Introduction

In this article, we will know how to Audit Admin logs in Google Workspace. Auditing Admin logs help to record, track, and create documentation about the Admin activities in Google Workspace. The process helps to identify unauthorized activities and inform about the security loopholes. As an Admin, you can download the CSV of Admin logs from the Admin Console. But Foresight makes this process easier by automating it.

What do you mean by 'columns' in log event data?

In log event data, 'columns' refer to specific attributes or fields that store detailed information about each logged event, allowing for easy searching and filtering of data. Each column represents a key piece of data related to the log event. Common examples of columns include:

  • Actor: The email address of the user who initiated the log event.
  • Event: The specific action logged, such as "Activity Rule Creation" or "Investigation Query." These are grouped by types like Domain Settings or User Settings.
  • IP Address: The IP address associated with the user, which could be tied to their physical location or through a virtual private network (VPN) or proxy server.
  • Actor Organizational Unit: The organizational unit (OU) to which the actor belongs, revealing the user's department or team.

These columns are used to filter and search log data effectively in order to monitor and analyze activities within an organization.

What are admin logs in Google Admin, and why do they exist?

Admin logs are a feature in the Google Admin Console that allows you to audit, investigate, and identify the admins and users, their activities, and much more. The data helps you to track the Admin and users’ activity and ensure there are no malpractices. When you enable audit logs, they let your security, compliance, and auditing entities examine Google Cloud data and systems for any possible security threat. In this way, it maintains data consistency.

How to find Admin logs in Google Admin?

Automate Auditing and Exporting Admin logs with xFanatical Foresight Automation tool

xFanatical Foresight Automation tool  is an advanced automation tool designed to simplify and streamline the administration of Google Workspace. It offers a user-friendly interface and powerful features to automate repetitive tasks, including the auditing of admin logs. With xFanatical Foresight, you can set up automated workflows to regularly check and report on admin activities, ensuring no suspicious activity goes unnoticed.

Video Demo

Instructions

Create a calendar event for exporting Admin logs weekly to Google Drive

Create a calendar event for exporting Admin logs weekly to Google Drive
  1. Log in to your xFanatical Foresight account with your Google Admin account. 
  2. Go to the Rules page and click the New Rule button.
  3. Select the Calendar event started trigger from the select a trigger screen.
  4. Select Primary Calendar in the Calendars field and Admin Activity in the Event title field.Calendar event
  5. Click Next.New Rule - Primary Calendar
  6. On the Select an action screen, click the Convert datetime action.Convert Date Time Trigger
  7. Select Current Datetime in the Source datetime field.
    • Select these steps in the Time change steps - Subtract 1 Week, Set the Day of week to 1, and Set to the Start of Day.
    • Enter Start Datetime as the Variable name.
  8. Again click Add next action, and select the Convert datetime action.Covert-Date-Tine-Action
  9. Again, select Current Datetime in the Source datetime field.
    • Select Subtract 1 Week in the Time Change steps. Then, click Add Step to Set the Day of Week to 5. Again, click Add Step to Set to the End of Day.
    • Enter End Datetime as the Variable name.
  10. Click Add next action.Add Next Action
  11. On the Select an action screen, click the List admin activity logs action.List admin activity logs
  12. Select the Start Datetime and End Datetime variable using icon.
  13. Click Add next action.tart Datetime and End Datetime variable
  14. On the Select an action screen, click the Upload data to drive action.Upload data to drive
  15. Select Admin Logs CSV Download Link in the CSV file URL. Then, select the desired Google Drive Folder.
  16. Click Review.Review action
  17. Enter the Rule name, and click Create.Enter Rule name

Rule Triggering

  • The rule has been created successfully. You can now check the workflow in the Foresight interface.Rule-Workflow

Verifying Results

NotificationsLogs SheeetCSV File upload

Conclusion

Auditing admin logs in Google Workspace using the xFanatical Foresight Automation tool  is a proactive approach to maintaining the security and compliance of your organization's digital environment. By setting up automated workflows, interpreting the data effectively, and adhering to best practices, you can ensure that your Google Workspace remains secure and well-managed. 

Start leveraging xFanatical Foresight today to gain a deeper insight into your admin activities and safeguard your valuable data.