GCE Firewall issue firewall rule deleted in 10 Minutes

101 views
Skip to first unread message

Radha Krishnan

unread,
Apr 12, 2018, 9:36:26 AM4/12/18
to gce-dis...@googlegroups.com
GCE Firewall issue firewall rule deleted in 10 Minutes

Log


I  Compute Engine insert global:tcp-rule-cygnetclient us...@gmail.com {"@type":"type.googleapis.com/google.cloud.audit.AuditLog","authenticationInfo":{"principalEmail":"user@gmail.com"},"requestMetadata":{"callerIp":"14.140.238.4","callerSuppliedUserAgent":"google-cloud-sdk gcloud/196.0.0 command/gcloud.compute.firewall-rules.create invocation-id/e503062af16246… Compute Engine insert global:tcp-rule-cygnetclient us...@gmail.com
I  compute.firewalls.insert {"ip_address":"","request":{"body":"null","url":"https://www.googleapis.com/compute/v1/projects/nmsworks-poc/global/firewalls?alt=json"},"event_timestamp_us":"1523460107482613","actor":{"user":"us...@gmail.com"},"resource":{"id":"3193159121367176932","global":true,"name":"tcp-rule-cygnetclient… compute.firewalls.insert
I  Compute Engine insert global:tcp-rule-cygnetclient us...@gmail.com {"@type":"type.googleapis.com/google.cloud.audit.AuditLog","authenticationInfo":{"principalEmail":"user@gmail.com"},"requestMetadata":{"callerIp":"","callerSuppliedUserAgent":"google-cloud-sdk gcloud/196.0.0 command/gcloud.compute.firewall-rules.create invocation-id/e503062af16246… Compute Engine insert global:tcp-rule-cygnetclient us...@gmail.com
I  compute.firewalls.insert {"actor":{"user":"user@gmail.com"},"resource":{"name":"tcp-rule-cygnetclient","type":"firewall","id":"3193159121367176932","global":true},"trace_id":"operation-1523460106258-5699432768650-6c5ee311-96fe33de","event_type":"GCE_OPERATION_DONE","operation":{"id":"6322158691900692196","global":tru… compute.firewalls.insert
I  Compute Engine delete global:tcp-rule-cygnetclient {"@type":"type.googleapis.com/google.cloud.audit.AuditLog","authenticationInfo":{"principalEmail":"},"requestMetadata":{"callerIp":":","callerSuppliedUserAgent":"google-api-python-client/1.6.5 (gzip),gzip(gfe)"},"serviceName":"compute.googleap… Compute Engine delete global:tcp-rule-cygnetclient
I  compute.firewalls.delete {"actor":{"user":"},"resource":{"global":true,"name":"tcp-rule-cygnetclient","type":"firewall","id":"3193159121367176932"},"event_type":"GCE_API_CALL","trace_id":"operation-1523460680282-5699454ad6f91-665fc23d-5a6be3f9","operation":{"global":true,"name":"operat… compute.firewalls.delete
I  Compute Engine delete global:tcp-rule-cygnetclient  {"@type":"type.googleapis.com/google.cloud.audit.AuditLog","authenticationInfo":{"principalEmail":"},"requestMetadata":{"callerIp":"::","callerSuppliedUserAgent":"google-api-python-client/1.6.5 (gzip),gzip(gfe)"},"serviceName":"compute.googleap… Compute Engine delete global:tcp-rule-cygnetclient
I  compute.firewalls.delete {"event_subtype":"compute.firewalls.delete","version":"1.2","event_timestamp_us":"1523460687347715","actor":{"user":"},"resource":{"global":true,"name":"tcp-rule-cygnetclient","type":"firewall","id":"3193159121367176932"},"event_type":"GCE_OPERATION_DONE","trac… compute.firewalls.delete
  undefined

Fady (Google Cloud Platform)

unread,
Apr 12, 2018, 7:18:37 PM4/12/18
to gce-discussion

Radha,


For privacy reasons, I redacted some of your project information and IP addresses from the log. As I mentioned at this thread, you should check with your organization level admins as you are affected by organizational level policies.


Reply all
Reply to author
Forward
0 new messages