GCP records activity in two layers: Cloud Audit Logs capture the API calls, and Cloud Logging routes everything through log sinks to buckets and external destinations, with Security Command Center raising findings on top. An operator degrades these to act unseen, choosing between the blunt (delete a sink, disable a log type) and the quiet (an exclusion filter that drops only your events), weighed against what still records at the organization level above the project.
What folds in here#
- Cloud Logging: deleting or diverting log sinks and adding exclusion filters to drop activity from the logs.
- Audit Logs: disabling or narrowing Cloud Audit Logs, especially the data-access logs, to hide API calls.
- Security Command Center: muting or disabling findings and sources to suppress alerting.