logging.projects.exclusions.create
logging.projects.exclusions.create
Event
CreateExclusion adds an exclusion to the named resource’s _Default sink. The illustrated AND expression only matches cloud_function entries at INFO severity or below that also match one of two principal emails.
Security Context
Unauthorized filtering can impair cloud logging (T1685.002). This filter does not match every action by those principals, remove existing entries, or suppress independent sinks and protected _Required records.
Log Source
Cloud Audit Logs: logging.googleapis.com, method google.logging.v2.ConfigServiceV2.CreateExclusion. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Inspect filter grouping, parent scope, disabled state, and approval; test matching and nonmatching entries.
- Compare created configuration with actual log resource types, severity, and identity-field presence.
- Check other routing and retained copies to determine the monitoring gap and affected time range.
Sample Event
Synthetic scenario. The sample creates low-noise-cloudfunctions. Its restrictive resource/severity conjunction is retained and accurately described; the name does not prove its purpose.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.logging.exclusions.create invocation-id/90000000000000000000001111111110 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T15:51:02.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "logging.googleapis.com", "methodName": "google.logging.v2.ConfigServiceV2.CreateExclusion", "authorizationInfo": [ { "resource": "projects/fantasticlogs-prod", "permission": "logging.exclusions.create", "granted": true, "resourceAttributes": { "service": "logging.googleapis.com", "name": "projects/fantasticlogs-prod", "type": "logging.googleapis.com/Project" } } ], "resourceName": "projects/fantasticlogs-prod/exclusions/low-noise-cloudfunctions", "request": { "@type": "type.googleapis.com/google.logging.v2.CreateExclusionRequest", "parent": "projects/fantasticlogs-prod", "exclusion": { "name": "low-noise-cloudfunctions", "description": "Suppress noisy CloudFunctions debug entries", "filter": "resource.type=\"cloud_function\" AND severity<=INFO AND (protoPayload.authenticationInfo.principalEmail=\"draco@fantasticlogs.cloud\" OR protoPayload.authenticationInfo.principalEmail=\"draco-malfoy-666@gmail.com\")", "disabled": false } }, "response": { "@type": "type.googleapis.com/google.logging.v2.LogExclusion", "name": "low-noise-cloudfunctions", "description": "Suppress noisy CloudFunctions debug entries", "filter": "resource.type=\"cloud_function\" AND severity<=INFO AND (protoPayload.authenticationInfo.principalEmail=\"draco@fantasticlogs.cloud\" OR protoPayload.authenticationInfo.principalEmail=\"draco-malfoy-666@gmail.com\")", "disabled": false, "createTime": "2026-04-15T15:51:02.321987Z", "updateTime": "2026-04-15T15:51:02.321987Z" } }, "insertId": "evt001111111110", "resource": { "type": "audited_resource", "labels": { "project_id": "fantasticlogs-prod", "service": "logging.googleapis.com", "method": "google.logging.v2.ConfigServiceV2.CreateExclusion" } }, "timestamp": "2026-04-15T15:51:02.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T15:51:02.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...