GCP add-iam-policy-binding
Adds a role binding through a resource-specific IAM policy update.
All events with tag GCP.
Adds a role binding through a resource-specific IAM policy update.
Submits a BigQuery query, load, extract, or copy job.
Requests a Cloud SQL export to Cloud Storage.
Replaces the IAM allow policy on a Compute Engine persistent disk.
Deletes a VPC firewall rule.
Patches an existing VPC firewall rule.
Adds an external IPv4 access configuration to a VM network interface.
Replaces instance-level metadata on a Compute Engine VM.
Changes a VM’s attached service account and access scopes.
Replaces project-wide Compute Engine metadata.
Creates a custom IAM role definition.
Enables a disabled service account.
Requests a short-lived OAuth access token for a service account.
Changes the mute state of a Security Command Center finding.
Creates a user-managed service-account key.
Deletes a service account, potentially disrupting dependent workloads.
Deletes a service-account key.
Sets the IAM allow policy on a service account.
Uploads a public key certificate for a service account.
Updates an exclusion in a resource’s _Default logging sink.
Deletes a named log’s entries from the global _Default log bucket.
Records a connection to a VM’s interactive serial console.
Updates a custom IAM role definition.
Records permission to attach a service account to a resource.
Identifies delegated service-account token generation.
Signs a JWT using a service account’s Google-managed key.
Creates an exclusion in a resource’s _Default logging sink.
Deletes a Cloud Logging sink.
Updates a Cloud Logging sink’s configuration.
Deletes a Secret Manager secret and all its versions.
Accesses the payload of a Secret Manager secret version.
Destroys or schedules destruction of a Secret Manager secret version.
Updates legacy Security Command Center organization settings through a deprecated API.
Deletes a Cloud Storage bucket, subject to contents and soft-delete policy.
Creates an HMAC key for a service account’s Cloud Storage XML API access.
Deletes a Cloud Storage object or a specified object generation.
Records a Cloud Storage access-policy change; this example changes bucket IAM.
Imports an SSH public key into an OS Login profile.
Updates an existing OS Login SSH public-key record; the method is not audit-logged.