Class: Google::Cloud::Dlp::V2::Action

Inherits:
Object
  • Object
show all
Extended by:
Protobuf::MessageExts::ClassMethods
Includes:
Protobuf::MessageExts
Defined in:
proto_docs/google/privacy/dlp/v2/dlp.rb

Overview

A task to execute on the completion of a job. See https://cloud.google.com/sensitive-data-protection/docs/concepts-actions to learn more.

Defined Under Namespace

Classes: Deidentify, JobNotificationEmails, PublishFindingsToCloudDataCatalog, PublishFindingsToDataplexCatalog, PublishSummaryToCscc, PublishToPubSub, PublishToStackdriver, SaveFindings

Instance Attribute Summary collapse

Instance Attribute Details

#deidentify::Google::Cloud::Dlp::V2::Action::Deidentify

Returns Create a de-identified copy of the input data.

Note: The following fields are mutually exclusive: deidentify, save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.

Returns:

  • (::Google::Cloud::Dlp::V2::Action::Deidentify)

    Create a de-identified copy of the input data.

    Note: The following fields are mutually exclusive: deidentify, save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.



3969
3970
3971
3972
3973
3974
3975
3976
3977
3978
3979
3980
3981
3982
3983
3984
3985
3986
3987
3988
3989
3990
3991
3992
3993
3994
3995
3996
3997
3998
3999
4000
4001
4002
4003
4004
4005
4006
4007
4008
4009
4010
4011
4012
4013
4014
4015
4016
4017
4018
4019
4020
4021
4022
4023
4024
4025
4026
4027
4028
4029
4030
4031
4032
4033
4034
4035
4036
4037
4038
4039
4040
4041
4042
4043
4044
4045
4046
4047
4048
4049
4050
4051
4052
4053
4054
4055
4056
4057
4058
4059
4060
4061
4062
4063
4064
4065
4066
4067
4068
4069
4070
4071
4072
4073
4074
4075
4076
4077
4078
4079
4080
4081
4082
4083
4084
4085
4086
4087
4088
4089
4090
4091
4092
4093
4094
4095
4096
4097
4098
4099
4100
4101
4102
4103
4104
4105
4106
4107
4108
4109
4110
4111
4112
4113
4114
4115
4116
4117
4118
4119
4120
4121
4122
4123
4124
4125
4126
4127
4128
4129
4130
4131
4132
4133
4134
4135
4136
4137
4138
4139
4140
4141
4142
4143
4144
4145
4146
4147
4148
4149
4150
4151
4152
4153
4154
4155
4156
4157
4158
4159
4160
4161
4162
4163
4164
4165
4166
4167
# File 'proto_docs/google/privacy/dlp/v2/dlp.rb', line 3969

class Action
  include ::Google::Protobuf::MessageExts
  extend ::Google::Protobuf::MessageExts::ClassMethods

  # If set, the detailed findings will be persisted to the specified
  # OutputStorageConfig. Only a single instance of this action can be
  # specified.
  # Compatible with: Inspect, Risk
  # @!attribute [rw] output_config
  #   @return [::Google::Cloud::Dlp::V2::OutputStorageConfig]
  #     Location to store findings outside of DLP.
  class SaveFindings
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish a message into a given Pub/Sub topic when DlpJob has completed. The
  # message contains a single field, `DlpJobName`, which is equal to the
  # finished job's
  # [`DlpJob.name`](https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/projects.dlpJobs#DlpJob).
  # Compatible with: Inspect, Risk
  # @!attribute [rw] topic
  #   @return [::String]
  #     Cloud Pub/Sub topic to send notifications to. The topic must have given
  #     publishing access rights to the DLP API service account executing
  #     the long running DlpJob sending the notifications.
  #     Format is projects/\\{project}/topics/\\{topic}.
  class PublishToPubSub
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish the result summary of a DlpJob to [Security Command
  # Center](https://cloud.google.com/security-command-center). This action is
  # available for only projects that belong to an organization. This action
  # publishes the count of finding instances and their infoTypes. The summary
  # of findings are persisted in Security Command Center and are governed by
  # [service-specific policies for Security Command
  # Center](https://cloud.google.com/terms/service-terms). Only a single
  # instance of this action can be specified. Compatible with: Inspect
  class PublishSummaryToCscc
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Data Catalog. In Data Catalog, tag
  # templates are applied to the resource that Cloud DLP scanned. Data
  # Catalog tag templates are stored in the same project and region where the
  # BigQuery table exists. For Cloud DLP to create and apply the tag template,
  # the Cloud DLP service agent must have the
  # `roles/datacatalog.tagTemplateOwner` permission on the project. The tag
  # template contains fields summarizing the results of the DlpJob. Any field
  # values previously written by another DlpJob are deleted. [InfoType naming
  # patterns][google.privacy.dlp.v2.InfoType] are strictly enforced when using
  # this feature.
  #
  # Findings are persisted in Data Catalog storage and are governed by
  # service-specific policies for Data Catalog. For more information, see
  # [Service Specific Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToCloudDataCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Dataplex Universal Catalog as a
  # `sensitive-data-protection-job-result` aspect. For more information,
  # see [Send inspection results to Dataplex Universal Catalog as
  # aspects](https://cloud.google.com/sensitive-data-protection/docs/add-aspects-inspection-job).
  #
  # Aspects are stored in Dataplex Universal Catalog storage and are
  # governed by service-specific policies for Dataplex Universal Catalog. For
  # more information, see [Service Specific
  # Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToDataplexCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Create a de-identified copy of a storage bucket. Only compatible
  # with Cloud Storage buckets.
  #
  #
  # A TransformationDetail will be created for each transformation.
  #
  #
  # Compatible with: Inspection of Cloud Storage
  # @!attribute [rw] transformation_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationConfig]
  #     User specified deidentify templates and configs for structured,
  #     unstructured, and image files.
  # @!attribute [rw] transformation_details_storage_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationDetailsStorageConfig]
  #     Config for storing transformation details.
  #
  #     This field specifies the configuration for storing detailed metadata
  #     about each transformation performed during a de-identification process.
  #     The metadata is stored separately from the de-identified content itself
  #     and provides a granular record of both successful transformations and any
  #     failures that occurred.
  #
  #     Enabling this configuration is essential for users who need to access
  #     comprehensive information about the status, outcome, and specifics of
  #     each transformation. The details are captured in the
  #     {::Google::Cloud::Dlp::V2::TransformationDetails TransformationDetails}
  #     message for each operation.
  #
  #     Key use cases:
  #
  #     * **Auditing and compliance**
  #         * Provides a verifiable audit trail of de-identification activities,
  #         which is crucial for meeting regulatory requirements and internal
  #         data governance policies.
  #         * Logs what data was transformed, what transformations were applied,
  #         when they occurred, and their success status. This helps
  #         demonstrate accountability and due diligence in protecting
  #         sensitive data.
  #
  #     * **Troubleshooting and debugging**
  #         * Offers detailed error messages and context if a transformation
  #         fails. This information is useful for diagnosing and resolving
  #         issues in the de-identification pipeline.
  #         * Helps pinpoint the exact location and nature of failures, speeding
  #         up the debugging process.
  #
  #     * **Process verification and quality assurance**
  #         * Allows users to confirm that de-identification rules and
  #         transformations were applied correctly and consistently across
  #         the dataset as intended.
  #         * Helps in verifying the effectiveness of the chosen
  #         de-identification strategies.
  #
  #     * **Data lineage and impact analysis**
  #         * Creates a record of how data elements were modified, contributing
  #         to data lineage. This is useful for understanding the provenance
  #         of de-identified data.
  #         * Aids in assessing the potential impact of de-identification choices
  #         on downstream analytical processes or data usability.
  #
  #     * **Reporting and operational insights**
  #         * You can analyze the metadata stored in a queryable BigQuery table
  #         to generate reports on transformation success rates, common
  #         error types, processing volumes (e.g., transformedBytes), and the
  #         types of transformations applied.
  #         * These insights can inform optimization of de-identification
  #         configurations and resource planning.
  #
  #     To take advantage of these benefits, set this configuration. The stored
  #     details include a description of the transformation, success or
  #     error codes, error messages, the number of bytes transformed, the
  #     location of the transformed content, and identifiers for the job and
  #     source data.
  # @!attribute [rw] cloud_storage_output
  #   @return [::String]
  #     Required. User settable Cloud Storage bucket and folders to store
  #     de-identified files. This field must be set for Cloud Storage
  #     deidentification. The output Cloud Storage bucket must be different
  #     from the input bucket. De-identified files will overwrite files in the
  #     output path.
  #
  #     Form of: gs://bucket/folder/ or gs://bucket
  # @!attribute [rw] file_types_to_transform
  #   @return [::Array<::Google::Cloud::Dlp::V2::FileType>]
  #     List of user-specified file type groups to transform. If specified, only
  #     the files with these file types are transformed. If empty, all
  #     supported files are transformed. Supported types may be automatically
  #     added over time. Any unsupported file types that are set in this field
  #     are excluded from de-identification. An error is recorded for each
  #     unsupported file in the TransformationDetails output table. Currently the
  #     only file types supported are: IMAGES, TEXT_FILES, CSV, TSV.
  class Deidentify
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Sends an email when the job completes. The email goes to IAM project owners
  # and technical [Essential
  # Contacts](https://cloud.google.com/resource-manager/docs/managing-notification-contacts).
  class JobNotificationEmails
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Enable Stackdriver metric dlp.googleapis.com/finding_count. This
  # will publish a metric to stack driver on each infotype requested and
  # how many findings were found for it. CustomDetectors will be bucketed
  # as 'Custom' under the Stackdriver label 'info_type'.
  class PublishToStackdriver
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end
end

#job_notification_emails::Google::Cloud::Dlp::V2::Action::JobNotificationEmails

Returns Sends an email when the job completes. The email goes to IAM project owners and technical Essential Contacts.

Note: The following fields are mutually exclusive: job_notification_emails, save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, deidentify, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.

Returns:

  • (::Google::Cloud::Dlp::V2::Action::JobNotificationEmails)

    Sends an email when the job completes. The email goes to IAM project owners and technical Essential Contacts.

    Note: The following fields are mutually exclusive: job_notification_emails, save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, deidentify, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.



3969
3970
3971
3972
3973
3974
3975
3976
3977
3978
3979
3980
3981
3982
3983
3984
3985
3986
3987
3988
3989
3990
3991
3992
3993
3994
3995
3996
3997
3998
3999
4000
4001
4002
4003
4004
4005
4006
4007
4008
4009
4010
4011
4012
4013
4014
4015
4016
4017
4018
4019
4020
4021
4022
4023
4024
4025
4026
4027
4028
4029
4030
4031
4032
4033
4034
4035
4036
4037
4038
4039
4040
4041
4042
4043
4044
4045
4046
4047
4048
4049
4050
4051
4052
4053
4054
4055
4056
4057
4058
4059
4060
4061
4062
4063
4064
4065
4066
4067
4068
4069
4070
4071
4072
4073
4074
4075
4076
4077
4078
4079
4080
4081
4082
4083
4084
4085
4086
4087
4088
4089
4090
4091
4092
4093
4094
4095
4096
4097
4098
4099
4100
4101
4102
4103
4104
4105
4106
4107
4108
4109
4110
4111
4112
4113
4114
4115
4116
4117
4118
4119
4120
4121
4122
4123
4124
4125
4126
4127
4128
4129
4130
4131
4132
4133
4134
4135
4136
4137
4138
4139
4140
4141
4142
4143
4144
4145
4146
4147
4148
4149
4150
4151
4152
4153
4154
4155
4156
4157
4158
4159
4160
4161
4162
4163
4164
4165
4166
4167
# File 'proto_docs/google/privacy/dlp/v2/dlp.rb', line 3969

class Action
  include ::Google::Protobuf::MessageExts
  extend ::Google::Protobuf::MessageExts::ClassMethods

  # If set, the detailed findings will be persisted to the specified
  # OutputStorageConfig. Only a single instance of this action can be
  # specified.
  # Compatible with: Inspect, Risk
  # @!attribute [rw] output_config
  #   @return [::Google::Cloud::Dlp::V2::OutputStorageConfig]
  #     Location to store findings outside of DLP.
  class SaveFindings
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish a message into a given Pub/Sub topic when DlpJob has completed. The
  # message contains a single field, `DlpJobName`, which is equal to the
  # finished job's
  # [`DlpJob.name`](https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/projects.dlpJobs#DlpJob).
  # Compatible with: Inspect, Risk
  # @!attribute [rw] topic
  #   @return [::String]
  #     Cloud Pub/Sub topic to send notifications to. The topic must have given
  #     publishing access rights to the DLP API service account executing
  #     the long running DlpJob sending the notifications.
  #     Format is projects/\\{project}/topics/\\{topic}.
  class PublishToPubSub
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish the result summary of a DlpJob to [Security Command
  # Center](https://cloud.google.com/security-command-center). This action is
  # available for only projects that belong to an organization. This action
  # publishes the count of finding instances and their infoTypes. The summary
  # of findings are persisted in Security Command Center and are governed by
  # [service-specific policies for Security Command
  # Center](https://cloud.google.com/terms/service-terms). Only a single
  # instance of this action can be specified. Compatible with: Inspect
  class PublishSummaryToCscc
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Data Catalog. In Data Catalog, tag
  # templates are applied to the resource that Cloud DLP scanned. Data
  # Catalog tag templates are stored in the same project and region where the
  # BigQuery table exists. For Cloud DLP to create and apply the tag template,
  # the Cloud DLP service agent must have the
  # `roles/datacatalog.tagTemplateOwner` permission on the project. The tag
  # template contains fields summarizing the results of the DlpJob. Any field
  # values previously written by another DlpJob are deleted. [InfoType naming
  # patterns][google.privacy.dlp.v2.InfoType] are strictly enforced when using
  # this feature.
  #
  # Findings are persisted in Data Catalog storage and are governed by
  # service-specific policies for Data Catalog. For more information, see
  # [Service Specific Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToCloudDataCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Dataplex Universal Catalog as a
  # `sensitive-data-protection-job-result` aspect. For more information,
  # see [Send inspection results to Dataplex Universal Catalog as
  # aspects](https://cloud.google.com/sensitive-data-protection/docs/add-aspects-inspection-job).
  #
  # Aspects are stored in Dataplex Universal Catalog storage and are
  # governed by service-specific policies for Dataplex Universal Catalog. For
  # more information, see [Service Specific
  # Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToDataplexCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Create a de-identified copy of a storage bucket. Only compatible
  # with Cloud Storage buckets.
  #
  #
  # A TransformationDetail will be created for each transformation.
  #
  #
  # Compatible with: Inspection of Cloud Storage
  # @!attribute [rw] transformation_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationConfig]
  #     User specified deidentify templates and configs for structured,
  #     unstructured, and image files.
  # @!attribute [rw] transformation_details_storage_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationDetailsStorageConfig]
  #     Config for storing transformation details.
  #
  #     This field specifies the configuration for storing detailed metadata
  #     about each transformation performed during a de-identification process.
  #     The metadata is stored separately from the de-identified content itself
  #     and provides a granular record of both successful transformations and any
  #     failures that occurred.
  #
  #     Enabling this configuration is essential for users who need to access
  #     comprehensive information about the status, outcome, and specifics of
  #     each transformation. The details are captured in the
  #     {::Google::Cloud::Dlp::V2::TransformationDetails TransformationDetails}
  #     message for each operation.
  #
  #     Key use cases:
  #
  #     * **Auditing and compliance**
  #         * Provides a verifiable audit trail of de-identification activities,
  #         which is crucial for meeting regulatory requirements and internal
  #         data governance policies.
  #         * Logs what data was transformed, what transformations were applied,
  #         when they occurred, and their success status. This helps
  #         demonstrate accountability and due diligence in protecting
  #         sensitive data.
  #
  #     * **Troubleshooting and debugging**
  #         * Offers detailed error messages and context if a transformation
  #         fails. This information is useful for diagnosing and resolving
  #         issues in the de-identification pipeline.
  #         * Helps pinpoint the exact location and nature of failures, speeding
  #         up the debugging process.
  #
  #     * **Process verification and quality assurance**
  #         * Allows users to confirm that de-identification rules and
  #         transformations were applied correctly and consistently across
  #         the dataset as intended.
  #         * Helps in verifying the effectiveness of the chosen
  #         de-identification strategies.
  #
  #     * **Data lineage and impact analysis**
  #         * Creates a record of how data elements were modified, contributing
  #         to data lineage. This is useful for understanding the provenance
  #         of de-identified data.
  #         * Aids in assessing the potential impact of de-identification choices
  #         on downstream analytical processes or data usability.
  #
  #     * **Reporting and operational insights**
  #         * You can analyze the metadata stored in a queryable BigQuery table
  #         to generate reports on transformation success rates, common
  #         error types, processing volumes (e.g., transformedBytes), and the
  #         types of transformations applied.
  #         * These insights can inform optimization of de-identification
  #         configurations and resource planning.
  #
  #     To take advantage of these benefits, set this configuration. The stored
  #     details include a description of the transformation, success or
  #     error codes, error messages, the number of bytes transformed, the
  #     location of the transformed content, and identifiers for the job and
  #     source data.
  # @!attribute [rw] cloud_storage_output
  #   @return [::String]
  #     Required. User settable Cloud Storage bucket and folders to store
  #     de-identified files. This field must be set for Cloud Storage
  #     deidentification. The output Cloud Storage bucket must be different
  #     from the input bucket. De-identified files will overwrite files in the
  #     output path.
  #
  #     Form of: gs://bucket/folder/ or gs://bucket
  # @!attribute [rw] file_types_to_transform
  #   @return [::Array<::Google::Cloud::Dlp::V2::FileType>]
  #     List of user-specified file type groups to transform. If specified, only
  #     the files with these file types are transformed. If empty, all
  #     supported files are transformed. Supported types may be automatically
  #     added over time. Any unsupported file types that are set in this field
  #     are excluded from de-identification. An error is recorded for each
  #     unsupported file in the TransformationDetails output table. Currently the
  #     only file types supported are: IMAGES, TEXT_FILES, CSV, TSV.
  class Deidentify
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Sends an email when the job completes. The email goes to IAM project owners
  # and technical [Essential
  # Contacts](https://cloud.google.com/resource-manager/docs/managing-notification-contacts).
  class JobNotificationEmails
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Enable Stackdriver metric dlp.googleapis.com/finding_count. This
  # will publish a metric to stack driver on each infotype requested and
  # how many findings were found for it. CustomDetectors will be bucketed
  # as 'Custom' under the Stackdriver label 'info_type'.
  class PublishToStackdriver
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end
end

#pub_sub::Google::Cloud::Dlp::V2::Action::PublishToPubSub

Returns Publish a notification to a Pub/Sub topic.

Note: The following fields are mutually exclusive: pub_sub, save_findings, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, deidentify, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.

Returns:

  • (::Google::Cloud::Dlp::V2::Action::PublishToPubSub)

    Publish a notification to a Pub/Sub topic.

    Note: The following fields are mutually exclusive: pub_sub, save_findings, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, deidentify, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.



3969
3970
3971
3972
3973
3974
3975
3976
3977
3978
3979
3980
3981
3982
3983
3984
3985
3986
3987
3988
3989
3990
3991
3992
3993
3994
3995
3996
3997
3998
3999
4000
4001
4002
4003
4004
4005
4006
4007
4008
4009
4010
4011
4012
4013
4014
4015
4016
4017
4018
4019
4020
4021
4022
4023
4024
4025
4026
4027
4028
4029
4030
4031
4032
4033
4034
4035
4036
4037
4038
4039
4040
4041
4042
4043
4044
4045
4046
4047
4048
4049
4050
4051
4052
4053
4054
4055
4056
4057
4058
4059
4060
4061
4062
4063
4064
4065
4066
4067
4068
4069
4070
4071
4072
4073
4074
4075
4076
4077
4078
4079
4080
4081
4082
4083
4084
4085
4086
4087
4088
4089
4090
4091
4092
4093
4094
4095
4096
4097
4098
4099
4100
4101
4102
4103
4104
4105
4106
4107
4108
4109
4110
4111
4112
4113
4114
4115
4116
4117
4118
4119
4120
4121
4122
4123
4124
4125
4126
4127
4128
4129
4130
4131
4132
4133
4134
4135
4136
4137
4138
4139
4140
4141
4142
4143
4144
4145
4146
4147
4148
4149
4150
4151
4152
4153
4154
4155
4156
4157
4158
4159
4160
4161
4162
4163
4164
4165
4166
4167
# File 'proto_docs/google/privacy/dlp/v2/dlp.rb', line 3969

class Action
  include ::Google::Protobuf::MessageExts
  extend ::Google::Protobuf::MessageExts::ClassMethods

  # If set, the detailed findings will be persisted to the specified
  # OutputStorageConfig. Only a single instance of this action can be
  # specified.
  # Compatible with: Inspect, Risk
  # @!attribute [rw] output_config
  #   @return [::Google::Cloud::Dlp::V2::OutputStorageConfig]
  #     Location to store findings outside of DLP.
  class SaveFindings
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish a message into a given Pub/Sub topic when DlpJob has completed. The
  # message contains a single field, `DlpJobName`, which is equal to the
  # finished job's
  # [`DlpJob.name`](https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/projects.dlpJobs#DlpJob).
  # Compatible with: Inspect, Risk
  # @!attribute [rw] topic
  #   @return [::String]
  #     Cloud Pub/Sub topic to send notifications to. The topic must have given
  #     publishing access rights to the DLP API service account executing
  #     the long running DlpJob sending the notifications.
  #     Format is projects/\\{project}/topics/\\{topic}.
  class PublishToPubSub
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish the result summary of a DlpJob to [Security Command
  # Center](https://cloud.google.com/security-command-center). This action is
  # available for only projects that belong to an organization. This action
  # publishes the count of finding instances and their infoTypes. The summary
  # of findings are persisted in Security Command Center and are governed by
  # [service-specific policies for Security Command
  # Center](https://cloud.google.com/terms/service-terms). Only a single
  # instance of this action can be specified. Compatible with: Inspect
  class PublishSummaryToCscc
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Data Catalog. In Data Catalog, tag
  # templates are applied to the resource that Cloud DLP scanned. Data
  # Catalog tag templates are stored in the same project and region where the
  # BigQuery table exists. For Cloud DLP to create and apply the tag template,
  # the Cloud DLP service agent must have the
  # `roles/datacatalog.tagTemplateOwner` permission on the project. The tag
  # template contains fields summarizing the results of the DlpJob. Any field
  # values previously written by another DlpJob are deleted. [InfoType naming
  # patterns][google.privacy.dlp.v2.InfoType] are strictly enforced when using
  # this feature.
  #
  # Findings are persisted in Data Catalog storage and are governed by
  # service-specific policies for Data Catalog. For more information, see
  # [Service Specific Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToCloudDataCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Dataplex Universal Catalog as a
  # `sensitive-data-protection-job-result` aspect. For more information,
  # see [Send inspection results to Dataplex Universal Catalog as
  # aspects](https://cloud.google.com/sensitive-data-protection/docs/add-aspects-inspection-job).
  #
  # Aspects are stored in Dataplex Universal Catalog storage and are
  # governed by service-specific policies for Dataplex Universal Catalog. For
  # more information, see [Service Specific
  # Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToDataplexCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Create a de-identified copy of a storage bucket. Only compatible
  # with Cloud Storage buckets.
  #
  #
  # A TransformationDetail will be created for each transformation.
  #
  #
  # Compatible with: Inspection of Cloud Storage
  # @!attribute [rw] transformation_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationConfig]
  #     User specified deidentify templates and configs for structured,
  #     unstructured, and image files.
  # @!attribute [rw] transformation_details_storage_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationDetailsStorageConfig]
  #     Config for storing transformation details.
  #
  #     This field specifies the configuration for storing detailed metadata
  #     about each transformation performed during a de-identification process.
  #     The metadata is stored separately from the de-identified content itself
  #     and provides a granular record of both successful transformations and any
  #     failures that occurred.
  #
  #     Enabling this configuration is essential for users who need to access
  #     comprehensive information about the status, outcome, and specifics of
  #     each transformation. The details are captured in the
  #     {::Google::Cloud::Dlp::V2::TransformationDetails TransformationDetails}
  #     message for each operation.
  #
  #     Key use cases:
  #
  #     * **Auditing and compliance**
  #         * Provides a verifiable audit trail of de-identification activities,
  #         which is crucial for meeting regulatory requirements and internal
  #         data governance policies.
  #         * Logs what data was transformed, what transformations were applied,
  #         when they occurred, and their success status. This helps
  #         demonstrate accountability and due diligence in protecting
  #         sensitive data.
  #
  #     * **Troubleshooting and debugging**
  #         * Offers detailed error messages and context if a transformation
  #         fails. This information is useful for diagnosing and resolving
  #         issues in the de-identification pipeline.
  #         * Helps pinpoint the exact location and nature of failures, speeding
  #         up the debugging process.
  #
  #     * **Process verification and quality assurance**
  #         * Allows users to confirm that de-identification rules and
  #         transformations were applied correctly and consistently across
  #         the dataset as intended.
  #         * Helps in verifying the effectiveness of the chosen
  #         de-identification strategies.
  #
  #     * **Data lineage and impact analysis**
  #         * Creates a record of how data elements were modified, contributing
  #         to data lineage. This is useful for understanding the provenance
  #         of de-identified data.
  #         * Aids in assessing the potential impact of de-identification choices
  #         on downstream analytical processes or data usability.
  #
  #     * **Reporting and operational insights**
  #         * You can analyze the metadata stored in a queryable BigQuery table
  #         to generate reports on transformation success rates, common
  #         error types, processing volumes (e.g., transformedBytes), and the
  #         types of transformations applied.
  #         * These insights can inform optimization of de-identification
  #         configurations and resource planning.
  #
  #     To take advantage of these benefits, set this configuration. The stored
  #     details include a description of the transformation, success or
  #     error codes, error messages, the number of bytes transformed, the
  #     location of the transformed content, and identifiers for the job and
  #     source data.
  # @!attribute [rw] cloud_storage_output
  #   @return [::String]
  #     Required. User settable Cloud Storage bucket and folders to store
  #     de-identified files. This field must be set for Cloud Storage
  #     deidentification. The output Cloud Storage bucket must be different
  #     from the input bucket. De-identified files will overwrite files in the
  #     output path.
  #
  #     Form of: gs://bucket/folder/ or gs://bucket
  # @!attribute [rw] file_types_to_transform
  #   @return [::Array<::Google::Cloud::Dlp::V2::FileType>]
  #     List of user-specified file type groups to transform. If specified, only
  #     the files with these file types are transformed. If empty, all
  #     supported files are transformed. Supported types may be automatically
  #     added over time. Any unsupported file types that are set in this field
  #     are excluded from de-identification. An error is recorded for each
  #     unsupported file in the TransformationDetails output table. Currently the
  #     only file types supported are: IMAGES, TEXT_FILES, CSV, TSV.
  class Deidentify
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Sends an email when the job completes. The email goes to IAM project owners
  # and technical [Essential
  # Contacts](https://cloud.google.com/resource-manager/docs/managing-notification-contacts).
  class JobNotificationEmails
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Enable Stackdriver metric dlp.googleapis.com/finding_count. This
  # will publish a metric to stack driver on each infotype requested and
  # how many findings were found for it. CustomDetectors will be bucketed
  # as 'Custom' under the Stackdriver label 'info_type'.
  class PublishToStackdriver
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end
end

#publish_findings_to_cloud_data_catalog::Google::Cloud::Dlp::V2::Action::PublishFindingsToCloudDataCatalog

Deprecated.

This field is deprecated and may be removed in the next major version update.

Returns Deprecated because Data Catalog is being turned down. Use publish_findings_to_dataplex_catalog to publish findings to Dataplex Universal Catalog.

Note: The following fields are mutually exclusive: publish_findings_to_cloud_data_catalog, save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_dataplex_catalog, deidentify, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.

Returns:

  • (::Google::Cloud::Dlp::V2::Action::PublishFindingsToCloudDataCatalog)

    Deprecated because Data Catalog is being turned down. Use publish_findings_to_dataplex_catalog to publish findings to Dataplex Universal Catalog.

    Note: The following fields are mutually exclusive: publish_findings_to_cloud_data_catalog, save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_dataplex_catalog, deidentify, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.



3969
3970
3971
3972
3973
3974
3975
3976
3977
3978
3979
3980
3981
3982
3983
3984
3985
3986
3987
3988
3989
3990
3991
3992
3993
3994
3995
3996
3997
3998
3999
4000
4001
4002
4003
4004
4005
4006
4007
4008
4009
4010
4011
4012
4013
4014
4015
4016
4017
4018
4019
4020
4021
4022
4023
4024
4025
4026
4027
4028
4029
4030
4031
4032
4033
4034
4035
4036
4037
4038
4039
4040
4041
4042
4043
4044
4045
4046
4047
4048
4049
4050
4051
4052
4053
4054
4055
4056
4057
4058
4059
4060
4061
4062
4063
4064
4065
4066
4067
4068
4069
4070
4071
4072
4073
4074
4075
4076
4077
4078
4079
4080
4081
4082
4083
4084
4085
4086
4087
4088
4089
4090
4091
4092
4093
4094
4095
4096
4097
4098
4099
4100
4101
4102
4103
4104
4105
4106
4107
4108
4109
4110
4111
4112
4113
4114
4115
4116
4117
4118
4119
4120
4121
4122
4123
4124
4125
4126
4127
4128
4129
4130
4131
4132
4133
4134
4135
4136
4137
4138
4139
4140
4141
4142
4143
4144
4145
4146
4147
4148
4149
4150
4151
4152
4153
4154
4155
4156
4157
4158
4159
4160
4161
4162
4163
4164
4165
4166
4167
# File 'proto_docs/google/privacy/dlp/v2/dlp.rb', line 3969

class Action
  include ::Google::Protobuf::MessageExts
  extend ::Google::Protobuf::MessageExts::ClassMethods

  # If set, the detailed findings will be persisted to the specified
  # OutputStorageConfig. Only a single instance of this action can be
  # specified.
  # Compatible with: Inspect, Risk
  # @!attribute [rw] output_config
  #   @return [::Google::Cloud::Dlp::V2::OutputStorageConfig]
  #     Location to store findings outside of DLP.
  class SaveFindings
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish a message into a given Pub/Sub topic when DlpJob has completed. The
  # message contains a single field, `DlpJobName`, which is equal to the
  # finished job's
  # [`DlpJob.name`](https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/projects.dlpJobs#DlpJob).
  # Compatible with: Inspect, Risk
  # @!attribute [rw] topic
  #   @return [::String]
  #     Cloud Pub/Sub topic to send notifications to. The topic must have given
  #     publishing access rights to the DLP API service account executing
  #     the long running DlpJob sending the notifications.
  #     Format is projects/\\{project}/topics/\\{topic}.
  class PublishToPubSub
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish the result summary of a DlpJob to [Security Command
  # Center](https://cloud.google.com/security-command-center). This action is
  # available for only projects that belong to an organization. This action
  # publishes the count of finding instances and their infoTypes. The summary
  # of findings are persisted in Security Command Center and are governed by
  # [service-specific policies for Security Command
  # Center](https://cloud.google.com/terms/service-terms). Only a single
  # instance of this action can be specified. Compatible with: Inspect
  class PublishSummaryToCscc
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Data Catalog. In Data Catalog, tag
  # templates are applied to the resource that Cloud DLP scanned. Data
  # Catalog tag templates are stored in the same project and region where the
  # BigQuery table exists. For Cloud DLP to create and apply the tag template,
  # the Cloud DLP service agent must have the
  # `roles/datacatalog.tagTemplateOwner` permission on the project. The tag
  # template contains fields summarizing the results of the DlpJob. Any field
  # values previously written by another DlpJob are deleted. [InfoType naming
  # patterns][google.privacy.dlp.v2.InfoType] are strictly enforced when using
  # this feature.
  #
  # Findings are persisted in Data Catalog storage and are governed by
  # service-specific policies for Data Catalog. For more information, see
  # [Service Specific Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToCloudDataCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Dataplex Universal Catalog as a
  # `sensitive-data-protection-job-result` aspect. For more information,
  # see [Send inspection results to Dataplex Universal Catalog as
  # aspects](https://cloud.google.com/sensitive-data-protection/docs/add-aspects-inspection-job).
  #
  # Aspects are stored in Dataplex Universal Catalog storage and are
  # governed by service-specific policies for Dataplex Universal Catalog. For
  # more information, see [Service Specific
  # Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToDataplexCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Create a de-identified copy of a storage bucket. Only compatible
  # with Cloud Storage buckets.
  #
  #
  # A TransformationDetail will be created for each transformation.
  #
  #
  # Compatible with: Inspection of Cloud Storage
  # @!attribute [rw] transformation_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationConfig]
  #     User specified deidentify templates and configs for structured,
  #     unstructured, and image files.
  # @!attribute [rw] transformation_details_storage_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationDetailsStorageConfig]
  #     Config for storing transformation details.
  #
  #     This field specifies the configuration for storing detailed metadata
  #     about each transformation performed during a de-identification process.
  #     The metadata is stored separately from the de-identified content itself
  #     and provides a granular record of both successful transformations and any
  #     failures that occurred.
  #
  #     Enabling this configuration is essential for users who need to access
  #     comprehensive information about the status, outcome, and specifics of
  #     each transformation. The details are captured in the
  #     {::Google::Cloud::Dlp::V2::TransformationDetails TransformationDetails}
  #     message for each operation.
  #
  #     Key use cases:
  #
  #     * **Auditing and compliance**
  #         * Provides a verifiable audit trail of de-identification activities,
  #         which is crucial for meeting regulatory requirements and internal
  #         data governance policies.
  #         * Logs what data was transformed, what transformations were applied,
  #         when they occurred, and their success status. This helps
  #         demonstrate accountability and due diligence in protecting
  #         sensitive data.
  #
  #     * **Troubleshooting and debugging**
  #         * Offers detailed error messages and context if a transformation
  #         fails. This information is useful for diagnosing and resolving
  #         issues in the de-identification pipeline.
  #         * Helps pinpoint the exact location and nature of failures, speeding
  #         up the debugging process.
  #
  #     * **Process verification and quality assurance**
  #         * Allows users to confirm that de-identification rules and
  #         transformations were applied correctly and consistently across
  #         the dataset as intended.
  #         * Helps in verifying the effectiveness of the chosen
  #         de-identification strategies.
  #
  #     * **Data lineage and impact analysis**
  #         * Creates a record of how data elements were modified, contributing
  #         to data lineage. This is useful for understanding the provenance
  #         of de-identified data.
  #         * Aids in assessing the potential impact of de-identification choices
  #         on downstream analytical processes or data usability.
  #
  #     * **Reporting and operational insights**
  #         * You can analyze the metadata stored in a queryable BigQuery table
  #         to generate reports on transformation success rates, common
  #         error types, processing volumes (e.g., transformedBytes), and the
  #         types of transformations applied.
  #         * These insights can inform optimization of de-identification
  #         configurations and resource planning.
  #
  #     To take advantage of these benefits, set this configuration. The stored
  #     details include a description of the transformation, success or
  #     error codes, error messages, the number of bytes transformed, the
  #     location of the transformed content, and identifiers for the job and
  #     source data.
  # @!attribute [rw] cloud_storage_output
  #   @return [::String]
  #     Required. User settable Cloud Storage bucket and folders to store
  #     de-identified files. This field must be set for Cloud Storage
  #     deidentification. The output Cloud Storage bucket must be different
  #     from the input bucket. De-identified files will overwrite files in the
  #     output path.
  #
  #     Form of: gs://bucket/folder/ or gs://bucket
  # @!attribute [rw] file_types_to_transform
  #   @return [::Array<::Google::Cloud::Dlp::V2::FileType>]
  #     List of user-specified file type groups to transform. If specified, only
  #     the files with these file types are transformed. If empty, all
  #     supported files are transformed. Supported types may be automatically
  #     added over time. Any unsupported file types that are set in this field
  #     are excluded from de-identification. An error is recorded for each
  #     unsupported file in the TransformationDetails output table. Currently the
  #     only file types supported are: IMAGES, TEXT_FILES, CSV, TSV.
  class Deidentify
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Sends an email when the job completes. The email goes to IAM project owners
  # and technical [Essential
  # Contacts](https://cloud.google.com/resource-manager/docs/managing-notification-contacts).
  class JobNotificationEmails
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Enable Stackdriver metric dlp.googleapis.com/finding_count. This
  # will publish a metric to stack driver on each infotype requested and
  # how many findings were found for it. CustomDetectors will be bucketed
  # as 'Custom' under the Stackdriver label 'info_type'.
  class PublishToStackdriver
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end
end

#publish_findings_to_dataplex_catalog::Google::Cloud::Dlp::V2::Action::PublishFindingsToDataplexCatalog

Returns Publish findings as an aspect to Dataplex Universal Catalog.

Note: The following fields are mutually exclusive: publish_findings_to_dataplex_catalog, save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, deidentify, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.

Returns:

  • (::Google::Cloud::Dlp::V2::Action::PublishFindingsToDataplexCatalog)

    Publish findings as an aspect to Dataplex Universal Catalog.

    Note: The following fields are mutually exclusive: publish_findings_to_dataplex_catalog, save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, deidentify, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.



3969
3970
3971
3972
3973
3974
3975
3976
3977
3978
3979
3980
3981
3982
3983
3984
3985
3986
3987
3988
3989
3990
3991
3992
3993
3994
3995
3996
3997
3998
3999
4000
4001
4002
4003
4004
4005
4006
4007
4008
4009
4010
4011
4012
4013
4014
4015
4016
4017
4018
4019
4020
4021
4022
4023
4024
4025
4026
4027
4028
4029
4030
4031
4032
4033
4034
4035
4036
4037
4038
4039
4040
4041
4042
4043
4044
4045
4046
4047
4048
4049
4050
4051
4052
4053
4054
4055
4056
4057
4058
4059
4060
4061
4062
4063
4064
4065
4066
4067
4068
4069
4070
4071
4072
4073
4074
4075
4076
4077
4078
4079
4080
4081
4082
4083
4084
4085
4086
4087
4088
4089
4090
4091
4092
4093
4094
4095
4096
4097
4098
4099
4100
4101
4102
4103
4104
4105
4106
4107
4108
4109
4110
4111
4112
4113
4114
4115
4116
4117
4118
4119
4120
4121
4122
4123
4124
4125
4126
4127
4128
4129
4130
4131
4132
4133
4134
4135
4136
4137
4138
4139
4140
4141
4142
4143
4144
4145
4146
4147
4148
4149
4150
4151
4152
4153
4154
4155
4156
4157
4158
4159
4160
4161
4162
4163
4164
4165
4166
4167
# File 'proto_docs/google/privacy/dlp/v2/dlp.rb', line 3969

class Action
  include ::Google::Protobuf::MessageExts
  extend ::Google::Protobuf::MessageExts::ClassMethods

  # If set, the detailed findings will be persisted to the specified
  # OutputStorageConfig. Only a single instance of this action can be
  # specified.
  # Compatible with: Inspect, Risk
  # @!attribute [rw] output_config
  #   @return [::Google::Cloud::Dlp::V2::OutputStorageConfig]
  #     Location to store findings outside of DLP.
  class SaveFindings
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish a message into a given Pub/Sub topic when DlpJob has completed. The
  # message contains a single field, `DlpJobName`, which is equal to the
  # finished job's
  # [`DlpJob.name`](https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/projects.dlpJobs#DlpJob).
  # Compatible with: Inspect, Risk
  # @!attribute [rw] topic
  #   @return [::String]
  #     Cloud Pub/Sub topic to send notifications to. The topic must have given
  #     publishing access rights to the DLP API service account executing
  #     the long running DlpJob sending the notifications.
  #     Format is projects/\\{project}/topics/\\{topic}.
  class PublishToPubSub
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish the result summary of a DlpJob to [Security Command
  # Center](https://cloud.google.com/security-command-center). This action is
  # available for only projects that belong to an organization. This action
  # publishes the count of finding instances and their infoTypes. The summary
  # of findings are persisted in Security Command Center and are governed by
  # [service-specific policies for Security Command
  # Center](https://cloud.google.com/terms/service-terms). Only a single
  # instance of this action can be specified. Compatible with: Inspect
  class PublishSummaryToCscc
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Data Catalog. In Data Catalog, tag
  # templates are applied to the resource that Cloud DLP scanned. Data
  # Catalog tag templates are stored in the same project and region where the
  # BigQuery table exists. For Cloud DLP to create and apply the tag template,
  # the Cloud DLP service agent must have the
  # `roles/datacatalog.tagTemplateOwner` permission on the project. The tag
  # template contains fields summarizing the results of the DlpJob. Any field
  # values previously written by another DlpJob are deleted. [InfoType naming
  # patterns][google.privacy.dlp.v2.InfoType] are strictly enforced when using
  # this feature.
  #
  # Findings are persisted in Data Catalog storage and are governed by
  # service-specific policies for Data Catalog. For more information, see
  # [Service Specific Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToCloudDataCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Dataplex Universal Catalog as a
  # `sensitive-data-protection-job-result` aspect. For more information,
  # see [Send inspection results to Dataplex Universal Catalog as
  # aspects](https://cloud.google.com/sensitive-data-protection/docs/add-aspects-inspection-job).
  #
  # Aspects are stored in Dataplex Universal Catalog storage and are
  # governed by service-specific policies for Dataplex Universal Catalog. For
  # more information, see [Service Specific
  # Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToDataplexCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Create a de-identified copy of a storage bucket. Only compatible
  # with Cloud Storage buckets.
  #
  #
  # A TransformationDetail will be created for each transformation.
  #
  #
  # Compatible with: Inspection of Cloud Storage
  # @!attribute [rw] transformation_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationConfig]
  #     User specified deidentify templates and configs for structured,
  #     unstructured, and image files.
  # @!attribute [rw] transformation_details_storage_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationDetailsStorageConfig]
  #     Config for storing transformation details.
  #
  #     This field specifies the configuration for storing detailed metadata
  #     about each transformation performed during a de-identification process.
  #     The metadata is stored separately from the de-identified content itself
  #     and provides a granular record of both successful transformations and any
  #     failures that occurred.
  #
  #     Enabling this configuration is essential for users who need to access
  #     comprehensive information about the status, outcome, and specifics of
  #     each transformation. The details are captured in the
  #     {::Google::Cloud::Dlp::V2::TransformationDetails TransformationDetails}
  #     message for each operation.
  #
  #     Key use cases:
  #
  #     * **Auditing and compliance**
  #         * Provides a verifiable audit trail of de-identification activities,
  #         which is crucial for meeting regulatory requirements and internal
  #         data governance policies.
  #         * Logs what data was transformed, what transformations were applied,
  #         when they occurred, and their success status. This helps
  #         demonstrate accountability and due diligence in protecting
  #         sensitive data.
  #
  #     * **Troubleshooting and debugging**
  #         * Offers detailed error messages and context if a transformation
  #         fails. This information is useful for diagnosing and resolving
  #         issues in the de-identification pipeline.
  #         * Helps pinpoint the exact location and nature of failures, speeding
  #         up the debugging process.
  #
  #     * **Process verification and quality assurance**
  #         * Allows users to confirm that de-identification rules and
  #         transformations were applied correctly and consistently across
  #         the dataset as intended.
  #         * Helps in verifying the effectiveness of the chosen
  #         de-identification strategies.
  #
  #     * **Data lineage and impact analysis**
  #         * Creates a record of how data elements were modified, contributing
  #         to data lineage. This is useful for understanding the provenance
  #         of de-identified data.
  #         * Aids in assessing the potential impact of de-identification choices
  #         on downstream analytical processes or data usability.
  #
  #     * **Reporting and operational insights**
  #         * You can analyze the metadata stored in a queryable BigQuery table
  #         to generate reports on transformation success rates, common
  #         error types, processing volumes (e.g., transformedBytes), and the
  #         types of transformations applied.
  #         * These insights can inform optimization of de-identification
  #         configurations and resource planning.
  #
  #     To take advantage of these benefits, set this configuration. The stored
  #     details include a description of the transformation, success or
  #     error codes, error messages, the number of bytes transformed, the
  #     location of the transformed content, and identifiers for the job and
  #     source data.
  # @!attribute [rw] cloud_storage_output
  #   @return [::String]
  #     Required. User settable Cloud Storage bucket and folders to store
  #     de-identified files. This field must be set for Cloud Storage
  #     deidentification. The output Cloud Storage bucket must be different
  #     from the input bucket. De-identified files will overwrite files in the
  #     output path.
  #
  #     Form of: gs://bucket/folder/ or gs://bucket
  # @!attribute [rw] file_types_to_transform
  #   @return [::Array<::Google::Cloud::Dlp::V2::FileType>]
  #     List of user-specified file type groups to transform. If specified, only
  #     the files with these file types are transformed. If empty, all
  #     supported files are transformed. Supported types may be automatically
  #     added over time. Any unsupported file types that are set in this field
  #     are excluded from de-identification. An error is recorded for each
  #     unsupported file in the TransformationDetails output table. Currently the
  #     only file types supported are: IMAGES, TEXT_FILES, CSV, TSV.
  class Deidentify
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Sends an email when the job completes. The email goes to IAM project owners
  # and technical [Essential
  # Contacts](https://cloud.google.com/resource-manager/docs/managing-notification-contacts).
  class JobNotificationEmails
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Enable Stackdriver metric dlp.googleapis.com/finding_count. This
  # will publish a metric to stack driver on each infotype requested and
  # how many findings were found for it. CustomDetectors will be bucketed
  # as 'Custom' under the Stackdriver label 'info_type'.
  class PublishToStackdriver
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end
end

#publish_summary_to_cscc::Google::Cloud::Dlp::V2::Action::PublishSummaryToCscc

Returns Publish summary to Cloud Security Command Center (Alpha).

Note: The following fields are mutually exclusive: publish_summary_to_cscc, save_findings, pub_sub, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, deidentify, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.

Returns:

  • (::Google::Cloud::Dlp::V2::Action::PublishSummaryToCscc)

    Publish summary to Cloud Security Command Center (Alpha).

    Note: The following fields are mutually exclusive: publish_summary_to_cscc, save_findings, pub_sub, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, deidentify, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.



3969
3970
3971
3972
3973
3974
3975
3976
3977
3978
3979
3980
3981
3982
3983
3984
3985
3986
3987
3988
3989
3990
3991
3992
3993
3994
3995
3996
3997
3998
3999
4000
4001
4002
4003
4004
4005
4006
4007
4008
4009
4010
4011
4012
4013
4014
4015
4016
4017
4018
4019
4020
4021
4022
4023
4024
4025
4026
4027
4028
4029
4030
4031
4032
4033
4034
4035
4036
4037
4038
4039
4040
4041
4042
4043
4044
4045
4046
4047
4048
4049
4050
4051
4052
4053
4054
4055
4056
4057
4058
4059
4060
4061
4062
4063
4064
4065
4066
4067
4068
4069
4070
4071
4072
4073
4074
4075
4076
4077
4078
4079
4080
4081
4082
4083
4084
4085
4086
4087
4088
4089
4090
4091
4092
4093
4094
4095
4096
4097
4098
4099
4100
4101
4102
4103
4104
4105
4106
4107
4108
4109
4110
4111
4112
4113
4114
4115
4116
4117
4118
4119
4120
4121
4122
4123
4124
4125
4126
4127
4128
4129
4130
4131
4132
4133
4134
4135
4136
4137
4138
4139
4140
4141
4142
4143
4144
4145
4146
4147
4148
4149
4150
4151
4152
4153
4154
4155
4156
4157
4158
4159
4160
4161
4162
4163
4164
4165
4166
4167
# File 'proto_docs/google/privacy/dlp/v2/dlp.rb', line 3969

class Action
  include ::Google::Protobuf::MessageExts
  extend ::Google::Protobuf::MessageExts::ClassMethods

  # If set, the detailed findings will be persisted to the specified
  # OutputStorageConfig. Only a single instance of this action can be
  # specified.
  # Compatible with: Inspect, Risk
  # @!attribute [rw] output_config
  #   @return [::Google::Cloud::Dlp::V2::OutputStorageConfig]
  #     Location to store findings outside of DLP.
  class SaveFindings
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish a message into a given Pub/Sub topic when DlpJob has completed. The
  # message contains a single field, `DlpJobName`, which is equal to the
  # finished job's
  # [`DlpJob.name`](https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/projects.dlpJobs#DlpJob).
  # Compatible with: Inspect, Risk
  # @!attribute [rw] topic
  #   @return [::String]
  #     Cloud Pub/Sub topic to send notifications to. The topic must have given
  #     publishing access rights to the DLP API service account executing
  #     the long running DlpJob sending the notifications.
  #     Format is projects/\\{project}/topics/\\{topic}.
  class PublishToPubSub
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish the result summary of a DlpJob to [Security Command
  # Center](https://cloud.google.com/security-command-center). This action is
  # available for only projects that belong to an organization. This action
  # publishes the count of finding instances and their infoTypes. The summary
  # of findings are persisted in Security Command Center and are governed by
  # [service-specific policies for Security Command
  # Center](https://cloud.google.com/terms/service-terms). Only a single
  # instance of this action can be specified. Compatible with: Inspect
  class PublishSummaryToCscc
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Data Catalog. In Data Catalog, tag
  # templates are applied to the resource that Cloud DLP scanned. Data
  # Catalog tag templates are stored in the same project and region where the
  # BigQuery table exists. For Cloud DLP to create and apply the tag template,
  # the Cloud DLP service agent must have the
  # `roles/datacatalog.tagTemplateOwner` permission on the project. The tag
  # template contains fields summarizing the results of the DlpJob. Any field
  # values previously written by another DlpJob are deleted. [InfoType naming
  # patterns][google.privacy.dlp.v2.InfoType] are strictly enforced when using
  # this feature.
  #
  # Findings are persisted in Data Catalog storage and are governed by
  # service-specific policies for Data Catalog. For more information, see
  # [Service Specific Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToCloudDataCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Dataplex Universal Catalog as a
  # `sensitive-data-protection-job-result` aspect. For more information,
  # see [Send inspection results to Dataplex Universal Catalog as
  # aspects](https://cloud.google.com/sensitive-data-protection/docs/add-aspects-inspection-job).
  #
  # Aspects are stored in Dataplex Universal Catalog storage and are
  # governed by service-specific policies for Dataplex Universal Catalog. For
  # more information, see [Service Specific
  # Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToDataplexCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Create a de-identified copy of a storage bucket. Only compatible
  # with Cloud Storage buckets.
  #
  #
  # A TransformationDetail will be created for each transformation.
  #
  #
  # Compatible with: Inspection of Cloud Storage
  # @!attribute [rw] transformation_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationConfig]
  #     User specified deidentify templates and configs for structured,
  #     unstructured, and image files.
  # @!attribute [rw] transformation_details_storage_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationDetailsStorageConfig]
  #     Config for storing transformation details.
  #
  #     This field specifies the configuration for storing detailed metadata
  #     about each transformation performed during a de-identification process.
  #     The metadata is stored separately from the de-identified content itself
  #     and provides a granular record of both successful transformations and any
  #     failures that occurred.
  #
  #     Enabling this configuration is essential for users who need to access
  #     comprehensive information about the status, outcome, and specifics of
  #     each transformation. The details are captured in the
  #     {::Google::Cloud::Dlp::V2::TransformationDetails TransformationDetails}
  #     message for each operation.
  #
  #     Key use cases:
  #
  #     * **Auditing and compliance**
  #         * Provides a verifiable audit trail of de-identification activities,
  #         which is crucial for meeting regulatory requirements and internal
  #         data governance policies.
  #         * Logs what data was transformed, what transformations were applied,
  #         when they occurred, and their success status. This helps
  #         demonstrate accountability and due diligence in protecting
  #         sensitive data.
  #
  #     * **Troubleshooting and debugging**
  #         * Offers detailed error messages and context if a transformation
  #         fails. This information is useful for diagnosing and resolving
  #         issues in the de-identification pipeline.
  #         * Helps pinpoint the exact location and nature of failures, speeding
  #         up the debugging process.
  #
  #     * **Process verification and quality assurance**
  #         * Allows users to confirm that de-identification rules and
  #         transformations were applied correctly and consistently across
  #         the dataset as intended.
  #         * Helps in verifying the effectiveness of the chosen
  #         de-identification strategies.
  #
  #     * **Data lineage and impact analysis**
  #         * Creates a record of how data elements were modified, contributing
  #         to data lineage. This is useful for understanding the provenance
  #         of de-identified data.
  #         * Aids in assessing the potential impact of de-identification choices
  #         on downstream analytical processes or data usability.
  #
  #     * **Reporting and operational insights**
  #         * You can analyze the metadata stored in a queryable BigQuery table
  #         to generate reports on transformation success rates, common
  #         error types, processing volumes (e.g., transformedBytes), and the
  #         types of transformations applied.
  #         * These insights can inform optimization of de-identification
  #         configurations and resource planning.
  #
  #     To take advantage of these benefits, set this configuration. The stored
  #     details include a description of the transformation, success or
  #     error codes, error messages, the number of bytes transformed, the
  #     location of the transformed content, and identifiers for the job and
  #     source data.
  # @!attribute [rw] cloud_storage_output
  #   @return [::String]
  #     Required. User settable Cloud Storage bucket and folders to store
  #     de-identified files. This field must be set for Cloud Storage
  #     deidentification. The output Cloud Storage bucket must be different
  #     from the input bucket. De-identified files will overwrite files in the
  #     output path.
  #
  #     Form of: gs://bucket/folder/ or gs://bucket
  # @!attribute [rw] file_types_to_transform
  #   @return [::Array<::Google::Cloud::Dlp::V2::FileType>]
  #     List of user-specified file type groups to transform. If specified, only
  #     the files with these file types are transformed. If empty, all
  #     supported files are transformed. Supported types may be automatically
  #     added over time. Any unsupported file types that are set in this field
  #     are excluded from de-identification. An error is recorded for each
  #     unsupported file in the TransformationDetails output table. Currently the
  #     only file types supported are: IMAGES, TEXT_FILES, CSV, TSV.
  class Deidentify
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Sends an email when the job completes. The email goes to IAM project owners
  # and technical [Essential
  # Contacts](https://cloud.google.com/resource-manager/docs/managing-notification-contacts).
  class JobNotificationEmails
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Enable Stackdriver metric dlp.googleapis.com/finding_count. This
  # will publish a metric to stack driver on each infotype requested and
  # how many findings were found for it. CustomDetectors will be bucketed
  # as 'Custom' under the Stackdriver label 'info_type'.
  class PublishToStackdriver
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end
end

#publish_to_stackdriver::Google::Cloud::Dlp::V2::Action::PublishToStackdriver

Returns Enable Stackdriver metric dlp.googleapis.com/finding_count.

Note: The following fields are mutually exclusive: publish_to_stackdriver, save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, deidentify, job_notification_emails. If a field in that set is populated, all other fields in the set will automatically be cleared.

Returns:

  • (::Google::Cloud::Dlp::V2::Action::PublishToStackdriver)

    Enable Stackdriver metric dlp.googleapis.com/finding_count.

    Note: The following fields are mutually exclusive: publish_to_stackdriver, save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, deidentify, job_notification_emails. If a field in that set is populated, all other fields in the set will automatically be cleared.



3969
3970
3971
3972
3973
3974
3975
3976
3977
3978
3979
3980
3981
3982
3983
3984
3985
3986
3987
3988
3989
3990
3991
3992
3993
3994
3995
3996
3997
3998
3999
4000
4001
4002
4003
4004
4005
4006
4007
4008
4009
4010
4011
4012
4013
4014
4015
4016
4017
4018
4019
4020
4021
4022
4023
4024
4025
4026
4027
4028
4029
4030
4031
4032
4033
4034
4035
4036
4037
4038
4039
4040
4041
4042
4043
4044
4045
4046
4047
4048
4049
4050
4051
4052
4053
4054
4055
4056
4057
4058
4059
4060
4061
4062
4063
4064
4065
4066
4067
4068
4069
4070
4071
4072
4073
4074
4075
4076
4077
4078
4079
4080
4081
4082
4083
4084
4085
4086
4087
4088
4089
4090
4091
4092
4093
4094
4095
4096
4097
4098
4099
4100
4101
4102
4103
4104
4105
4106
4107
4108
4109
4110
4111
4112
4113
4114
4115
4116
4117
4118
4119
4120
4121
4122
4123
4124
4125
4126
4127
4128
4129
4130
4131
4132
4133
4134
4135
4136
4137
4138
4139
4140
4141
4142
4143
4144
4145
4146
4147
4148
4149
4150
4151
4152
4153
4154
4155
4156
4157
4158
4159
4160
4161
4162
4163
4164
4165
4166
4167
# File 'proto_docs/google/privacy/dlp/v2/dlp.rb', line 3969

class Action
  include ::Google::Protobuf::MessageExts
  extend ::Google::Protobuf::MessageExts::ClassMethods

  # If set, the detailed findings will be persisted to the specified
  # OutputStorageConfig. Only a single instance of this action can be
  # specified.
  # Compatible with: Inspect, Risk
  # @!attribute [rw] output_config
  #   @return [::Google::Cloud::Dlp::V2::OutputStorageConfig]
  #     Location to store findings outside of DLP.
  class SaveFindings
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish a message into a given Pub/Sub topic when DlpJob has completed. The
  # message contains a single field, `DlpJobName`, which is equal to the
  # finished job's
  # [`DlpJob.name`](https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/projects.dlpJobs#DlpJob).
  # Compatible with: Inspect, Risk
  # @!attribute [rw] topic
  #   @return [::String]
  #     Cloud Pub/Sub topic to send notifications to. The topic must have given
  #     publishing access rights to the DLP API service account executing
  #     the long running DlpJob sending the notifications.
  #     Format is projects/\\{project}/topics/\\{topic}.
  class PublishToPubSub
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish the result summary of a DlpJob to [Security Command
  # Center](https://cloud.google.com/security-command-center). This action is
  # available for only projects that belong to an organization. This action
  # publishes the count of finding instances and their infoTypes. The summary
  # of findings are persisted in Security Command Center and are governed by
  # [service-specific policies for Security Command
  # Center](https://cloud.google.com/terms/service-terms). Only a single
  # instance of this action can be specified. Compatible with: Inspect
  class PublishSummaryToCscc
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Data Catalog. In Data Catalog, tag
  # templates are applied to the resource that Cloud DLP scanned. Data
  # Catalog tag templates are stored in the same project and region where the
  # BigQuery table exists. For Cloud DLP to create and apply the tag template,
  # the Cloud DLP service agent must have the
  # `roles/datacatalog.tagTemplateOwner` permission on the project. The tag
  # template contains fields summarizing the results of the DlpJob. Any field
  # values previously written by another DlpJob are deleted. [InfoType naming
  # patterns][google.privacy.dlp.v2.InfoType] are strictly enforced when using
  # this feature.
  #
  # Findings are persisted in Data Catalog storage and are governed by
  # service-specific policies for Data Catalog. For more information, see
  # [Service Specific Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToCloudDataCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Dataplex Universal Catalog as a
  # `sensitive-data-protection-job-result` aspect. For more information,
  # see [Send inspection results to Dataplex Universal Catalog as
  # aspects](https://cloud.google.com/sensitive-data-protection/docs/add-aspects-inspection-job).
  #
  # Aspects are stored in Dataplex Universal Catalog storage and are
  # governed by service-specific policies for Dataplex Universal Catalog. For
  # more information, see [Service Specific
  # Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToDataplexCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Create a de-identified copy of a storage bucket. Only compatible
  # with Cloud Storage buckets.
  #
  #
  # A TransformationDetail will be created for each transformation.
  #
  #
  # Compatible with: Inspection of Cloud Storage
  # @!attribute [rw] transformation_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationConfig]
  #     User specified deidentify templates and configs for structured,
  #     unstructured, and image files.
  # @!attribute [rw] transformation_details_storage_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationDetailsStorageConfig]
  #     Config for storing transformation details.
  #
  #     This field specifies the configuration for storing detailed metadata
  #     about each transformation performed during a de-identification process.
  #     The metadata is stored separately from the de-identified content itself
  #     and provides a granular record of both successful transformations and any
  #     failures that occurred.
  #
  #     Enabling this configuration is essential for users who need to access
  #     comprehensive information about the status, outcome, and specifics of
  #     each transformation. The details are captured in the
  #     {::Google::Cloud::Dlp::V2::TransformationDetails TransformationDetails}
  #     message for each operation.
  #
  #     Key use cases:
  #
  #     * **Auditing and compliance**
  #         * Provides a verifiable audit trail of de-identification activities,
  #         which is crucial for meeting regulatory requirements and internal
  #         data governance policies.
  #         * Logs what data was transformed, what transformations were applied,
  #         when they occurred, and their success status. This helps
  #         demonstrate accountability and due diligence in protecting
  #         sensitive data.
  #
  #     * **Troubleshooting and debugging**
  #         * Offers detailed error messages and context if a transformation
  #         fails. This information is useful for diagnosing and resolving
  #         issues in the de-identification pipeline.
  #         * Helps pinpoint the exact location and nature of failures, speeding
  #         up the debugging process.
  #
  #     * **Process verification and quality assurance**
  #         * Allows users to confirm that de-identification rules and
  #         transformations were applied correctly and consistently across
  #         the dataset as intended.
  #         * Helps in verifying the effectiveness of the chosen
  #         de-identification strategies.
  #
  #     * **Data lineage and impact analysis**
  #         * Creates a record of how data elements were modified, contributing
  #         to data lineage. This is useful for understanding the provenance
  #         of de-identified data.
  #         * Aids in assessing the potential impact of de-identification choices
  #         on downstream analytical processes or data usability.
  #
  #     * **Reporting and operational insights**
  #         * You can analyze the metadata stored in a queryable BigQuery table
  #         to generate reports on transformation success rates, common
  #         error types, processing volumes (e.g., transformedBytes), and the
  #         types of transformations applied.
  #         * These insights can inform optimization of de-identification
  #         configurations and resource planning.
  #
  #     To take advantage of these benefits, set this configuration. The stored
  #     details include a description of the transformation, success or
  #     error codes, error messages, the number of bytes transformed, the
  #     location of the transformed content, and identifiers for the job and
  #     source data.
  # @!attribute [rw] cloud_storage_output
  #   @return [::String]
  #     Required. User settable Cloud Storage bucket and folders to store
  #     de-identified files. This field must be set for Cloud Storage
  #     deidentification. The output Cloud Storage bucket must be different
  #     from the input bucket. De-identified files will overwrite files in the
  #     output path.
  #
  #     Form of: gs://bucket/folder/ or gs://bucket
  # @!attribute [rw] file_types_to_transform
  #   @return [::Array<::Google::Cloud::Dlp::V2::FileType>]
  #     List of user-specified file type groups to transform. If specified, only
  #     the files with these file types are transformed. If empty, all
  #     supported files are transformed. Supported types may be automatically
  #     added over time. Any unsupported file types that are set in this field
  #     are excluded from de-identification. An error is recorded for each
  #     unsupported file in the TransformationDetails output table. Currently the
  #     only file types supported are: IMAGES, TEXT_FILES, CSV, TSV.
  class Deidentify
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Sends an email when the job completes. The email goes to IAM project owners
  # and technical [Essential
  # Contacts](https://cloud.google.com/resource-manager/docs/managing-notification-contacts).
  class JobNotificationEmails
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Enable Stackdriver metric dlp.googleapis.com/finding_count. This
  # will publish a metric to stack driver on each infotype requested and
  # how many findings were found for it. CustomDetectors will be bucketed
  # as 'Custom' under the Stackdriver label 'info_type'.
  class PublishToStackdriver
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end
end

#save_findings::Google::Cloud::Dlp::V2::Action::SaveFindings

Returns Save resulting findings in a provided location.

Note: The following fields are mutually exclusive: save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, deidentify, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.

Returns:

  • (::Google::Cloud::Dlp::V2::Action::SaveFindings)

    Save resulting findings in a provided location.

    Note: The following fields are mutually exclusive: save_findings, pub_sub, publish_summary_to_cscc, publish_findings_to_cloud_data_catalog, publish_findings_to_dataplex_catalog, deidentify, job_notification_emails, publish_to_stackdriver. If a field in that set is populated, all other fields in the set will automatically be cleared.



3969
3970
3971
3972
3973
3974
3975
3976
3977
3978
3979
3980
3981
3982
3983
3984
3985
3986
3987
3988
3989
3990
3991
3992
3993
3994
3995
3996
3997
3998
3999
4000
4001
4002
4003
4004
4005
4006
4007
4008
4009
4010
4011
4012
4013
4014
4015
4016
4017
4018
4019
4020
4021
4022
4023
4024
4025
4026
4027
4028
4029
4030
4031
4032
4033
4034
4035
4036
4037
4038
4039
4040
4041
4042
4043
4044
4045
4046
4047
4048
4049
4050
4051
4052
4053
4054
4055
4056
4057
4058
4059
4060
4061
4062
4063
4064
4065
4066
4067
4068
4069
4070
4071
4072
4073
4074
4075
4076
4077
4078
4079
4080
4081
4082
4083
4084
4085
4086
4087
4088
4089
4090
4091
4092
4093
4094
4095
4096
4097
4098
4099
4100
4101
4102
4103
4104
4105
4106
4107
4108
4109
4110
4111
4112
4113
4114
4115
4116
4117
4118
4119
4120
4121
4122
4123
4124
4125
4126
4127
4128
4129
4130
4131
4132
4133
4134
4135
4136
4137
4138
4139
4140
4141
4142
4143
4144
4145
4146
4147
4148
4149
4150
4151
4152
4153
4154
4155
4156
4157
4158
4159
4160
4161
4162
4163
4164
4165
4166
4167
# File 'proto_docs/google/privacy/dlp/v2/dlp.rb', line 3969

class Action
  include ::Google::Protobuf::MessageExts
  extend ::Google::Protobuf::MessageExts::ClassMethods

  # If set, the detailed findings will be persisted to the specified
  # OutputStorageConfig. Only a single instance of this action can be
  # specified.
  # Compatible with: Inspect, Risk
  # @!attribute [rw] output_config
  #   @return [::Google::Cloud::Dlp::V2::OutputStorageConfig]
  #     Location to store findings outside of DLP.
  class SaveFindings
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish a message into a given Pub/Sub topic when DlpJob has completed. The
  # message contains a single field, `DlpJobName`, which is equal to the
  # finished job's
  # [`DlpJob.name`](https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/projects.dlpJobs#DlpJob).
  # Compatible with: Inspect, Risk
  # @!attribute [rw] topic
  #   @return [::String]
  #     Cloud Pub/Sub topic to send notifications to. The topic must have given
  #     publishing access rights to the DLP API service account executing
  #     the long running DlpJob sending the notifications.
  #     Format is projects/\\{project}/topics/\\{topic}.
  class PublishToPubSub
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish the result summary of a DlpJob to [Security Command
  # Center](https://cloud.google.com/security-command-center). This action is
  # available for only projects that belong to an organization. This action
  # publishes the count of finding instances and their infoTypes. The summary
  # of findings are persisted in Security Command Center and are governed by
  # [service-specific policies for Security Command
  # Center](https://cloud.google.com/terms/service-terms). Only a single
  # instance of this action can be specified. Compatible with: Inspect
  class PublishSummaryToCscc
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Data Catalog. In Data Catalog, tag
  # templates are applied to the resource that Cloud DLP scanned. Data
  # Catalog tag templates are stored in the same project and region where the
  # BigQuery table exists. For Cloud DLP to create and apply the tag template,
  # the Cloud DLP service agent must have the
  # `roles/datacatalog.tagTemplateOwner` permission on the project. The tag
  # template contains fields summarizing the results of the DlpJob. Any field
  # values previously written by another DlpJob are deleted. [InfoType naming
  # patterns][google.privacy.dlp.v2.InfoType] are strictly enforced when using
  # this feature.
  #
  # Findings are persisted in Data Catalog storage and are governed by
  # service-specific policies for Data Catalog. For more information, see
  # [Service Specific Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToCloudDataCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Publish findings of a DlpJob to Dataplex Universal Catalog as a
  # `sensitive-data-protection-job-result` aspect. For more information,
  # see [Send inspection results to Dataplex Universal Catalog as
  # aspects](https://cloud.google.com/sensitive-data-protection/docs/add-aspects-inspection-job).
  #
  # Aspects are stored in Dataplex Universal Catalog storage and are
  # governed by service-specific policies for Dataplex Universal Catalog. For
  # more information, see [Service Specific
  # Terms](https://cloud.google.com/terms/service-terms).
  #
  # Only a single instance of this action can be specified. This action is
  # allowed only if all resources being scanned are BigQuery tables.
  # Compatible with: Inspect
  class PublishFindingsToDataplexCatalog
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Create a de-identified copy of a storage bucket. Only compatible
  # with Cloud Storage buckets.
  #
  #
  # A TransformationDetail will be created for each transformation.
  #
  #
  # Compatible with: Inspection of Cloud Storage
  # @!attribute [rw] transformation_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationConfig]
  #     User specified deidentify templates and configs for structured,
  #     unstructured, and image files.
  # @!attribute [rw] transformation_details_storage_config
  #   @return [::Google::Cloud::Dlp::V2::TransformationDetailsStorageConfig]
  #     Config for storing transformation details.
  #
  #     This field specifies the configuration for storing detailed metadata
  #     about each transformation performed during a de-identification process.
  #     The metadata is stored separately from the de-identified content itself
  #     and provides a granular record of both successful transformations and any
  #     failures that occurred.
  #
  #     Enabling this configuration is essential for users who need to access
  #     comprehensive information about the status, outcome, and specifics of
  #     each transformation. The details are captured in the
  #     {::Google::Cloud::Dlp::V2::TransformationDetails TransformationDetails}
  #     message for each operation.
  #
  #     Key use cases:
  #
  #     * **Auditing and compliance**
  #         * Provides a verifiable audit trail of de-identification activities,
  #         which is crucial for meeting regulatory requirements and internal
  #         data governance policies.
  #         * Logs what data was transformed, what transformations were applied,
  #         when they occurred, and their success status. This helps
  #         demonstrate accountability and due diligence in protecting
  #         sensitive data.
  #
  #     * **Troubleshooting and debugging**
  #         * Offers detailed error messages and context if a transformation
  #         fails. This information is useful for diagnosing and resolving
  #         issues in the de-identification pipeline.
  #         * Helps pinpoint the exact location and nature of failures, speeding
  #         up the debugging process.
  #
  #     * **Process verification and quality assurance**
  #         * Allows users to confirm that de-identification rules and
  #         transformations were applied correctly and consistently across
  #         the dataset as intended.
  #         * Helps in verifying the effectiveness of the chosen
  #         de-identification strategies.
  #
  #     * **Data lineage and impact analysis**
  #         * Creates a record of how data elements were modified, contributing
  #         to data lineage. This is useful for understanding the provenance
  #         of de-identified data.
  #         * Aids in assessing the potential impact of de-identification choices
  #         on downstream analytical processes or data usability.
  #
  #     * **Reporting and operational insights**
  #         * You can analyze the metadata stored in a queryable BigQuery table
  #         to generate reports on transformation success rates, common
  #         error types, processing volumes (e.g., transformedBytes), and the
  #         types of transformations applied.
  #         * These insights can inform optimization of de-identification
  #         configurations and resource planning.
  #
  #     To take advantage of these benefits, set this configuration. The stored
  #     details include a description of the transformation, success or
  #     error codes, error messages, the number of bytes transformed, the
  #     location of the transformed content, and identifiers for the job and
  #     source data.
  # @!attribute [rw] cloud_storage_output
  #   @return [::String]
  #     Required. User settable Cloud Storage bucket and folders to store
  #     de-identified files. This field must be set for Cloud Storage
  #     deidentification. The output Cloud Storage bucket must be different
  #     from the input bucket. De-identified files will overwrite files in the
  #     output path.
  #
  #     Form of: gs://bucket/folder/ or gs://bucket
  # @!attribute [rw] file_types_to_transform
  #   @return [::Array<::Google::Cloud::Dlp::V2::FileType>]
  #     List of user-specified file type groups to transform. If specified, only
  #     the files with these file types are transformed. If empty, all
  #     supported files are transformed. Supported types may be automatically
  #     added over time. Any unsupported file types that are set in this field
  #     are excluded from de-identification. An error is recorded for each
  #     unsupported file in the TransformationDetails output table. Currently the
  #     only file types supported are: IMAGES, TEXT_FILES, CSV, TSV.
  class Deidentify
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Sends an email when the job completes. The email goes to IAM project owners
  # and technical [Essential
  # Contacts](https://cloud.google.com/resource-manager/docs/managing-notification-contacts).
  class JobNotificationEmails
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end

  # Enable Stackdriver metric dlp.googleapis.com/finding_count. This
  # will publish a metric to stack driver on each infotype requested and
  # how many findings were found for it. CustomDetectors will be bucketed
  # as 'Custom' under the Stackdriver label 'info_type'.
  class PublishToStackdriver
    include ::Google::Protobuf::MessageExts
    extend ::Google::Protobuf::MessageExts::ClassMethods
  end
end