<  Back to rules search

GCP GCE network route created or modified

gcp

Classification:

compliance

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Goal

Detect when a firewall rule is created or modified.

Strategy

This rule lets you monitor GCP GCE activity audit logs to determine if a firewall is being adjusted by showing you when any of the following methods are invoked:

  • beta.compute.routes.insert
  • beta.compute.routes.patch

Triage and response

  1. Veirify that the GCP route is configured properly and that the user intended to modify the firewall.