Lakehouse untuk Apache Iceberg memungkinkan Anda menggunakan Cloud Audit Logs untuk memeriksa catatan yang dapat diverifikasi dari aktivitas akses data dan administratif untuk endpoint katalog REST Apache Iceberg dalam katalog runtime Lakehouse.
Log ini melacak peristiwa siklus proses operasi, pembaruan kebijakan, dan perubahan autentikasi.
Sebelum memulai
- Baca Tentang katalog runtime Lakehouse untuk memahami cara kerja katalog runtime Lakehouse dan batasan untuk layanan ini.
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles. - Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API.
Roles required to enable APIs
To enable APIs, you need the Service Usage Admin IAM
role (roles/serviceusage.serviceUsageAdmin), which
contains the serviceusage.services.enable permission. Learn how to grant
roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API.
Roles required to enable APIs
To enable APIs, you need the Service Usage Admin IAM
role (roles/serviceusage.serviceUsageAdmin), which
contains the serviceusage.services.enable permission. Learn how to grant
roles.
Peran yang diperlukan
Untuk mendapatkan izin yang diperlukan untuk melihat log audit di konsol Google Cloud , minta administrator untuk memberi Anda peran IAM berikut di project Anda:
- Admin BigLake (
roles/biglake.admin) - Storage Admin (
roles/storage.admin)
Untuk mengetahui informasi selengkapnya tentang pemberian peran, lihat Mengelola akses ke project, folder, dan organisasi.
Anda mungkin juga bisa mendapatkan izin yang diperlukan melalui peran khusus atau peran bawaan lainnya.
Lihat log audit
Di konsol Google Cloud , buka halaman Lakehouse.
Di baris katalog yang Anda lihat, klik Tindakan katalog lainnya > Lihat log audit.