GCP (Cloud Identity) GoogleWorkspace-gcp

7 operations, identified by eventName in the audit log.

eventNameDescription
anySource-only rules that filter on applicationName 'gcp' without specifying an eventName attribute here.
IMPORT_SSH_PUBLIC_KEYAn SSH public key was imported for a GCP/Cloud Identity managed user.
DELETE_POSIX_ACCOUNTA POSIX account entry was deleted for a managed user.
DELETE_SSH_PUBLIC_KEYAn SSH public key was deleted for a managed user.
UPDATE_SSH_PUBLIC_KEYAn SSH public key was updated for a managed user.
GET_LOGIN_PROFILEA login profile was retrieved for a managed user.
GET_SSH_PUBLIC_KEYAn SSH public key was retrieved for a managed user.

any: GCP (Cloud Identity) (any event)

#
Application
GoogleWorkspace-gcp

Description

Source-only rules that filter on applicationName 'gcp' without specifying an eventName attribute here.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

IMPORT_SSH_PUBLIC_KEY: Import SSH Public Key

#
Application
GoogleWorkspace-gcp

Description

An SSH public key was imported for a GCP/Cloud Identity managed user.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

DELETE_POSIX_ACCOUNT: Delete POSIX Account

#
Application
GoogleWorkspace-gcp

Description

A POSIX account entry was deleted for a managed user.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

DELETE_SSH_PUBLIC_KEY: Delete SSH Public Key

#
Application
GoogleWorkspace-gcp

Description

An SSH public key was deleted for a managed user.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

UPDATE_SSH_PUBLIC_KEY: Update SSH Public Key

#
Application
GoogleWorkspace-gcp

Description

An SSH public key was updated for a managed user.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

GET_LOGIN_PROFILE: Get Login Profile

#
Application
GoogleWorkspace-gcp

Description

A login profile was retrieved for a managed user.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

GET_SSH_PUBLIC_KEY: Get SSH Public Key

#
Application
GoogleWorkspace-gcp

Description

An SSH public key was retrieved for a managed user.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #