Closed JenRed777 closed 2 years ago
Heads up @daxmc99 @JenRed777 @danieldides - the "team/devops" label was applied to this issue.
@JenRed777 should this be included in handbook?
How and where are logs stored - documented in excel.
Note: example for CloudSQL instance connect action via GCP web console.
resource.type="cloudsql_database"
activity
or type: log_name="projects/sourcegraph-dev/logs/cloudaudit.googleapis.com%2Factivity"
resource.labels.database_id="sourcegraph-dev:sg-cloud-732a936743"
protoPayload.methodName="cloudsql.instances.connect"
Note: if particular actions has to be found, please use PG audit log operation types@JenRed777 created document
Needs managed instance portion added
Syncing with @sourcegraph/security to see if we can couple this with their current managed instance work
Asked @ferozsalam a few questions in slack to complete the document How long are the logs stored for? What GCP bucket are they being sent to? Are they stored int he same GCP project as the sourcegrpah.com GCP audit logs?
Hey @JenRed777 - have replied on Slack!
This one is complete
Due: February 1, 2022 Sourcegraph uses a logging tool to log, continuously monitor, and retain account activity related to user actions throughout the production environment. Logs are stored encrypted and access to logs is restricted to those who require access to perform their job duties.
Provide a walkthrough of how to view logs. Cloud: "How can I see if a user deleted the production database" Managed Instance: "How can I see if a user deleted the production database"