Cloud Data Loss Prevention (DLP)

methodNameDescriptionLog typeSampleRule
anyCatch-all entry for dlp.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.activityNN
projects.content.reidentifyRe-identifies content that has been de-identified. The items listed in the request were previously de-identified. This method is only permitted when the caller has been granted the dlp.content.reidentify permission.data_accessNY

any: dlp.googleapis.com (any method)

#
ServiceName
dlp.googleapis.com

Description

Catch-all entry for dlp.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

projects.content.reidentify: Re-identify content

#
ServiceName
dlp.googleapis.com

Description

Re-identifies content that has been de-identified. The items listed in the request were previously de-identified. This method is only permitted when the caller has been granted the dlp.content.reidentify permission.

Data Access audit logs are disabled by default.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #