Change theme
Help
Press space for more information.
Show links for this issue (Shortcut: i, l)
Copy issue ID
Previous Issue (Shortcut: k)
Next Issue (Shortcut: j)
Sign in to use full features.
Vote: I am impacted
Notification menu
Refresh (Shortcut: Shift+r)
Go home (Shortcut: u)
Use Markdown for this comment
Set severity, which reflects how much the issue affects the use of the product
Assign issue to yourself
Pending code changes (auto-populated)
[ID: 82937]
Primary programming language affected, if applicable [ID: 82936]
[ID: 82935]
[ID: 82940]
[ID: 82941]
Set the version(s) of the product affected by this issue (comma-separated list)
Set the version(s) of the product in which the issue should be fixed (comma-separated list)
Set the version(s) of the product in which the issue fix was verified (comma-separated list)
Set if this issue occurs in production
Set Reporter
Set Type
Set priority, which reflects how soon the issue should be fixed
Set Status
Set Assignee
Set Verifier
Remove item
View or edit staffing
View issue level access limits(Press Alt + Right arrow for more information)
Description
Problem you have encountered:
Customer has an organization that contains a lot of projects and a lot of buckets. Audit logging for bucket data access is enabled at the organization level. Customers would like to figure out a way to route audit logs for specific buckets to a Pub/Sub topic.
There are 3 ways that customer is considering but they have disadvantages so there are no optimal solutions:
What you expected to happen:
It would be great if labels on projects or buckets were available in the audit logs for filtering purposes or they can route logs based on some mutable attribute of a project or log bucket.
Other information (workarounds you have tried, documentation consulted, etc):
We have proposed to the customer to create a new project with a new bucket log (Pub/Sub) in this new project and then create an aggregate sink [1] at organizational level going to Log Router > Create Sink > Sink destination, choose the new bucket log created at project level and in "Choose logs to include in sink” > “Include logs ingested by this organizacion and all child resources''
But the customer wants to collect audit logs from many google buckets in his organization. He wants to be able to easily add more buckets to the list for which he wants to collect audit logs.
References [1]https://cloud.google.com/sdk/gcloud/reference/logging/sinks/create