739ca1246208f746789acd4d806 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:49.259163Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/targetVpnGateways",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:50.182992379Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.targetVpnGateways.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:49.139697Z"
}
compute.targetVpnGateways.delete: delete
#Description
Deletes the specified target VPN gateway.
Example Audit Log Entry #
{
"insertId": "ftq1h3dkply",
"labels": {
"compute.googleapis.com/root_trigger_id": "f7b3ea03-aeea-4f61-bb13-e8e0de91520c"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782751041762-6556712913470-2c7bc076-b63a6ff8",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.targetVpnGateways.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
"service": "compute",
"type": "compute.targetVpnGateways"
}
}
],
"methodName": "v1.compute.targetVpnGateways.delete",
"request": {
"@type": "type.googleapis.com/compute.targetVpnGateways.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-vpn-gateways.delete invocation-id/43f96eb83b6442828edf6bc842a20fbe environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:37:21.964771Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
"response": {
"@type": "type.googleapis.com/operation",
"id": "350832198996140462",
"insertTime": "2026-06-29T09:37:21.885-07:00",
"name": "operation-1782751041762-6556712913470-2c7bc076-b63a6ff8",
"operationType": "delete",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782751041762-6556712913470-2c7bc076-b63a6ff8",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/350832198996140462",
"startTime": "2026-06-29T09:37:21.908-07:00",
"status": "RUNNING",
"targetId": "5216856529901134626",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:37:22.731965164Z",
"resource": {
"labels": {
"gateway_id": "5216856529901134626",
"project_id": "example-project-id",
"region": "us-central1"
},
"type": "vpn_gateway"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:37:21.725980Z"
}
compute.targetVpnGateways.get: get
#Description
Returns the specified target VPN gateway.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "4ga1idd9l0g",
"labels": {
"compute.googleapis.com/root_trigger_id": "20ff4afe-09cf-4437-8238-caf40a5ccb33"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.targetVpnGateways.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
"service": "compute",
"type": "compute.targetVpnGateways"
}
}
],
"methodName": "v1.compute.targetVpnGateways.get",
"request": {
"@type": "type.googleapis.com/compute.targetVpnGateways.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-vpn-gateways.create invocation-id/bc1305e24fe340ce9ff31686dfe4680c environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:31:11.332300Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:31:12.126907392Z",
"resource": {
"labels": {
"gateway_id": "5216856529901134626",
"project_id": "example-project-id",
"region": "us-central1"
},
"type": "vpn_gateway"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:31:11.095312Z"
}
compute.targetVpnGateways.insert: insert
#Description
Creates a target VPN gateway in the specified project and region using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-4e3xu0e5a780",
"labels": {
"compute.googleapis.com/root_trigger_id": "f575c4f9-9c14-4bdd-bce5-edf210eabe36"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750669910-65566fc6733cf-0c2262c8-9e703843",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.targetVpnGateways.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
"service": "compute",
"type": "compute.targetVpnGateways"
}
},
{
"granted": true,
"permission": "compute.networks.updatePolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/dwn7c068744",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/dwn7c068744",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.targetVpnGateways.insert",
"request": {
"@type": "type.googleapis.com/compute.targetVpnGateways.insert",
"name": "dwtgw7c068744",
"network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn7c068744"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.target-vpn-gateways.create invocation-id/bc1305e24fe340ce9ff31686dfe4680c environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:31:10.158861Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
"response": {
"@type": "type.googleapis.com/operation",
"id": "4882535682875007777",
"insertTime": "2026-06-29T09:31:10.081-07:00",
"name": "operation-1782750669910-65566fc6733cf-0c2262c8-9e703843",
"operationType": "insert",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750669910-65566fc6733cf-0c2262c8-9e703843",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/4882535682875007777",
"startTime": "2026-06-29T09:31:10.086-07:00",
"status": "RUNNING",
"targetId": "5216856529901134626",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/targetVpnGateways/dwtgw7c068744",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:31:10.450450667Z",
"resource": {
"labels": {
"gateway_id": "5216856529901134626",
"project_id": "example-project-id",
"region": "us-central1"
},
"type": "vpn_gateway"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:31:09.888202Z"
}
compute.targetVpnGateways.list: list
#Description
Retrieves a list of target VPN gateways available to the specified project and region.
Data Access audit logs are disabled by default.
compute.targetVpnGateways.setLabels: setLabels
#Description
Sets the labels on a TargetVpnGateway. To learn more about labels, read theLabeling Resources documentation.
compute.urlMaps.aggregatedList: aggregatedList
#Description
Retrieves the list of all UrlMap resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-1dujd6e82pew",
"labels": {
"compute.googleapis.com/root_trigger_id": "940566fa-c1fb-4c52-877b-64350e12b0d8"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.urlMaps.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.urlMaps.aggregatedList",
"numResponseItems": "176",
"request": {
"@type": "type.googleapis.com/compute.urlMaps.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.url-maps.list invocation-id/eb971c4e4e7b4ebebf027935b674a967 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:30.781542Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/urlMaps",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:31.010108302Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"url_map_id": ""
},
"type": "gce_url_map"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:30.621835Z"
}
compute.urlMaps.delete: delete
#Description
Deletes the specified UrlMap resource.
compute.urlMaps.get: get
#Description
Returns the specified UrlMap resource.
Data Access audit logs are disabled by default.
compute.urlMaps.insert: insert
#Description
Creates a UrlMap resource in the specified project using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-r6q7ake5qmiq",
"labels": {
"compute.googleapis.com/root_trigger_id": "779daba9-970c-4e1d-8896-1a1b3a7e1b3e"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782745423512-65565c3b18405-349e89e9-987d262d",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.urlMaps.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/urlMaps/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/urlMaps/dwn3-dw745304",
"service": "compute",
"type": "compute.urlMaps"
}
},
{
"granted": true,
"permission": "compute.backendServices.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/backendServices/dwn3-dw745304",
"resourceAttributes": {
"name": "projects/example-project-id/global/backendServices/dwn3-dw745304",
"service": "compute",
"type": "compute.backendServices"
}
}
],
"methodName": "v1.compute.urlMaps.insert",
"request": {
"@type": "type.googleapis.com/compute.urlMaps.insert",
"defaultService": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/backendServices/dwn3-dw745304",
"name": "dwn3-dw745304"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.url-maps.create invocation-id/e29028d8d6b2422195ca5b958cf3b5b7 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T15:03:44.030673Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/urlMaps/dwn3-dw745304",
"response": {
"@type": "type.googleapis.com/operation",
"id": "2482222853646137248",
"insertTime": "2026-06-29T08:03:43.723-07:00",
"name": "operation-1782745423512-65565c3b18405-349e89e9-987d262d",
"operationType": "insert",
"progress": "0",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/operation-1782745423512-65565c3b18405-349e89e9-987d262d",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/operations/2482222853646137248",
"startTime": "2026-06-29T08:03:43.727-07:00",
"status": "RUNNING",
"targetId": "2488935084370900896",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/global/urlMaps/dwn3-dw745304",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T15:03:44.880118331Z",
"resource": {
"labels": {
"project_id": "example-project-id",
"url_map_id": "2488935084370900896"
},
"type": "gce_url_map"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T15:03:43.491671Z"
}
compute.urlMaps.invalidateCache: invalidateCache
#Description
Initiates a cache invalidation operation, invalidating the specified path, scoped to the specified UrlMap. For more information, see Invalidating cached content.
compute.urlMaps.list: list
#Description
Retrieves the list of UrlMap resources available to the specified project.
Data Access audit logs are disabled by default.
compute.urlMaps.patch: patch
#Description
Patches the specified UrlMap resource with the data included in the request. This method supportsPATCH semantics and uses theJSON merge patch format and processing rules.
compute.urlMaps.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.urlMaps.update: update
#Description
Updates the specified UrlMap resource with the data included in the request.
compute.urlMaps.validate: validate
#Description
Runs static validation for the UrlMap. In particular, the tests of the provided UrlMap will be run. Calling this method does NOT create the UrlMap.
compute.vpnGateways.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of VPN gateways. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.
compute.vpnGateways.delete: delete
#Description
Deletes the specified VPN gateway.
Example Audit Log Entry #
{
"insertId": "1xzcwke2nvig",
"labels": {
"compute.googleapis.com/root_trigger_id": "1b3c0734-e4da-4f59-b7d7-1833be579287"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750835440-655670644fc65-cfad3dc4-166caf3e",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.vpnGateways.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"service": "compute",
"type": "compute.vpnGateways"
}
}
],
"methodName": "v1.compute.vpnGateways.delete",
"request": {
"@type": "type.googleapis.com/compute.vpnGateways.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-gateways.delete invocation-id/69239331a76e4c81aa22e626c7dbfb5e environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:33:55.569523Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"response": {
"@type": "type.googleapis.com/operation",
"id": "479278259749462172",
"insertTime": "2026-06-29T09:33:55.527-07:00",
"name": "operation-1782750835440-655670644fc65-cfad3dc4-166caf3e",
"operationType": "compute.vpnGateways.delete",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750835440-655670644fc65-cfad3dc4-166caf3e",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/479278259749462172",
"startTime": "2026-06-29T09:33:55.534-07:00",
"status": "RUNNING",
"targetId": "1638926550725239489",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:33:56.331797686Z",
"resource": {
"labels": {
"location": "us-central1",
"method": "compute.vpnGateways.delete",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:33:55.402698Z"
}
compute.vpnGateways.get: get
#Description
Returns the specified VPN gateway.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "b45h5be7pfss",
"labels": {
"compute.googleapis.com/root_trigger_id": "876f8749-2ee6-4439-a4f8-41afd1180525"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.vpnGateways.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"service": "compute",
"type": "compute.vpnGateways"
}
}
],
"methodName": "v1.compute.vpnGateways.get",
"request": {
"@type": "type.googleapis.com/compute.vpnGateways.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-gateways.create invocation-id/3f9c3929eae44ebfad9d61ea26ad4230 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:24:16.933317Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:24:17.256770325Z",
"resource": {
"labels": {
"location": "us-central1",
"method": "compute.vpnGateways.get",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:24:16.866812Z"
}
compute.vpnGateways.getStatus: getStatus
#Description
Returns the status for the specified VPN gateway.
Data Access audit logs are disabled by default.
compute.vpnGateways.insert: insert
#Description
Creates a VPN gateway in the specified project and region using the data included in the request.
Example Audit Log Entry #
{
"insertId": "-2harb5e38zl4",
"labels": {
"compute.googleapis.com/root_trigger_id": "d7231aa9-2c6c-4fce-9fb4-ee3f5d8cc3a5"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750254474-65566e3a424a6-204ec108-78927688",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.vpnGateways.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"service": "compute",
"type": "compute.vpnGateways"
}
},
{
"granted": true,
"permission": "compute.networks.updatePolicy",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/networks/dwn7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/networks/dwn7201353",
"service": "compute",
"type": "compute.networks"
}
}
],
"methodName": "v1.compute.vpnGateways.insert",
"request": {
"@type": "type.googleapis.com/compute.vpnGateways.insert",
"name": "dwvgw7201353",
"network": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/networks/dwn7201353"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-gateways.create invocation-id/3f9c3929eae44ebfad9d61ea26ad4230 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:24:14.959942Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"response": {
"@type": "type.googleapis.com/operation",
"id": "1110148817399784129",
"insertTime": "2026-06-29T09:24:14.679-07:00",
"name": "operation-1782750254474-65566e3a424a6-204ec108-78927688",
"operationType": "compute.vpnGateways.insert",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750254474-65566e3a424a6-204ec108-78927688",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/1110148817399784129",
"startTime": "2026-06-29T09:24:14.731-07:00",
"status": "RUNNING",
"targetId": "1638926550725239489",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:24:15.307627570Z",
"resource": {
"labels": {
"location": "us-central1",
"method": "compute.vpnGateways.insert",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:24:14.457224Z"
}
compute.vpnGateways.list: list
#Description
Retrieves a list of VPN gateways available to the specified project and region.
Data Access audit logs are disabled by default.
compute.vpnGateways.setLabels: setLabels
#Description
Sets the labels on a VpnGateway. To learn more about labels, read theLabeling Resources documentation.
compute.vpnGateways.testIamPermissions: testIamPermissions
#Description
Returns permissions that a caller has on the specified resource.
Data Access audit logs are disabled by default.
compute.vpnTunnels.aggregatedList: aggregatedList
#Description
Retrieves an aggregated list of VPN tunnels. To prevent failure, Google recommends that you set the `returnPartialSuccess` parameter to `true`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "p9bmsydws6m",
"labels": {
"compute.googleapis.com/root_trigger_id": "c6ce3a2c-8f72-45e7-a510-f95ba33e4df7"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.vpnTunnels.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.vpnTunnels.aggregatedList",
"numResponseItems": "43",
"request": {
"@type": "type.googleapis.com/compute.vpnTunnels.aggregatedList"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-tunnels.list invocation-id/df3e7b2f41d44dcfb422a4728d7927b6 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:47.873098Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/global/vpnTunnels",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:48.021049276Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.vpnTunnels.aggregatedList",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:47.747318Z"
}
compute.vpnTunnels.delete: Delete VPN tunnel
#Description
Deletes the specified VPN Tunnel resource.
Example Audit Log Entry #
{
"insertId": "-psnk3fe8f1sa",
"labels": {
"compute.googleapis.com/root_trigger_id": "7d7e77b3-867b-4d77-aa37-7895ee396907"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750778591-6556702e18a79-63b26ed9-70dbd948",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.vpnTunnels.delete",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
"service": "compute",
"type": "compute.vpnTunnels"
}
}
],
"methodName": "v1.compute.vpnTunnels.delete",
"request": {
"@type": "type.googleapis.com/compute.vpnTunnels.delete"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-tunnels.delete invocation-id/d8a67df265bb4e8d9ca98bb962e772d0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:32:58.777772Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
"response": {
"@type": "type.googleapis.com/operation",
"id": "3828055915319206101",
"insertTime": "2026-06-29T09:32:58.677-07:00",
"name": "operation-1782750778591-6556702e18a79-63b26ed9-70dbd948",
"operationType": "delete",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750778591-6556702e18a79-63b26ed9-70dbd948",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/3828055915319206101",
"startTime": "2026-06-29T09:32:58.692-07:00",
"status": "RUNNING",
"targetId": "3874875912158650568",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:32:59.669466345Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"tunnel_id": "3874875912158650568",
"tunnel_name": "dwvt7d068744"
},
"type": "vpn_tunnel"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:32:58.564332Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
compute.vpnTunnels.get: get
#Description
Returns the specified VpnTunnel resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "47bxo0e4fwus",
"labels": {
"compute.googleapis.com/root_trigger_id": "361a09b7-91cd-4bf6-bb3f-e52cd2c8c38f"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.vpnTunnels.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
"service": "compute",
"type": "compute.vpnTunnels"
}
}
],
"methodName": "v1.compute.vpnTunnels.get",
"request": {
"@type": "type.googleapis.com/compute.vpnTunnels.get"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-tunnels.create invocation-id/b682445225614e4985bc3da1a77f1766 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:32:53.301945Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7d068744",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:32:53.982005924Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"tunnel_id": "3874875912158650568",
"tunnel_name": "dwvt7d068744"
},
"type": "vpn_tunnel"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:32:53.238897Z"
}
compute.vpnTunnels.insert: Insert VPN tunnel
#Description
Creates a VpnTunnel resource in the specified project and region using the data included in the request.
Example Audit Log Entry #
{
"insertId": "svdnsqe8m9xc",
"labels": {
"compute.googleapis.com/root_trigger_id": "097573d5-ace8-4c6b-b377-4a16bac8e003"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"first": true,
"id": "operation-1782750261941-65566e4161577-f9d5e578-f1d237e3",
"producer": "compute.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.vpnTunnels.create",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7201353",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7201353",
"service": "compute",
"type": "compute.vpnTunnels"
}
},
{
"granted": true,
"permission": "compute.routers.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
"service": "compute",
"type": "compute.routers"
}
},
{
"granted": true,
"permission": "compute.vpnGateways.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"resourceAttributes": {
"name": "projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"service": "compute",
"type": "compute.vpnGateways"
}
},
{
"granted": true,
"permission": "compute.externalVpnGateways.use",
"permissionType": "ADMIN_WRITE",
"resource": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"resourceAttributes": {
"name": "projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"service": "compute",
"type": "compute.externalVpnGateways"
}
}
],
"methodName": "v1.compute.vpnTunnels.insert",
"request": {
"@type": "type.googleapis.com/compute.vpnTunnels.insert",
"ikeVersion": "2",
"name": "dwvt7201353",
"peerExternalGateway": "https://compute.googleapis.com/compute/v1/projects/example-project-id/global/externalVpnGateways/dwegw7201353",
"peerExternalGatewayInterface": "0",
"router": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/routers/dwrtr7201353",
"vpnGateway": "https://compute.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/vpnGateways/dwvgw7201353",
"vpnGatewayInterface": "0"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.vpn-tunnels.create invocation-id/03c6b384dc7c4362a7df7f74e0b700e9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T16:24:22.359864Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
},
"resourceName": "projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7201353",
"response": {
"@type": "type.googleapis.com/operation",
"id": "4833237373941654233",
"insertTime": "2026-06-29T09:24:22.231-07:00",
"name": "operation-1782750261941-65566e4161577-f9d5e578-f1d237e3",
"operationType": "insert",
"progress": "0",
"region": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1",
"selfLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/operation-1782750261941-65566e4161577-f9d5e578-f1d237e3",
"selfLinkWithId": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/operations/4833237373941654233",
"startTime": "2026-06-29T09:24:22.234-07:00",
"status": "RUNNING",
"targetId": "744197005117432538",
"targetLink": "https://www.googleapis.com/compute/v1/projects/example-project-id/regions/us-central1/vpnTunnels/dwvt7201353",
"user": "user@example.com"
},
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:24:22.897923033Z",
"resource": {
"labels": {
"location": "us-central1",
"project_id": "example-project-id",
"tunnel_id": "744197005117432538",
"tunnel_name": "dwvt7201353"
},
"type": "vpn_tunnel"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:24:21.904200Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
compute.vpnTunnels.list: list
#Description
Retrieves a list of VpnTunnel resources contained in the specified project and region.
Data Access audit logs are disabled by default.
compute.vpnTunnels.setLabels: setLabels
#Description
Sets the labels on a VpnTunnel. To learn more about labels, read theLabeling Resources documentation.
compute.wireGroups.delete: delete
#Description
Deletes the specified wire group in the given scope.
compute.wireGroups.get: get
#Description
Gets the specified wire group resource in the given scope.
Data Access audit logs are disabled by default.
compute.wireGroups.insert: insert
#Description
Creates a wire group in the specified project in the given scope using the parameters that are included in the request.
compute.wireGroups.list: list
#Description
Lists the wire groups for a project in the given scope.
Data Access audit logs are disabled by default.
compute.wireGroups.patch: patch
#Description
Updates the specified wire group resource with the data included in the request. This method supportsPATCH semantics and usesJSON merge patch format and processing rules.
compute.zoneOperations.delete: delete
#Description
Deletes the specified zone-specific Operations resource.
compute.zoneOperations.get: get
#Description
Retrieves the specified zone-specific Operations resource.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "6o7gmee1mdn2",
"labels": {
"compute.googleapis.com/root_trigger_id": "35ef1567-722d-466e-83d2-c6163002ba53"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.zoneOperations.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/zones/us-central1-a/operations/operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/operations/operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
"service": "compute",
"type": "compute.zoneOperations"
}
}
],
"methodName": "v1.compute.zoneOperations.get",
"request": {
"@type": "type.googleapis.com/compute.zoneOperations.get"
},
"requestMetadata": {
"callerIp": "private",
"callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:42:34.621053Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/operations/operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:42:34.726139448Z",
"resource": {
"labels": {
"location": "us-central1-a",
"operation_name": "operation-1782744011492-655656f87ce35-20d8ddfe-5e9dba38",
"project_id": "example-project-id"
},
"type": "gce_operation"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:42:34.574392Z"
}
compute.zoneOperations.list: list
#Description
Retrieves a list of Operation resources contained within the specified zone.
Data Access audit logs are disabled by default.
compute.zoneOperations.wait: wait
#Description
Waits for the specified Operation resource to return as `DONE` or for the request to approach the 2 minute deadline, and retrieves the specified Operation resource. This method waits for no more than the 2 minutes and then returns the current state of the operation, which might be `DONE` or still in progress. This method is called on a best-effort basis. Specifically: - In uncommon cases, when the server is overloaded, the request might return before the default deadline is reached, or might return after zero seconds. - If the default deadline is reached, there is no guarantee that the operation is actually done when the method returns. Be prepared to retry if the operation is not `DONE`.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-r5ifl7e3af0a",
"labels": {
"compute.googleapis.com/root_trigger_id": "c17059cf-4203-4a9d-8cb8-11889725eaf4"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.zoneOperations.get",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id/zones/us-central1-a/operations/operation-1782739348249-65564599459f9-31ad5434-c32a2182",
"resourceAttributes": {
"name": "projects/example-project-id/zones/us-central1-a/operations/operation-1782739348249-65564599459f9-31ad5434-c32a2182",
"service": "compute",
"type": "compute.zoneOperations"
}
}
],
"methodName": "v1.compute.zoneOperations.wait",
"request": {
"@type": "type.googleapis.com/compute.zoneOperations.wait"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.instances.create invocation-id/d3a99ae5add44e01b925c5905c2c65e4 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:22:41.190270Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-a/operations/operation-1782739348249-65564599459f9-31ad5434-c32a2182",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:22:41.655811575Z",
"resource": {
"labels": {
"location": "us-central1-a",
"operation_name": "operation-1782739348249-65564599459f9-31ad5434-c32a2182",
"project_id": "example-project-id"
},
"type": "gce_operation"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:22:29.468907Z"
}
compute.zoneVmExtensionPolicies.delete: delete
#Description
Deletes a specified zone VM extension policy within a project.
compute.zoneVmExtensionPolicies.get: get
#Description
Retrieves details of a specific zone VM extension policy within a project.
Data Access audit logs are disabled by default.
compute.zoneVmExtensionPolicies.insert: insert
#Description
Creates a new zone-level VM extension policy within a project.
compute.zoneVmExtensionPolicies.list: list
#Description
Lists all VM extension policies within a specific zone for a project.
Data Access audit logs are disabled by default.
compute.zoneVmExtensionPolicies.update: update
#Description
Modifies an existing zone VM extension policy within a project.
compute.zones.get: get
#Description
Returns the specified Zone resource.
Data Access audit logs are disabled by default.
compute.zones.list: list
#Description
Retrieves the list of Zone resources available to the specified project.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "u9v4p4dttk4",
"labels": {
"compute.googleapis.com/root_trigger_id": "090249a6-6518-4b9a-b681-82367b9d44a7"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.zones.list",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "v1.compute.zones.list",
"numResponseItems": "130",
"request": {
"@type": "type.googleapis.com/compute.zones.list"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.compute.zones.list invocation-id/567c3c40de4b4f279757afac8b8a3055 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T13:18:43.515312Z"
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
},
"resourceName": "projects/example-project-id/zones",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:18:43.773626168Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.zones.list",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "v1"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T13:18:43.329939Z"
}
compute.reservations.listConsumableReservations: listConsumableReservations
#Description
List the reservations a project is allowed to consume.
Data Access audit logs are disabled by default.Example Audit Log Entry #
{
"insertId": "-s9pwize7n3ku",
"labels": {
"compute.googleapis.com/root_trigger_id": "56214f99-b6ff-40c2-a50c-4c86497e1ec2"
},
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "110162197178770594910"
},
"principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com",
"principalSubject": "serviceAccount:service-000000000000@container-engine-robot.iam.gserviceaccount.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "compute.reservations.listConsumableReservations",
"permissionType": "ADMIN_READ",
"resource": "projects/example-project-id",
"resourceAttributes": {
"name": "projects/example-project-id",
"service": "resourcemanager",
"type": "resourcemanager.projects"
}
}
],
"methodName": "beta.compute.reservations.listConsumableReservations",
"request": {
"@type": "type.googleapis.com/compute.reservations.listConsumableReservations"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-api-go-client/0.5 vertex-gke-integration-pipeline,gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {
"auth": {},
"time": "2026-06-29T14:39:41.859947Z"
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-f"
]
},
"resourceName": "projects/example-project-id/zones/us-central1-f/consumableReservations",
"serviceName": "compute.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:39:42.042643663Z",
"resource": {
"labels": {
"location": "global",
"method": "compute.reservations.listConsumableReservations",
"project_id": "example-project-id",
"service": "compute.googleapis.com",
"version": "beta"
},
"type": "api"
},
"severity": "INFO",
"timestamp": "2026-06-29T14:39:41.823808Z"
}