Configure filters for your cloud log sink

    1. On the console, open the export sink for which you wish to create a filter.  Click on the export filter and select Convert to advanced filter
    2. Append the approprirate filters will be exported by this sink, separating each filter specification with an "OR"
Log Types Supported by the GCP Sensor
Log Type Filter to Capture This Log Notes
Audit Logs at the Organization Level organizations/<organization-id>/logs/cloudaudit.googleapis.com To filter these logs further, append:

  • %2Factivity: For activity logs
  • %2Fdata_access: For data access logs
  • %2Fsystem_event: For system events
Audit Logs at the Project Level projects/<project-id>/logs/cloudaudit.googleapis.com To filter these logs futher, append:

  • %2Factivity: For activity logs
  • %2Fdata_access: For data access logs
  • %2Fsystem_event: For system events
VPC Flow Logs projects/<project-id>/logs/compute.googleapis.com%2Fvpc_flows
Firewall Logs projects/<project-id>/logs/compute.googleapis.com%2Ffirewall
Syslog projects/<project-id>/logs/syslog These logs are delivered via the Stackdriver logging agent
Apache Logs projects/<project-id>/logs/apache
  • -access: For access logs
  • -error: For error logs
Nginx Logs projects/<project-id>/logs/nginx
  • -access: For access logs
  • -error: For error logs




Need an experienced AWS/GCP/Azure Professional to help out with your Public Cloud Strategy? Set up a time with Anuj Varma.