Google Cloud services write audit logs that record administrative activities and accesses within your Google Cloud resources.
data:image/s3,"s3://crabby-images/06766/06766df9800feb7859f264291868b9bae5134c80" alt=""
To view audit logs, you must have the appropriate IAM permissions and roles:
data:image/s3,"s3://crabby-images/67859/6785957a3a12127ec79aff857fff6605418b5da7" alt=""
Enable data access logging for cloudsql:
> gcloud projects get-iam-policy myproject123 > /tmp/policy.yaml
# Append to policy.yaml
auditConfigs:
- auditLogConfigs:
- logType: DATA_READ
- logType: DATA_WRITE
service: cloudsql.googleapis.com
- exemptedMembers:
- 123456789123-compute@developer.gserviceaccount.com
> gcloud projects set-iam-policy myproject123 /tmp/policy.yaml