Using Cloud Monitoring to monitor App Check and Security Rules
Blog post from Firebase
Firebase serverless products integrate with Google Cloud Monitoring to improve security observability, particularly for Firebase Security Rules and App Check. Security Rules metrics, including access denials, are available in both the Firebase Console and Cloud Monitoring’s Metrics Explorer, where teams can filter and analyze rule evaluations in detail. Teams can create alerting policies that notify support staff when denied requests exceed a chosen threshold, such as 20 queries per second for five minutes, while configuring notification channels, severity labels, incident-response documentation, and handling for missing data. Such alerts can reveal faulty rule deployments or potential malicious access attempts and automatically close when denial rates return to normal. App Check metrics can similarly support alerts for spikes in invalid Firestore requests or declining numbers of outdated clients, helping teams identify attacks and determine when enforcement is safe. The guidance recommends using Cloud Monitoring as a baseline for Firebase production applications and extending monitoring to Cloud Functions and Firebase Authentication for performance, usage, and failed-login issues.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Observability | 3 | 786 | 185 | 72 | -40% |
| Serverless | 2 | 601 | 116 | 65 | -58% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.