This page shows you how to enable and disable logging for hierarchical and network firewall policy rules. For instructions about logging for firewall policy rules, see Enable and disable firewall policy rules logging. You can also learn how to view generated logs for firewall policy rules. To understand firewall policy rules logging, see Firewall policy rules logging overview.
If you enable logging on a firewall policy rule, you can view insights and recommendations for it from Firewall Insights. For more information, see Firewall Insights in the Network Intelligence Center documentation.
Permissions
To modify firewall policy rules or access logs, Identity and Access Management (IAM) principals need one of the following roles.
| Task | Required role |
|---|---|
| Create, delete, or update firewall rules | Project
owner or editor
or
Security Admin role (roles/compute.securityAdmin)
|
| View logs | Project
owner, editor or viewer
or
Logs Viewer role (roles/logging.viewer)
For details about Logging IAM roles and permissions, see Predefined roles. |
Enable and disable firewall policy rules logging
When you create a firewall policy rule, you can enable firewall policy rules logging. For more information, see the following: