代管式 Microsoft AD 审核日志记录

本文档介绍 Managed Service for Microsoft Active Directory 的审核日志记录。Google Cloud 服务会生成审核日志,以记录 Google Cloud 资源中的管理和访问活动。 如需详细了解 Cloud Audit Logs,请参阅以下内容:

服务名称

托管式 Microsoft Active Directory 审核日志使用服务名称 managedidentities.googleapis.com。 针对此服务的过滤条件:

    protoPayload.serviceName="managedidentities.googleapis.com"
  

方法(按权限类型)

每个 IAM 权限都有一个 type 属性,该属性的值是一个枚举,可以是以下四个值之一:ADMIN_READADMIN_WRITEDATA_READDATA_WRITE。当您调用某个方法时,Managed Service for Microsoft Active Directory 会生成审核日志,其类别取决于执行该方法所需权限的 type 属性。需要 IAM 权限且 type 属性值为 DATA_READDATA_WRITEADMIN_READ 的方法会生成数据访问审核日志。需要 IAM 权限且 type 属性值为 ADMIN_WRITE 的方法会生成管理员活动审核日志。

权限类型 方法
ADMIN_READ GetIamPolicy
google.cloud.managedidentities.v1.ManagedIdentitiesService.CheckMigrationPermission
google.cloud.managedidentities.v1.ManagedIdentitiesService.GetDomain
google.cloud.managedidentities.v1.ManagedIdentitiesService.GetLDAPSSettings
google.cloud.managedidentities.v1.ManagedIdentitiesService.GetPeering
google.cloud.managedidentities.v1.ManagedIdentitiesService.GetSqlIntegration
google.cloud.managedidentities.v1.ManagedIdentitiesService.ListDomains
google.cloud.managedidentities.v1.ManagedIdentitiesService.ListPeerings
google.cloud.managedidentities.v1.ManagedIdentitiesService.ListSqlIntegrations
google.cloud.managedidentities.v1.ManagedIdentitiesService.ValidateTrust
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CheckMigrationPermission
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetDomain
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetLDAPSSettings
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetPeering
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetSQLIntegration
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ListDomains
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ListPeerings
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ListSQLIntegrations
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ValidateTrust
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CheckMigrationPermission
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetDomain
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetLDAPSSettings
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetPeering
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetSqlIntegration
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ListDomains
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ListPeerings
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ListSqlIntegrations
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ValidateTrust
google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.GetInternalIntegratedNetwork
google.longrunning.Operations.GetOperation
google.longrunning.Operations.ListOperations
ADMIN_WRITE SetIamPolicy
google.cloud.managedidentities.v1.ManagedIdentitiesService.AttachTrust
google.cloud.managedidentities.v1.ManagedIdentitiesService.CreateBackup
google.cloud.managedidentities.v1.ManagedIdentitiesService.CreateMicrosoftAdDomain
google.cloud.managedidentities.v1.ManagedIdentitiesService.CreatePeering
google.cloud.managedidentities.v1.ManagedIdentitiesService.DeleteBackup
google.cloud.managedidentities.v1.ManagedIdentitiesService.DeleteDomain
google.cloud.managedidentities.v1.ManagedIdentitiesService.DeletePeering
google.cloud.managedidentities.v1.ManagedIdentitiesService.DetachTrust
google.cloud.managedidentities.v1.ManagedIdentitiesService.DisableMigration
google.cloud.managedidentities.v1.ManagedIdentitiesService.DomainJoinMachine
google.cloud.managedidentities.v1.ManagedIdentitiesService.EnableMigration
google.cloud.managedidentities.v1.ManagedIdentitiesService.ExtendSchema
google.cloud.managedidentities.v1.ManagedIdentitiesService.ReconfigureTrust
google.cloud.managedidentities.v1.ManagedIdentitiesService.ResetAdminPassword
google.cloud.managedidentities.v1.ManagedIdentitiesService.RestoreDomain
google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdateBackup
google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdateDomain
google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdateLDAPSSettings
google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdatePeering
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.AttachTrust
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CreateBackup
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CreateMicrosoftAdDomain
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CreatePeering
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DeleteBackup
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DeleteDomain
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DeletePeering
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DetachTrust
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DisableMigration
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DomainJoinMachine
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.EnableMigration
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ExtendSchema
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ReconfigureTrust
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ResetAdminPassword
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.RestoreDomain
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdateBackup
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdateDomain
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdateLDAPSSettings
google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdatePeering
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.AttachTrust
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CreateBackup
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CreateMicrosoftAdDomain
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CreatePeering
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DeleteBackup
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DeleteDomain
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DeletePeering
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DetachTrust
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DisableMigration
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DomainJoinMachine
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.EnableMigration
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ExtendSchema
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ReconfigureTrust
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ResetAdminPassword
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.RestoreDomain
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdateBackup
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdateDomain
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdateLDAPSSettings
google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdatePeering
google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.CreateInternalIntegratedNetwork
google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.CreateInternalSQLIntegration
google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.DeleteInternalIntegratedNetwork
google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.DeleteInternalSQLIntegration
google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.ResetInternalSQLPassword
google.longrunning.Operations.CancelOperation
google.longrunning.Operations.DeleteOperation

API 接口审核日志

如需了解如何评估每种方法的权限以及评估哪些权限,请参阅 Managed Service for Microsoft Active Directory 的 Identity and Access Management 文档。

google.cloud.managedidentities.v1.ManagedIdentitiesService

以下审核日志与属于 google.cloud.managedidentities.v1.ManagedIdentitiesService 的方法相关联。

AttachTrust

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.AttachTrust
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.attachTrust - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.AttachTrust"

CheckMigrationPermission

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.CheckMigrationPermission
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.checkMigrationPermission - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.CheckMigrationPermission"

CreateBackup

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.CreateBackup
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.backups.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.CreateBackup"

CreateMicrosoftAdDomain

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.CreateMicrosoftAdDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.CreateMicrosoftAdDomain"

CreatePeering

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.CreatePeering
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.peerings.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.CreatePeering"

DeleteBackup

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.DeleteBackup
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.backups.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.DeleteBackup"

DeleteDomain

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.DeleteDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.DeleteDomain"

DeletePeering

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.DeletePeering
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.peerings.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.DeletePeering"

DetachTrust

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.DetachTrust
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.detachTrust - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.DetachTrust"

DisableMigration

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.DisableMigration
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.disableMigration - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.DisableMigration"

DomainJoinMachine

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.DomainJoinMachine
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.domainJoinMachine - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.DomainJoinMachine"

EnableMigration

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.EnableMigration
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.enableMigration - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.EnableMigration"

ExtendSchema

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.ExtendSchema
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.extendSchema - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.ExtendSchema"

GetDomain

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.GetDomain
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.GetDomain"

GetLDAPSSettings

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.GetLDAPSSettings
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.GetLDAPSSettings"

GetPeering

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.GetPeering
  • 审核日志类型数据访问
  • 权限
    • managedidentities.peerings.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.GetPeering"

GetSqlIntegration

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.GetSqlIntegration
  • 审核日志类型数据访问
  • 权限
    • managedidentities.sqlintegrations.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.GetSqlIntegration"

ListDomains

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.ListDomains
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.ListDomains"

ListPeerings

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.ListPeerings
  • 审核日志类型数据访问
  • 权限
    • managedidentities.peerings.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.ListPeerings"

ListSqlIntegrations

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.ListSqlIntegrations
  • 审核日志类型数据访问
  • 权限
    • managedidentities.sqlintegrations.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.ListSqlIntegrations"

ReconfigureTrust

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.ReconfigureTrust
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.reconfigureTrust - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.ReconfigureTrust"

ResetAdminPassword

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.ResetAdminPassword
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.resetpassword - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.ResetAdminPassword"

RestoreDomain

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.RestoreDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.restore - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.RestoreDomain"

UpdateBackup

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdateBackup
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.backups.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdateBackup"

UpdateDomain

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdateDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdateDomain"

UpdateLDAPSSettings

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdateLDAPSSettings
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.updateLDAPSSettings - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdateLDAPSSettings"

UpdatePeering

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdatePeering
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.peerings.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.UpdatePeering"

ValidateTrust

  • 方法google.cloud.managedidentities.v1.ManagedIdentitiesService.ValidateTrust
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.validateTrust - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1.ManagedIdentitiesService.ValidateTrust"

google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService

以下审核日志与属于 google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService 的方法相关联。

AttachTrust

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.AttachTrust
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.attachTrust - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.AttachTrust"

CheckMigrationPermission

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CheckMigrationPermission
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.checkMigrationPermission - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CheckMigrationPermission"

CreateBackup

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CreateBackup
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.backups.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CreateBackup"

CreateMicrosoftAdDomain

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CreateMicrosoftAdDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CreateMicrosoftAdDomain"

CreatePeering

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CreatePeering
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.peerings.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.CreatePeering"

DeleteBackup

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DeleteBackup
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.backups.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DeleteBackup"

DeleteDomain

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DeleteDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DeleteDomain"

DeletePeering

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DeletePeering
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.peerings.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DeletePeering"

DetachTrust

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DetachTrust
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.detachTrust - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DetachTrust"

DisableMigration

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DisableMigration
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.disableMigration - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DisableMigration"

DomainJoinMachine

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DomainJoinMachine
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.domainJoinMachine - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.DomainJoinMachine"

EnableMigration

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.EnableMigration
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.enableMigration - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.EnableMigration"

ExtendSchema

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ExtendSchema
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.extendSchema - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ExtendSchema"

GetDomain

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetDomain
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetDomain"

GetLDAPSSettings

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetLDAPSSettings
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetLDAPSSettings"

GetPeering

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetPeering
  • 审核日志类型数据访问
  • 权限
    • managedidentities.peerings.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetPeering"

GetSQLIntegration

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetSQLIntegration
  • 审核日志类型数据访问
  • 权限
    • managedidentities.sqlintegrations.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.GetSQLIntegration"

ListDomains

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ListDomains
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ListDomains"

ListPeerings

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ListPeerings
  • 审核日志类型数据访问
  • 权限
    • managedidentities.peerings.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ListPeerings"

ListSQLIntegrations

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ListSQLIntegrations
  • 审核日志类型数据访问
  • 权限
    • managedidentities.sqlintegrations.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ListSQLIntegrations"

ReconfigureTrust

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ReconfigureTrust
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.reconfigureTrust - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ReconfigureTrust"

ResetAdminPassword

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ResetAdminPassword
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.resetpassword - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ResetAdminPassword"

RestoreDomain

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.RestoreDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.restore - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.RestoreDomain"

UpdateBackup

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdateBackup
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.backups.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdateBackup"

UpdateDomain

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdateDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdateDomain"

UpdateLDAPSSettings

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdateLDAPSSettings
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.updateLDAPSSettings - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdateLDAPSSettings"

UpdatePeering

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdatePeering
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.peerings.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.UpdatePeering"

ValidateTrust

  • 方法google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ValidateTrust
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.validateTrust - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1alpha1.ManagedIdentitiesService.ValidateTrust"

google.cloud.managedidentities.v1beta1.ManagedIdentitiesService

以下审核日志与属于 google.cloud.managedidentities.v1beta1.ManagedIdentitiesService 的方法相关联。

AttachTrust

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.AttachTrust
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.attachTrust - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.AttachTrust"

CheckMigrationPermission

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CheckMigrationPermission
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.checkMigrationPermission - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CheckMigrationPermission"

CreateBackup

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CreateBackup
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.backups.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CreateBackup"

CreateMicrosoftAdDomain

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CreateMicrosoftAdDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CreateMicrosoftAdDomain"

CreatePeering

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CreatePeering
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.peerings.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.CreatePeering"

DeleteBackup

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DeleteBackup
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.backups.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DeleteBackup"

DeleteDomain

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DeleteDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DeleteDomain"

DeletePeering

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DeletePeering
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.peerings.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DeletePeering"

DetachTrust

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DetachTrust
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.detachTrust - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DetachTrust"

DisableMigration

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DisableMigration
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.disableMigration - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DisableMigration"

DomainJoinMachine

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DomainJoinMachine
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.domainJoinMachine - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.DomainJoinMachine"

EnableMigration

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.EnableMigration
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.enableMigration - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.EnableMigration"

ExtendSchema

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ExtendSchema
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.extendSchema - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ExtendSchema"

GetDomain

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetDomain
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetDomain"

GetLDAPSSettings

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetLDAPSSettings
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetLDAPSSettings"

GetPeering

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetPeering
  • 审核日志类型数据访问
  • 权限
    • managedidentities.peerings.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetPeering"

GetSqlIntegration

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetSqlIntegration
  • 审核日志类型数据访问
  • 权限
    • managedidentities.sqlintegrations.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.GetSqlIntegration"

ListDomains

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ListDomains
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ListDomains"

ListPeerings

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ListPeerings
  • 审核日志类型数据访问
  • 权限
    • managedidentities.peerings.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ListPeerings"

ListSqlIntegrations

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ListSqlIntegrations
  • 审核日志类型数据访问
  • 权限
    • managedidentities.sqlintegrations.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ListSqlIntegrations"

ReconfigureTrust

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ReconfigureTrust
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.reconfigureTrust - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ReconfigureTrust"

ResetAdminPassword

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ResetAdminPassword
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.resetpassword - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ResetAdminPassword"

RestoreDomain

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.RestoreDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.restore - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.RestoreDomain"

UpdateBackup

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdateBackup
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.backups.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdateBackup"

UpdateDomain

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdateDomain
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdateDomain"

UpdateLDAPSSettings

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdateLDAPSSettings
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.updateLDAPSSettings - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdateLDAPSSettings"

UpdatePeering

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdatePeering
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.peerings.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.UpdatePeering"

ValidateTrust

  • 方法google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ValidateTrust
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.validateTrust - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1beta1.ManagedIdentitiesService.ValidateTrust"

google.cloud.managedidentities.v1internal1.ManagedIdentitiesService

以下审核日志与属于 google.cloud.managedidentities.v1internal1.ManagedIdentitiesService 的方法相关联。

CreateInternalIntegratedNetwork

  • 方法google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.CreateInternalIntegratedNetwork
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.integratednetworks.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.CreateInternalIntegratedNetwork"

CreateInternalSQLIntegration

  • 方法google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.CreateInternalSQLIntegration
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.sqlintegrations.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.CreateInternalSQLIntegration"

DeleteInternalIntegratedNetwork

  • 方法google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.DeleteInternalIntegratedNetwork
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.integratednetworks.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.DeleteInternalIntegratedNetwork"

DeleteInternalSQLIntegration

  • 方法google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.DeleteInternalSQLIntegration
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.sqlintegrations.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.DeleteInternalSQLIntegration"

GetInternalIntegratedNetwork

  • 方法google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.GetInternalIntegratedNetwork
  • 审核日志类型数据访问
  • 权限
    • managedidentities.integratednetworks.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.GetInternalIntegratedNetwork"

ResetInternalSQLPassword

  • 方法google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.ResetInternalSQLPassword
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.sqlintegrations.resetsqlpassword - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.managedidentities.v1internal1.ManagedIdentitiesService.ResetInternalSQLPassword"

google.iam.v1.IAMPolicy

以下审核日志与属于 google.iam.v1.IAMPolicy 的方法相关联。

GetIamPolicy

  • 方法GetIamPolicy
  • 审核日志类型数据访问
  • 权限
    • managedidentities.domains.getIamPolicy - ADMIN_READ
    • managedidentities.peerings.getIamPolicy - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="GetIamPolicy"

SetIamPolicy

  • 方法SetIamPolicy
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.domains.setIamPolicy - ADMIN_WRITE
    • managedidentities.peerings.setIamPolicy - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="SetIamPolicy"

google.longrunning.Operations

以下审核日志与属于 google.longrunning.Operations 的方法相关联。

CancelOperation

  • 方法google.longrunning.Operations.CancelOperation
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.operations.cancel - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.longrunning.Operations.CancelOperation"

DeleteOperation

  • 方法google.longrunning.Operations.DeleteOperation
  • 审核日志类型管理员活动
  • 权限
    • managedidentities.operations.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.longrunning.Operations.DeleteOperation"

GetOperation

  • 方法google.longrunning.Operations.GetOperation
  • 审核日志类型数据访问
  • 权限
    • managedidentities.operations.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.longrunning.Operations.GetOperation"

ListOperations

  • 方法google.longrunning.Operations.ListOperations
  • 审核日志类型数据访问
  • 权限
    • managedidentities.operations.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.longrunning.Operations.ListOperations"