All skills
google avatar

/cloud-logging-query-generation

@becc4b8
by googlegoogle/skills21k stars
1,698

Generates Logging Query Language (LQL) queries for Google Cloud Logging from natural language. Use this skill when you need to query log data or when you are debugging issues. You can filter log data by Google Cloud service. Don't use this skill to query other databases, such as SQL or Cloud Spanner.

Use this Skill: https://skilld.dev/gh/google/skills/cloud-logging-query-generation

This session only. Nothing lands on disk.

referencesquery_iam.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

IAM and service accounts LQL queries

Table of contents

Base schema and structural patterns

IAM operations span multiple resource types. Always constrain your query to the correct target resource before writing payload logic.

Log types

  • Use log_id("cloudaudit.googleapis.com/activity") for mutating operations (for example, granting roles, creating service accounts).
  • Use log_id("cloudaudit.googleapis.com/data_access") for read operations (for example, GetRole, GetIamPolicy, ListServiceAccounts).

Resource types

  • project, folder, or organization: Use when the intent is to audit IAM role bindings or permissions assigned at the hierarchy level (for example, "Who granted the editor role on my project?").
  • service_account: Use when the intent is the creation, deletion, or modification of the Service Account identity itself, or the generation of its authentication keys.
  • iam_role: Use when auditing modifications made to Custom IAM Roles directly (for example, adding a new permission to an existing custom role).

PolicyDelta (Role Bindings)

When auditing who was granted or revoked a role, do NOT look in the raw request. Google Cloud translates all access control changes into a unified policyDelta object.

  • protoPayload.methodName: Usually "SetIamPolicy".
  • protoPayload.serviceData.policyDelta.bindingDeltas.action: The action taken, either "ADD" or "REMOVE".
  • protoPayload.serviceData.policyDelta.bindingDeltas.member: The principal being modified (for example, "user:alice@example.com" or "serviceAccount:my-sa@example.com").
  • protoPayload.serviceData.policyDelta.bindingDeltas.role: The precise IAM role being modified (for example, "roles/editor").

Service account credentials

When a user asks about Service Account Keys (which present a high security risk if leaked), target the admin API methods directly:

  • protoPayload.methodName: Use "google.iam.admin.v1.CreateServiceAccountKey" for key generation events, and "google.iam.admin.v1.CreateServiceAccount" for the initial account creation.

Example queries

Service account creation logs

Variables to replace: <EMAIL_ID>

resource.type="service_account" AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.methodName="google.iam.admin.v1.CreateServiceAccount" AND
protoPayload.response.email="<EMAIL_ID>"

Service account creation key logs

Variables to replace: None

resource.type="service_account" AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.methodName="google.iam.admin.v1.CreateServiceAccountKey"

Set access control policy logs

Variables to replace: None

resource.type="project" AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.methodName="SetIamPolicy"

External principal granted access to organization

Variables to replace: <DOMAIN_NAME>

resource.type="project" AND
log_id("cloudaudit.googleapis.com/activity") AND
protoPayload.@type="type.googleapis.com/google.cloud.audit.AuditLog" AND
protoPayload.request.@type:"IamPolicy" AND
protoPayload.serviceData.policyDelta.bindingDeltas.member:* AND
NOT protoPayload.serviceData.policyDelta.bindingDeltas.member:"@<DOMAIN_NAME>.com"

Resource creation, modification, or deletion

Variables to replace: None

log_id("cloudaudit.googleapis.com/activity") AND
(SEARCH(protoPayload.methodName, "create") OR SEARCH(protoPayload.methodName, "delete") OR SEARCH(protoPayload.methodName, "update"))

Role granted to principal

Variables to replace: <EMAIL_ID>

log_id("cloudaudit.googleapis.com/activity") AND
resource.type="project" AND
protoPayload.serviceName="cloudresourcemanager.googleapis.com" AND
protoPayload.methodName="SetIamPolicy" AND
protoPayload.serviceData.policyDelta.bindingDeltas.action="ADD" AND
protoPayload.serviceData.policyDelta.bindingDeltas.member:"<EMAIL_ID>"

Role removed from principal

Variables to replace: <EMAIL_ID>

log_id("cloudaudit.googleapis.com/activity") AND
resource.type="project" AND
protoPayload.serviceName="cloudresourcemanager.googleapis.com" AND
protoPayload.methodName="SetIamPolicy" AND
protoPayload.serviceData.policyDelta.bindingDeltas.action="Remove" AND
protoPayload.serviceData.policyDelta.bindingDeltas.member:"<EMAIL_ID>"

Permission updated in a custom role

Variables to replace: <ROLE_ID>

log_id("cloudaudit.googleapis.com/activity") AND
resource.type="iam_role" AND
protoPayload.serviceName="iam.googleapis.com" AND
SEARCH(protoPayload.methodName, "UpdateRole") AND
resource.labels.role_name:"<ROLE_ID>"

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    This skill is designed to generate Logging Query Language (LQL) queries for Google Cloud Logging from natural language input. It provides comprehensive reference guides, syntax rules, and examples for various Google Cloud services. No security issues were detected.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "1.0.0",
  "category": "CloudObservabilityAndMonitoring"
}

README badge

README badge for google/skills/cloud-logging-query-generation