Skip to content

logging.sinks.update

GCP

logging.sinks.update

service: GCP - Cloud Logging
techniques:

Event

UpdateSink changes sink properties selected by updateMask. The sample updates only filter to exclude entries attributed to one principal from that route.

Security Context

Unauthorized selective routing changes can impair collection (T1685.002) while other entries continue arriving. Existing destination data is not erased, and independent routing remains a separate source of evidence.

Log Source

Cloud Audit Logs: logging.googleapis.com, method google.logging.v2.ConfigServiceV2.UpdateSink. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Compare prior/resulting filter and updateMask, along with destination, exclusions, disabled state, and scope.
  3. Test the filter on representative records, including absent identity fields; check content coverage as well as ingestion volume.
  4. Identify other routes and compare destination gaps with actual activity before attributing deliberate concealment.

Sample Event

Synthetic scenario. The example updates a BigQuery sink filter. The previous filter is absent, so a new omission requires comparison with earlier configuration. No claim of guaranteed alert evasion is made.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.logging.sinks.update invocation-id/90000000000000000000010000000000 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T16:00:48.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "logging.googleapis.com",
"methodName": "google.logging.v2.ConfigServiceV2.UpdateSink",
"authorizationInfo": [
{
"resource": "projects/fantasticlogs-prod/sinks/niffler-archive-bigquery-export",
"permission": "logging.sinks.update",
"granted": true,
"resourceAttributes": {
"service": "logging.googleapis.com",
"name": "projects/fantasticlogs-prod/sinks/niffler-archive-bigquery-export",
"type": "logging.googleapis.com/Sink"
}
}
],
"resourceName": "projects/fantasticlogs-prod/sinks/niffler-archive-bigquery-export",
"request": {
"@type": "type.googleapis.com/google.logging.v2.UpdateSinkRequest",
"sinkName": "projects/fantasticlogs-prod/sinks/niffler-archive-bigquery-export",
"sink": {
"name": "niffler-archive-bigquery-export",
"destination": "bigquery.googleapis.com/projects/fantasticlogs-sec/datasets/audit_logs",
"filter": "logName:\"cloudaudit.googleapis.com\" AND NOT protoPayload.authenticationInfo.principalEmail=\"draco@fantasticlogs.cloud\"",
"disabled": false,
"writerIdentity": "serviceAccount:p555123456789-niffler-archive-bigquery-export@gcp-sa-logging.iam.gserviceaccount.com"
},
"updateMask": "filter"
},
"response": {
"@type": "type.googleapis.com/google.logging.v2.LogSink",
"name": "niffler-archive-bigquery-export",
"destination": "bigquery.googleapis.com/projects/fantasticlogs-sec/datasets/audit_logs",
"filter": "logName:\"cloudaudit.googleapis.com\" AND NOT protoPayload.authenticationInfo.principalEmail=\"draco@fantasticlogs.cloud\"",
"disabled": false,
"writerIdentity": "serviceAccount:p555123456789-niffler-archive-bigquery-export@gcp-sa-logging.iam.gserviceaccount.com",
"createTime": "2026-01-12T08:14:32.123456789Z",
"updateTime": "2026-04-15T16:00:48.321987Z"
}
},
"insertId": "evt010000000000",
"resource": {
"type": "audited_resource",
"labels": {
"project_id": "fantasticlogs-prod",
"service": "logging.googleapis.com",
"method": "google.logging.v2.ConfigServiceV2.UpdateSink"
}
},
"timestamp": "2026-04-15T16:00:48.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T16:00:48.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.