Cloud Data Loss Prevention (DLP) GCP-dlp.googleapis.com

2 operations, identified by methodName in the audit log.

methodNameDescription
anyCatch-all entry for dlp.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.
projects-content-reidentifyRe-identifies content that has been de-identified. The items listed in the request were previously de-identified. This method is only permitted when the caller has been granted the dlp.content.reidentify permission.

any: dlp.googleapis.com (any method)

#
Service
GCP-dlp.googleapis.com

Description

Catch-all entry for dlp.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

Fields #

NameDescription
protoPayload.serviceNameThe GCP service endpoint that processed the request (e.g. compute.googleapis.com).
protoPayload.methodNameThe specific API operation that was audited (versioned form, e.g. v1.compute.instances.insert).
protoPayload.resourceNameScheme-less URI of the resource targeted by the operation.
protoPayload.authenticationInfo.principalEmailEmail address of the principal that performed the operation.
protoPayload.requestMetadata.callerIpIP address of the caller.
protoPayload.requestMetadata.callerSuppliedUserAgentUser agent reported by the caller.
protoPayload.authorizationInfoList of authorization checks performed (resource, permission, granted).
protoPayload.requestAPI request object (service-specific structure).
protoPayload.responseAPI response object (service-specific structure).
logNameLog stream identifier; suffix encodes the audit log type (activity, data_access, system_event, policy).

projects-content-reidentify: Re-identify content

#
Service
GCP-dlp.googleapis.com

Description

Re-identifies content that has been de-identified. The items listed in the request were previously de-identified. This method is only permitted when the caller has been granted the dlp.content.reidentify permission.

Fields #

NameDescription
protoPayload.serviceNameThe GCP service endpoint that processed the request (e.g. compute.googleapis.com).
protoPayload.methodNameThe specific API operation that was audited (versioned form, e.g. v1.compute.instances.insert).
protoPayload.resourceNameScheme-less URI of the resource targeted by the operation.
protoPayload.authenticationInfo.principalEmailEmail address of the principal that performed the operation.
protoPayload.requestMetadata.callerIpIP address of the caller.
protoPayload.requestMetadata.callerSuppliedUserAgentUser agent reported by the caller.
protoPayload.authorizationInfoList of authorization checks performed (resource, permission, granted).
protoPayload.requestAPI request object (service-specific structure).
protoPayload.responseAPI response object (service-specific structure).
logNameLog stream identifier; suffix encodes the audit log type (activity, data_access, system_event, policy).

Detection Rules #

View all rules referencing this event →

Sigma #