Depending on your Google Workspace edition, you might have access to the security investigation tool, which has more advanced features. For example, super admins can identify, triage, and take action on security and privacy issues. Learn more
As your organization's administrator, you can run searches and take action on Drive log events. For example, you can view a record of actions of your organization's user activity in Drive. Drive log events include content your users create in Google Docs, Sheets, Slides, and other Google Workspace apps, and content that your users upload to Drive, such as PDFs and Microsoft Word files.
You can use the Activity API to access basic reports data. If your Google Workspace edition supports it, you can use the Reports API to access advanced Google Workspace reports data.
Important:
- Not all activities in Drive are logged. For a list of what's included, go to Logged and unlogged events.
- For details on when data becomes available and how long it's retained, go to Data retention and lag times.
- Most Drive audit events are logged only for files owned by users with supported editions. However, URL Accessed events are logged when the user who starts a Google Apps Script script that accesses a URL is in your organization and has a supported edition.
Run a search for log events
Your ability to run a search depends on your Google edition, your administrative privileges, and the data source. You can run a search on all users, regardless of their Google Workspace edition.
Audit and investigation tool
To run a search for log events, first choose a data source. Then choose one or more filters for your search.
-
In the Google Admin console, go to Menu
Reporting
Audit and investigation
Drive log events.
Requires having the Audit & Investigation administrator privilege.
-
To filter events that occurred before or after a specific date, for Date, select Before or After. By default, events from the last 7 days are shown. You can select a different date range or click
to remove the date filter.
-
Click Add a filter
select an attribute. For example, to filter by a specific event type, select Event.
-
Select an operator
select a value
click Apply.
- (Optional) To create multiple filters for your search, repeat this step.
- (Optional) To add a search operator, above Add a filter, select AND or OR.
- Click Search. Note: Using the Filter tab, you can include simple parameter and value pairs to filter the search results. You can also use the Condition builder tab, where the filters are represented as conditions with AND or OR operators.
Security investigation tool
To run a search in the security investigation tool, first choose a data source. Then, choose one or more conditions for your search. For each condition, choose an attribute, an operator, and a value.
-
In the Google Admin console, go to Menu
Security
Security center
Investigation tool.
Requires having the Security center administrator privilege.
- Click Data source and select Drive log events.
-
To filter events that occurred before or after a specific date, for Date, select Before or After. By default, events from the last 7 days are shown. You can select a different date range or click
to remove the date filter.
-
Click Add Condition.