Review audit-configuration change logs and alerts

Record changes to audit coverage and notify the responsible operators.

Description

Changing GCP audit-log settings changes which activities are recorded. Without metrics and alerts for audit-configuration changes, operators may notice a reduction in important audit coverage too late.

Potential impact

  • Changes that weaken auditing may go unnoticed for too long.
  • Activity records needed for an investigation may be missing.

Remediation

  • Inspect actual audit logs and configure a filter covering audit-setting changes, including SetIamPolicy and auditConfigDeltas where applicable.
  • Configure an alert condition that references the log metric and set notification_channels. Use an authorized test change to verify logs, metrics and notifications, accounting for ingestion delay.

Examples

These excerpts compare part of the configuration; the initial alert configuration is incomplete. For the revised example, supply var.audit_monitored_resource_type with a monitored resource type actually present in the metric, and configure the channel and project separately. Adjust the evaluation window for ingestion delay and operational needs.

Before

hcl
resource "google_logging_metric" "audit_config_change" {
  name        = "audit_config_change"
  description = "Detects changes to audit configurations via SetIamPolicy"
  filter      = "protoPayload.methodName=\"wrong_method\" AND protoPayload.serviceData.policyDelta.auditConfigDeltas:*"
}

resource "google_monitoring_alert_policy" "audit_config_alert" {
  display_name = "Audit Config Change Alert"
  combiner     = "OR"

  conditions {
    display_name = "Audit Config Change Condition"

    condition_threshold {
      filter = "resource.type=\"gce_instance\" AND metric.type=\"logging.googleapis.com/user/audit_config_change\""
    }
  }
}

After

hcl
resource "google_logging_metric" "audit_config_change" {
  name        = "audit_config_change"
  description = "Detects changes to audit configurations via SetIamPolicy"
  filter      = "protoPayload.methodName=\"SetIamPolicy\" AND protoPayload.serviceData.policyDelta.auditConfigDeltas:*"
}

resource "google_monitoring_alert_policy" "audit_config_alert" {
  display_name          = "Audit Config Change Alert"
  combiner              = "OR"
  notification_channels = [google_monitoring_notification_channel.security_ops.name]

  conditions {
    display_name = "Matching audit events"
    condition_threshold {
      filter = "metric.type=\"logging.googleapis.com/user/${google_logging_metric.audit_config_change.name}\" AND resource.type=\"${var.audit_monitored_resource_type}\""
      comparison      = "COMPARISON_GT"
      threshold_value = 0
      duration        = "0s"
      aggregations {
        alignment_period   = "600s"
        per_series_aligner = "ALIGN_SUM"
      }
    }
  }
}

Explanation:

  • Before: The incorrect method filter may exclude intended changes, and the alert condition is incomplete.
  • After: The change filter, metric threshold condition and notification channel are connected. Verify the actual event format and delivery.

References