Skip to content

google.logging.v2.ConfigServiceV2.UpdateExclusion

GCP

google.logging.v2.ConfigServiceV2.UpdateExclusion

service: GCP - Cloud Logging
techniques:

Event

UpdateExclusion changes selected properties of an existing _Default sink exclusion. Matching entries can stop being routed through that sink; the update does not delete stored history.

Security Context

Unauthorized exclusion changes can impair cloud logging (T1685.002). They do not suppress every independent route or disable protected _Required storage. Establish the affected coverage instead of claiming the actor becomes invisible.

Log Source

Cloud Audit Logs: logging.googleapis.com, method google.logging.v2.ConfigServiceV2.UpdateExclusion. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Compare old/new filter, updateMask, disabled state, and affected resource.
  3. Evaluate the Boolean filter against representative entries, including entries without principalEmail.
  4. Inspect independent sinks, retained copies, and downstream detections to measure the actual coverage gap.

Sample Event

Synthetic scenario. The example uses OR to match low-severity Cloud Function entries or entries attributed to Draco. The earlier filter is not present; neither a benign origin nor total audit suppression is established.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.logging.exclusions.update invocation-id/90000000000000000000001111110110 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T15:55:24.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "logging.googleapis.com",
"methodName": "google.logging.v2.ConfigServiceV2.UpdateExclusion",
"authorizationInfo": [
{
"resource": "projects/fantasticlogs-prod/exclusions/low-priority-cloudfunctions-debug",
"permission": "logging.exclusions.update",
"granted": true,
"resourceAttributes": {
"service": "logging.googleapis.com",
"name": "projects/fantasticlogs-prod/exclusions/low-priority-cloudfunctions-debug",
"type": "logging.googleapis.com/Exclusion"
}
}
],
"resourceName": "projects/fantasticlogs-prod/exclusions/low-priority-cloudfunctions-debug",
"request": {
"@type": "type.googleapis.com/google.logging.v2.UpdateExclusionRequest",
"name": "projects/fantasticlogs-prod/exclusions/low-priority-cloudfunctions-debug",
"exclusion": {
"name": "low-priority-cloudfunctions-debug",
"description": "Suppress low-priority CloudFunctions debug entries (cost optimization)",
"filter": "(resource.type=\"cloud_function\" AND severity<=INFO) OR protoPayload.authenticationInfo.principalEmail=\"draco@fantasticlogs.cloud\"",
"disabled": false
},
"updateMask": "filter"
},
"response": {
"@type": "type.googleapis.com/google.logging.v2.LogExclusion",
"name": "low-priority-cloudfunctions-debug",
"description": "Suppress low-priority CloudFunctions debug entries (cost optimization)",
"filter": "(resource.type=\"cloud_function\" AND severity<=INFO) OR protoPayload.authenticationInfo.principalEmail=\"draco@fantasticlogs.cloud\"",
"disabled": false,
"createTime": "2026-03-01T08:14:32.123456789Z",
"updateTime": "2026-04-15T15:55:24.321987Z"
}
},
"insertId": "evt001111110110",
"resource": {
"type": "audited_resource",
"labels": {
"project_id": "fantasticlogs-prod",
"service": "logging.googleapis.com",
"method": "google.logging.v2.ConfigServiceV2.UpdateExclusion"
}
},
"timestamp": "2026-04-15T15:55:24.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T15:55:24.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.