Drive log events

View user Google Drive file activity

Depending on your Google Workspace edition, you might have access to the security investigation tool, which has more advanced features. For example, super admins can identify, triage, and take action on security and privacy issues. Learn more

As your organization's administrator, you can run searches and take action on Drive log events. For example, you can view a record of actions of your organization's user activity in Drive. Drive log events include content your users create in Google Docs, Sheets, Slides, and other Google Workspace apps, and content that your users upload to Drive, such as PDFs and Microsoft Word files.

You can use the Activity API to access basic reports data. If your Google Workspace edition supports it, you can use the Reports API to access advanced Google Workspace reports data.

Important:

  • Not all activities in Drive are logged. For a list of what's included, go to Logged and unlogged events.
  • For details on when data becomes available and how long it's retained, go to Data retention and lag times.
  • Most Drive audit events are logged only for files owned by users with supported editions. However, URL Accessed events are logged when the user who starts a Google Apps Script script that accesses a URL is in your organization and has a supported edition.

Your ability to run a search depends on your Google edition, your administrative privileges, and the data source. You can run a search on all users, regardless of their Google Workspace edition.

Audit and investigation tool

To run a search for log events, first choose a data source. Then choose one or more filters for your search.

  1. In the Google Admin console, go to Menu and then Reporting and then Audit and investigation and then Drive log events.

    Requires having the Audit & Investigation administrator privilege.

  2. To filter events that occurred before or after a specific date, for Date, select Before or After. By default, events from the last 7 days are shown. You can select a different date range or click to remove the date filter.

  3. Click Add a filter and then select an attribute. For example, to filter by a specific event type, select Event.
  4. Select an operator and then select a value and then click Apply.
    • (Optional) To create multiple filters for your search, repeat this step.
    • (Optional) To add a search operator, above Add a filter, select AND or OR.
  5. Click Search. Note: Using the Filter tab, you can include simple parameter and value pairs to filter the search results. You can also use the Condition builder tab, where the filters are represented as conditions with AND or OR operators.

Security investigation tool

Supported editions for this feature: Frontline Standard and Frontline Plus; Enterprise Standard and Enterprise Plus; Education Standard and Education Plus; Enterprise Essentials Plus; Cloud Identity Premium. Compare your edition

To run a search in the security investigation tool, first choose a data source. Then, choose one or more conditions for your search. For each condition, choose an attribute, an operator, and a value.

  1. In the Google Admin console, go to Menu and then Security and then Security center and then Investigation tool.

    Requires having the Security center administrator privilege.

  2. Click Data source and select Drive log events.
  3. To filter events that occurred before or after a specific date, for Date, select Before or After. By default, events from the last 7 days are shown. You can select a different date range or click to remove the date filter.

  4. Click Add Condition.