Google Cloud SQL database modified

Goal

Detect when a Google Cloud SQL database has been modified.

Strategy

This rule lets you monitor Google Cloud SQL admin activity audit logs to determine when one of the following methods is invoked:

  • cloudsql.instances.create
  • cloudsql.instances.create
  • cloudsql.users.update

Triage and response

  1. Review the Google Cloud SQL database and ensure it is configured properly with the correct permissions.