google.logging.v2.LoggingServiceV2.DeleteLog
google.logging.v2.LoggingServiceV2.DeleteLog
Event
The documented DeleteLog operation applies to the global _Default log bucket. New entries can recreate the log; recent and late-arriving entries have documented deletion timing caveats.
Security Context
Unauthorized deletion can impair cloud-log evidence (T1685.002), but it does not purge every copy in other buckets, projects, or external destinations. Protected _Required records remain a separate evidence source.
Log Source
Cloud Audit Logs: logging.googleapis.com, method google.logging.v2.LoggingServiceV2.DeleteLog. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Verify the URL-encoded log name, caller authority, outcome, and applicable bucket/location.
- Assess deletion timing and query surviving records; do not equate an empty API response with universal erasure.
- Find routed copies and preserved Admin Activity records; investigate the actual missing interval and future ingestion separately.
Sample Event
Synthetic scenario. The example targets the project’s data_access log. It does not establish prior secret/snapshot reads or destruction of all forensic evidence.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.logging.logs.delete invocation-id/90000000000000000000000000000100 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T15:48:02.778899100Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "logging.googleapis.com", "methodName": "google.logging.v2.LoggingServiceV2.DeleteLog", "authorizationInfo": [ { "resource": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access", "permission": "logging.logs.delete", "granted": true, "resourceAttributes": { "service": "logging.googleapis.com", "name": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access", "type": "logging.googleapis.com/Log" } } ], "resourceName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access", "request": { "@type": "type.googleapis.com/google.logging.v2.DeleteLogRequest", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access" }, "response": { "@type": "type.googleapis.com/google.protobuf.Empty" } }, "insertId": "evt0000000100", "resource": { "type": "audited_resource", "labels": { "project_id": "fantasticlogs-prod", "service": "logging.googleapis.com", "method": "google.logging.v2.LoggingServiceV2.DeleteLog" } }, "timestamp": "2026-04-15T15:48:02.978899Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T15:48:03.378899Z"}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...