Network Management

methodNameDescriptionLog typeSampleRule
anyCatch-all entry for networkmanagement.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.activityNN
google.cloud.networkmanagement.VpcFlowLogsService.CreateVpcFlowLogsConfigactivityYN
google.cloud.networkmanagement.VpcFlowLogsService.DeleteVpcFlowLogsConfigactivityYY
google.cloud.networkmanagement.VpcFlowLogsService.GetVpcFlowLogsConfigdata_accessYN
google.cloud.networkmanagement.VpcFlowLogsService.ListVpcFlowLogsConfigsdata_accessNN
google.cloud.networkmanagement.VpcFlowLogsService.QueryOrgVpcFlowLogsConfigsdata_accessNN
google.cloud.networkmanagement.VpcFlowLogsService.ShowEffectiveFlowLogsConfigsactivityNN
google.cloud.networkmanagement.VpcFlowLogsService.UpdateVpcFlowLogsConfigactivityNN
google.cloud.networkmanagement.ReachabilityService.CreateConnectivityTestCreate a Network Management connectivity (reachability) test.activityYN
google.cloud.networkmanagement.ReachabilityService.GetConnectivityTestRead a Network Management connectivity (reachability) test.data_accessYN

any: networkmanagement.googleapis.com (any method)

#
ServiceName
networkmanagement.googleapis.com

Description

Catch-all entry for networkmanagement.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

google.cloud.networkmanagement.VpcFlowLogsService.CreateVpcFlowLogsConfig: CreateVpcFlowLogsConfig

#
ServiceName
networkmanagement.googleapis.com

Example Audit Log Entry #

{
  "insertId": "13fy3ttd1gd7",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "projects/example-project-id/locations/global/operations/operation-1782750575933-65566f6cd37cd-7025132a-1a885917",
    "producer": "networkmanagement.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "networkmanagement.vpcflowlogsconfigs.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/locations/global/vpcFlowLogsConfigs/dwvflc7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/locations/global/vpcFlowLogsConfigs/dwvflc7b671061",
          "service": "networkmanagement.googleapis.com"
        }
      }
    ],
    "methodName": "google.cloud.networkmanagement.v1.VpcFlowLogsService.CreateVpcFlowLogsConfig",
    "request": {
      "@type": "type.googleapis.com/google.cloud.networkmanagement.v1.CreateVpcFlowLogsConfigRequest",
      "parent": "projects/example-project-id/locations/global",
      "vpc_flow_logs_config": {
        "state": "ENABLED"
      },
      "vpc_flow_logs_config_id": "dwvflc7b671061"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.network-management.vpc-flow-logs-configs.create invocation-id/5682ecaa79bc4e53aad4e10bc5b1a234 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:29:35.932917043Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/locations/global/vpcFlowLogsConfigs/dwvflc7b671061",
    "response": {
      "@type": "type.googleapis.com/google.longrunning.Operation"
    },
    "serviceName": "networkmanagement.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:29:36.363492429Z",
  "resource": {
    "labels": {
      "method": "google.cloud.networkmanagement.v1.VpcFlowLogsService.CreateVpcFlowLogsConfig",
      "project_id": "example-project-id",
      "service": "networkmanagement.googleapis.com"
    },
    "type": "audited_resource"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:29:36.030363330Z"
}

google.cloud.networkmanagement.VpcFlowLogsService.DeleteVpcFlowLogsConfig: DeleteVpcFlowLogsConfig

#
ServiceName
networkmanagement.googleapis.com

Example Audit Log Entry #

{
  "insertId": "781fnrd4kb3",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "projects/example-project-id/locations/global/operations/operation-1782750582699-65566f734746e-8f5555cf-9e68bd2f",
    "producer": "networkmanagement.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "networkmanagement.vpcflowlogsconfigs.delete",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/locations/global/vpcFlowLogsConfigs/dwvflc7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/locations/global/vpcFlowLogsConfigs/dwvflc7b671061",
          "service": "networkmanagement.googleapis.com"
        }
      }
    ],
    "methodName": "google.cloud.networkmanagement.v1.VpcFlowLogsService.DeleteVpcFlowLogsConfig",
    "request": {
      "@type": "type.googleapis.com/google.cloud.networkmanagement.v1.DeleteVpcFlowLogsConfigRequest",
      "name": "projects/example-project-id/locations/global/vpcFlowLogsConfigs/dwvflc7b671061"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.network-management.vpc-flow-logs-configs.delete invocation-id/3d2a169785a54d06ab2d1b75159d2e63 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:29:42.697853478Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/locations/global/vpcFlowLogsConfigs/dwvflc7b671061",
    "response": {
      "@type": "type.googleapis.com/google.longrunning.Operation"
    },
    "serviceName": "networkmanagement.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:29:43.238410696Z",
  "resource": {
    "labels": {
      "method": "google.cloud.networkmanagement.v1.VpcFlowLogsService.DeleteVpcFlowLogsConfig",
      "project_id": "example-project-id",
      "service": "networkmanagement.googleapis.com"
    },
    "type": "audited_resource"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T16:29:42.783377787Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
PermissionType (kusto rule field)eqADMIN_WRITE1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • GCP Audit Logs - VPC Flow Logs Disabled source high: Detects when Google Cloud Platform VPC Flow Logs configurations are disabled or deleted. VPC Flow Logs capture information about IP traffic going to and from network interfaces in VPC networks, providing critical visibility for security monitoring and forensic analysis. Disabling VPC Flow Logs reduces network visibility and may indicate an attempt to evade detection before performing malicious activities. Adversaries may disable flow logs to hide lateral movement, data exfiltration, or command and control traffic.T1562, T1562.001

google.cloud.networkmanagement.VpcFlowLogsService.GetVpcFlowLogsConfig: GetVpcFlowLogsConfig

#
ServiceName
networkmanagement.googleapis.com

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "1uxbzhtd1uwa",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "networkmanagement.vpcflowlogsconfigs.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/locations/global/vpcFlowLogsConfigs/dwvflc7b671061",
        "resourceAttributes": {
          "name": "projects/example-project-id/locations/global/vpcFlowLogsConfigs/dwvflc7b671061",
          "service": "networkmanagement.googleapis.com"
        }
      }
    ],
    "methodName": "google.cloud.networkmanagement.v1.VpcFlowLogsService.GetVpcFlowLogsConfig",
    "request": {
      "@type": "type.googleapis.com/google.cloud.networkmanagement.v1.GetVpcFlowLogsConfigRequest",
      "name": "projects/example-project-id/locations/global/vpcFlowLogsConfigs/dwvflc7b671061"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.network-management.vpc-flow-logs-configs.create invocation-id/5682ecaa79bc4e53aad4e10bc5b1a234 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:29:41.332783986Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/locations/global/vpcFlowLogsConfigs/dwvflc7b671061",
    "serviceName": "networkmanagement.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:29:41.475679925Z",
  "resource": {
    "labels": {
      "method": "google.cloud.networkmanagement.v1.VpcFlowLogsService.GetVpcFlowLogsConfig",
      "project_id": "example-project-id",
      "service": "networkmanagement.googleapis.com"
    },
    "type": "audited_resource"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:29:41.361528182Z"
}

google.cloud.networkmanagement.VpcFlowLogsService.ListVpcFlowLogsConfigs: ListVpcFlowLogsConfigs

#
ServiceName
networkmanagement.googleapis.com

Data Access audit logs are disabled by default.

google.cloud.networkmanagement.VpcFlowLogsService.QueryOrgVpcFlowLogsConfigs: QueryOrgVpcFlowLogsConfigs

#
ServiceName
networkmanagement.googleapis.com

Data Access audit logs are disabled by default.

google.cloud.networkmanagement.VpcFlowLogsService.ShowEffectiveFlowLogsConfigs: ShowEffectiveFlowLogsConfigs

#
ServiceName
networkmanagement.googleapis.com

google.cloud.networkmanagement.VpcFlowLogsService.UpdateVpcFlowLogsConfig: UpdateVpcFlowLogsConfig

#
ServiceName
networkmanagement.googleapis.com

google.cloud.networkmanagement.ReachabilityService.CreateConnectivityTest: CreateConnectivityTest

#
ServiceName
networkmanagement.googleapis.com

Description

Create a Network Management connectivity (reachability) test.

Example Audit Log Entry #

{
  "insertId": "1uxbzhtd1t71",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "operation": {
    "first": true,
    "id": "projects/example-project-id/locations/global/operations/operation-1782739342794-655645941204a-05426a29-fbb85221",
    "producer": "networkmanagement.googleapis.com"
  },
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "networkmanagement.connectivitytests.create",
        "permissionType": "ADMIN_WRITE",
        "resource": "projects/example-project-id/locations/global/connectivityTests/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/locations/global/connectivityTests/dwgen-dw739065",
          "service": "networkmanagement.googleapis.com"
        }
      }
    ],
    "methodName": "google.cloud.networkmanagement.v1.ReachabilityService.CreateConnectivityTest",
    "request": {
      "@type": "type.googleapis.com/google.cloud.networkmanagement.v1.CreateConnectivityTestRequest",
      "parent": "projects/example-project-id/locations/global",
      "resource": {
        "bypass_firewall_checks": false,
        "destination": {
          "ip_address": "8.8.8.8",
          "port": 443
        },
        "protocol": "TCP",
        "round_trip": false,
        "source": {
          "ip_address": "10.8.0.2",
          "network_type": "NETWORK_TYPE_UNSPECIFIED"
        }
      },
      "test_id": "dwgen-dw739065"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.network-management.connectivity-tests.create invocation-id/19e930a6f95c4f9c8d25b7e903288dc0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:22:22.794229737Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/locations/global/connectivityTests/dwgen-dw739065",
    "response": {
      "@type": "type.googleapis.com/google.longrunning.Operation"
    },
    "serviceName": "networkmanagement.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:22:23.861983922Z",
  "resource": {
    "labels": {
      "method": "google.cloud.networkmanagement.v1.ReachabilityService.CreateConnectivityTest",
      "project_id": "example-project-id",
      "service": "networkmanagement.googleapis.com"
    },
    "type": "audited_resource"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T13:22:22.933388945Z"
}

google.cloud.networkmanagement.ReachabilityService.GetConnectivityTest: GetConnectivityTest

#
ServiceName
networkmanagement.googleapis.com

Description

Read a Network Management connectivity (reachability) test.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "1bq5ij4c31t",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com",
      "principalSubject": "user:user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "networkmanagement.connectivitytests.get",
        "permissionType": "ADMIN_READ",
        "resource": "projects/example-project-id/locations/global/connectivityTests/dwgen-dw739065",
        "resourceAttributes": {
          "name": "projects/example-project-id/locations/global/connectivityTests/dwgen-dw739065",
          "service": "networkmanagement.googleapis.com"
        }
      }
    ],
    "methodName": "google.cloud.networkmanagement.v1.ReachabilityService.GetConnectivityTest",
    "request": {
      "@type": "type.googleapis.com/google.cloud.networkmanagement.v1.GetConnectivityTestRequest",
      "name": "projects/example-project-id/locations/global/connectivityTests/dwgen-dw739065"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.network-management.connectivity-tests.create invocation-id/19e930a6f95c4f9c8d25b7e903288dc0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:22:24.809742164Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/example-project-id/locations/global/connectivityTests/dwgen-dw739065",
    "serviceName": "networkmanagement.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:22:25.400087615Z",
  "resource": {
    "labels": {
      "method": "google.cloud.networkmanagement.v1.ReachabilityService.GetConnectivityTest",
      "project_id": "example-project-id",
      "service": "networkmanagement.googleapis.com"
    },
    "type": "audited_resource"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:22:24.830127033Z"
}