Google Cloud VMware Engine 审核日志记录

本文档介绍了 Google Cloud VMware Engine 的审核日志记录。Google Cloud 服务会生成审核日志,以记录 Google Cloud 资源中的管理和访问活动。 如需详细了解 Cloud Audit Logs,请参阅以下内容:

服务名称

Google Cloud VMware Engine 审核日志使用服务名称 vmwareengine.googleapis.com。 针对此服务的过滤条件:

    protoPayload.serviceName="vmwareengine.googleapis.com"
  

方法(按权限类型)

每个 IAM 权限都有一个 type 属性,该属性的值是一个枚举,可以是以下四个值之一:ADMIN_READADMIN_WRITEDATA_READDATA_WRITE。在您调用某个方法时,Google Cloud VMware Engine 会生成一个审核日志,其类别取决于执行该方法所需权限的 type 属性。需要 IAM 权限且 type 属性值为 DATA_READDATA_WRITEADMIN_READ 的方法会生成数据访问审核日志。需要 IAM 权限且 type 属性值为 ADMIN_WRITE 的方法会生成管理员活动审核日志。

权限类型 方法
ADMIN_READ GetIamPolicy
google.cloud.vmwareengine.v1.VmwareEngine.FetchNetworkPolicyExternalAddresses
google.cloud.vmwareengine.v1.VmwareEngine.GetCluster
google.cloud.vmwareengine.v1.VmwareEngine.GetDnsBindPermission
google.cloud.vmwareengine.v1.VmwareEngine.GetDnsForwarding
google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAccessRule
google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAddress
google.cloud.vmwareengine.v1.VmwareEngine.GetHcxActivationKey
google.cloud.vmwareengine.v1.VmwareEngine.GetLoggingServer
google.cloud.vmwareengine.v1.VmwareEngine.GetManagementDnsZoneBinding
google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPeering
google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPolicy
google.cloud.vmwareengine.v1.VmwareEngine.GetNode
google.cloud.vmwareengine.v1.VmwareEngine.GetNodeType
google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateCloud
google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateConnection
google.cloud.vmwareengine.v1.VmwareEngine.GetSubnet
google.cloud.vmwareengine.v1.VmwareEngine.GetVmwareEngineNetwork
google.cloud.vmwareengine.v1.VmwareEngine.ListClusters
google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAccessRules
google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAddresses
google.cloud.vmwareengine.v1.VmwareEngine.ListHcxActivationKeys
google.cloud.vmwareengine.v1.VmwareEngine.ListLoggingServers
google.cloud.vmwareengine.v1.VmwareEngine.ListManagementDnsZoneBindings
google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPeerings
google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPolicies
google.cloud.vmwareengine.v1.VmwareEngine.ListNodeTypes
google.cloud.vmwareengine.v1.VmwareEngine.ListNodes
google.cloud.vmwareengine.v1.VmwareEngine.ListPeeringRoutes
google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateClouds
google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnectionPeeringRoutes
google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnections
google.cloud.vmwareengine.v1.VmwareEngine.ListSubnets
google.cloud.vmwareengine.v1.VmwareEngine.ListVmwareEngineNetworks
google.cloud.vmwareengine.v1.VmwareEngine.ShowNsxCredentials
google.cloud.vmwareengine.v1.VmwareEngine.ShowVcenterCredentials
google.longrunning.Operations.GetOperation
google.longrunning.Operations.ListOperations
ADMIN_WRITE SetIamPolicy
google.cloud.vmwareengine.v1.VmwareEngine.CreateCluster
google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAccessRule
google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAddress
google.cloud.vmwareengine.v1.VmwareEngine.CreateHcxActivationKey
google.cloud.vmwareengine.v1.VmwareEngine.CreateLoggingServer
google.cloud.vmwareengine.v1.VmwareEngine.CreateManagementDnsZoneBinding
google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPeering
google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPolicy
google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateCloud
google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateConnection
google.cloud.vmwareengine.v1.VmwareEngine.CreateVmwareEngineNetwork
google.cloud.vmwareengine.v1.VmwareEngine.DeleteCluster
google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAccessRule
google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAddress
google.cloud.vmwareengine.v1.VmwareEngine.DeleteLoggingServer
google.cloud.vmwareengine.v1.VmwareEngine.DeleteManagementDnsZoneBinding
google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPeering
google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPolicy
google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateCloud
google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateConnection
google.cloud.vmwareengine.v1.VmwareEngine.DeleteVmwareEngineNetwork
google.cloud.vmwareengine.v1.VmwareEngine.GrantDnsBindPermission
google.cloud.vmwareengine.v1.VmwareEngine.RepairManagementDnsZoneBinding
google.cloud.vmwareengine.v1.VmwareEngine.ResetNsxCredentials
google.cloud.vmwareengine.v1.VmwareEngine.ResetVcenterCredentials
google.cloud.vmwareengine.v1.VmwareEngine.RevokeDnsBindPermission
google.cloud.vmwareengine.v1.VmwareEngine.UndeletePrivateCloud
google.cloud.vmwareengine.v1.VmwareEngine.UpdateCluster
google.cloud.vmwareengine.v1.VmwareEngine.UpdateDnsForwarding
google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAccessRule
google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAddress
google.cloud.vmwareengine.v1.VmwareEngine.UpdateLoggingServer
google.cloud.vmwareengine.v1.VmwareEngine.UpdateManagementDnsZoneBinding
google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPeering
google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPolicy
google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateCloud
google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateConnection
google.cloud.vmwareengine.v1.VmwareEngine.UpdateSubnet
google.cloud.vmwareengine.v1.VmwareEngine.UpdateVmwareEngineNetwork
google.longrunning.Operations.DeleteOperation

API 接口审核日志

如需了解如何评估每种方法的权限以及评估哪些权限,请参阅 Google Cloud VMware Engine 的 Identity and Access Management 文档。

google.cloud.vmwareengine.v1.VmwareEngine

以下审核日志与属于 google.cloud.vmwareengine.v1.VmwareEngine 的方法相关联。

CreateCluster

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateCluster
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.clusters.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateCluster"

CreateExternalAccessRule

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAccessRule
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.externalAccessRules.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAccessRule"

CreateExternalAddress

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAddress
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.externalAddresses.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAddress"

CreateHcxActivationKey

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateHcxActivationKey
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.hcxActivationKeys.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateHcxActivationKey"

CreateLoggingServer

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateLoggingServer
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.loggingServers.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateLoggingServer"

CreateManagementDnsZoneBinding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateManagementDnsZoneBinding
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.managementDnsZoneBindings.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateManagementDnsZoneBinding"

CreateNetworkPeering

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPeering
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.networkPeerings.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPeering"

CreateNetworkPolicy

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPolicy
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.networkPolicies.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPolicy"

CreatePrivateCloud

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateCloud
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.privateClouds.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateCloud"

CreatePrivateConnection

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateConnection
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.privateConnections.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateConnection"

CreateVmwareEngineNetwork

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateVmwareEngineNetwork
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.vmwareEngineNetworks.create - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateVmwareEngineNetwork"

DeleteCluster

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteCluster
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.clusters.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteCluster"

DeleteExternalAccessRule

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAccessRule
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.externalAccessRules.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAccessRule"

DeleteExternalAddress

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAddress
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.externalAddresses.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAddress"

DeleteLoggingServer

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteLoggingServer
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.loggingServers.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteLoggingServer"

DeleteManagementDnsZoneBinding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteManagementDnsZoneBinding
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.managementDnsZoneBindings.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteManagementDnsZoneBinding"

DeleteNetworkPeering

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPeering
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.networkPeerings.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPeering"

DeleteNetworkPolicy

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPolicy
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.networkPolicies.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPolicy"

DeletePrivateCloud

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateCloud
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.privateClouds.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateCloud"

DeletePrivateConnection

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateConnection
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.privateConnections.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateConnection"

DeleteVmwareEngineNetwork

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteVmwareEngineNetwork
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.vmwareEngineNetworks.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteVmwareEngineNetwork"

FetchNetworkPolicyExternalAddresses

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.FetchNetworkPolicyExternalAddresses
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.networkPolicies.fetchExternalAddresses - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.FetchNetworkPolicyExternalAddresses"

GetCluster

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetCluster
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.clusters.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetCluster"

GetDnsBindPermission

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetDnsBindPermission
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.dnsBindPermission.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetDnsBindPermission"

GetDnsForwarding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetDnsForwarding
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.dnsForwarding.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetDnsForwarding"

GetExternalAccessRule

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAccessRule
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.externalAccessRules.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAccessRule"

GetExternalAddress

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAddress
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.externalAddresses.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAddress"

GetHcxActivationKey

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetHcxActivationKey
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.hcxActivationKeys.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetHcxActivationKey"

GetLoggingServer

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetLoggingServer
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.loggingServers.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetLoggingServer"

GetManagementDnsZoneBinding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetManagementDnsZoneBinding
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.managementDnsZoneBindings.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetManagementDnsZoneBinding"

GetNetworkPeering

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPeering
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.networkPeerings.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPeering"

GetNetworkPolicy

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPolicy
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.networkPolicies.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPolicy"

GetNode

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetNode
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.nodes.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetNode"

GetNodeType

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetNodeType
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.nodeTypes.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetNodeType"

GetPrivateCloud

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateCloud
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.privateClouds.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateCloud"

GetPrivateConnection

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateConnection
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.privateConnections.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateConnection"

GetSubnet

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetSubnet
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.subnets.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetSubnet"

GetVmwareEngineNetwork

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetVmwareEngineNetwork
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.vmwareEngineNetworks.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetVmwareEngineNetwork"

GrantDnsBindPermission

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GrantDnsBindPermission
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.dnsBindPermission.grant - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GrantDnsBindPermission"

ListClusters

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListClusters
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.clusters.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListClusters"

ListExternalAccessRules

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAccessRules
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.externalAccessRules.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAccessRules"

ListExternalAddresses

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAddresses
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.externalAddresses.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAddresses"

ListHcxActivationKeys

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListHcxActivationKeys
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.hcxActivationKeys.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListHcxActivationKeys"

ListLoggingServers

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListLoggingServers
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.loggingServers.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListLoggingServers"

ListManagementDnsZoneBindings

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListManagementDnsZoneBindings
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.managementDnsZoneBindings.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListManagementDnsZoneBindings"

ListNetworkPeerings

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPeerings
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.networkPeerings.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPeerings"

ListNetworkPolicies

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPolicies
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.networkPolicies.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPolicies"

ListNodeTypes

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListNodeTypes
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.nodeTypes.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListNodeTypes"

ListNodes

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListNodes
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.nodes.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListNodes"

ListPeeringRoutes

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListPeeringRoutes
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.networkPeerings.listPeeringRoutes - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListPeeringRoutes"

ListPrivateClouds

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateClouds
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.privateClouds.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateClouds"

ListPrivateConnectionPeeringRoutes

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnectionPeeringRoutes
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.privateConnections.listPeeringRoutes - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnectionPeeringRoutes"

ListPrivateConnections

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnections
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.privateConnections.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnections"

ListSubnets

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListSubnets
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.subnets.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListSubnets"

ListVmwareEngineNetworks

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListVmwareEngineNetworks
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.vmwareEngineNetworks.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListVmwareEngineNetworks"

RepairManagementDnsZoneBinding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.RepairManagementDnsZoneBinding
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.managementDnsZoneBindings.repair - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.RepairManagementDnsZoneBinding"

ResetNsxCredentials

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ResetNsxCredentials
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.privateClouds.resetNsxCredentials - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ResetNsxCredentials"

ResetVcenterCredentials

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ResetVcenterCredentials
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.privateClouds.resetVcenterCredentials - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ResetVcenterCredentials"

RevokeDnsBindPermission

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.RevokeDnsBindPermission
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.dnsBindPermission.revoke - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.RevokeDnsBindPermission"

ShowNsxCredentials

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ShowNsxCredentials
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.privateClouds.showNsxCredentials - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ShowNsxCredentials"

ShowVcenterCredentials

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ShowVcenterCredentials
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.privateClouds.showVcenterCredentials - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ShowVcenterCredentials"

UndeletePrivateCloud

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UndeletePrivateCloud
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.privateClouds.undelete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UndeletePrivateCloud"

UpdateCluster

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateCluster
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.clusters.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateCluster"

UpdateDnsForwarding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateDnsForwarding
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.dnsForwarding.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateDnsForwarding"

UpdateExternalAccessRule

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAccessRule
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.externalAccessRules.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAccessRule"

UpdateExternalAddress

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAddress
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.externalAddresses.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAddress"

UpdateLoggingServer

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateLoggingServer
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.loggingServers.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateLoggingServer"

UpdateManagementDnsZoneBinding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateManagementDnsZoneBinding
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.managementDnsZoneBindings.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateManagementDnsZoneBinding"

UpdateNetworkPeering

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPeering
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.networkPeerings.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPeering"

UpdateNetworkPolicy

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPolicy
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.networkPolicies.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPolicy"

UpdatePrivateCloud

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateCloud
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.privateClouds.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateCloud"

UpdatePrivateConnection

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateConnection
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.privateConnections.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateConnection"

UpdateSubnet

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateSubnet
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.subnets.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateSubnet"

UpdateVmwareEngineNetwork

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateVmwareEngineNetwork
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.vmwareEngineNetworks.update - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作长时间运行的操作
  • 此方法的过滤条件 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateVmwareEngineNetwork"

google.iam.v1.IAMPolicy

以下审核日志与属于 google.iam.v1.IAMPolicy 的方法相关联。

GetIamPolicy

  • 方法GetIamPolicy
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.clusters.getIamPolicy - ADMIN_READ
    • vmwareengine.hcxActivationKeys.getIamPolicy - ADMIN_READ
    • vmwareengine.privateClouds.getIamPolicy - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="GetIamPolicy"

SetIamPolicy

  • 方法SetIamPolicy
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.clusters.setIamPolicy - ADMIN_WRITE
    • vmwareengine.hcxActivationKeys.setIamPolicy - ADMIN_WRITE
    • vmwareengine.privateClouds.setIamPolicy - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="SetIamPolicy"

google.longrunning.Operations

以下审核日志与属于 google.longrunning.Operations 的方法相关联。

DeleteOperation

  • 方法google.longrunning.Operations.DeleteOperation
  • 审核日志类型管理员活动
  • 权限
    • vmwareengine.operations.delete - ADMIN_WRITE
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.longrunning.Operations.DeleteOperation"

GetOperation

  • 方法google.longrunning.Operations.GetOperation
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.operations.get - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.longrunning.Operations.GetOperation"

ListOperations

  • 方法google.longrunning.Operations.ListOperations
  • 审核日志类型数据访问
  • 权限
    • vmwareengine.operations.list - ADMIN_READ
  • 方法是长时间运行的操作或流式传输操作:否。
  • 此方法的过滤条件 protoPayload.methodName="google.longrunning.Operations.ListOperations"

系统事件

系统事件审核日志是 GCP 系统生成的,而不是通过直接用户操作生成的。如需了解详情,请参阅系统事件审核日志

方法名称 过滤此事件 备注
system.privateCloud.addNodes protoPayload.methodName="system.privateCloud.addNodes"

不会生成审核日志的方法

由于以下一个或多个原因,方法可能不会生成审核日志:

  • 这是一种高容量方法,涉及较高的日志生成和存储费用。
  • 它的审核价值较低。
  • 其他审核或平台日志已提供方法。

以下方法不会生成审核日志:

  • google.cloud.location.Locations.GetLocation
  • google.cloud.location.Locations.ListLocations
  • google.longrunning.Operations.WaitOperation