For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/3b3-32c-73c.md. A documentation index is available at /llms.txt.

Google Compute Engine network route created or modified

Goal

Detect when a firewall rule is created or modified.

Strategy

This rule lets you monitor GCE activity audit logs to determine if a firewall is being adjusted by showing you when any of the following methods are invoked:

  • beta.compute.routes.insert
  • beta.compute.routes.patch

Triage and response

Verify that the GCE network route is configured properly and that the user intended to modify the firewall.