Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Table 1-1: Port requirements for LCP communication.

Source

Destination

Port

Description

LCP

Google Cloud

443(https)

Default port

Configuring Google Cloud Platform

...

2. In the Query field run the following query after filling the Project_ID field

Code Block

logName=("projects/PROJECT_ID/logs/cloudaudit.googleapis.com%2Factivity" OR "projects/PROJECT_ID/logs/cloudaudit.googleapis.com%2Fdata_access" OR "projects/PROJECT_ID/logs/cloudaudit.googleapis.com%2Fsystem_event" OR "projects/PROJECT_ID/logs/cloudaudit.googleapis.com%2Fpolicy")

3. Click on the Action drop-down button and select Create Sink

...

11. Provide a unique name and description for the Service account details and click CREATE AND CONTINUE.

...


12. Select Role as Pub/Sub PublisherSubscriber and Pub/Sub Viewer and click CONTINUE 

...

Table 1-2: The Google Cloud Platform Audit event collector (Custom – 3950) properties to be configured by MDR are shown in the table.

Property

Default Value

Description

Project ID

Custom Value

Project ID mentioned in the Pre-Installation Questionnaire (PIQ).

This value retrieved from project_id field in the JSON file downloaded above

Private Key ID

Custom Value

Private Key ID mentioned in the  Pre-Installation Questionnaire (PIQ).

This value retrieved from private_key_id field in the JSON file downloaded above

Private Key

Custom Value

Private Key mentioned in the Pre-Installation Questionnaire (PIQ).

This value retrieved from private_key field in the JSON file downloaded above

Client Email

Custom Value

Client Email mentioned in the Pre-Installation Questionnaire (PIQ).

This value retrieved from client_email field in the JSON file downloaded above

Client ID

Custom Value

Project ID mentioned in the Pre-Installation Questionnaire (PIQ).

This value retrieved from project_id field in the JSON file downloaded above

Subscription Name

Custom Value

Name of the subscription created in the log configuration steps above