Cloud Data Loss Prevention (DLP)
| methodName | Description | Log type | Sample | Rule |
|---|---|---|---|---|
| any | Catch-all entry for dlp.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation. | activity | N | N |
| projects. | Re-identifies content that has been de-identified. The items listed in the request were previously de-identified. This method is only permitted when the caller has been granted the dlp.content.reidentify permission. | data_access | N | Y |
any: dlp.googleapis.com (any method)
#Description
Catch-all entry for dlp.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.
projects.content.reidentify: Re-identify content
#Description
Re-identifies content that has been de-identified. The items listed in the request were previously de-identified. This method is only permitted when the caller has been granted the dlp.content.reidentify permission.
Data Access audit logs are disabled by default. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors method_name1 detection rule Sigma Detection Rules #
Sigma #
T1565