Risk Level: High (not acceptable risk)
Rule ID: CloudLoadBalancing-004
Ensure that your Google Cloud HTTP(S) load balancers are configured to log all network traffic.
Enabling logging for Google Cloud load balancers in order to view HTTP(S) network traffic to your web applications is vital because it allows you to monitor and analyze the incoming traffic, identify potential security threats or issues, troubleshoot application performance problems, and gain insights for optimizing your web application's performance and security.
Audit
To determine if your HTTP(S) load balancers are configured to log all network traffic, perform the following operations:
Remediation / Resolution
To ensure that your Google Cloud HTTP(S) load balancers are configured to log all network traffic, perform the following actions:
References
- Google Cloud Platform (GCP) Documentation
- Cloud Load Balancing
- Cloud Load Balancing overview
- Global external Application Load Balancer logging and monitoring
- GCP Command Line Interface (CLI) Documentation
- gcloud projects list
- gcloud compute url-maps list
- gcloud compute url-maps describe
- gcloud compute backend-services describe
- gcloud compute backend-services update
Publication date Jun 29, 2023