Reference
Google Workspace audit logs and their retention
Google Workspace audit logs are split by service, and retention differs per log rather than being a single tenant-wide setting: admin and login activity is retained for 6 months, Drive and most user-facing service logs for 6 months, and longer retention requires exporting to BigQuery or a SIEM before the window closes.
| Admin log | Console changes, role grants and setting edits; 6 months |
|---|---|
| Login log | Sign-in successes, failures and suspicious login flags; 6 months |
| Drive log | View, edit, share and download events; 6 months, Business Standard and above |
| Gmail log | Message-level events; Enterprise editions, searchable in the console |
| OAuth token log | Third-party application grants and scopes |
| Longer retention | Export to BigQuery or a SIEM; retention then follows that system |
The first three logs to open after a compromise
Start with the login log filtered to the affected account, then the OAuth token log for any grant issued around the same timestamp, then the admin log for role or forwarding changes. That sequence answers how they got in, what they kept, and whether they left a way back.
Mail forwarding rules and delegated access are the persistence mechanisms that survive a password reset, so they belong in the first pass rather than the tidy-up.
Export before you need it
Six months sounds long until an investigation asks about an event from last year. The BigQuery export is configured once and costs little at typical volumes, and it is the difference between answering an insurer's question and estimating.
Set it up while nothing is wrong. Configuring log export during an incident means the events you most want were already discarded.
- Enable BigQuery log export at tenant setup, not after an incident
- Alert on super admin role grants rather than reading logs monthly
- Record the timestamp and timezone of every finding you export
- Check delegated access and forwarding on any compromised account
- Keep an offline copy of exports relating to an open investigation
What we see that others don't say
In the account compromises we investigate, a mail forwarding rule or delegated access grant is left behind more often than the attacker returns to the password, which is why log review outlasts the reset.
What this doesn't cover
- Retention windows are Google's defaults and can change; verify the current window in the admin console before relying on a date.
- Some logs require Business Standard, Business Plus or Enterprise; lower editions see a reduced event set.
Want this done for you?
Three fields. We come back with whether this is a 20-minute fix or a project, and what it costs.
Prefer to talk? Call +44 20 7183 3436 (Mon–Fri 08:00–18:00 GMT), or message WhatsApp +44 7403 423563.
Questions we get asked
- How long does Google Workspace keep audit logs?
- Most Workspace audit logs, including admin and login activity, are retained for around six months. Longer retention requires exporting the logs to BigQuery or an external SIEM before the retention window closes.
- What should I check first after a Workspace account compromise?
- The login log for the account, the OAuth token log for grants issued near that time, and the admin log for role, forwarding or delegation changes. Forwarding and delegation survive a password reset.
How this page is verified
Reviewed by Workspace Migration Services security desk, Workspace security and compliance reviewers. Last checked .
- Log types and retention windows verified against Google's audit and investigation documentation at the review date.
- Investigation sequence drawn from account compromise work we have performed on Workspace tenants.
Sources you can check
Related pages
- What changes between Workspace editions
- How organizational units and policy inheritance work
- Shared drive against My Drive, compared
- The real Gmail attachment size limit
- Review logging and alerting coverage
- Incident response plan template
- Independent Workspace security audit
- Book an incident readiness review
Need log evidence you can hand to an insurer?
We configure export and alerting so the events exist when you need them, and we run the investigation sequence for you if an account is already compromised.