Change log for GCP_CLOUDAUDIT

Date Changes
2026-07-24
2026-07-14 - additional.fields[key]: Newly mapped labels object raw log fields with additional.fields[key] UDM field.
Buganizer Ids: 532168995, 532459475, 533307191
- target.resource.attribute.labels: Newly mapped protoPayload.request.bucket.retentionDays raw log field with target.resource.attribute.labels[req_bucket_retention_days] UDM field.
- target.ip: Newly mapped protoPayload.response.items raw log field with target.ip UDM field.
- metadata.event_type: Enhance event validation logic that uses the principal.user.userid UDM field in validation.
2026-06-30 - Added mappings below for google.cloud.chronicle.v1alpha.RuleService.ModifyRules MethodName:
- security_result.detection_fields[req_requests_%{index}_update_mask]: Newly mapped protoPayload.request.requests.updateMask raw log field with security_result.detection_fields[req_requests_%{index}_update_mask] UDM field.
- security_result.rule_labels[req_requests_%{index}_rule_live_mode_enabled]: Newly mapped protoPayload.request.requests.rule.liveModeEnabled raw log field with security_result.rule_labels[req_requests_%{index}_rule_live_mode_enabled] UDM field.
- security_result.rule_name: Newly mapped protoPayload.request.requests.rule.name raw log field with security_result.rule_name UDM field.
2026-06-05 - target.resource.attribute.labels[req_rule_text]: Newly mapped protoPayload.request.rule.text raw log field with target.resource.attribute.labels[req_rule_text] UDM field.
- target.resource.attribute.labels[res_text]: Newly mapped protoPayload.response.text raw log field with target.resource.attribute.labels[res_text] UDM field.
2026-05-14 - Added mappings below for google.cloud.chronicle.v1alpha.RuleService.UpdateRuleDeployment MethodName:
- target.resource.attribute.labels[req_rule_deployment_name]: Newly mapped protoPayload.request.ruleDeployment.name raw log field with target.resource.attribute.labels[req_rule_deployment_name] UDM field.
- target.resource.attribute.labels[req_rule_deployment_alerting]: Newly mapped protoPayload.request.ruleDeployment.alerting raw log field with target.resource.attribute.labels[req_rule_deployment_alerting] UDM field.
- target.resource.attribute.labels[res_last_alert_status_change_time]: Newly mapped protoPayload.response.lastAlertStatusChangeTime raw log field with target.resource.attribute.labels[res_last_alert_status_change_time] UDM field.
- target.resource.attribute.labels[res_enabled]: Newly mapped protoPayload.response.enabled raw log field with target.resource.attribute.labels[res_enabled] UDM field.
- target.resource.attribute.labels[res_execution_state]: Newly mapped protoPayload.response.executionState raw log field with target.resource.attribute.labels[res_execution_state] UDM field.
- target.resource.attribute.labels[res_archive_time]: Newly mapped protoPayload.response.archiveTime raw log field with target.resource.attribute.labels[res_archive_time] UDM field.
- target.resource.attribute.labels[res_archived]: Newly mapped protoPayload.response.archived raw log field with target.resource.attribute.labels[res_archived] UDM field.
- Added mappings below for google.cloud.resourcemanager.v3.TagBindings.CreateTagBinding MethodName:
- target.resource.attribute.labels[res_tag_value_namespaced_name]: Newly mapped protoPayload.response.tagValueNamespacedName raw log field with target.resource.attribute.labels[res_tag_value_namespaced_name] UDM field.
2026-04-02 - Added mappings below for google.cloud.chronicle.v1alpha.CuratedRuleService.BatchUpdateCuratedRuleSetDeployments MethodName:
- target.resource.attribute.labels: Newly mapped protoPayload.request.requests.curatedRuleSetDeployment.enabled raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.requests.curatedRuleSetDeployment.precision raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.requests.curatedRuleSetDeployment.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.requests.curatedRuleSetDeployment.alerting raw log field with target.resource.attribute.labels UDM field.
- Added mappings below for beta.compute.instances.insert MethodName:
- target.resource.attribute.labels: Newly mapped protoPayload.request.networkInterfaces.nicType raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.networkInterfaces.network raw log field with target.resource.attribute.labels UDM field.
- target.ip: Newly mapped protoPayload.request.networkInterfaces.networkIP raw log field with target.ip UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.networkInterfaces.networkAttachment raw log field with target.resource.attribute.labels UDM field.
2026-01-22 - Optimize the mapping pattern to reduce the configuration file size.
- target.resource.attribute.labels: Updated key from oauth_client_id to metadata_oauth_client_id for raw log field protoPayload.metadata.oauth_client_id.
- target.resource.attribute.labels: Updated key from req_spec_username to request_spec_user for raw log field protoPayload.request.spec.user.
- target.resource.attribute.labels: Updated key from request_constraint to request_policy_boolean_policy_constraint for raw log field protoPayload.request.policy.booleanPolicy.enforced.
- target.resource.attribute.labels: Updated key from cls_name to resource_labels_cluster_name for raw log field resource.labels.cluster_name.
- target.resource.attribute.labels: Updated key from email_id to resource_email_id for raw log field resource.email_id.
- target.resource.attribute.labels: Updated key from email_id to resource_labels_email_id for raw log field resource.labels.email_id.
- target.resource.attribute.labels: Updated key from imagepolicywebhook.image-policy.k8s.io/dry-run to imagepolicywebhook_image_policy_k8s_io_dry_run for raw log field labels.imagepolicywebhook.image-policy.k8s.io/dry-run.
- target.resource.attribute.labels: Updated key from request.metadata.name to request_metadata_name for raw log field protoPayload.request.metadata.name.
- target.resource.attribute.labels: Updated key from Denied Protocol to Denied_Protocol for raw log field protoPayload.request.denieds.0.IPProtocol.
- target.resource.attribute.labels: Updated key from Request Priority to Request_Priority for raw log field protoPayload.request.priority.
- target.resource.attribute.labels: Updated key from request apiVersion to request_apiVersion for raw log field protoPayload.request.apiVersion.
- target.resource.attribute.labels: Updated key from Request Network to Request_Network for raw log field protoPayload.request.network.
- additional.fields: Updated key from req_page_size to request_page_size for raw log field request.pagesize.
- target.resource.attribute.labels: Removed duplicate key mappings within the labels block to improve parser efficiency and maintainability.
2025-12-15 - principal.ip: Removed mapping of httpRequest.serverIp from principal.ip UDM field and mapped httpRequest.remoteIp instead.
- principal.asset.ip: Removed mapping of httpRequest.serverIp from principal.asset.ip UDM field and mapped httpRequest.remoteIp instead.
- target.ip: Removed mapping of httpRequest.remoteIp from target.ip UDM field and mapped httpRequest.serverIp instead.
- target.asset.ip: Removed mapping of httpRequest.remoteIp from target.asset.ip UDM field and mapped httpRequest.serverIp instead.
2025-11-05 Added support for kubernetes API resources as part of GCP Cloudaudit parser update.
2025-09-05 principal.namespace: Removed mapping of protoPayload.request.metadata.namespace from principal.namespace UDM field and mapped to security_result.about.namespace in order to prevent the feed namespace from being overwritten by the prebuilt parser.
2025-08-28 Handled edge case for raw log field protoPayload.request.disks[].mode for event v1.compute.instances.startWithEncryptionKey.
2025-07-29 Improve validation logic to handle protoPayload.request.cluster when it appears as either an object or a string.
2025-05-05 Renamed incorrectly labeled variable used for populating about.resource.name.
2025-04-28 - target.resource_ancestors.attribute.labels: Newly mapped protoPayload.response.spec.template.spec.containers.securityContext.runAsUser raw log field with target.resource_ancestors.attribute.labels UDM field
2025-04-11 - target.resource.attribute.labels: Newly mapped protoPayload.request.metadata.generateName raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.metadata.annotations raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.metadata.labels raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.rules.host raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.rules.http.paths.path raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.rules.http.paths.pathType raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.rules.http.paths.backend.service.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.rules.http.paths.backend.service.port.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.rules.http.paths.backend.service.port.number raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.rules.http.paths.backend.resource.kind raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.rules.http.paths.backend.resource.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.rules.http.paths.backend.resource.apiGroup raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.rules.http.paths.backend.serviceName raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.rules.http.paths.backend.servicePort raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.status.loadBalancer.ingress.hostname raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.status.loadBalancer.ingress.ports.port raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.status.loadBalancer.ingress.ports.protocol raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.status.loadBalancer.ingress.ports.error raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.backend.serviceName raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.backend.servicePort raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.defaultBackend.service.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.defaultBackend.service.port.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.defaultBackend.service.port.number raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.defaultBackend.resource.kind raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.defaultBackend.resource.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.defaultBackend.resource.apiGroup raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.ingressClassName raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.tls.hosts raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.metadata.generateName raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.metadata.annotations raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.metadata.labels raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.rules.host raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.rules.http.paths.path raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.rules.http.paths.pathType raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.rules.http.paths.backend.service.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.rules.http.paths.backend.service.port.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.rules.http.paths.backend.service.port.number raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.rules.http.paths.backend.resource.kind raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.rules.http.paths.backend.resource.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.rules.http.paths.backend.resource.apiGroup raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.rules.http.paths.backend.serviceName raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.rules.http.paths.backend.servicePort raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.status.loadBalancer.ingress.hostname raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.status.loadBalancer.ingress.ports.port raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.status.loadBalancer.ingress.ports.protocol raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.status.loadBalancer.ingress.ports.error raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.backend.serviceName raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.backend.servicePort raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.defaultBackend.service.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.defaultBackend.service.port.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.defaultBackend.service.port.number raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.defaultBackend.resource.kind raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.defaultBackend.resource.name raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.defaultBackend.resource.apiGroup raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.ingressClassName raw log field with target.resource.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.tls.hosts raw log field with target.resource.attribute.labels UDM field.
- security_result.detection_fields: Newly mapped protoPayload.request.spec.tls.secretName raw log field with security_result.detection_fields UDM field.
- security_result.detection_fields: Newly mapped protoPayload.request.data.tls.crt raw log field with security_result.detection_fields UDM field.
- security_result.detection_fields: Newly mapped protoPayload.request.data.tls.key raw log field with security_result.detection_fields UDM field.
- security_result.detection_fields: Newly mapped protoPayload.response.spec.tls.secretName raw log field with security_result.detection_fields UDM field.
- security_result.detection_fields: Newly mapped protoPayload.response.data.tls.crt raw log field with security_result.detection_fields UDM field.
- security_result.detection_fields: Newly mapped protoPayload.response.data.tls.key raw log field with security_result.detection_fields UDM field.
- target.ip: Newly mapped protoPayload.request.status.loadBalancer.ingress.ip raw log field with target.ip UDM field.
- target.ip: Newly mapped protoPayload.response.status.loadBalancer.ingress.ip raw log field with target.ip UDM field.
- target.resource_ancestors.name: Newly mapped protoPayload.request.spec.containers.name raw log field with target.resource_ancestors.name UDM field.
- target.resource_ancestors.name: Newly mapped protoPayload.response.spec.containers.name raw log field with target.resource_ancestors.name UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.containers.image raw log field with target.resource_ancestors.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.containers.image raw log field with target.resource_ancestors.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.request.spec.containers.ports.containerPort raw log field with target.resource_ancestors.attribute.labels UDM field.
- target.resource.attribute.labels: Newly mapped protoPayload.response.spec.containers.ports.containerPort raw log field with target.resource_ancestors.attribute.labels UDM field.
2025-03-11 - additional.fields[validate_only]: Newly mapped protoPayload.request.validateOnly raw log field with additional.fields[validate_only] UDM field.
2025-01-27 - Added mapping for the raw log field protoPayload.request.spec.template.spec.containers.securityContext.runAsUser to target.resource.attribute.labels[req_spec_template_spec_containers_securitycontext_run_as_user] UDM field.
2024-12-16 - Added mapping for the raw log fields protoPayload.request.serialConsoleOptions, protoPayload.request.username and protoPayload.response.duration
2024-12-13 - Removed mapping of callerIp raw log field from principal.hostname and principal.asset.hostname UDM field.
2024-10-15 - Added mapping for these fields: protoPayload.metadata.jobInsertion.reason, protoPayload.metadata.jobInsertion.job.jobConfig.queryConfig.statementType and protoPayload.metadata.jobInsertion.job.jobStatus.jobState
- Added support for the raw log fields protoPayload.response.state and protoPayload.request.metadata.state.
2024-10-11 - Added support for the raw log fields under protoPayload.metadata.jobChange and protoPayload.metadata.jobInsertion objects.
2024-10-01 - Set metadata.event_type UDM field as USER_LOGIN if the value of protoPayload.request.cmd raw field is connect.
2024-09-17 - Updated mapping of metadata.event_type UDM field.
2024-09-13 - Updated the GCP_CLOUDAUDIT Gold parser to update mandatory UDM field for event_type USER_UNCATEGORIZED.
2024-09-03 - Added mapping for protoPayload.request.spec.template.spec.shareProcessNamespace log field.
- Added mapping for protoPayload.response.spec.type log field.
- Updated the logic of target.resource.resource_type UDM field.
- Extracted and mapped organization ids.
- Added mapping for protoPayload.metadata.event.parameter.boolValue log field.
- Added mapping for protoPayload.response.vulnerability.shortDescription, protoPayload.response.vulnerability.effectiveSeverity and protoPayload.response.resourceUri log fields.
2024-08-30 - Added mapping for protoPayload.request.permissions raw log field.
2024-08-14 - Added mapping for protoPayload.response.roleRef.name raw log field.
- Added mapping for protoPayload.authorizationInfo.permissionType raw log field.
- Set the security_result.action as BLOCK for every error blob.
- Added mapping for protoPayload.metadata.instanceMetadataDelta.addedMetadataKeys raw log field.
- Added mapping for protoPayload.authenticationInfo.serviceAccountDelegationInfo.firstPartyPrincipal.principalEmail raw log field.
2024-07-19 - Updated mapping for security_result.action based on the protoPayload.response.status log field.
- Added mapping for protoPayload.response.reason log field.
- Update mapping for protoPayload.response.code log field.
- Removed mapping of protoPayload.metadata.event raw log field form target.resource_ancestors.
- Updated mapping for metadata.description based on the protoPayload.status.message log field.
- Updated mapping for protoPayload.request.policy.bindings.members raw log field.
2024-07-03 - Mapped protoPayload.response.bindings to additional.fields.
- Mapped protoPayload.request.bindings to additional.fields.
2024-06-20 - Added mappings for the following fields:
- protoPayload.request.projection
- protoPayload.response.items.metageneration
- protoPayload.response.items.labels.created_date
- protoPayload.response.items.labels.team_email
- protoPayload.response.items.labels.team_name
- protoPayload.response.items.labels.office_number
- protoPayload.response.items.labels.department
- protoPayload.response.items.labels.business_project_number
- protoPayload.response.items.labels.owner_email
- protoPayload.response.items.labels.purchase_order_number
- protoPayload.response.items.labels.office_name
- protoPayload.response.items.labels.environment
- protoPayload.response.items.labels.created_by
- protoPayload.response.items.labels.project_name
- protoPayload.response.items.labels.finops_tag
- protoPayload.response.items.labels.owner_role
- protoPayload.response.items.versioning.enabled
- protoPayload.response.items.iamConfiguration.publicAccessPrevention
- protoPayload.response.items.iamConfiguration.uniformBucketLevelAccess.lockedTime
- protoPayload.response.items.iamConfiguration.uniformBucketLevelAccess.enabled
- protoPayload.response.items.id
- protoPayload.response.items.updated
- protoPayload.response.items.storageClass
- protoPayload.response.items.timeCreated
- protoPayload.response.items.location
- protoPayload.response.items.locationType
- protoPayload.response.items.projectNumber
- protoPayload.response.items.name
- protoPayload.response.items.softDeletePolicy.effectiveTime
- protoPayload.response.items.softDeletePolicy.retentionDurationSeconds
- protoPayload.response.items.etag
2024-06-19 - Added mappings for the following raw log fields: protoPayload.response.displayName, protoPayload.request.referenceList.displayName.
- Extracted values from the following raw log fields: protoPayload.authenticationInfo.principalSubject, protoPayload.resourceName.
2024-05-29 - Removed mapping of the protoPayload.authenticationInfo.principalEmail raw log field from the target.user.userid UDM field.
- Updated the Grok pattern to support multiple values of the protoPayload.metadata.membershipDelta.member raw log field.
- Added mappings of the protoPayload.metadata.updatedGrant.state, protoPayload.metadata.updatedGrant.privilegedAccess.gcpIamAccess.resource,
protoPayload.metadata.updatedGrant.privilegedAccess.gcpIamAccess.resourceType, protoPayload.metadata.updatedGrant.privilegedAccess.gcpIamAccess.roleBindings.role,
protoPayload.metadata.updatedGrant.justification.unstructuredJustification, protoPayload.metadata.updatedGrant.requestedDuration,
protoPayload.metadata.updatedGrant.requester, protoPayload.metadata.jobInsertion.job.jobConfig.labels.looker_studio_report_id,
protoPayload.metadata.jobInsertion.job.jobConfig.labels.requestor and protoPayload.metadata.jobInsertion.job.jobConfig.labels.looker_studio_datasource_id" raw log fields.
2024-05-22 - Added mappings for the following fields: protoPayload.metadata.tableChange.table.policy.bindings.members, protoPayload.metadata.datasetChange.dataset.acl.policy.bindings.members, protoPayload.request.bindings.members, protoPayload.metadata.tableChange.bindingDeltas.member
2024-05-15 - Added mapping for fields: protoPayload.metadata.jobChange.job.jobConfig.labels.looker_studio_report_id, protoPayload.metadata.jobChange.job.jobConfig.labels.requestor and protoPayload.metadata.jobChange.job.jobConfig.labels.looker_studio_datasource_id
2024-05-01 - Added a mapping for the protoPayload.response.serviceConfig.timeoutSeconds raw log field.
2024-04-24 - Added mapping for fields: protoPayload.serviceData.jobCompletedEvent.job.jobConfiguration.labels.requestor, protoPayload.serviceData.jobCompletedEvent.job.jobConfiguration.labels.looker_studio_datasource_id, protoPayload.serviceData.jobCompletedEvent.job.jobConfiguration.labels.looker_studio_report_id and protoPayload.metadata.jobChange.job.jobConfig.queryConfig.query.
- Added support for protoPayload.response.overrideValue and protoPayload.request.override.overrideValue log fields.
2024-04-17 - Add mapping for protoPayload.request.timestampRange,
protoPayload.request.regexSearch, protoPayload.request.productSources,
protoPayload.request.query, protoPayload.request.caseSensitive raw log fields.
2024-03-27 - Handled the jumpcloud function audit logs in the parser.
2024-03-06 - Added mapping of protoPayload.request.New Data and protoPayload.request.Original Data raw log fields.
- Added mapping for fields of protoPayload.request.service.metadata.annotations and protoPayload.request.service.spec.template.metadata.annotations object.
- Added mapping for fields of protoPayload.response.spec.template object.
2024-02-28 - Added mapping of protoPayload.request.metadata.resourceVersion raw log field.
- Change mapping of protoPayload.metadata.projectMetadataDelta and protoPayload.request.action raw log field.
2024-01-31 - Added additional field mapping for GroupsService.UpdateGroup MethodName.
2024-01-17 - Added mapping of protoPayload.metadata.datasetChange.bindingDeltas raw log field block.
- Added additional field mapping of io.k8s.certificates.v1.certificatesigningrequest, UpdateCryptoKeyVersion, google.cloud.orgpolicy.v2.OrgPolicy.DeletePolicy, UpdateEventThreatDetectionSettings, SetIamPolicy and beta.compute.images.setIamPolicy MethodName.
- Removed duplicate mapping of security_result.action UDM field.
2023-12-13 - Changed mapping of target.application UDM field for Kubernetes Engine events.
2023-11-29 - Added mapping of securityContext.capabilities.add, securityContext.seccompProfile.type and spec.Containers.shareProcessNamespace raw log fields.
- Added mapping of membershipDelta raw log block.
- Added support of SelfSubjectAccessReviews MethodName.
- Added mappings of the raw log fields which were mapped to the deprecated field noun.labels.
2023-11-09 - Added mapping of request.roleRef.name log field.
- Added support for the clusterroles.create MethodName.
- Added support for the daemonsets.create MethodName.
- Align principal/target.hostname and principal/target.asset.hostname mapping.
2023-10-18 - Added mapping of labels.imagepolicywebhook.image-policy.k8s.io/dry-run log field.
2023-08-28 - Updated metadata.event_type for DisableServiceAccount and EnableServiceAccount MethodName.
2023-07-26 - Updated metadata.event_type for v1.compute.disks.insert MethodName.
- Updated mapping of protoPayload.status.code log field.
2023-07-12 Added support for the io.k8s.batch.v1.jobs.create MethodName.
2023-06-14 Updated the parser to include parse_network_http_user_agent to use Parsed User Agent and User Agent.
2023-05-02 Added mapping for protoPayload.request.action log field of
methodName v1.compute.securityPolicies.patchRule and set value of
security_result.action UDM field based on the protoPayload.request.action
log field.
2023-04-12 Promoted GCP_CLOUDAUDIT parser to default.
For the field mapping reference, see https://cloud.google.com/chronicle/docs/ingestion/default-parsers/collect-audit-logs#field-mapping.