Log types
Each source carries one log type.Authentication
Cotool uses workload identity federation, so no service account key is created or stored. Cotool’s runtime identity presents a Google-signed token whose audience is unique to your Cotool organization; your workload identity provider accepts only that subject and audience, so no other Cotool customer can use your setup. You can grant the subscription to the federated principal directly, or have Cotool impersonate a service account of yours.If your organization restricts workload identity pool providers with the
iam.workloadIdentityPoolProviders policy, allow
https://accounts.google.com.Step 1: Create the sink, subscription, and federation
On the integration page, select Add log source and enter your project ID. The setup section fills it, the logs to route, and Cotool’s Subject and your Audience into a Terraform configuration and a gcloud script. Each creates:- a topic and a subscription dedicated to Cotool (
cotool-logs-<suffix>; 120-second ack deadline, 7-day retention, no expiry), - a dead-letter topic and subscription (
cotool-logs-<suffix>-dead-letter) that keep messages Pub/Sub could not deliver after 100 attempts, with the Pub/Sub service agent allowed to move them there, - a log sink with the filter you build under Logs to route, with permission to publish to the topic,
- a workload identity pool (
cotool-<suffix>) and OIDC provider that trusthttps://accounts.google.comonly for Cotool’s subject and your audience, roles/pubsub.subscriberon the subscription for the federated principal.
<suffix> is a short random value generated for each setup, so several sources can live in the same project.
Under Logs to route, choose one of:
- Log types: combine Cloud Audit Logs (the default), VPC flow logs, firewall rule logs, Cloud DNS queries, load balancer and Cloud Armor logs, GKE workloads, Cloud Run, and Compute Engine VMs.
- All logs: every entry in the project.
- Custom filter: any Cloud Logging query, for example
resource.type="k8s_container" AND severity>=WARNING.
- Terraform
- gcloud CLI
- Save the configuration in your infrastructure repository, and authenticate the Google provider, for example with
gcloud auth application-default login. - Turn on the APIs it uses if they are off:
gcloud services enable pubsub.googleapis.com logging.googleapis.com iam.googleapis.com sts.googleapis.com --project=<project-id>. - For an organization-wide sink, use
google_logging_organization_sinkwithinclude_children = trueinstead of the project sink. - Run
terraform init, reviewterraform plan, then runterraform apply. terraform outputprintssubscriptionandworkload_identity_providerfor the connection form.
Step 2: Connect the source
- Connect: enter your project ID and choose the logs to route. Deploy the setup, then paste the subscription path, the workload identity provider resource name, and optionally a service account to impersonate.
- Test: Cotool exchanges its token at your provider, checks that it can consume the subscription, and pulls up to ten messages. Tested messages are returned to the subscription, not acknowledged. If the subscription is empty, paste a sample log entry.
- Format: name the source and choose GCP Cloud Audit Logs, Generic JSON, or Custom format, normalized to OCSF. Cotool previews the sampled entries parsed with that format. The Cloud Audit Logs format skips other entries, so choose Generic JSON or OCSF when the sink routes more than audit logs.
- Select Enable source, or Save paused to enable it later. Enabling needs a passing test.
Reliability
- Messages are acknowledged only after their entries are archived and indexed. If Cotool restarts mid-run, the ack deadline lapses and Pub/Sub redelivers them.
- A temporary failure delays redelivery with backoff and leaves the messages in the subscription. The dead-letter policy is what lets Pub/Sub report each message’s delivery attempt: without one, the access test warns, Pub/Sub redelivers failing messages indefinitely, and entries Cotool Logs rejects are kept only in the raw archive after their first delivery.
- Undecodable messages are kept in the raw archive with their original bytes and the reason, and acknowledged so they cannot block the subscription.
- Redeliveries do not create duplicates: audit entries are keyed by log name, insert ID, and timestamp, and generic entries by message ID.