Lokasi workload |
Block storage |
Sumber log audit |
Block storage |
Contoh operasi yang diaudit |
Membuat volume
Kolom dalam entri log yang berisi informasi audit | ||
---|---|---|
Metadata audit | Nama kolom audit | Nilai |
Identitas pengguna atau layanan | message.user.identity |
Misalnya,
"message":"{"user":{"identity":"root-admin-client-cert"}} |
Target (Kolom dan nilai yang memanggil API) |
message.action |
Misalnya,
"message":"{"action":"volume-create"}" |
Tindakan (Kolom yang berisi operasi yang dilakukan) |
action
|
Misalnya,
|
Stempel waktu peristiwa |
time
|
Misalnya,
|
Sumber tindakan | message.sourceIPs |
Misalnya, "message":"{"sourceIPs":["10.252.143.2"]}" |
Hasil | message.response |
Misalnya, "message":"{"response":"success"}" |
Kolom lainnya | Tidak berlaku |
Tidak berlaku |
Contoh log
{
"pri":"14",
"time":"2022-12-07T13:46:49.133781Z",
"host":"storage",
"ident":"storage",
"pid":"-",
"msgid":"-",
"extradata":"-",
"message":"{"time":"2022-12-07T13:40:18Z","auditID":"90199274229","user":{"identity":"root-admin-client-cert"},"resource":"{"Application":"ontapi","Hostname":"zh-ad-stge02-02","StorageVirtualMachine":"root-admin"}","action":"volume-create","sourceIPs":["10.252.143.2"],"response":"success","_gdch_org":"root-admin"}",
"_gdch_cluster":"root-admin",
"_gdch_fluentbit_pod":"anthos-audit-logs-forwarder-vn8f9",
"_gdch_service_name":"admin-audit-logs"
}
Menetapkan ukuran volume
Kolom dalam entri log yang berisi informasi audit | ||
---|---|---|
Metadata audit | Nama kolom audit | Nilai |
Identitas pengguna atau layanan | message.user.identity |
Misalnya,
"message":"{"user":{"identity":"root-admin-client-cert"}} |
Target (Kolom dan nilai yang memanggil API) |
message.action |
Misalnya,
"message":"{"action":"volume-size"}" |
Tindakan (Kolom yang berisi operasi yang dilakukan) |
action
|
Misalnya,
|
Stempel waktu peristiwa |
time
|
Misalnya,
|
Sumber tindakan | message.sourceIPs |
Misalnya, "message":"{"sourceIPs":["10.252.143.2"]}" |
Hasil | message.response |
Misalnya, "message":"{"response":"success"}" |
Kolom lainnya | Tidak berlaku |
Tidak berlaku |
Contoh log
{
"pri":"14",
"time":"2022-12-07T13:46:49.135968Z",
"host":"storage",
"ident":"storage",
"pid":"-",
"msgid":"-",
"extradata":"-",
"message":"{"time":"2022-12-07T13:46:36Z","auditID":"120264072202","user":{"identity":"root-admin-client-cert"},"resource":"{"Application":"ontapi","Hostname":"zh-ad-stge03-01","StorageVirtualMachine":"root-admin"}","action":"volume-size","sourceIPs":["10.252.143.2"],"response":"success","_gdch_org":"root-admin"}",
"_gdch_cluster":"root-admin",
"_gdch_fluentbit_pod":"anthos-audit-logs-forwarder-vn8f9",
"_gdch_service_name":"admin-audit-logs"
}
Menghapus volume
Kolom dalam entri log yang berisi informasi audit | ||
---|---|---|
Metadata audit | Nama kolom audit | Nilai |
Identitas pengguna atau layanan | message.user.identity |
Misalnya,
"message":"{"user":{"identity":"root-admin-client-cert"}} |
Target (Kolom dan nilai yang memanggil API) |
message.action |
Misalnya,
"message":"{"action":"volume-destroy"}" |
Tindakan (Kolom yang berisi operasi yang dilakukan) |
action
|
Misalnya,
|
Stempel waktu peristiwa |
time
|
Misalnya,
|
Sumber tindakan | message.sourceIPs |
Misalnya, "message":"{"sourceIPs":["10.252.143.2"]}" |
Hasil | message.response |
Misalnya, "message":"{"response":"success"}" |
Kolom lainnya | Tidak berlaku |
Tidak berlaku |
Contoh log
{
"pri":"14",
"time":"2022-12-07T13:46:49.136236Z",
"host":"storage",
"ident":"storage",
"pid":"-",
"msgid":"-",
"extradata":"-",
"message":"{"time":"2022-12-07T13:46:37Z","auditID":"90203137689","user":{"identity":"root-admin-client-cert"},"resource":"{"Application":"ontapi","Hostname":"zh-ad-stge01-02","StorageVirtualMachine":"root-admin"}","action":"volume-destroy","sourceIPs":["10.252.143.2"],"response":"success","_gdch_org":"root-admin"}",
"_gdch_cluster":"root-admin",
"_gdch_fluentbit_pod":"anthos-audit-logs-forwarder-vn8f9",
"_gdch_service_name":"admin-audit-logs"
}