Champs de l'entrée de journal contenant des informations d'audit
Métadonnées d'audit
Nom du champ d'audit
Valeur
Identité de l'utilisateur ou du service
gdch_service_name
Par exemple,
"_gdch_service_name":"bm_nodes"
Cible
(Champs et valeurs qui appellent l'API)
description
"description": "The overall security state of the system is at \"Risk\"
Action
(Champs contenant l'opération effectuée)
description
"description": "The overall security state of the system is at \"Risk\"
Code temporel de l'événement
time
Par exemple,
"time": "2022-12-02T16:06:29Z"
Source de l'action
resource
Par exemple,
"resource": "zb-ab-bm07"
Résultat
Non applicable
Non applicable
Autres champs
Non applicable
Non applicable
Exemple de journal
{"description":"The overall security state of the system is at \"Risk\".","_gdch_service_name":"bm_nodes","resource":"zb-ab-bm07","auditID":"IEL#32321","user":{},"time":"2022-12-02T16:06:29Z","_gdch_cluster":"root-admin","_gdch_fluentbit_pod":"anthos-audit-logs-forwarder-5k8l2"}
Modifications des données (opérations CRUD)
Champs de l'entrée de journal contenant des informations d'audit
{"user":{"groups":["system:serviceaccounts","system:serviceaccounts:gpc-system""system:authenticated"]"extra":{"authentication.kubernetes.io/pod-uid":["8a33590d-bbf2-4a23-b5de-851a451fac32"],"authentication.kubernetes.io/pod-name":["root-admin-controller-5c5d44f45-2r5d4"]},"username":"system:serviceaccount:gpc-system:root-admin-controller-sa","uid":"ecaee5a1-f7e0-47e7-ae46-1cbd42fb2e99"},"requestURI":"/apis/system.private.gdc.goog/v1alpha1/namespaces/gpc-system/servers/zb-aa-bm07/status","sourceIPs":["10.251.127.4"],"verb":"patch","userAgent":"root-admin-cm/v0.0.0 (linux/amd64) kubernetes/$Format","requestReceivedTimestamp":"2022-12-02T23:52:22.509246Z","stageTimestamp":"2022-12-02T23:52:22.527613Z","_gdch_cluster":"root-admin","responseStatus":{"metadata":{},"code":200},"annotations":{"authorization.k8s.io/reason":"RBAC: allowed by ClusterRoleBinding \"root-admin-rootadmin-controllers-rolebinding\" of ClusterRole \"root-admin-rootadmin-controllers-role\" to ServiceAccount \"root-admin-controller-sa/gpc-system\"","authorization.k8s.io/decision":"allow"},"objectRef":{"resource":"servers","apiGroup":"system.private.gdc.goog","name":"zb-aa-bm07","apiVersion":"v1alpha1","namespace":"gpc-system","subresource":"status"},"gdch_fluentbit_pod":"anthos-audit-logs-forwarder-kp68x","kind":"Event","apiVersion":"audit.k8s.io/v1","stage":"ResponseComplete","level":"Metadata","auditID":"2b2b0ec8-627b-4f69-aa19-b6ba2c3e20cb","_gdch_service_name":"apiserver"}
Sauf indication contraire, le contenu de cette page est régi par une licence Creative Commons Attribution 4.0, et les échantillons de code sont régis par une licence Apache 2.0. Pour en savoir plus, consultez les Règles du site Google Developers. Java est une marque déposée d'Oracle et/ou de ses sociétés affiliées.
Dernière mise à jour le 2025/09/04 (UTC).
[[["Facile à comprendre","easyToUnderstand","thumb-up"],["J'ai pu résoudre mon problème","solvedMyProblem","thumb-up"],["Autre","otherUp","thumb-up"]],[["Difficile à comprendre","hardToUnderstand","thumb-down"],["Informations ou exemple de code incorrects","incorrectInformationOrSampleCode","thumb-down"],["Il n'y a pas l'information/les exemples dont j'ai besoin","missingTheInformationSamplesINeed","thumb-down"],["Problème de traduction","translationIssue","thumb-down"],["Autre","otherDown","thumb-down"]],["Dernière mise à jour le 2025/09/04 (UTC)."],[[["\u003cp\u003eThe audit logs are generated from organization-only workloads, sourced from physical servers and server custom resources.\u003c/p\u003e\n"],["\u003cp\u003eAudited operations include both machine events and data changes, covering CRUD (Create, Read, Update, Delete) operations.\u003c/p\u003e\n"],["\u003cp\u003eMachine event logs contain crucial details such as user/service identity (\u003ccode\u003egdch_service_name\u003c/code\u003e), target (\u003ccode\u003edescription\u003c/code\u003e), action (\u003ccode\u003edescription\u003c/code\u003e), event timestamp (\u003ccode\u003etime\u003c/code\u003e), and source of action (\u003ccode\u003eresource\u003c/code\u003e).\u003c/p\u003e\n"],["\u003cp\u003eData change logs capture information like user/service identity (\u003ccode\u003eusername\u003c/code\u003e), target (\u003ccode\u003erequestURI\u003c/code\u003e), action (\u003ccode\u003everb\u003c/code\u003e), event timestamp (\u003ccode\u003erequestReceivedTimestamp\u003c/code\u003e), source of action (\u003ccode\u003esourceIPs\u003c/code\u003e), and the outcome (\u003ccode\u003eresponseStatus\u003c/code\u003e).\u003c/p\u003e\n"]]],[],null,["# Physical servers (SERV)\n\nMachine events\n--------------\n\n**Example log** \n\n\n {\n \"description\": \"The overall security state of the system is at \\\"Risk\\\".\",\n \"_gdch_service_name\": \"bm_nodes\",\n \"resource\": \"zb-ab-bm07\",\n \"auditID\": \"IEL#32321\",\n \"user\": {},\n \"time\": \"2022-12-02T16:06:29Z\",\n \"_gdch_cluster\": \"root-admin\",\n \"_gdch_fluentbit_pod\": \"anthos-audit-logs-forwarder-5k8l2\"\n }\n\nData changes (CRUD operations)\n------------------------------\n\n**Example log** \n\n {\n \"user\":{\n \"groups\":[\"system:serviceaccounts\",\"system:serviceaccounts:gpc-system\"\n \"system:authenticated\"]\n \"extra\":{\"authentication.kubernetes.io/pod-uid\":[\"8a33590d-bbf2-4a23-b5de-851a451fac32\"],\n \"authentication.kubernetes.io/pod-name\":[\"root-admin-controller-5c5d44f45-2r5d4\"]\n },\n \"username\":\"system:serviceaccount:gpc-system:root-admin-controller-sa\",\n \"uid\":\"ecaee5a1-f7e0-47e7-ae46-1cbd42fb2e99\"\n },\n \"requestURI\":\"/apis/system.private.gdc.goog/v1alpha1/namespaces/gpc-system/servers/zb-aa-bm07/status\",\n \"sourceIPs\":[\"10.251.127.4\"],\n \"verb\":\"patch\",\n \"userAgent\":\"root-admin-cm/v0.0.0 (linux/amd64) kubernetes/$Format\",\n \"requestReceivedTimestamp\":\"2022-12-02T23:52:22.509246Z\",\n \"stageTimestamp\":\"2022-12-02T23:52:22.527613Z\",\n \"_gdch_cluster\":\"root-admin\",\n \"responseStatus\":{\"metadata\":{},\"code\":200},\n \"annotations\":{\n \"authorization.k8s.io/reason\":\"RBAC: allowed by ClusterRoleBinding \\\n \"root-admin-rootadmin-controllers-rolebinding\\\" of ClusterRole \\\n \"root-admin-rootadmin-controllers-role\\\" to ServiceAccount \\\n \"root-admin-controller-sa/gpc-system\\\"\",\"authorization.k8s.io/decision\":\"allow\"\n },\n \"objectRef\":{\n \"resource\":\"servers\",\n \"apiGroup\":\n \"system.private.gdc.goog\",\n \"name\":\"zb-aa-bm07\",\n \"apiVersion\":\"v1alpha1\",\n \"namespace\":\"gpc-system\",\n \"subresource\":\"status\"\n },\n \"gdch_fluentbit_pod\":\"anthos-audit-logs-forwarder-kp68x\",\n \"kind\":\"Event\",\n \"apiVersion\":\"audit.k8s.io/v1\",\n \"stage\":\"ResponseComplete\",\n \"level\":\"Metadata\",\n \"auditID\":\"2b2b0ec8-627b-4f69-aa19-b6ba2c3e20cb\",\n \"_gdch_service_name\":\"apiserver\"\n }"]]