forked from GoogleCloudPlatform/professional-services
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathvpc-sc-policy-violation.log
65 lines (65 loc) · 2.12 KB
/
vpc-sc-policy-violation.log
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
VPC Service Controls Deny:
{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"status": {
"code": 7,
"message": "PERMISSION_DENIED",
"details": [
{
"@type": "type.googleapis.com/google.rpc.PreconditionFailure",
"violations": [
{
"type": "VPC_SERVICE_CONTROLS",
"description": "ljv4RZNmza4g69MMoOXBtRrlNKRYTcQdoxQiqlfhmDZhClaMVgjoWA"
}
]
}
]
},
"authenticationInfo": {},
"requestMetadata": {
"callerIp": "8.8.8.8",
"requestAttributes": {},
"destinationAttributes": {}
},
"serviceName": "storage.googleapis.com",
"methodName": "google.storage.buckets.get",
"resourceName": "projects/598897393088",
"metadata": {
"securityPolicyInfo": {
"servicePerimeterName": "accessPolicies/30507210272/servicePerimeters/gsec_monitoring_prod",
"organizationId": "614830067722"
},
"vpcServiceControlsUniqueId": "ljv4RZNmza4g69MMoOXBtRrlNKRYTcQdoxQiqlfhmDZhClaMVgjoWA",
"accessLevels": [
"accessPolicies/30507210272/accessLevels/thingy",
"accessPolicies/30507210272/accessLevels/test_us"
],
"@type": "type.googleapis.com/google.cloud.audit.VpcServiceControlAuditMetadata",
"ingressViolations": [
{
"servicePerimeter": "accessPolicies/30507210272/servicePerimeters/gsec_monitoring_prod",
"targetResource": "projects/598897393088/buckets/scc-export-sample"
}
],
"violationReason": "NO_MATCHING_ACCESS_LEVEL",
"resourceNames": [
"projects/598897393088/buckets/scc-export-sample"
]
}
},
"insertId": "d21cmyd7av9",
"resource": {
"type": "audited_resource",
"labels": {
"project_id": "gsec-monitoring-prod",
"method": "google.storage.buckets.get",
"service": "storage.googleapis.com"
}
},
"timestamp": "2021-09-13T03:10:14.801613786Z",
"severity": "ERROR",
"logName": "projects/gsec-monitoring-prod/logs/cloudaudit.googleapis.com%2Fpolicy",
"receiveTimestamp": "2021-09-13T03:10:15.410616031Z"
}