Description
Cloud Storage usage logs record requests to a bucket, while storage logs provide capacity information. Without the required access records, investigating unusual requests or an incident may be difficult.
The bucket’s logging setting stores these logs in another bucket and is separate from Cloud Audit Logs. Google recommends Cloud Audit Logs for auditing most API operations. Usage logs can help analyze access to public objects, but timely and complete delivery is not guaranteed.
Potential impact
- Missing request records can delay discovery of unauthorized access or leave gaps in an investigation.
- Unnoticed delivery failures may give a false impression that logs are being collected.
Remediation
Configure Cloud Audit Logs for your audit needs. If usage logs are required, specify a destination bucket in logging.logBucket. Configure delivery permissions and retention, then verify that log objects arrive.
Examples
These excerpts assume a separately prepared log bucket named accessLogs. Keep it in the source bucket’s location and organization, or the same project if there is no organization. Grant the cloud-storage-analytics@google.com group roles/storage.objectCreator on that bucket.
Before
resources:
example:
type: gcp:storage:Bucket
properties:
location: US-CENTRAL1
After
resources:
example:
type: gcp:storage:Bucket
properties:
location: US-CENTRAL1
logging:
logBucket: ${accessLogs.name}
logObjectPrefix: some_obj_prefix
logBucket identifies the destination, and logObjectPrefix sets the log object prefix. This does not configure Cloud Audit Logs or guarantee immediate records for every request.