Google Cloud Service Account created

Goal

Detect when a new service account is created.

Strategy

This rule lets you monitor Google Cloud admin activity audit logs to determine when a service account is created.

Triage and response

Contact the user who created the service account and ensure that the account is needed and that the role is scoped properly.

PREVIEWING: seth.samuel/DBMON-5258-add-public-documentation-on-database-instance-identifier