systemwrap action

The systemwrap action means that a systemwrap request has been made. This is the case every time a Google DLP rule is triggered. For more information, refer to Using data loss prevention rules for Google Drive (Beta).

This action generates an "info" severity log in the event of success, or a "crit" severity log in the event of an error.

The log fields for these actions are as follows:

Field

Description

Type

Mandatory/
Optional

tenant_id

Tenant identifier.

Example: 025f02fe-bee2-444b-bf76-b5ead30327c0

String in uuid v4 format Mandatory

reason

Additional context about the operation.

Example: Reason of the request

String Mandatory

email

User's email address.

Example: alice.dupont@gmail.com

String Mandatory

google_application

Google Workspace application concerned by the operation.

Prescribed values:

  • drive

String Mandatory

resource_name

Resource identifier.

Example: //googleapis.com/drive/files/1OJsaKJM5JES1yi79QCKx-13wOR1i8JPU"

String Mandatory

perimeter_id

Identifier for additional verification of authentication and authorization requests. Example: Perimeter_id of the request String Mandatory
kek_id

Identifier of the KEK used.

Example: ed7e4c13-6199-30a3-7bce-1c82a9e31e21

String Mandatory