Description
The ADMIN_READ, DATA_READ and DATA_WRITE types in google_project_iam_audit_config configure Data Access audit logs. They are distinct from automatically enabled Admin Activity audit logs. Missing required types or exempted principals can leave gaps in records of the corresponding activity.
Potential impact
- Required data-read or modification history may be unavailable for investigations.
- Broad exemptions can omit the activities of particular principals from auditing.
Remediation
- Configure required log types for the target service or
allServices, and remove unjustifiedexempted_members. Select a scope that accounts for cost and sensitive content. - Verify actual receipt, retention and read permissions. Review inherited organization/folder settings and service-specific behavior.
Examples
The initial INVALID_TYPE is unsupported and cannot be applied. The project ID and exempted principal are illustrative. The revised example enables reads of administrative information and data; add DATA_WRITE when write auditing is required.
Before
hcl
resource "google_project_iam_audit_config" "example" {
project = "your-project-id"
service = "allServices"
audit_log_config {
log_type = "INVALID_TYPE"
}
audit_log_config {
log_type = "DATA_READ"
exempted_members = [
"user:joebloggs@example.com"
]
}
}
After
hcl
resource "google_project_iam_audit_config" "example" {
project = "your-project-id"
service = "allServices"
audit_log_config {
log_type = "ADMIN_READ"
}
audit_log_config {
log_type = "DATA_READ"
}
}
Explanation:
- Before: The configuration contains an invalid log type and a read-audit exemption.
- After: Supported ADMIN_READ and DATA_READ types are configured and the exemption is removed. This does not configure every audit type.