What is Google Workspace audit logging and how do I use it?
Google Workspace audit logging records user and admin activity across Drive, Gmail and the Admin console so you can investigate incidents, demonstrate GDPR compliance to the ICO and prove who accessed what. Use the Google Workspace Admin console to view, filter and export logs; capabilities vary by Workspace edition.
What audit logging actually captures and where to find it
Audit logging collects a range of discrete events that show who did what, when and from where. In Google Workspace the common log categories you’ll use are:
- Drive file events (create, view, share, download).
- Gmail actions (send, forward, message deletion, mailbox delegation).
- Admin console changes (role changes, user creation, OAuth app grants).
- Login and authentication events (successful and failed sign-ins, 2FA activity).
Find these in the Google Workspace Admin console under Reports → Audit. Filters let you narrow by user, time window, IP address and activity type. Some advanced telemetry — such as data access by third‑party apps or Chrome device logs — may require additional admin APIs or higher-tier Workspace editions.
Using logs for security, compliance and everyday investigations
Logs are not just for disaster scenes. Use them to spot lateral movement after a compromise, check whether an employee actually deleted a file, or show auditors a chain of custody for data access. A sensible workflow looks like this:
- Start with a clear question: “Which accounts downloaded X between date A and B?”
- Apply filters for the user, file and time window in the Admin console.
- Export matching events to CSV or BigQuery for deeper analysis if needed.
For compliance with ICO expectations and basic security hygiene, maintain regular review routines and alerts for unusual patterns (mass downloads, unexpected admin role grants). The NCSC offers practical advice on logging and monitoring that helps shape what to keep an eye on and why.
Making audit logs actually useful: retention, exports and alerts
Raw logs are only valuable if you can search them quickly and keep them for a long enough window to investigate incidents. Practical steps make logs actionable:
- Define a retention baseline and export policy (automated exports to a secure storage or BigQuery work well).
- Create alerts for high‑risk events: admin role changes, mass downloads, external sharing outside your domain.
- Test an incident drill quarterly so staff know how to run a query and interpret results.
Quick comparison of common approaches:
| Approach | When to use |
|---|---|
| Admin console exports | Ad‑hoc investigations and short retention needs |
| Automated export to BigQuery or secure S3 | Longer retention, repeated analysis and SIEM integration |
If you need help checking your Workspace logging configuration or setting up automated exports and alerts, our Google Workspace support for business service helps configure exports, alerts and role separation so logs are reliable and easy to use.
When to ask for help
If you cannot answer simple questions from a log (who downloaded a sensitive file, which admin changed permissions, when an account logged in from a foreign IP) within a business day, get external help. A short engagement will usually reduce investigation time, cut wasted admin hours and make audit evidence presentable to the ICO or auditors.
Related reading
- our google workspace support for business guide
- Google Workspace support London — practical help for growing UK firms
- Google Workspace compliance support — options, gaps and when to upgrade
- Google Workspace support UK SMEs — practical help for growing businesses
- Google Workspace support teams: practical help for UK businesses
FAQ
how long should i keep google workspace audit logs?
A common baseline for operational investigations is to retain audit logs for at least 90 days — longer if you need to meet contractual or regulatory requirements; see NCSC’s guidance on logging and monitoring.
can i export logs automatically for long-term storage?
Yes. Export to BigQuery or an archived storage bucket and rotate keys; this lets you keep searchable records beyond the Admin console retention window and integrate logs with SIEM tools.
do i need a higher Workspace edition for useful logs?
Some audit features and longer retention are only available on Business Plus, Enterprise or add-ons. If you rely on logging for security or compliance, check your edition’s reporting limits before assuming you have full coverage.
what should i prioritise when reviewing logs weekly?
Prioritise admin role changes, large file downloads or external sharing, repeated failed logins and new OAuth app grants; these tend to indicate compromise or misconfiguration fast.







