Dashboard: Audit Log Activity Dashboard
This dashboard contains 1 card.
Usage
Install the mod:
mkdir dashboardscd dashboardspowerpipe mod initpowerpipe mod install github.com/turbot/tailpipe-mod-gcp-audit-log-detections
Start the Powerpipe server:
powerpipe server
Open http://localhost:9033 in your browser and select Audit Log Activity Dashboard dashboard.
You could also snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe dashboard run gcp_audit_log_detections.dashboard.activity_dashboard --share
Queries
This dashboard uses the the following queries:
select authentication_info.principal_email as "Actor", count(*) as "Logs"from gcp_audit_logwhere authentication_info.principal_email is not nullgroup by authentication_info.principal_emailorder by count(*) desclimit 10;