Cloud DNS

methodNameDescriptionLog typeSampleRule
anyCatch-all entry for dns.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.activityNN
dns.changes.createAtomically updates the ResourceRecordSet collection.activityNY
dns.changes.getFetches the representation of an existing Change.data_accessNN
dns.changes.listEnumerates Changes to a ResourceRecordSet collection.data_accessNN
dns.dnsKeys.getFetches the representation of an existing DnsKey.data_accessNN
dns.dnsKeys.listEnumerates DnsKeys to a ResourceRecordSet collection.data_accessNN
dns.managedZoneOperations.getFetches the representation of an existing Operation.data_accessYN
dns.managedZoneOperations.listEnumerates Operations for the given ManagedZone.data_accessNN
dns.managedZones.createCreates a new managed zone.activityYN
dns.managedZones.deleteDeletes a previously created managed zone.activityYY
dns.managedZones.getFetches the representation of an existing ManagedZone.data_accessNN
dns.managedZones.getIamPolicyGets the access control policy for a resource. Returns an empty policy if the resource exists and does not have a policy set.data_accessNN
dns.managedZones.listEnumerates ManagedZones that have been created but not yet deleted.data_accessYN
dns.managedZones.patchApplies a partial update to an existing managed zone.activityYY
dns.managedZones.setIamPolicySets the access control policy on the specified resource. Replaces any existing policy. Can return `NOT_FOUND`, `INVALID_ARGUMENT`, and `PERMISSION_DENIED` errors.activityNN
dns.managedZones.testIamPermissionsReturns permissions that a caller has on the specified resource. If the resource does not exist, this returns an empty set of permissions, not a `NOT_FOUND` error. Note: This operation is designed to be used for building permission-aware UIs and command-line tools, not for authorization checking. This operation may "fail open" without warning.data_accessNN
dns.managedZones.updateUpdates an existing managed zone.activityNY
dns.policies.createCreates a new policy.activityYN
dns.policies.deleteDeletes a previously created policy. Fails if the policy is still being referenced by a network.activityYN
dns.policies.getFetches the representation of an existing policy.data_accessNN
dns.policies.listEnumerates all policies associated with a project.data_accessYN
dns.policies.patchApplies a partial update to an existing policy.activityNN
dns.policies.updateUpdates an existing policy.activityNN
dns.projects.getFetches the representation of an existing Project.data_accessNN
dns.resourceRecordSets.createCreates a new ResourceRecordSet.activityYN
dns.resourceRecordSets.deleteDeletes a previously created ResourceRecordSet.activityNN
dns.resourceRecordSets.getFetches the representation of an existing ResourceRecordSet.data_accessNN
dns.resourceRecordSets.listEnumerates ResourceRecordSets that you have created but not yet deleted.data_accessNN
dns.resourceRecordSets.patchApplies a partial update to an existing ResourceRecordSet.activityNN
dns.responsePolicies.createCreates a new Response PolicyactivityNN
dns.responsePolicies.deleteDeletes a previously created Response Policy. Fails if the response policy is non-empty or still being referenced by a network.activityNN
dns.responsePolicies.getFetches the representation of an existing Response Policy.data_accessYN
dns.responsePolicies.listEnumerates all Response Policies associated with a project.data_accessYN
dns.responsePolicies.patchApplies a partial update to an existing Response Policy.activityNN
dns.responsePolicies.updateUpdates an existing Response Policy.activityNN
dns.responsePolicyRules.createCreates a new Response Policy Rule.activityNN
dns.responsePolicyRules.deleteDeletes a previously created Response Policy Rule.activityNN
dns.responsePolicyRules.getFetches the representation of an existing Response Policy Rule.data_accessNN
dns.responsePolicyRules.listEnumerates all Response Policy Rules associated with a project.data_accessNN
dns.responsePolicyRules.patchApplies a partial update to an existing Response Policy Rule.activityNN
dns.responsePolicyRules.updateUpdates an existing Response Policy Rule.activityNN

any: dns.googleapis.com (any method)

#
ServiceName
dns.googleapis.com

Description

Catch-all entry for dns.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

dns.changes.create: create

#
ServiceName
dns.googleapis.com

Description

Atomically updates the ResourceRecordSet collection.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

dns.changes.get: get

#
ServiceName
dns.googleapis.com

Description

Fetches the representation of an existing Change.

Data Access audit logs are disabled by default.

dns.changes.list: list

#
ServiceName
dns.googleapis.com

Description

Enumerates Changes to a ResourceRecordSet collection.

Data Access audit logs are disabled by default.

dns.dnsKeys.get: get

#
ServiceName
dns.googleapis.com

Description

Fetches the representation of an existing DnsKey.

Data Access audit logs are disabled by default.

dns.dnsKeys.list: list

#
ServiceName
dns.googleapis.com

Description

Enumerates DnsKeys to a ResourceRecordSet collection.

Data Access audit logs are disabled by default.

dns.managedZoneOperations.get: get

#
ServiceName
dns.googleapis.com

Description

Fetches the representation of an existing Operation.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "227iyehiugq",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "dns.managedZoneOperations.get",
        "permissionType": "DATA_READ",
        "resourceAttributes": {
          "service": "dns.googleapis.com",
          "type": "dns.googleapis.com/Operation"
        }
      }
    ],
    "methodName": "dns.managedZoneOperations.get",
    "request": {
      "@type": "type.googleapis.com/cloud.dns.api.ManagedZoneOperationsGetRequest",
      "managedZone": "dwz7201353",
      "operation": "cd278119-b6d5-498c-9043-447c783639ac",
      "project": "example-project-id"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.dns.managed-zones.update invocation-id/2bed869452a94ec1b314081e5171b5bc environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:21:40.330826Z"
      }
    },
    "resourceName": "managedZones/dwz7201353",
    "serviceName": "dns.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:21:41.320607744Z",
  "resource": {
    "labels": {
      "location": "global",
      "project_id": "example-project-id",
      "zone_name": "dwz7201353"
    },
    "type": "dns_managed_zone"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:21:40.268665Z"
}

dns.managedZoneOperations.list: list

#
ServiceName
dns.googleapis.com

Description

Enumerates Operations for the given ManagedZone.

Data Access audit logs are disabled by default.

dns.managedZones.create: Create managed zone

#
ServiceName
dns.googleapis.com

Description

Creates a new managed zone.

Example Audit Log Entry #

{
  "insertId": "-fi92hfe1usnk",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "dns.managedZones.create",
        "permissionType": "ADMIN_WRITE",
        "resourceAttributes": {
          "name": "projects/000000000000/managedzones/dwgen-dw739065",
          "service": "dns.googleapis.com",
          "type": "dns.googleapis.com/ManagedZone"
        }
      }
    ],
    "methodName": "dns.managedZones.create",
    "request": {
      "@type": "type.googleapis.com/cloud.dns.api.ManagedZonesCreateRequest",
      "managedZone": {
        "description": "dw audit gen",
        "dnsName": "dwgen-dw739065.example.com.",
        "name": "dwgen-dw739065",
        "visibility": "PUBLIC"
      },
      "project": "example-project-id"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.dns.managed-zones.create invocation-id/7cc4f6d833cc49759b3621460e48c132 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:05.874406Z"
      }
    },
    "resourceName": "managedZones/dwgen-dw739065",
    "response": {
      "@type": "type.googleapis.com/cloud.dns.api.ManagedZonesCreateResponse",
      "managedZone": {
        "cloudLoggingConfig": {},
        "creationTime": "2026-06-29T13:20:05.708Z",
        "description": "dw audit gen",
        "dnsName": "dwgen-dw739065.example.com.",
        "fingerprint": "39c53aa8bb7379bb0000019f13897e4c",
        "id": "4162797926947715515",
        "name": "dwgen-dw739065",
        "nameServers": [
          "ns-cloud-e1.googledomains.com.",
          "ns-cloud-e2.googledomains.com.",
          "ns-cloud-e3.googledomains.com.",
          "ns-cloud-e4.googledomains.com."
        ],
        "rrsetCount": 2,
        "visibility": "PUBLIC"
      }
    },
    "serviceName": "dns.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:06.255744620Z",
  "resource": {
    "labels": {
      "location": "global",
      "project_id": "example-project-id",
      "zone_name": "dwgen-dw739065"
    },
    "type": "dns_managed_zone"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T13:20:05.577659Z"
}

dns.managedZones.delete: Delete managed zone

#
ServiceName
dns.googleapis.com

Description

Deletes a previously created managed zone.

Example Audit Log Entry #

{
  "insertId": "227iyehiuo2",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "dns.managedZones.delete",
        "permissionType": "ADMIN_WRITE",
        "resourceAttributes": {
          "service": "dns.googleapis.com",
          "type": "dns.googleapis.com/ManagedZone"
        }
      }
    ],
    "methodName": "dns.managedZones.delete",
    "request": {
      "@type": "type.googleapis.com/cloud.dns.api.ManagedZonesDeleteRequest",
      "managedZone": "dwz7201353",
      "project": "example-project-id"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.dns.managed-zones.delete invocation-id/1d730065baf54506bd201c535f0fa10a environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:21:42.393189Z"
      }
    },
    "resourceName": "managedZones/dwz7201353",
    "response": {
      "@type": "type.googleapis.com/cloud.dns.api.ManagedZonesDeleteResponse"
    },
    "serviceName": "dns.googleapis.com",
    "status": {
      "code": 9
    }
  },
  "receiveTimestamp": "2026-06-29T16:21:43.311965150Z",
  "resource": {
    "labels": {
      "location": "global",
      "project_id": "example-project-id",
      "zone_name": "dwz7201353"
    },
    "type": "dns_managed_zone"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T16:21:42.365793Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Panther #

dns.managedZones.get: get

#
ServiceName
dns.googleapis.com

Description

Fetches the representation of an existing ManagedZone.

Data Access audit logs are disabled by default.

dns.managedZones.getIamPolicy: getIamPolicy

#
ServiceName
dns.googleapis.com

Description

Gets the access control policy for a resource. Returns an empty policy if the resource exists and does not have a policy set.

Data Access audit logs are disabled by default.

dns.managedZones.list: list

#
ServiceName
dns.googleapis.com

Description

Enumerates ManagedZones that have been created but not yet deleted.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "227iyegtp9e",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "dns.managedZones.list",
        "permissionType": "ADMIN_READ",
        "resourceAttributes": {
          "service": "cloudresourcemanager.googleapis.com",
          "type": "cloudresourcemanager.googleapis.com/Project"
        }
      }
    ],
    "methodName": "dns.managedZones.list",
    "request": {
      "@type": "type.googleapis.com/cloud.dns.api.ManagedZonesListRequest",
      "project": "example-project-id"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.dns.managed-zones.list invocation-id/8596e04d195e4ca6803e18a73cef5c88 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:17:58.920594Z"
      }
    },
    "resourceName": "managedZones/",
    "serviceName": "dns.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:17:58.974838334Z",
  "resource": {
    "labels": {
      "location": "global",
      "project_id": "example-project-id",
      "zone_name": ""
    },
    "type": "dns_managed_zone"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:17:58.902586Z"
}

dns.managedZones.patch: Patch managed zone

#
ServiceName
dns.googleapis.com

Description

Applies a partial update to an existing managed zone.

Example Audit Log Entry #

{
  "insertId": "227iyeh2qym",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "dns.managedZones.update",
        "permissionType": "ADMIN_WRITE",
        "resourceAttributes": {
          "name": "projects/000000000000/managedzones/dwzone-dw743447",
          "service": "dns.googleapis.com",
          "type": "dns.googleapis.com/ManagedZone"
        }
      }
    ],
    "methodName": "dns.managedZones.patch",
    "request": {
      "@type": "type.googleapis.com/cloud.dns.api.ManagedZonesPatchRequest",
      "managedZone": "dwzone-dw743447",
      "managedZoneResource": {
        "description": "dw updated",
        "name": "dwzone-dw743447"
      },
      "project": "example-project-id"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.dns.managed-zones.update invocation-id/de7ae61a17ac4326b7e2d7ac92a10a5a environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:34:08.334827Z"
      }
    },
    "resourceName": "managedZones/dwzone-dw743447",
    "response": {
      "@type": "type.googleapis.com/cloud.dns.api.ManagedZonesPatchResponse",
      "managedZone": {
        "cloudLoggingConfig": {},
        "creationTime": "2026-06-29T14:34:07.219Z",
        "description": "dw updated",
        "dnsName": "dwg2-dw743447.example.com.",
        "fingerprint": "1617d81c05fa2f670000019f13cd4813",
        "id": "1591978608169725799",
        "name": "dwzone-dw743447",
        "nameServers": [
          "ns-cloud-c1.googledomains.com.",
          "ns-cloud-c2.googledomains.com.",
          "ns-cloud-c3.googledomains.com.",
          "ns-cloud-c4.googledomains.com."
        ],
        "rrsetCount": 2,
        "visibility": "PUBLIC"
      },
      "operation": {
        "id": "3b8f9702-87c4-45d1-984a-a3b0aeb41bf8",
        "startTime": "2026-06-29T14:34:08.285Z",
        "status": "DONE",
        "type": "UPDATE",
        "user": "user@example.com",
        "zoneContext": {
          "newValue": {
            "cloudLoggingConfig": {},
            "creationTime": "2026-06-29T14:34:07.219Z",
            "description": "dw updated",
            "dnsName": "dwg2-dw743447.example.com.",
            "fingerprint": "1617d81c05fa2f670000019f13cd4813",
            "id": "1591978608169725799",
            "name": "dwzone-dw743447",
            "nameServers": [
              "ns-cloud-c1.googledomains.com.",
              "ns-cloud-c2.googledomains.com.",
              "ns-cloud-c3.googledomains.com.",
              "ns-cloud-c4.googledomains.com."
            ],
            "rrsetCount": 2,
            "visibility": "PUBLIC"
          },
          "oldValue": {
            "cloudLoggingConfig": {},
            "creationTime": "2026-06-29T14:34:07.219Z",
            "description": "dw",
            "dnsName": "dwg2-dw743447.example.com.",
            "fingerprint": "1617d81c05fa2f670000019f13cd43f3",
            "id": "1591978608169725799",
            "name": "dwzone-dw743447",
            "nameServers": [
              "ns-cloud-c1.googledomains.com.",
              "ns-cloud-c2.googledomains.com.",
              "ns-cloud-c3.googledomains.com.",
              "ns-cloud-c4.googledomains.com."
            ],
            "rrsetCount": 2,
            "visibility": "PUBLIC"
          }
        }
      }
    },
    "serviceName": "dns.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:34:08.471957589Z",
  "resource": {
    "labels": {
      "location": "global",
      "project_id": "example-project-id",
      "zone_name": "dwzone-dw743447"
    },
    "type": "dns_managed_zone"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:34:08.265249Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Severity (kusto rule field)eqNOTICE1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

Panther #

dns.managedZones.setIamPolicy: setIamPolicy

#
ServiceName
dns.googleapis.com

Description

Sets the access control policy on the specified resource. Replaces any existing policy. Can return `NOT_FOUND`, `INVALID_ARGUMENT`, and `PERMISSION_DENIED` errors.

dns.managedZones.testIamPermissions: testIamPermissions

#
ServiceName
dns.googleapis.com

Description

Returns permissions that a caller has on the specified resource. If the resource does not exist, this returns an empty set of permissions, not a `NOT_FOUND` error. Note: This operation is designed to be used for building permission-aware UIs and command-line tools, not for authorization checking. This operation may "fail open" without warning.

Data Access audit logs are disabled by default.

dns.managedZones.update: Update managed zone

#
ServiceName
dns.googleapis.com

Description

Updates an existing managed zone.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Severity (kusto rule field)eqNOTICE1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Kusto #

Panther #

dns.policies.create: create

#
ServiceName
dns.googleapis.com

Description

Creates a new policy.

Example Audit Log Entry #

{
  "insertId": "227iyehbep4",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "dns.policies.create",
        "permissionType": "ADMIN_WRITE",
        "resourceAttributes": {
          "name": "projects/000000000000/policies/dwpol-dw746783",
          "service": "dns.googleapis.com",
          "type": "dns.googleapis.com/Policy"
        }
      }
    ],
    "methodName": "dns.policies.create",
    "request": {
      "@type": "type.googleapis.com/cloud.dns.api.PoliciesCreateRequest",
      "policy": {
        "description": "dw",
        "dns64Config": {
          "scope": {
            "allQueries": false
          }
        },
        "enableInboundForwarding": false,
        "enableLogging": false,
        "name": "dwpol-dw746783"
      },
      "project": "example-project-id"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.dns.policies.create invocation-id/9f698822a22d409683334a24ec025aab environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:28:54.136770Z"
      }
    },
    "resourceName": "policies/dwpol-dw746783",
    "response": {
      "@type": "type.googleapis.com/cloud.dns.api.PoliciesCreateResponse",
      "policy": {
        "description": "dw",
        "dns64Config": {
          "scope": {
            "allQueries": false
          }
        },
        "enableInboundForwarding": false,
        "enableLogging": false,
        "fingerprint": "5917c1499ce98d8f0000019f13ff6b44",
        "id": "6419812315749256591",
        "name": "dwpol-dw746783"
      }
    },
    "serviceName": "dns.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:28:55.113466498Z",
  "resource": {
    "labels": {
      "location": "global",
      "policy_name": "dwpol-dw746783",
      "project_id": "example-project-id"
    },
    "type": "dns_policy"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:28:54.064401Z"
}

dns.policies.delete: delete

#
ServiceName
dns.googleapis.com

Description

Deletes a previously created policy. Fails if the policy is still being referenced by a network.

Example Audit Log Entry #

{
  "insertId": "q4axzmehrof4",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "dns.policies.delete",
        "permissionType": "ADMIN_WRITE",
        "resourceAttributes": {
          "service": "dns.googleapis.com",
          "type": "dns.googleapis.com/Policy"
        }
      }
    ],
    "methodName": "dns.policies.delete",
    "request": {
      "@type": "type.googleapis.com/cloud.dns.api.PoliciesDeleteRequest",
      "policy": "dwpol-dw746783",
      "project": "example-project-id"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.dns.policies.delete invocation-id/9ca3e68a42ec4d7d83c1f32ede8fd370 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:32:02.681604Z"
      }
    },
    "resourceName": "policies/dwpol-dw746783",
    "response": {
      "@type": "type.googleapis.com/cloud.dns.api.PoliciesDeleteResponse"
    },
    "serviceName": "dns.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:32:03.164140932Z",
  "resource": {
    "labels": {
      "location": "global",
      "policy_name": "dwpol-dw746783",
      "project_id": "example-project-id"
    },
    "type": "dns_policy"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:32:02.629467Z"
}

dns.policies.get: get

#
ServiceName
dns.googleapis.com

Description

Fetches the representation of an existing policy.

Data Access audit logs are disabled by default.

dns.policies.list: list

#
ServiceName
dns.googleapis.com

Description

Enumerates all policies associated with a project.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-vadto3e28sw2",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "dns.policies.list",
        "permissionType": "ADMIN_READ",
        "resourceAttributes": {
          "service": "cloudresourcemanager.googleapis.com",
          "type": "cloudresourcemanager.googleapis.com/Project"
        }
      }
    ],
    "methodName": "dns.policies.list",
    "request": {
      "@type": "type.googleapis.com/cloud.dns.api.PoliciesListRequest",
      "project": "example-project-id"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.dns.policies.list invocation-id/d94ab746eb664d8ab423dd522226d3d6 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:38:32.948275Z"
      }
    },
    "resourceName": "policies/",
    "serviceName": "dns.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:38:33.572984425Z",
  "resource": {
    "labels": {
      "location": "global",
      "policy_name": "",
      "project_id": "example-project-id"
    },
    "type": "dns_policy"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T15:38:32.929061Z"
}

dns.policies.patch: patch

#
ServiceName
dns.googleapis.com

Description

Applies a partial update to an existing policy.

dns.policies.update: update

#
ServiceName
dns.googleapis.com

Description

Updates an existing policy.

dns.projects.get: get

#
ServiceName
dns.googleapis.com

Description

Fetches the representation of an existing Project.

Data Access audit logs are disabled by default.

dns.resourceRecordSets.create: create

#
ServiceName
dns.googleapis.com

Description

Creates a new ResourceRecordSet.

Example Audit Log Entry #

{
  "insertId": "-r4thvge8qy5k",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "dns.changes.create",
        "permissionType": "ADMIN_WRITE",
        "resourceAttributes": {}
      }
    ],
    "methodName": "dns.resourceRecordSets.create",
    "request": {
      "@type": "type.googleapis.com/cloud.dns.api.ResourceRecordSetsCreateRequest",
      "managedZone": "dwgen-dw739065",
      "project": "example-project-id",
      "rrset": {
        "name": "test.dwgen-dw739065.example.com.",
        "rrdata": [
          "192.0.2.1"
        ],
        "ttl": 300,
        "type": "A"
      }
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.dns.record-sets.create invocation-id/50b6d1c6039b426b9433d9e0d5d3b4b3 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:20:06.901584Z"
      }
    },
    "resourceName": "resourceRecordSets/test.dwgen-dw739065.example.com./A",
    "response": {
      "@type": "type.googleapis.com/cloud.dns.api.ResourceRecordSetsCreateResponse",
      "rrset": {
        "name": "test.dwgen-dw739065.example.com.",
        "rrdata": [
          "192.0.2.1"
        ],
        "ttl": 300,
        "type": "A"
      }
    },
    "serviceName": "dns.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:20:07.288975833Z",
  "resource": {
    "labels": {
      "location": "global",
      "name": "test.dwgen-dw739065.example.com.",
      "project_id": "example-project-id",
      "type": "A"
    },
    "type": "dns_resource_record_set"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T13:20:06.825021Z"
}

dns.resourceRecordSets.delete: delete

#
ServiceName
dns.googleapis.com

Description

Deletes a previously created ResourceRecordSet.

dns.resourceRecordSets.get: get

#
ServiceName
dns.googleapis.com

Description

Fetches the representation of an existing ResourceRecordSet.

Data Access audit logs are disabled by default.

dns.resourceRecordSets.list: list

#
ServiceName
dns.googleapis.com

Description

Enumerates ResourceRecordSets that you have created but not yet deleted.

Data Access audit logs are disabled by default.

dns.resourceRecordSets.patch: patch

#
ServiceName
dns.googleapis.com

Description

Applies a partial update to an existing ResourceRecordSet.

dns.responsePolicies.create: create

#
ServiceName
dns.googleapis.com

Description

Creates a new Response Policy

dns.responsePolicies.delete: delete

#
ServiceName
dns.googleapis.com

Description

Deletes a previously created Response Policy. Fails if the response policy is non-empty or still being referenced by a network.

dns.responsePolicies.get: get

#
ServiceName
dns.googleapis.com

Description

Fetches the representation of an existing Response Policy.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "icr08pe4nfws",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "dns.responsePolicies.list",
        "permissionType": "ADMIN_READ",
        "resourceAttributes": {
          "service": "cloudresourcemanager.googleapis.com",
          "type": "cloudresourcemanager.googleapis.com/Project"
        }
      }
    ],
    "methodName": "dns.responsePolicies.get",
    "request": {
      "@type": "type.googleapis.com/cloud.dns.api.ResponsePoliciesGetRequest",
      "location": "global",
      "project": "example-project-id",
      "responsePolicy": "gke-2470140894-rp"
    },
    "requestMetadata": {
      "callerIp": "private",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:41:17.999723Z"
      }
    },
    "resourceName": "responsePolicies/gke-2470140894-rp",
    "serviceName": "dns.googleapis.com",
    "status": {
      "code": 5
    }
  },
  "receiveTimestamp": "2026-06-29T14:41:18.377861434Z",
  "resource": {
    "labels": {
      "location": "global",
      "project_id": "example-project-id",
      "response_policy_name": "gke-2470140894-rp"
    },
    "type": "dns_response_policy"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T14:41:17.992755Z"
}

dns.responsePolicies.list: list

#
ServiceName
dns.googleapis.com

Description

Enumerates all Response Policies associated with a project.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "-kia0oie8dnug",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "principalEmail": "service-000000000000@container-engine-robot.iam.gserviceaccount.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "dns.responsePolicies.list",
        "permissionType": "ADMIN_READ",
        "resourceAttributes": {
          "service": "cloudresourcemanager.googleapis.com",
          "type": "cloudresourcemanager.googleapis.com/Project"
        }
      }
    ],
    "methodName": "dns.responsePolicies.list",
    "request": {
      "@type": "type.googleapis.com/cloud.dns.api.ResponsePoliciesListRequest",
      "location": "us-central1-a",
      "project": "example-project-id"
    },
    "requestMetadata": {
      "callerIp": "private",
      "callerSuppliedUserAgent": "google-api-go-client/0.5 GoogleContainerEngine/v1",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:41:18.361155Z"
      }
    },
    "resourceName": "responsePolicies/",
    "serviceName": "dns.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:41:19.251258447Z",
  "resource": {
    "labels": {
      "location": "us-central1-a",
      "project_id": "example-project-id",
      "response_policy_name": ""
    },
    "type": "dns_response_policy"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T14:41:18.347944Z"
}

dns.responsePolicies.patch: patch

#
ServiceName
dns.googleapis.com

Description

Applies a partial update to an existing Response Policy.

dns.responsePolicies.update: update

#
ServiceName
dns.googleapis.com

Description

Updates an existing Response Policy.

dns.responsePolicyRules.create: create

#
ServiceName
dns.googleapis.com

Description

Creates a new Response Policy Rule.

dns.responsePolicyRules.delete: delete

#
ServiceName
dns.googleapis.com

Description

Deletes a previously created Response Policy Rule.

dns.responsePolicyRules.get: get

#
ServiceName
dns.googleapis.com

Description

Fetches the representation of an existing Response Policy Rule.

Data Access audit logs are disabled by default.

dns.responsePolicyRules.list: list

#
ServiceName
dns.googleapis.com

Description

Enumerates all Response Policy Rules associated with a project.

Data Access audit logs are disabled by default.

dns.responsePolicyRules.patch: patch

#
ServiceName
dns.googleapis.com

Description

Applies a partial update to an existing Response Policy Rule.

dns.responsePolicyRules.update: update

#
ServiceName
dns.googleapis.com

Description

Updates an existing Response Policy Rule.