Description
Changing GCP audit-log settings changes which activities are recorded. Without metrics and alerts for audit-configuration changes, operators may notice a reduction in important audit coverage too late.
Potential impact
- Changes that weaken auditing may go unnoticed for too long.
- Activity records needed for an investigation may be missing.
Remediation
- Inspect actual audit logs and configure a filter covering audit-setting changes, including
SetIamPolicyandauditConfigDeltaswhere applicable. - Configure an alert condition that references the log metric and set
notification_channels. Use an authorized test change to verify logs, metrics and notifications, accounting for ingestion delay.
Examples
These excerpts compare part of the configuration; the initial alert configuration is incomplete. For the revised example, supply var.audit_monitored_resource_type with a monitored resource type actually present in the metric, and configure the channel and project separately. Adjust the evaluation window for ingestion delay and operational needs.
Before
hcl
resource "google_logging_metric" "audit_config_change" {
name = "audit_config_change"
description = "Detects changes to audit configurations via SetIamPolicy"
filter = "protoPayload.methodName=\"wrong_method\" AND protoPayload.serviceData.policyDelta.auditConfigDeltas:*"
}
resource "google_monitoring_alert_policy" "audit_config_alert" {
display_name = "Audit Config Change Alert"
combiner = "OR"
conditions {
display_name = "Audit Config Change Condition"
condition_threshold {
filter = "resource.type=\"gce_instance\" AND metric.type=\"logging.googleapis.com/user/audit_config_change\""
}
}
}
After
hcl
resource "google_logging_metric" "audit_config_change" {
name = "audit_config_change"
description = "Detects changes to audit configurations via SetIamPolicy"
filter = "protoPayload.methodName=\"SetIamPolicy\" AND protoPayload.serviceData.policyDelta.auditConfigDeltas:*"
}
resource "google_monitoring_alert_policy" "audit_config_alert" {
display_name = "Audit Config Change Alert"
combiner = "OR"
notification_channels = [google_monitoring_notification_channel.security_ops.name]
conditions {
display_name = "Matching audit events"
condition_threshold {
filter = "metric.type=\"logging.googleapis.com/user/${google_logging_metric.audit_config_change.name}\" AND resource.type=\"${var.audit_monitored_resource_type}\""
comparison = "COMPARISON_GT"
threshold_value = 0
duration = "0s"
aggregations {
alignment_period = "600s"
per_series_aligner = "ALIGN_SUM"
}
}
}
}
Explanation:
- Before: The incorrect method filter may exclude intended changes, and the alert condition is incomplete.
- After: The change filter, metric threshold condition and notification channel are connected. Verify the actual event format and delivery.