(logName =~ "logs/cloudaudit.googleapis.com%2Fdata_access" AND protoPayload.methodName:("google.cloud.aiplatform.")) OR ((logName="projects/<GCP_PROJECT_ID>/logs/compute.googleapis.com%2Fvpc_flows") AND (resource.labels.subnetwork_name="<SUBNET_1>" OR resource.labels.subnetwork_name="<SUBNET_2>"))
- <GCP Project ID>: Replace it with your GCP project
ID.
- <SUBNET_1>, <SUBNET_2>: Replace these with the
values for your subnets.
Consider using regular expressions if you have a high
number of subnets you need to protect.
Click Preview logs and run the query to verify the filter
settings and ensure the logs are correctly routed.Click Create sink.
Logs can take
up to an hour to populate in the bucket, which may result in a
lag in asset discovery and log correlation in Strata Cloud Manager during initial onboarding.