Google Cloud VMware Engine 稽核記錄

本文說明 Google Cloud VMware Engine 的稽核記錄。 Google Cloud 服務會產生稽核記錄,記錄資源中的管理和存取活動。 Google Cloud 如要進一步瞭解 Cloud 稽核記錄,請參閱下列文章:

服務名稱

Google Cloud VMware Engine 稽核記錄會使用服務名稱 vmwareengine.googleapis.com。篩選這項服務:

    protoPayload.serviceName="vmwareengine.googleapis.com"
  

依權限類型劃分的方法

每個 IAM 權限都有 type 屬性,其值為列舉,可以是下列四個值之一:ADMIN_READADMIN_WRITEDATA_READDATA_WRITE。呼叫方法時,Google Cloud VMware Engine 會產生稽核記錄,記錄的類別取決於執行方法所需權限的 type 屬性。如果方法需要 IAM 權限,且 type 屬性值為 DATA_READDATA_WRITEADMIN_READ,就會產生「資料存取」稽核記錄。需要 IAM 權限且 type 屬性值為 ADMIN_WRITE 的方法,會產生管理員活動稽核記錄。

下列清單中標示 (LRO) 的 API 方法,都是長時間執行的作業 (LRO)。這些方法通常會產生兩筆稽核記錄項目:一筆是在作業開始時產生,另一筆則是在作業結束時產生。詳情請參閱長時間執行的作業的稽核記錄
權限類型 方法
ADMIN_READ google.cloud.vmwareengine.v1.VmwareEngine.FetchNetworkPolicyExternalAddresses
google.cloud.vmwareengine.v1.VmwareEngine.GetCluster
google.cloud.vmwareengine.v1.VmwareEngine.GetDnsBindPermission
google.cloud.vmwareengine.v1.VmwareEngine.GetDnsForwarding
google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAccessRule
google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAddress
google.cloud.vmwareengine.v1.VmwareEngine.GetHcxActivationKey
google.cloud.vmwareengine.v1.VmwareEngine.GetLoggingServer
google.cloud.vmwareengine.v1.VmwareEngine.GetManagementDnsZoneBinding
google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPeering
google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPolicy
google.cloud.vmwareengine.v1.VmwareEngine.GetNode
google.cloud.vmwareengine.v1.VmwareEngine.GetNodeType
google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateCloud
google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateConnection
google.cloud.vmwareengine.v1.VmwareEngine.GetSubnet
google.cloud.vmwareengine.v1.VmwareEngine.GetVmwareEngineNetwork
google.cloud.vmwareengine.v1.VmwareEngine.ListClusters
google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAccessRules
google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAddresses
google.cloud.vmwareengine.v1.VmwareEngine.ListHcxActivationKeys
google.cloud.vmwareengine.v1.VmwareEngine.ListLoggingServers
google.cloud.vmwareengine.v1.VmwareEngine.ListManagementDnsZoneBindings
google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPeerings
google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPolicies
google.cloud.vmwareengine.v1.VmwareEngine.ListNodeTypes
google.cloud.vmwareengine.v1.VmwareEngine.ListNodes
google.cloud.vmwareengine.v1.VmwareEngine.ListPeeringRoutes
google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateClouds
google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnectionPeeringRoutes
google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnections
google.cloud.vmwareengine.v1.VmwareEngine.ListSubnets
google.cloud.vmwareengine.v1.VmwareEngine.ListVmwareEngineNetworks
google.cloud.vmwareengine.v1.VmwareEngine.ShowNsxCredentials
google.cloud.vmwareengine.v1.VmwareEngine.ShowVcenterCredentials
GetIamPolicy
google.longrunning.Operations.GetOperation
google.longrunning.Operations.ListOperations
ADMIN_WRITE google.cloud.vmwareengine.v1.VmwareEngine.CreateCluster (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAccessRule (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAddress (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.CreateHcxActivationKey (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.CreateLoggingServer (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.CreateManagementDnsZoneBinding (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPeering (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPolicy (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateCloud (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateConnection (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.CreateVmwareEngineNetwork (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.DeleteCluster (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAccessRule (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAddress (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.DeleteLoggingServer (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.DeleteManagementDnsZoneBinding (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPeering (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPolicy (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateCloud (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateConnection (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.DeleteVmwareEngineNetwork (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.GrantDnsBindPermission (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.RepairManagementDnsZoneBinding
google.cloud.vmwareengine.v1.VmwareEngine.ResetNsxCredentials (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.ResetVcenterCredentials (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.RevokeDnsBindPermission (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UndeletePrivateCloud (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UpdateCluster (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UpdateDnsForwarding (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAccessRule (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAddress (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UpdateLoggingServer (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UpdateManagementDnsZoneBinding (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPeering (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPolicy (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateCloud (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateConnection (LRO)
google.cloud.vmwareengine.v1.VmwareEngine.UpdateSubnet
google.cloud.vmwareengine.v1.VmwareEngine.UpdateVmwareEngineNetwork (LRO)
SetIamPolicy
google.longrunning.Operations.DeleteOperation

API 介面稽核記錄

如要瞭解每種方法評估權限的方式和內容,請參閱 Google Cloud VMware Engine 的 Identity and Access Management 說明文件。

google.cloud.vmwareengine.v1.VmwareEngine

下列稽核記錄與屬於 google.cloud.vmwareengine.v1.VmwareEngine 的方法相關聯。

CreateCluster

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateCluster
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.clusters.create - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateCluster"

CreateExternalAccessRule

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAccessRule
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.externalAccessRules.create - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAccessRule"

CreateExternalAddress

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAddress
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.externalAddresses.create - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateExternalAddress"

CreateHcxActivationKey

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateHcxActivationKey
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.hcxActivationKeys.create - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateHcxActivationKey"

CreateLoggingServer

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateLoggingServer
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.loggingServers.create - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateLoggingServer"

CreateManagementDnsZoneBinding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateManagementDnsZoneBinding
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.managementDnsZoneBindings.create - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateManagementDnsZoneBinding"

CreateNetworkPeering

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPeering
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.networkPeerings.create - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPeering"

CreateNetworkPolicy

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPolicy
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.networkPolicies.create - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateNetworkPolicy"

CreatePrivateCloud

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateCloud
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.privateClouds.create - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateCloud"

CreatePrivateConnection

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateConnection
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.privateConnections.create - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreatePrivateConnection"

CreateVmwareEngineNetwork

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.CreateVmwareEngineNetwork
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.vmwareEngineNetworks.create - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.CreateVmwareEngineNetwork"

DeleteCluster

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteCluster
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.clusters.delete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteCluster"

DeleteExternalAccessRule

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAccessRule
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.externalAccessRules.delete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAccessRule"

DeleteExternalAddress

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAddress
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.externalAddresses.delete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteExternalAddress"

DeleteLoggingServer

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteLoggingServer
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.loggingServers.delete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteLoggingServer"

DeleteManagementDnsZoneBinding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteManagementDnsZoneBinding
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.managementDnsZoneBindings.delete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteManagementDnsZoneBinding"

DeleteNetworkPeering

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPeering
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.networkPeerings.delete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPeering"

DeleteNetworkPolicy

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPolicy
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.networkPolicies.delete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteNetworkPolicy"

DeletePrivateCloud

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateCloud
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.privateClouds.delete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateCloud"

DeletePrivateConnection

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateConnection
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.privateConnections.delete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeletePrivateConnection"

DeleteVmwareEngineNetwork

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.DeleteVmwareEngineNetwork
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.vmwareEngineNetworks.delete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.DeleteVmwareEngineNetwork"

FetchNetworkPolicyExternalAddresses

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.FetchNetworkPolicyExternalAddresses
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.networkPolicies.fetchExternalAddresses - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.FetchNetworkPolicyExternalAddresses"

GetCluster

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetCluster
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.clusters.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetCluster"

GetDnsBindPermission

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetDnsBindPermission
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.dnsBindPermission.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetDnsBindPermission"

GetDnsForwarding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetDnsForwarding
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.dnsForwarding.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetDnsForwarding"

GetExternalAccessRule

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAccessRule
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.externalAccessRules.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAccessRule"

GetExternalAddress

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAddress
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.externalAddresses.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetExternalAddress"

GetHcxActivationKey

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetHcxActivationKey
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.hcxActivationKeys.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetHcxActivationKey"

GetLoggingServer

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetLoggingServer
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.loggingServers.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetLoggingServer"

GetManagementDnsZoneBinding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetManagementDnsZoneBinding
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.managementDnsZoneBindings.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetManagementDnsZoneBinding"

GetNetworkPeering

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPeering
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.networkPeerings.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPeering"

GetNetworkPolicy

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPolicy
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.networkPolicies.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetNetworkPolicy"

GetNode

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetNode
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.nodes.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetNode"

GetNodeType

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetNodeType
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.nodeTypes.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetNodeType"

GetPrivateCloud

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateCloud
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.privateClouds.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateCloud"

GetPrivateConnection

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateConnection
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.privateConnections.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetPrivateConnection"

GetSubnet

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetSubnet
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.subnets.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetSubnet"

GetVmwareEngineNetwork

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GetVmwareEngineNetwork
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.vmwareEngineNetworks.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GetVmwareEngineNetwork"

GrantDnsBindPermission

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.GrantDnsBindPermission
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.dnsBindPermission.grant - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.GrantDnsBindPermission"

ListClusters

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListClusters
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.clusters.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListClusters"

ListExternalAccessRules

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAccessRules
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.externalAccessRules.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAccessRules"

ListExternalAddresses

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAddresses
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.externalAddresses.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListExternalAddresses"

ListHcxActivationKeys

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListHcxActivationKeys
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.hcxActivationKeys.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListHcxActivationKeys"

ListLoggingServers

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListLoggingServers
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.loggingServers.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListLoggingServers"

ListManagementDnsZoneBindings

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListManagementDnsZoneBindings
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.managementDnsZoneBindings.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListManagementDnsZoneBindings"

ListNetworkPeerings

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPeerings
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.networkPeerings.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPeerings"

ListNetworkPolicies

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPolicies
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.networkPolicies.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListNetworkPolicies"

ListNodeTypes

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListNodeTypes
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.nodeTypes.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListNodeTypes"

ListNodes

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListNodes
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.nodes.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListNodes"

ListPeeringRoutes

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListPeeringRoutes
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.networkPeerings.listPeeringRoutes - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListPeeringRoutes"

ListPrivateClouds

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateClouds
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.privateClouds.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateClouds"

ListPrivateConnectionPeeringRoutes

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnectionPeeringRoutes
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.privateConnections.listPeeringRoutes - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnectionPeeringRoutes"

ListPrivateConnections

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnections
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.privateConnections.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListPrivateConnections"

ListSubnets

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListSubnets
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.subnets.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListSubnets"

ListVmwareEngineNetworks

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ListVmwareEngineNetworks
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.vmwareEngineNetworks.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ListVmwareEngineNetworks"

RepairManagementDnsZoneBinding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.RepairManagementDnsZoneBinding
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.managementDnsZoneBindings.repair - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.RepairManagementDnsZoneBinding"

ResetNsxCredentials

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ResetNsxCredentials
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.privateClouds.resetNsxCredentials - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ResetNsxCredentials"

ResetVcenterCredentials

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ResetVcenterCredentials
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.privateClouds.resetVcenterCredentials - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ResetVcenterCredentials"

RevokeDnsBindPermission

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.RevokeDnsBindPermission
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.dnsBindPermission.revoke - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.RevokeDnsBindPermission"

ShowNsxCredentials

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ShowNsxCredentials
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.privateClouds.showNsxCredentials - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ShowNsxCredentials"

ShowVcenterCredentials

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.ShowVcenterCredentials
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.privateClouds.showVcenterCredentials - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.ShowVcenterCredentials"

UndeletePrivateCloud

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UndeletePrivateCloud
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.privateClouds.undelete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UndeletePrivateCloud"

UpdateCluster

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateCluster
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.clusters.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateCluster"

UpdateDnsForwarding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateDnsForwarding
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.dnsForwarding.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateDnsForwarding"

UpdateExternalAccessRule

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAccessRule
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.externalAccessRules.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAccessRule"

UpdateExternalAddress

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAddress
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.externalAddresses.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateExternalAddress"

UpdateLoggingServer

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateLoggingServer
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.loggingServers.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateLoggingServer"

UpdateManagementDnsZoneBinding

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateManagementDnsZoneBinding
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.managementDnsZoneBindings.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateManagementDnsZoneBinding"

UpdateNetworkPeering

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPeering
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.networkPeerings.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPeering"

UpdateNetworkPolicy

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPolicy
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.networkPolicies.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateNetworkPolicy"

UpdatePrivateCloud

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateCloud
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.privateClouds.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateCloud"

UpdatePrivateConnection

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateConnection
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.privateConnections.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdatePrivateConnection"

UpdateSubnet

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateSubnet
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.subnets.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateSubnet"

UpdateVmwareEngineNetwork

  • 方法google.cloud.vmwareengine.v1.VmwareEngine.UpdateVmwareEngineNetwork
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.vmwareEngineNetworks.update - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業長時間執行的作業
  • 篩選這個方法 protoPayload.methodName="google.cloud.vmwareengine.v1.VmwareEngine.UpdateVmwareEngineNetwork"

google.iam.v1.IAMPolicy

下列稽核記錄與屬於 google.iam.v1.IAMPolicy 的方法相關聯。

GetIamPolicy

  • 方法GetIamPolicy
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.privateClouds.getIamPolicy - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="GetIamPolicy"

SetIamPolicy

  • 方法SetIamPolicy
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.clusters.setIamPolicy - ADMIN_WRITE
    • vmwareengine.hcxActivationKeys.setIamPolicy - ADMIN_WRITE
    • vmwareengine.privateClouds.setIamPolicy - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="SetIamPolicy"

google.longrunning.Operations

下列稽核記錄與屬於 google.longrunning.Operations 的方法相關聯。

DeleteOperation

  • 方法google.longrunning.Operations.DeleteOperation
  • 稽核記錄類型管理員活動
  • 權限
    • vmwareengine.operations.delete - ADMIN_WRITE
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.longrunning.Operations.DeleteOperation"

GetOperation

  • 方法google.longrunning.Operations.GetOperation
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.operations.get - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.longrunning.Operations.GetOperation"

ListOperations

  • 方法google.longrunning.Operations.ListOperations
  • 稽核記錄類型資料存取
  • 權限
    • vmwareengine.operations.list - ADMIN_READ
  • 方法是長時間執行的作業或串流作業: 否。
  • 篩選這個方法 protoPayload.methodName="google.longrunning.Operations.ListOperations"

系統事件

系統事件稽核記錄是由 GCP 系統產生,而非使用者直接操作。詳情請參閱「系統事件稽核記錄」。

方法名稱 篩選這個活動 附註
system.privateCloud.addNodes protoPayload.methodName="system.privateCloud.addNodes"

不會產生稽核記錄的方法

方法可能不會產生稽核記錄,原因如下:

  • 這項方法會產生大量記錄,因此記錄產生和儲存成本相當高。
  • 稽核價值偏低。
  • 其他稽核或平台記錄已提供方法涵蓋範圍。

下列方法不會產生稽核記錄:

  • google.cloud.location.Locations.GetLocation
  • google.cloud.location.Locations.ListLocations
  • google.longrunning.Operations.WaitOperation