I have configured on GCP the following Log Router Sink
logName=("projects/elastic-sa/logs/cloudaudit.googleapis.com%2Factivity" OR "projects/elastic-sa/logs/cloudaudit.googleapis.com%2Fdata_access" OR "projects/elastic-sa/logs/cloudaudit.googleapis.com%2Fsystem_event")
((resource.type:("k8s_cluster" OR "gke_cluster") AND resource.labels.project_id="elastic-sa" )
protoPayload.methodName:("CreateCluster" OR "DeleteCluster" OR "UpdateCluster" OR "deployments.create" OR "io.k8s.core.v1.pods.delete" OR "io.k8s.core.v1.pods.create" OR "io.k8s.core.v1.pods.binding_create" OR "io.k8s.core.v1.pods.attach.create")
protoPayload.serviceName="k8s.io"
-protoPayload.resourceName:"core/v1/namespaces/gkebackup"
-protoPayload.resourceName:"core/v1/namespaces/kube-system"
-protoPayload.resourceName:"core/v1/namespaces/gmp-system")
Hello
I have configured on GCP the following Log Router Sink
This will produce for instance the following logs
"resourceName": "core/v1/namespaces/default/pods/debug4" exists
So gcp.audit.resource_name should be set to "core/v1/namespaces/default/pods/debug4" but it is left empty