Lakehouse for Apache Iceberg supports Cloud Audit Logs for the Apache Iceberg REST catalog endpoint within the Lakehouse runtime catalog.
The Google Cloud console provides a record of administrative activities. These logs track operation lifecycle events, policy updates, and authentication changes.
Before you begin
-
Verify that billing is enabled for your Google Cloud project.
-
Enable the BigLake API.
Roles required to enable APIs
To enable APIs, you need the Service Usage Admin IAM role (
roles/serviceusage.serviceUsageAdmin), which contains theserviceusage.services.enablepermission. Learn how to grant roles.
Required roles
To get the permissions that you need to view audit logs in the Google Cloud console, ask your administrator to grant you the following IAM roles on your project:
- BigLake Admin (
roles/biglake.admin) - Storage Admin (
roles/storage.admin)
For more information about granting roles, see Manage access to projects, folders, and organizations.
You might also be able to get the required permissions through custom roles or other predefined roles.
View audit logs
In the Google Cloud console, open the Lakehouse page.
In the row of the catalog that you're viewing, click More catalog actions > View audit logs.