Glossary term
Cloud Audit Logs
Google Cloud's record of who did what, where and when on the control plane: Admin Activity, Data Access, System Event and Policy Denied audit logs.
Cloud Audit Logs are the audit trail Google Cloud writes for API calls on projects, folders and organizations. Each entry is a LogEntry whose protoPayload (type google.cloud.audit.AuditLog) records the method (methodName), the caller (authenticationInfo.principalEmail), the caller IP and user agent, the resource and the result.
There are four types: Admin Activity (always on, 400 days), System Event (always on, 400 days), Data Access (off by default except some BigQuery services, 30 days) and Policy Denied (on by default, 30 days). They are the primary evidence in a Google Cloud investigation.
Read more: Cloud Audit Logs types explained, and how to export them and Google's Cloud Audit Logs overview.