OS Login
| methodName | Description | Log type | Sample | Rule |
|---|---|---|---|---|
| any | Catch-all entry for oslogin.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation. | activity | N | N |
| google. | Checks whether a principal is authorized to log in to a VM via OS Login; emitted on every SSH login attempt. | data_access | N | Y |
| google. | Records completion of an OS Login two-factor authentication challenge. | data_access | N | Y |
| google. | Records initiation of an OS Login two-factor authentication challenge. | data_access | N | N |
| google. | Uploads an SSH public key to a user's OS Login profile (DATA_WRITE). | data_access | N | N |
| google. | Signs a short-lived SSH certificate for an OS Login user in the regional control plane (ADMIN_READ). | data_access | N | N |
| google. | Reads a user's OS Login profile (POSIX accounts, SSH keys). Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs. | not_audited | N | N |
| google. | Removes a POSIX account from a user's OS Login profile. Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs. | not_audited | N | N |
any: oslogin.googleapis.com (any method)
#Description
Catch-all entry for oslogin.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.
google.cloud.oslogin.dataplane.OsLoginDataPlaneService.CheckPolicy: Check policy
#Description
Checks whether a principal is authorized to log in to a VM via OS Login; emitted on every SSH login attempt.
Data Access audit logs are disabled by default. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors protoPayload.methodName1 detection rule Panther protoPayload.serviceName1 detection rule Panther protoPayload.status.message1 detection rule Panther Detection Rules #
Panther #
google.cloud.oslogin.dataplane.OsLoginDataPlaneService.ContinueSession: Continue session
#Description
Records completion of an OS Login two-factor authentication challenge.
Data Access audit logs are disabled by default. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors protoPayload.methodName1 detection rule Panther protoPayload.serviceName1 detection rule Panther protoPayload.status.message1 detection rule Panther Detection Rules #
Panther #
google.cloud.oslogin.dataplane.OsLoginDataPlaneService.StartSession: Start session
#Description
Records initiation of an OS Login two-factor authentication challenge.
Data Access audit logs are disabled by default.
google.cloud.oslogin.OsLoginService.ImportSshPublicKey: Import SSH public key
#Description
Uploads an SSH public key to a user's OS Login profile (DATA_WRITE).
Data Access audit logs are disabled by default.
google.cloud.oslogin.controlplane.regional.OsLoginRegionalService.SignSshPublicKey: Sign SSH public key
#Description
Signs a short-lived SSH certificate for an OS Login user in the regional control plane (ADMIN_READ).
Data Access audit logs are disabled by default.
google.cloud.oslogin.OsLoginService.GetLoginProfile: Get login profile
#Description
Reads a user's OS Login profile (POSIX accounts, SSH keys). Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs.
google.cloud.oslogin.OsLoginService.DeletePosixAccount: Delete POSIX account
#Description
Removes a POSIX account from a user's OS Login profile. Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs.