Skip to main content
compliance · gcp

Cloud Storage buckets with no usage and storage log delivery configured

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Cloud Storage buckets without a logging configuration produce no hourly usage logs, so requests from `allUsers`, lifecycle deletions and per-request latency on that bucket go unrecorded. ZopNight flags buckets whose `logging.logBucket` is not set, reported as a low-severity compliance finding with a $0 saving, and the fix is a single `gcloud storage buckets update --log-bucket` command.

Signal and threshold

How ZopNight evaluates Cloud Storage buckets with no usage and storage log delivery configured.
Field Value
Rule IDsRC-142
Categorycompliance
Severitylow
Metricnone — pure configuration read
Thresholdno log bucket configured
SourceZopNight
Permissions usedstorage.buckets.list · storage.buckets.get

What Cloud Storage usage logs record

Cloud Storage can deliver two CSV log types to a bucket you choose. The usage and storage logs page describes usage logs as a record of every request made on the bucket, created hourly, and storage logs as a daily record of the bucket’s storage consumption. Both land as ordinary objects and are billed like any other stored data.

Google is candid that Cloud Audit Logs are the recommended way to track API operations in most cases. Usage logs still cover things audit logs do not: access through allUsers or allAuthenticatedUsers on a public or static-website bucket, changes made by Object Lifecycle Management or Autoclass, request and response sizes and latency, and the full URL of each request. They also let you log one bucket without enabling Data Access logs for every bucket in the project.

Checking a bucket’s logging configuration

Terminal window
gcloud storage buckets describe gs://BUCKET_NAME --format="default(logging_config)"

An empty result means no log bucket is set. To sweep a project, run gcloud storage buckets list --format="value(name)" and describe each one.

How ZopNight decides logging is off

ZopNight first confirms it has the bucket’s full details by checking that a storage class was recorded. It then reads whether the bucket’s logging configuration names a log bucket. If it does not, the rule fires, whether the setting is explicitly empty or missing entirely. No request volume or time window is involved.

When a bucket is not flagged

A bucket whose details were not collected, with no storage class recorded, is skipped so a partial scan cannot flag everything. Any bucket with a log bucket configured is silent, even if that log bucket is in another project or has since been deleted. Project-wide Data Access audit logging is a separate check, GCP Audit Logging Not Enabled.

No saving; the cost is a blind spot

The saving is $0. Enabling logs adds a little storage cost for the log objects. Without them, an incident on a public bucket leaves no request trail to investigate.

Turning on usage logs

  1. Create or pick a log bucket in the same location as the bucket being logged and in the same organization. Google lists both as requirements.

  2. Let Cloud Storage write to it:

    Terminal window
    gcloud storage buckets add-iam-policy-binding gs://LOG_BUCKET \
    --member=group:cloud-storage-analytics@google.com \
    --role=roles/storage.objectCreator
  3. Enable logging on the source bucket:

    Terminal window
    gcloud storage buckets update gs://BUCKET_NAME \
    --log-bucket=gs://LOG_BUCKET --log-object-prefix=BUCKET_NAME
  4. Add a lifecycle rule on the log bucket so old CSVs expire, and remember that Google does not guarantee timely or complete delivery of these logs.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·