Skip to content

Commit 94d25ce

Browse files
authored
added PAM to default audit logging (#255)
1 parent a18817f commit 94d25ce

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

google_project/locals.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,6 @@ locals {
3535
]
3636
all_project_services = setunion(local.default_project_services, var.project_services)
3737

38-
default_data_access_logs = ["iam.googleapis.com", "secretmanager.googleapis.com", "sts.googleapis.com"]
38+
default_data_access_logs = ["iam.googleapis.com", "secretmanager.googleapis.com", "sts.googleapis.com", "privilegedaccessmanager.googleapis.com"]
3939
data_access_logs_filter = join("\n", toset([for v in concat(local.default_data_access_logs, var.additional_data_access_logs) : "AND NOT protoPayload.serviceName=\"${v}\""]))
4040
}

0 commit comments

Comments
 (0)