Workspace Migration Services

Reference

Google Workspace audit logs and their retention

Google Workspace audit logs are split by service, and retention differs per log rather than being a single tenant-wide setting: admin and login activity is retained for 6 months, Drive and most user-facing service logs for 6 months, and longer retention requires exporting to BigQuery or a SIEM before the window closes.

Logs, contents and retention
Admin logConsole changes, role grants and setting edits; 6 months
Login logSign-in successes, failures and suspicious login flags; 6 months
Drive logView, edit, share and download events; 6 months, Business Standard and above
Gmail logMessage-level events; Enterprise editions, searchable in the console
OAuth token logThird-party application grants and scopes
Longer retentionExport to BigQuery or a SIEM; retention then follows that system

The first three logs to open after a compromise

Start with the login log filtered to the affected account, then the OAuth token log for any grant issued around the same timestamp, then the admin log for role or forwarding changes. That sequence answers how they got in, what they kept, and whether they left a way back.

Mail forwarding rules and delegated access are the persistence mechanisms that survive a password reset, so they belong in the first pass rather than the tidy-up.

Export before you need it

Six months sounds long until an investigation asks about an event from last year. The BigQuery export is configured once and costs little at typical volumes, and it is the difference between answering an insurer's question and estimating.

Set it up while nothing is wrong. Configuring log export during an incident means the events you most want were already discarded.

  • Enable BigQuery log export at tenant setup, not after an incident
  • Alert on super admin role grants rather than reading logs monthly
  • Record the timestamp and timezone of every finding you export
  • Check delegated access and forwarding on any compromised account
  • Keep an offline copy of exports relating to an open investigation

What we see that others don't say

In the account compromises we investigate, a mail forwarding rule or delegated access grant is left behind more often than the attacker returns to the password, which is why log review outlasts the reset.

What this doesn't cover

  • Retention windows are Google's defaults and can change; verify the current window in the admin console before relying on a date.
  • Some logs require Business Standard, Business Plus or Enterprise; lower editions see a reduced event set.

Want this done for you?

Three fields. We come back with whether this is a 20-minute fix or a project, and what it costs.

Prefer to talk? Call +44 20 7183 3436 (Mon–Fri 08:00–18:00 GMT), or message WhatsApp +44 7403 423563.

Questions we get asked

How long does Google Workspace keep audit logs?
Most Workspace audit logs, including admin and login activity, are retained for around six months. Longer retention requires exporting the logs to BigQuery or an external SIEM before the retention window closes.
What should I check first after a Workspace account compromise?
The login log for the account, the OAuth token log for grants issued near that time, and the admin log for role, forwarding or delegation changes. Forwarding and delegation survive a password reset.

How this page is verified

Reviewed by Workspace Migration Services security desk, Workspace security and compliance reviewers. Last checked .

  • Log types and retention windows verified against Google's audit and investigation documentation at the review date.
  • Investigation sequence drawn from account compromise work we have performed on Workspace tenants.

Sources you can check

Related pages

Need log evidence you can hand to an insurer?

We configure export and alerting so the events exist when you need them, and we run the investigation sequence for you if an account is already compromised.