gcp-firewall-firewall-log-entries

Firewall logs include connection metadata and may contain sensitive network or workload identifiers.

gcphigh service: gcp:firewall emits CanReadData

Where it sits

locationlogging.entries.list.entries[].{textPayload,jsonPayload,protoPayload,labels}
location kindlog_field
data kindscredential customer_data pii sensitive_data
emits edgeCanReadData
serviceVPC Firewall (gcp:firewall)

Collection recipe

access moderead_api
operationlogging.entries.list
response pathentries[].{textPayload,jsonPayload,protoPayload,labels}
encodingjson
params{"filter": "logName:\u003cfirewall-log\u003e", "resourceNames": ["projects/\u003cproject\u003e"]}

Required permissions

logging.logEntries.list

References

move · open · esc close