Cloud Logging으로 Gemini Enterprise 사용량 감사 로그 액세스

이 페이지에서는 Gemini Enterprise의 사용 감사 로그를 설정하고 액세스하는 방법을 설명합니다.

주요 개념

이 섹션에서는 Gemini Enterprise의 관측 가능성과 관련된 주요 개념을 소개합니다.

개념 설명
사용 감사 로그 사용 감사 로그는 Google Cloud 리소스 내의 관리 활동 및 액세스를 기록한 것입니다. 이러한 로그는 누가 언제 어디에서 어떤 작업을 수행했는지에 관한 자세한 정보를 제공합니다. 이러한 로그는 보안 감사, 규정 준수, 리소스 사용 방식을 이해하는 데 필수적입니다.

시작하기 전에

감사 로그를 구성하기 전에 다음 사항을 확인하세요.

  • 관측 가능성 설정을 사용 설정합니다. 자세한 내용은 관측 가능성 설정 사용 설정하기를 참고하세요.
  • 감사 로깅을 사용 설정하려면 Gemini Enterprise 관리자 IAM 역할 (roles/discoveryengine.agentspaceAdmin)이 있어야 합니다.
  • Cloud Logging에 액세스하려면 로그 뷰어 IAM 역할 (roles/logging.viewer)이 있어야 합니다.
  • Gemini Enterprise 앱을 만들었는지 확인합니다. 앱을 만들려면 앱 만들기를 참고하세요.

로깅되는 정보

다음 표에는 Gemini Enterprise에서 로깅한 사용 데이터가 요약되어 있습니다. 각 필드에는 다음과 같은 라벨이 지정됩니다.

  • 민감함: 필드에 프롬프트, 대답 또는 기타 고객 콘텐츠가 포함될 수 있습니다. 프롬프트 입력 및 대답 출력 로깅 사용 설정 설정이 사용 설정된 경우에만 로깅됩니다. 이 설정이 사용 중지되면 텍스트 값이 <elided>로 대체되고 다른 값은 생략됩니다. 자세한 내용은 관측 가능성 설정 사용 설정하기를 참고하세요.
  • 민감하지 않음: 설정이 사용 설정되어 있는지 여부에 관계없이 필드가 기록됩니다.
  • 부분적으로 민감함: 나열된 하위 필드만 민감합니다. 다른 모든 하위 필드는 민감하지 않습니다.
서비스 경로 로깅된 데이터
SearchService.Search

그라운딩에 사용된 소스 또는 LLM 입력으로 사용된 소스의 데이터를 로깅합니다.

요청:
  • query (민감함)
  • user_info (부분적으로 민감함) 다음 하위 필드만 민감합니다.
    • time_zone
    • precise_location

대답:
  • attribution_token (민감하지 않음)
  • results.id (민감하지 않음)
AssistantService.Assist

Gemini Enterprise 어시스턴트의 요청과 응답을 로깅합니다.

요청:
  • name (민감하지 않음)
  • query.text (민감함)
  • query.parts (민감함)

대답:
  • assist_token (민감하지 않음)
  • answer.name (민감하지 않음)
  • answer.state (민감하지 않음)
  • answer.replies.grounded_content.text (민감함)
  • answer.replies.grounded_content.text_grounding_metadata.segments (민감함)
  • answer.replies.grounded_content.text_grounding_metadata.references (부분적으로 민감함) document_metadata.document 및 document_metadata.uri을 제외한 모든 하위 필드는 민감합니다.
  • answer.skipped_reasons (민감하지 않음)
  • agent_info.agent (민감하지 않음)
  • agent_info.display_name (민감함)
  • agent_info.core_assistant (민감하지 않음)
  • agent_info.agent_kind (민감하지 않음)
  • agent_info.spiffe_id (민감하지 않음)
AssistantService.StreamAssist 요청:
  • name (민감하지 않음)
  • query.text (민감함)
  • query.parts (민감함)
  • agents_spec (부분적으로 민감함) 다음 하위 필드만 민감합니다.
    • agent_specs.input_variables
    • agent_specs.node_context.node_input
    • agent_specs.node_context.agent_description
    • agent_specs.node_context.node_instruction
    • agent_specs.artifact_spec.tagged_artifact_content

대답:
  • assist_token (민감하지 않음)
  • answer.name (민감하지 않음)
  • answer.state (민감하지 않음)
  • answer.replies.grounded_content.text (민감함)
  • answer.replies.grounded_content.text_grounding_metadata.segments (민감함)
  • answer.replies.grounded_content.text_grounding_metadata.references (부분적으로 민감함) document_metadata.document 및 document_metadata.uri을 제외한 모든 하위 필드는 민감합니다.
  • answer.skipped_reasons (민감하지 않음)
  • agent_info.agent (민감하지 않음)
  • agent_info.display_name (민감함)
  • agent_info.core_assistant (민감하지 않음)
  • agent_info.agent_kind (민감하지 않음)
  • agent_info.spiffe_id (민감하지 않음)
  • model_info.model (민감하지 않음)
  • model_info.requested_model (민감하지 않음)
  • model_info.model_selection_mode (민감하지 않음)

model_info.model은 어시스턴트가 해당 턴에 실행한 모델입니다. 요청에서 모델을 고정하지 않으면 model_selection_mode는 MODEL_SELECTION_MODE_AUTO이고 requested_model는 비어 있습니다. 요청에서 모델을 고정하면 model_selection_mode는 MODEL_SELECTION_MODE_EXPLICIT이고 requested_model에는 요청된 모델이 포함됩니다.

턴은 다른 모델을 실행하는 전문 에이전트에게 핸드오프할 수 있습니다. model_info.model는 에이전트의 모델을 보고하지 않으며, 이러한 에이전트에서 모든 작업을 수행하는 턴은 model_info.model를 비워 둡니다.

ConversationSearchService.AnswerQuery 요청:
  • serving_config (민감하지 않음)
  • query.query_id (민감하지 않음)
  • query.text (민감함)
  • session (민감하지 않음)
  • user_pseudo_id (민감하지 않음)
  • end_user_spec (부분적으로 민감함) 다음 하위 필드만 민감합니다.
    • end_user_metadata.chunk_info.content
    • end_user_metadata.chunk_info.document_metadata.title
  • answer_generation_spec.model_spec.model_version (민감하지 않음)
  • answer_generation_spec.prompt_spec.preamble (민감함)
  • answer_generation_spec.include_citations (민감하지 않음)
  • answer_generation_spec.answer_language_code (민감함)
  • answer_generation_spec.ignore_adversarial_query (민감하지 않음)
  • answer_generation_spec.ignore_non_answer_seeking_query (민감하지 않음)
  • answer_generation_spec.ignore_jail_breaking_query (민감하지 않음)

대답:
  • answer (부분적으로 민감함) 다음 하위 필드만 민감합니다.
    • answer_text
    • grounding_supports
    • references
    • blob_attachments
    • steps.actions
  • answer_query_token (민감하지 않음)
EngineService.CreateEngine 요청:
  • engine_id (민감하지 않음)
  • engine.name (민감하지 않음)
  • engine.create_time (민감하지 않음)
  • engine.display_name (민감하지 않음)
  • engine.update_time (민감하지 않음)
  • engine.data_store_ids (민감하지 않음)
  • engine.data_stores (민감하지 않음)

대답:
  • engine_id (민감하지 않음)
  • engine.name (민감하지 않음)
  • engine.create_time (민감하지 않음)
  • engine.display_name (민감하지 않음)
  • engine.update_time (민감하지 않음)
  • engine.data_store_ids (민감하지 않음)
  • engine.data_stores (민감하지 않음)
EngineService.UpdateEngine 요청:
  • engine.name (민감하지 않음)
  • engine.create_time (민감하지 않음)
  • engine.display_name (민감하지 않음)
  • engine.update_time (민감하지 않음)
  • engine.data_store_ids (민감하지 않음)
  • engine.data_stores (민감하지 않음)
  • update_mask (민감하지 않음)

대답:
  • engine.name (민감하지 않음)
  • engine.create_time (민감하지 않음)
  • engine.display_name (민감하지 않음)
  • engine.update_time (민감하지 않음)
  • engine.data_store_ids (민감하지 않음)
  • engine.data_stores (민감하지 않음)
AgentService.SetIamPolicy 요청:
  • policy.bindings.roles (민감하지 않음)
  • policy.bindings.members (민감하지 않음)

대답:
  • policy.bindings.roles (민감하지 않음)
  • policy.bindings.members (민감하지 않음)
AgentService.CreateAgent 요청:
  • parent (민감하지 않음)
  • agent_id (민감하지 않음)
  • agent.name (민감하지 않음)
  • agent.display_name (민감함)
  • agent.create_time (민감하지 않음)
  • agent.update_time (민감하지 않음)
  • agent.definition_case (민감하지 않음)

대답:
  • agent.name (민감하지 않음)
  • agent.display_name (민감함)
  • agent.create_time (민감하지 않음)
  • agent.update_time (민감하지 않음)
  • agent.definition_case (민감하지 않음)
AgentService.UpdateAgent 요청:
  • agent.name (민감하지 않음)
  • agent.display_name (민감함)
  • agent.create_time (민감하지 않음)
  • agent.update_time (민감하지 않음)
  • agent.definition_case (민감하지 않음)
  • update_mask (민감하지 않음)

대답:
  • agent.name (민감하지 않음)
  • agent.display_name (민감함)
  • agent.create_time (민감하지 않음)
  • agent.update_time (민감하지 않음)
  • agent.definition_case (민감하지 않음)
AgentService.DeleteAgent 요청:
  • name (민감하지 않음)

대답:
  • 필드가 로깅되지 않음
GroundedGenerationService.GenerateGroundedContent 요청:
  • contents (민감함)
  • location (민감하지 않음)
  • generation_spec (부분적으로 민감함) 다음 하위 필드만 민감합니다.
    • language_code
  • system_instruction (민감함)
  • safety_settings (민감하지 않음)
  • user_labels (민감함)
  • grounding_spec.explicit_search_queries (민감함)
  • grounding_spec.grounding_sources (부분적으로 민감함) 다음 하위 필드만 민감합니다.
    • inline_source
    • search_source.filter
    • api_source.manifest.api_spec.open_api_yaml
    • elastic_source.search_template
    • elastic_source.num_hits
    • parallel_ai_source.custom_configs
    • exa_ai_source.custom_configs

대답:
  • content (민감함)
  • grounding_metadata (부분적으로 민감함) 다음 하위 필드만 민감합니다.
    • support_chunks(source 및 index 제외)
    • google_maps_support_chunks(source 및 index 제외)
    • api_calls.request_payload
    • api_calls.response_body
    • api_calls.uri
  • grounding_score (민감하지 않음)
DataConnectorService.UpdateDataConnector 요청:
  • data_connector.name (민감하지 않음)
  • data_connector.create_time (민감하지 않음)
  • data_connector.update_time (민감하지 않음)
  • data_connector.data_source (민감하지 않음)
  • data_connector.refresh_interval (민감하지 않음)
  • data_connector.bap_config (민감하지 않음)

대답:
  • data_connector.name (민감하지 않음)
  • data_connector.create_time (민감하지 않음)
  • data_connector.update_time (민감하지 않음)
  • data_connector.data_source (민감하지 않음)
  • data_connector.refresh_interval (민감하지 않음)
  • data_connector.bap_config (민감하지 않음)
AssistantService.AddContextFile 요청:
  • name (민감하지 않음)
  • file_name (민감함)

대답:
  • session (민감하지 않음)
  • file_id (민감하지 않음)
AssistantService.UploadSessionFile 요청:
  • name (민감하지 않음)
  • blob.filename (민감함)

대답:
  • file_id (민감하지 않음)
UserEventService.WriteUserEvent 요청:
  • 요청 본문의 모든 필드 (부분적으로 민감함) 다음 하위 필드만 민감합니다.
    • user_event.user_info.time_zone
    • user_event.user_info.precise_location
    • user_event.filter
    • user_event.attributes
    • user_event.panel.documents
    • user_event.panels.documents
    • user_event.search_info.search_query
    • user_event.completion_info.selected_suggestion
    • user_event.feedback.comment
    • user_event.feedback.conversation_info.query

대답:
  • 필드가 로깅되지 않음

사용 감사 로그 액세스

모든 Gemini Enterprise 사용 감사 로그에 액세스하고 이를 보려면 다음 단계를 따르세요.

  1. Google Cloud 콘솔에서 로그 탐색기 페이지로 이동합니다.

    로그 탐색기로 이동

  2. 감사 로깅을 사용 설정한 Google Cloud 프로젝트를 선택합니다.

  3. Gemini Enterprise 로그만 표시하려면 쿼리 편집기 필드에 다음 쿼리를 입력하고 쿼리 실행을 클릭합니다.

      logName="projects/PROJECT_ID/logs/discoveryengine.googleapis.com%2Fgemini_enterprise_user_activity" OR logName=~"projects/PROJECT_ID/logs/discoveryengine.googleapis.com%2Fgen_ai.*"
    

    다음을 바꿉니다.

    • PROJECT_ID: 프로젝트의 ID입니다.

로그 액세스 제어

Cloud Logging에서 로그에 대한 액세스를 제어할 수 있습니다. 세분화된 액세스를 위해 IAM 조건을 사용하는 등 액세스 제어 방법에 관한 자세한 안내는 IAM으로 액세스 제어를 참고하세요.

기본 액세스 제어

기본적으로 Gemini Enterprise는 Cloud Logging 데이터를 _Default 버킷으로 전송합니다. 다음 IAM 역할은 이 버킷에 대한 액세스를 제어합니다.

세분화된 액세스 제어

프로젝트에 민감도 수준이 다양한 로그가 포함된 경우 여러 Google Cloud 및 Cloud Logging 도구를 사용하여 더 세부적인 액세스 제어를 구성할 수 있습니다.

다음 옵션을 사용하여 세분화된 액세스 제어를 구성할 수 있습니다.

옵션 설명
IAM 조건 IAM 조건을 사용하여 세분화된 액세스 제어를 설정합니다. 자세한 내용은 Logging 역할을 참고하세요.
로그 뷰 로그 뷰를 사용하여 로그 버킷 내 로그의 하위 집합에 대한 사용자 액세스를 제한합니다. 자세한 내용은 로그 버킷에서 로그 뷰 구성을 참고하세요.
로그 싱크 로그 싱크를 사용하여 민감한 로그를 IAM 액세스가 더 제한적인 별도의 프로젝트로 라우팅합니다. 자세한 내용은 지원되는 대상으로 로그 라우팅을 참고하세요.
태그 태그를 사용하여 프로젝트 내 개별 로그 버킷에 대한 IAM 액세스를 관리합니다. 자세한 내용은 태그를 사용하여 로그 버킷에 대한 액세스 관리를 참고하세요.
필드 수준 액세스 제어 필드 수준 액세스 제어를 사용하여 로그 항목 내의 특정 필드를 숨기거나 액세스를 제한합니다. 자세한 내용은 필드 수준 액세스 구성을 참고하세요.

다음 단계