IAM logging
Google Cloud IAM writes audit logs and admin logs to help with questions such as “Who did what, where, and when?” These logs are vitally important for audit and forensic capabilities.
For information on Admin Activity and Data Access read audit logs, please check the Google Cloud product documentation.
IAM audit logs use one of the following resource types:
api
: A request to list information about multiple IAM roles or policiesaudited_resource
: A request to exchange credentials for a Google access tokeniam_role
: An IAM custom roleservice_account
: An IAM service account, or a service account key
Log name
Let us assume project_id
=
acme-project-id
, folder_id
=
acme-folder
, billing_account_id
=
123456
, and organization_id
=
987654321
:
projects/acme-project-id/logs/cloudaudit.googleapis.com%2Factivity projects/acme-project-id/logs/cloudaudit.googleapis.com%2Fdata_access projects/ acme-project-id/logs /cloudaudit.googleapis...