I have created a logging view inside _Default log bucket so a specific
user can only view logs on specific resource.Next, I have created a
custom role with
permissions:logging.logEntries.listlogging.queries.createlogging.queries.deletelogging.queries...