Description
Cloud Storage usage logs provide request records, while storage logs provide storage-consumption information as CSV files. Missing required access records can make abnormal-request analysis and incident investigation more difficult.
The bucket's logging configuration delivers these logs to a separate bucket; it is distinct from Cloud Audit Logs. Google recommends Cloud Audit Logs for most API auditing. Usage logs can provide additional information, including public-object access, but their timely and complete delivery is not guaranteed.
Potential impact
- Without the required request records, abnormal access may be discovered late or investigation evidence may be missing.
- Unnoticed delivery failures can create a false impression that collection is working.
Remediation
- Configure Cloud Audit Logs for your auditing needs, and specify
logging.logBucketfor buckets that also need usage logs. - Place the log bucket in the same location and organization as the source bucket, or the same project if there is no organization. Grant
cloud-storage-analytics@google.comtheroles/storage.objectCreatorrole on the log bucket. - Restrict log readers and retention, and verify delivery after test requests. With VPC Service Controls, the log bucket must also be in the same security perimeter.
Examples
These partial examples use the existing Crossplane API. Prepare the log bucket, delivery permissions and remaining settings separately.
Before
apiVersion: storage.gcp.crossplane.io/v1alpha3
kind: Bucket
spec:
location: EU
storageClass: MULTI_REGIONAL
No destination for usage and storage logs is specified. This alone does not mean Cloud Audit Logs is disabled.
After
apiVersion: storage.gcp.crossplane.io/v1alpha3
kind: Bucket
spec:
location: EU
logging:
logBucket: example-logs-bucket
storageClass: MULTI_REGIONAL
example-logs-bucket is the log destination. Check that it meets delivery requirements and that log objects actually arrive.