ServiceNow CMDB CI relationship sync: faster, more complete →
Mods
GCP

Policy: GCP > Turbot > Event Handlers > Logging > Sink > Compiled Filter > @turbot/gcp-iam

A GCP logs advanced filter used to specify a subset of log entries that will be forwarded by the logging sink on behalf of the gcp-iam mod

This is a read-only policy that is used internally by Turbot

Resource Types

This policy targets the following resource types:

Primary Policy

This policy is used with the following primary policy:

Policy Specification

Schema Type
string
Default
(((resource.type = iam_role AND protoPayload.authorizationInfo.permission != iam.roles.get AND protoPayload.authorizationInfo.permission != iam.roles.list) OR (resource.type = audited_resource AND (  protoPayload.authorizationInfo.permission = serviceusage.apiKeys.create OR protoPayload.authorizationInfo.permission = serviceusage.apiKeys.delete OR protoPayload.authorizationInfo.permission = serviceusage.apiKeys.update)) OR (resource.type = service_account AND protoPayload.authorizationInfo.permission != iam.serviceAccounts.get AND protoPayload.authorizationInfo.permission != iam.serviceAccounts.list AND protoPayload.authorizationInfo.permission != iam.serviceAccounts.getIamPolicy AND protoPayload.authorizationInfo.permission != iam.serviceAccountKeys.get AND protoPayload.authorizationInfo.permission != iam.serviceAccountKeys.list) OR (resource.type = project AND protoPayload.authorizationInfo.permission=resourcemanager.projects.setIamPolicy)) AND severity>=INFO AND severity<ERROR)

Category

In Your Workspace

Developers