Your security team needs to stream all Admin Activity audit logs from the production project to a third-party SIEM that subscribes to a Pub/Sub topic. You created the topic "prod-audit-topic" and then ran:
The sink shows as active, but the SIEM is not receiving any messages. What is the most likely action you still need to perform to make the export work?
Grant the Pub/Sub Subscriber role on prod-audit-topic to the default Compute Engine service account.
Increase the retention period of the _Default log bucket to 30 days.
Enable VPC Service Controls for the Pub/Sub API in the project.
Grant the Pub/Sub Publisher role on prod-audit-topic to the sink's writer identity service account.
When Cloud Logging creates a sink, it also creates a unique writer identity service account (formatted like serviceAccount:cloud-logs-sink-[ID]@system.gserviceaccount.com). For Pub/Sub destinations, that identity must have the Pub/Sub Publisher role on the target topic so it can write messages. Until this role is granted, the sink cannot publish any log entries. Granting Subscriber to other accounts, enabling VPC Service Controls, or changing log retention settings do not allow the sink itself to publish.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a writer identity service account in GCP logging sinks?
Open an interactive chat with Bash
What permissions does the Pub/Sub Publisher role provide?
Open an interactive chat with Bash
How do you check whether a Cloud Logging sink is correctly configured for exporting logs?
Open an interactive chat with Bash
What is a Pub/Sub Publisher role, and why is it needed for Cloud Logging sinks?
Open an interactive chat with Bash
What is a writer identity in Cloud Logging, and how is it used in sinks?
Open an interactive chat with Bash
How do you assign roles to a service account in GCP?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Ensuring successful operation of a cloud solution
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .