GCP Vertex AI Publisher Model Config Modified
Description
Detects changes to Vertex AI publisher model configuration via SetPublisherModelConfig (for example enabling or retargeting prompt/response BigQuery logging). Unexpected config changes can disable security-relevant logging or redirect logs.
Query · esql
from logs-gcp_vertexai.auditlogs-* metadata _id, _version, _index
| where
data_stream.dataset == "gcp_vertexai.auditlogs" and
event.action like "*SetPublisherModelConfig*" and
(gcp.vertexai.audit.status.code is null or gcp.vertexai.audit.status.code == 0)
| keep
_id,
_version,
_index,
@timestamp,
event.action,
cloud.project.id,
source.ip,
gcp.vertexai.audit.service_name,
gcp.vertexai.audit.resource_name,
client.user.email,
user_agent.original
Investigation fields
Pivot points the source recommends for triage.
event.actioncloud.project.idsource.ipgcp.vertexai.audit.service_namegcp.vertexai.audit.resource_nameclient.user.emailuser_agent.original
Implementation guide
Requires GCP Vertex AI auditlogs via Pub/Sub sink for aiplatform.googleapis.com.
Known false positives
- Approved platform engineering changes that update publisher logging destinations. Confirm the actor and change ticket.
Analyst notes
Investigating GCP Vertex AI Publisher Model Config Modified
Someone called SetPublisherModelConfig on a publisher model. That API can enable, disable, or
retarget prompt/response BigQuery logging and related publisher settings. Unexpected changes can
blind detection (logging off or redirected) or move sensitive prompt data to an unapproved sink.
Possible investigation steps
- Note
@timestamp,event.action,source.ip,client.user.email,gcp.vertexai.audit.resource_name, anduser_agent.originalon the alert. - Confirm the actor is an approved platform owner. Check change tickets / IaC pipelines for a matching change.
- In GCP, verify the publisher model config still points at the expected BigQuery dataset/table and sampling rate.
- Compare
prompt_response_logsvolume before and after the change for gaps or a sudden destination shift. - Hunt for other privilege or config changes by the same principal around the same time.
False positive analysis
- Approved platform engineering work that enables or retargets logging. Validate with the change ticket and expected actor/IP before escalating.
Response and remediation
- Revert unauthorized config to the last known-good logging destination and sampling settings.
- Restrict IAM who can call
SetPublisherModelConfig; rotate credentials for the actor if compromise is suspected.