本頁面說明如何使用 VPC Service Controls 疑難排解工具,瞭解並診斷 VPC Service Controls 記錄檔的問題。
VPC Service Controls 記錄包含對受保護資源提出要求的詳細資料,以及 VPC Service Controls 拒絕要求的原因。不過,這些詳細資料不一定很容易看出,您可能需要花費相當長的時間才能瞭解記錄。您可以使用 VPC Service Controls 疑難排解工具,診斷服務範圍的拒絕情形。如需違規原因的相關資訊,請參閱「偵錯 VPC Service Controls 封鎖的要求」。
您也可以使用疑難排解工具,診斷使用模擬執行設定的服務邊界拒絕情形。
事前準備
如要排解 VPC Service Controls 違規問題,請確認您在機構層級具備 VPC Service Controls 疑難排解工具檢視者 IAM 角色 (roles/accesscontextmanager.vpcScTroubleshooterViewer)。這個角色無法讓您修改邊界或存取層級。
存取 VPC Service Controls 疑難排解工具
疑難排解工具僅適用於 Google Cloud 控制台。您可以使用「Logs Explorer」或「VPC Service Controls」頁面存取疑難排解工具。
使用記錄檔探索工具
您可以使用記錄檔探索工具,直接從 VPC Service Controls 拒絕的記錄項目移至疑難排解工具。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-04 (世界標準時間)。"],[],[],null,["# Diagnose issues by using the VPC Service Controls troubleshooter\n\nThis page describes how you can use the VPC Service Controls troubleshooter to\nunderstand and diagnose issues that VPC Service Controls logs.\n\nVPC Service Controls logs include details about requests to protected resources and\nthe reason why VPC Service Controls denied the request. However, these details aren't\nalways easily apparent and you might spend considerable time understanding the logs.\nYou can use the VPC Service Controls troubleshooter to diagnose denials\nfrom a service perimeter. For information on violation reasons, see [Debugging requests blocked by VPC Service Controls](/vpc-service-controls/docs/troubleshooting#debugging).\n\nYou can also use the troubleshooter to diagnose denials from a service perimeter\nthat uses a dry-run configuration.\n\nBefore you begin\n----------------\n\nTo troubleshoot a VPC Service Controls violation, make sure that you have\nthe VPC Service Controls Troubleshooter Viewer IAM role\n(`roles/accesscontextmanager.vpcScTroubleshooterViewer`) at the organization level. This role doesn't\nlet you modify perimeters or access levels.\n\nAccessing the VPC Service Controls troubleshooter\n-------------------------------------------------\n\nThe troubleshooter is available only in the Google Cloud console.\nYou can access the troubleshooter using either the [Logs Explorer](/logging/docs/view/logs-explorer-summary)\nor the VPC Service Controls page.\n\n### Using the Logs Explorer\n\nBy using the [Logs Explorer](/logging/docs/view/logs-explorer-summary), you can move directly from a\nlog entry for a VPC Service Controls denial to the troubleshooter.\n\nTo access the troubleshooter from a log entry, do the following:\n\n1. Go to the **Logs Explorer** page in the Google Cloud console.\n\n [Go to Logs Explorer](https://console.cloud.google.com/logs/query)\n2. In the Logs Explorer, use the denial's [unique ID to access the log\n entry](/vpc-service-controls/docs/retrieve-troubleshoot-errors#unique-id).\n\n3. In the **Query Results** box, in the row for the denial that you want to\n troubleshoot, click **VPC Service Controls** , and then click **Troubleshoot\n denial**.\n\n### Using the VPC Service Controls page\n\nFrom the **VPC Service Controls** page, you can troubleshoot a denial using\nits unique ID.\n\nBefore you begin, [obtain the unique ID](/vpc-service-controls/docs/retrieve-troubleshoot-errors#unique-id) for the denial that you want\nto troubleshoot.\n\nTo access the troubleshooter from the **VPC Service Controls**\npage, do the following:\n\n1. In the Google Cloud console navigation menu, click **Security** , and then\n click **VPC Service Controls**.\n\n [Go to VPC Service Controls](https://console.cloud.google.com/security/service-perimeter)\n2. If you are prompted, select your organization. You can access the **VPC Service Controls**\n page only at the organization level.\n\n3. On the **VPC Service Controls** page, click **Troubleshoot**.\n\n4. On the **VPC Service Controls Troubleshooter** page, in the\n **Unique identifier** box, enter the unique ID for the denial that you want\n to troubleshoot.\n\n5. Click **Troubleshoot**.\n\nWhat's next\n-----------\n\n- [Understanding VPC Service Controls audit logs](/vpc-service-controls/docs/audit-logging)\n- Learn how [VPC Service Controls unique identifier helps troubleshoot\n issues related to service perimeters](https://cloud.google.com/blog/products/identity-security/unique-identifier-helps-troubleshooting-vpc-service-controls-perimeter).\n- [Diagnose an access denial event using the VPC Service Controls violation\n analyzer](/vpc-service-controls/docs/violation-analyzer) ([Preview](/products#product-launch-stages))."]]