elastic / elastic/cloudbeat

Missing GCP Rule 2.2 for Single project (Ensure That Sinks Are Configured for All Log Entries)

Open
#2,677 0 comments 0 reactions 0 assignees View on GitHub
bug cloudbeat Team:Cloud Security
Dominant language
Go
Stars
58
Forks
55
Avg merge
9h 9m
Merged PRs (30d)
424

Description

**Describe the bug**

I deployed a single project for GCP and realized it’s missing a finding related to the benchmark rule 2.2 (Ensure That Sinks Are Configured for All Log Entries), I can access the Log Router page and saw some configured sinks, but confirmed that there’s no sink with empty inclusion filter, this shouldn’t lead to a failed finding for this rule?

**Preconditions**
- Kibana 8.16.0 BC 2
- Cloudbeat agent 8.16.0 BC 2
- Confirm you have access to sinks and there's no sink with an `empty` inclusion filter.

**To Reproduce**
Steps to reproduce the behavior:
1. Install CSPM for GCP in a Single Project
2. Once data populates confirm that the `rule.benchmark.rule_number : 2.2` is missing

**Expected behavior**

There should be a `failed` finding for this rule.

**Screenshots**

![Image](https://github.com/user-attachments/assets/e62bf175-eff2-409c-b792-bb140d2fdd38)
![Image](https://github.com/user-attachments/assets/3498105c-886a-4734-bac8-fd9640c5d92b)
![Image](https://github.com/user-attachments/assets/66511f21-3c0a-418d-93e3-7da6c0bbc31f)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.