Cloud Data Loss Prevention (DLP)
| methodName | Description | Log type | Sample | Rule |
|---|---|---|---|---|
| any | Catch-all entry for dlp.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation. | activity | N | N |
| projects. | Re-identifies content that has been de-identified. The items listed in the request were previously de-identified. This method is only permitted when the caller has been granted the dlp.content.reidentify permission. | data_access | N | Y |
any: dlp.googleapis.com (any method)
#Description
Catch-all entry for dlp.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.
projects.content.reidentify: Re-identify content
#Description
Re-identifies content that has been de-identified. The items listed in the request were previously de-identified. This method is only permitted when the caller has been granted the dlp.content.reidentify permission.
Data Access audit logs are disabled by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Sigma #
T1565