Campi della voce di log contenenti le informazioni di controllo
Metadati di controllo
Nome del campo di controllo
Valore
Identità utente o servizio
gdch_service_name
Ad esempio,
"_gdch_service_name":"bm_nodes"
Destinazione
(Campi e valori che chiamano l'API)
description
"description": "The overall security state of the system is at \"Risk\"
Azione
(Campi contenenti l'operazione eseguita)
description
"description": "The overall security state of the system is at \"Risk\"
Timestamp evento
time
Ad esempio,
"time": "2022-12-02T16:06:29Z"
Origine dell'azione
resource
Ad esempio,
"resource": "zb-ab-bm07"
Risultato
Non applicabile
Non applicabile
Altri campi
Non applicabile
Non applicabile
Log di esempio
{"description":"The overall security state of the system is at \"Risk\".","_gdch_service_name":"bm_nodes","resource":"zb-ab-bm07","auditID":"IEL#32321","user":{},"time":"2022-12-02T16:06:29Z","_gdch_cluster":"root-admin","_gdch_fluentbit_pod":"anthos-audit-logs-forwarder-5k8l2"}
Modifiche ai dati (operazioni CRUD)
Campi della voce di log contenenti le informazioni di controllo
{"user":{"groups":["system:serviceaccounts","system:serviceaccounts:gpc-system""system:authenticated"]"extra":{"authentication.kubernetes.io/pod-uid":["8a33590d-bbf2-4a23-b5de-851a451fac32"],"authentication.kubernetes.io/pod-name":["root-admin-controller-5c5d44f45-2r5d4"]},"username":"system:serviceaccount:gpc-system:root-admin-controller-sa","uid":"ecaee5a1-f7e0-47e7-ae46-1cbd42fb2e99"},"requestURI":"/apis/system.private.gdc.goog/v1alpha1/namespaces/gpc-system/servers/zb-aa-bm07/status","sourceIPs":["10.251.127.4"],"verb":"patch","userAgent":"root-admin-cm/v0.0.0 (linux/amd64) kubernetes/$Format","requestReceivedTimestamp":"2022-12-02T23:52:22.509246Z","stageTimestamp":"2022-12-02T23:52:22.527613Z","_gdch_cluster":"root-admin","responseStatus":{"metadata":{},"code":200},"annotations":{"authorization.k8s.io/reason":"RBAC: allowed by ClusterRoleBinding \"root-admin-rootadmin-controllers-rolebinding\" of ClusterRole \"root-admin-rootadmin-controllers-role\" to ServiceAccount \"root-admin-controller-sa/gpc-system\"","authorization.k8s.io/decision":"allow"},"objectRef":{"resource":"servers","apiGroup":"system.private.gdc.goog","name":"zb-aa-bm07","apiVersion":"v1alpha1","namespace":"gpc-system","subresource":"status"},"gdch_fluentbit_pod":"anthos-audit-logs-forwarder-kp68x","kind":"Event","apiVersion":"audit.k8s.io/v1","stage":"ResponseComplete","level":"Metadata","auditID":"2b2b0ec8-627b-4f69-aa19-b6ba2c3e20cb","_gdch_service_name":"apiserver"}
[[["Facile da capire","easyToUnderstand","thumb-up"],["Il problema è stato risolto","solvedMyProblem","thumb-up"],["Altra","otherUp","thumb-up"]],[["Difficile da capire","hardToUnderstand","thumb-down"],["Informazioni o codice di esempio errati","incorrectInformationOrSampleCode","thumb-down"],["Mancano le informazioni o gli esempi di cui ho bisogno","missingTheInformationSamplesINeed","thumb-down"],["Problema di traduzione","translationIssue","thumb-down"],["Altra","otherDown","thumb-down"]],["Ultimo aggiornamento 2025-09-04 UTC."],[[["\u003cp\u003eThe audit logs are generated from organization-only workloads, sourced from physical servers and server custom resources.\u003c/p\u003e\n"],["\u003cp\u003eAudited operations include both machine events and data changes, covering CRUD (Create, Read, Update, Delete) operations.\u003c/p\u003e\n"],["\u003cp\u003eMachine event logs contain crucial details such as user/service identity (\u003ccode\u003egdch_service_name\u003c/code\u003e), target (\u003ccode\u003edescription\u003c/code\u003e), action (\u003ccode\u003edescription\u003c/code\u003e), event timestamp (\u003ccode\u003etime\u003c/code\u003e), and source of action (\u003ccode\u003eresource\u003c/code\u003e).\u003c/p\u003e\n"],["\u003cp\u003eData change logs capture information like user/service identity (\u003ccode\u003eusername\u003c/code\u003e), target (\u003ccode\u003erequestURI\u003c/code\u003e), action (\u003ccode\u003everb\u003c/code\u003e), event timestamp (\u003ccode\u003erequestReceivedTimestamp\u003c/code\u003e), source of action (\u003ccode\u003esourceIPs\u003c/code\u003e), and the outcome (\u003ccode\u003eresponseStatus\u003c/code\u003e).\u003c/p\u003e\n"]]],[],null,["# Physical servers (SERV)\n\nMachine events\n--------------\n\n**Example log** \n\n\n {\n \"description\": \"The overall security state of the system is at \\\"Risk\\\".\",\n \"_gdch_service_name\": \"bm_nodes\",\n \"resource\": \"zb-ab-bm07\",\n \"auditID\": \"IEL#32321\",\n \"user\": {},\n \"time\": \"2022-12-02T16:06:29Z\",\n \"_gdch_cluster\": \"root-admin\",\n \"_gdch_fluentbit_pod\": \"anthos-audit-logs-forwarder-5k8l2\"\n }\n\nData changes (CRUD operations)\n------------------------------\n\n**Example log** \n\n {\n \"user\":{\n \"groups\":[\"system:serviceaccounts\",\"system:serviceaccounts:gpc-system\"\n \"system:authenticated\"]\n \"extra\":{\"authentication.kubernetes.io/pod-uid\":[\"8a33590d-bbf2-4a23-b5de-851a451fac32\"],\n \"authentication.kubernetes.io/pod-name\":[\"root-admin-controller-5c5d44f45-2r5d4\"]\n },\n \"username\":\"system:serviceaccount:gpc-system:root-admin-controller-sa\",\n \"uid\":\"ecaee5a1-f7e0-47e7-ae46-1cbd42fb2e99\"\n },\n \"requestURI\":\"/apis/system.private.gdc.goog/v1alpha1/namespaces/gpc-system/servers/zb-aa-bm07/status\",\n \"sourceIPs\":[\"10.251.127.4\"],\n \"verb\":\"patch\",\n \"userAgent\":\"root-admin-cm/v0.0.0 (linux/amd64) kubernetes/$Format\",\n \"requestReceivedTimestamp\":\"2022-12-02T23:52:22.509246Z\",\n \"stageTimestamp\":\"2022-12-02T23:52:22.527613Z\",\n \"_gdch_cluster\":\"root-admin\",\n \"responseStatus\":{\"metadata\":{},\"code\":200},\n \"annotations\":{\n \"authorization.k8s.io/reason\":\"RBAC: allowed by ClusterRoleBinding \\\n \"root-admin-rootadmin-controllers-rolebinding\\\" of ClusterRole \\\n \"root-admin-rootadmin-controllers-role\\\" to ServiceAccount \\\n \"root-admin-controller-sa/gpc-system\\\"\",\"authorization.k8s.io/decision\":\"allow\"\n },\n \"objectRef\":{\n \"resource\":\"servers\",\n \"apiGroup\":\n \"system.private.gdc.goog\",\n \"name\":\"zb-aa-bm07\",\n \"apiVersion\":\"v1alpha1\",\n \"namespace\":\"gpc-system\",\n \"subresource\":\"status\"\n },\n \"gdch_fluentbit_pod\":\"anthos-audit-logs-forwarder-kp68x\",\n \"kind\":\"Event\",\n \"apiVersion\":\"audit.k8s.io/v1\",\n \"stage\":\"ResponseComplete\",\n \"level\":\"Metadata\",\n \"auditID\":\"2b2b0ec8-627b-4f69-aa19-b6ba2c3e20cb\",\n \"_gdch_service_name\":\"apiserver\"\n }"]]