---
title: Google Compute Engine network route created or modified
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > Google Compute Engine network route
  created or modified
---

# Google Compute Engine network route created or modified
Classification:attackTactic:[TA0005-defense-evasion](https://attack.mitre.org/tactics/TA0005)Technique:[T1578-modify-cloud-compute-infrastructure](https://attack.mitre.org/techniques/T1578) 
## Goal{% #goal %}

Detect when a firewall rule is created or modified.

## Strategy{% #strategy %}

This rule lets you monitor GCE activity audit logs to determine if a firewall is being adjusted by showing you when any of the following methods are invoked:

- `beta.compute.routes.insert`
- `beta.compute.routes.patch`

## Triage and response{% #triage-and-response %}

Verify that the GCE network route is configured properly and that the user intended to modify the firewall.
