logging.sinks.delete
logging.sinks.delete
Event
Deletes the sink configuration and stops future routing through it. Data already delivered to a destination is not deleted by DeleteSink.
Security Context
Unauthorized removal can impair collection (T1685.002). Other sinks and protected _Required storage can remain available. Retention and detection effects depend on the actual routing topology; there is no universal fallback to 30 days of history.
Log Source
Cloud Audit Logs: logging.googleapis.com, method google.logging.v2.ConfigServiceV2.DeleteSink. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Recover the prior destination, filter, exclusions, scope, and state; verify deletion outcome.
- Determine which consumers depended on this sink and inspect other local or aggregated routes.
- Check destination history and ingestion gaps separately; preserve evidence from surviving routes.
Sample Event
Synthetic scenario. The example deletes niffler-archive-bigquery-export. The request alone does not establish its former destination, all-audit coverage, or a complete SIEM outage; unsupported destination resource labels were removed.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.logging.sinks.delete invocation-id/90000000000000000000001111111111 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T15:58:14.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "logging.googleapis.com", "methodName": "google.logging.v2.ConfigServiceV2.DeleteSink", "authorizationInfo": [ { "resource": "projects/fantasticlogs-prod/sinks/niffler-archive-bigquery-export", "permission": "logging.sinks.delete", "granted": true, "resourceAttributes": { "service": "logging.googleapis.com", "name": "projects/fantasticlogs-prod/sinks/niffler-archive-bigquery-export", "type": "logging.googleapis.com/Sink" } } ], "resourceName": "projects/fantasticlogs-prod/sinks/niffler-archive-bigquery-export", "request": { "@type": "type.googleapis.com/google.logging.v2.DeleteSinkRequest", "sinkName": "projects/fantasticlogs-prod/sinks/niffler-archive-bigquery-export" }, "response": { "@type": "type.googleapis.com/google.protobuf.Empty" } }, "insertId": "evt001111111111", "resource": { "type": "audited_resource", "labels": { "project_id": "fantasticlogs-prod", "service": "logging.googleapis.com", "method": "google.logging.v2.ConfigServiceV2.DeleteSink" } }, "timestamp": "2026-04-15T15:58:14.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T15:58:14.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...