Diagnose and observe Google Cloud networking using first-party telemetry and operational practices.
---
name: google-cloud-networking-observability
description: >-
Investigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics. Use when investigating VPC Flow Logs (including cost estimation), NAT, firewall, or threat logs, querying latency and throughput metrics, or running Connectivity Tests for path diagnostics. Don't use for generic VM management or non-observability tasks.
---
# Google Cloud Networking Observability Expert
## 🛑 Core Directive: Results First
1. **Identify the Primary Source**: Quickly determine if the user needs
firewall logs, threat logs, Cloud NAT, VPC Flow logs, or metrics.
2. **Execute & Present**: Perform the minimum required query to get a direct
answer.
3. **Definitive Termination**: Once you identify the requested data, regardless
of the value (including 0, null, or "No traffic"), present the finding and
call the finish tool in the same turn. Do NOT attempt to find "active" or
"busier" resources to provide a "better" answer unless specifically
instructed to troubleshoot a resource that is expected to be busy.
## Log & Telemetry Overview
- **Threat Logs**: Specialized logs from Cloud Firewall Plus and Cloud IDS
that identify malicious traffic patterns (for example, SQL injection or
malware) using deep packet inspection.