SecureMyEmail logoSecureMyEmail

Google Workspace security guide

Switch on audit logs and alerts in Google Workspace

A practical guide for Australian businesses. Confirm audit-log access, configure Alert Centre rules, nominate recipients and establish a review process.

Google Workspace audit logs and security alerts monitoring

Recommended method: confirm Google Workspace audit logs are accessible, configure alert rules and establish a review process

Google Workspace automatically records many administrator and user activities in its audit logs; there is generally no single master switch to enable them. The essential task is to confirm that the logs are accessible, configure alert rules, nominate recipients and establish a review process. Google’s audit and investigation tool can track administrator and user activity, apply filters, download results and create reporting rules. Some advanced investigation and response features depend on your Google Workspace edition.

Before you begin

You will need:

  • A Google Workspace Super Administrator account, or an appropriately delegated admin role.
  • A monitored email address for security notifications.
  • At least two authorised people who can receive and respond to critical alerts.
  • An incident-response procedure defining who investigates each alert.

Use a separate administrator account rather than your everyday email account wherever possible.

1

Confirm audit logs are available

  • Sign in to the Google Admin console.
  • Open Menu.
  • Select Reporting.
  • Select Audit and investigation.
  • Open Admin log events.
  • Set the date range to a recent period.
  • Click Search.
  • Confirm that recent administrative activity appears.
  • Repeat the check for other relevant logs, where available.

Confirm that recent administrative activity appears, such as:

  • User creation or deletion
  • Password changes
  • Administrator-role changes
  • Google Workspace setting changes
  • Two-Step Verification changes

Repeat the check for other relevant logs, where available:

  • User log events
  • Login log events
  • Drive log events
  • Gmail log events
  • OAuth log events
  • SAML log events
  • Groups log events
  • Devices log events

The available log sources and search capabilities vary by subscription. Some events can also take time to appear.

2

Review Google’s Alert Centre

  • In the Admin console, go to Menu > Security > Alert centre.
  • Review all existing high- and medium-severity alerts.
  • Open each alert to see the affected user, when the activity occurred, the alert source and type, relevant IP addresses or devices, and recommended investigation steps.
  • Assign unresolved alerts to an administrator where the option is available.
  • Change the status to In progress while investigating.
  • Add comments describing what was checked or changed.
  • Mark the alert Closed only after it has been investigated and documented.

Access requires the appropriate Alert Centre administrator privilege. Google also retains a history of status, assignment, severity and comment changes within each alert.

3

Configure alert notification recipients

  • From the Admin console, go to Menu > Rules.
  • Select Manage rules.
  • Review the system-defined alert rules.
  • Open each important rule.
  • Locate the Actions or Notifications section.
  • Enable email notifications where the rule allows it.
  • Add the nominated administrators or security mailbox as recipients.
  • Save the changes.

Menu names may vary slightly according to the Workspace edition and Admin console updates.

Do not send alerts only to the potentially affected user. Use a separate monitored address such as security@yourdomain.com.au or an external IT support address so notifications remain accessible if an administrator account is compromised.

4

Prioritise important alert types

At minimum, configure or confirm notifications for:

  • Suspicious or compromised user activity
  • Suspicious login attempts
  • Leaked or compromised passwords
  • Government-backed attack warnings
  • User-reported phishing
  • Malware or phishing messages
  • Suspicious device activity
  • Changes to administrator roles
  • Super Administrator account changes
  • Two-Step Verification changes
  • Suspicious OAuth application activity
  • Changes to critical Google Workspace settings
  • Large or unusual Drive downloads, deletions or sharing activity
  • Data-loss prevention incidents, if supported
  • Suspicious email forwarding or routing changes

Avoid enabling email notifications for every low-risk event immediately. Excessive notifications can create alert fatigue and cause genuine incidents to be overlooked.

5

Create a custom reporting rule

  • Go to Menu > Reporting > Audit and investigation.
  • Select Admin log events.
  • Add one or more conditions, such as Event equals an administrator-role assignment, Event equals a security-setting change, or Actor is not an approved administrator.
  • Click Search and inspect the results to confirm that the filters are correct.
  • Select Create reporting rule.
  • Enter a clear name, such as Critical administrator changes.
  • Select an appropriate severity.
  • Enable Alert Centre generation.
  • Add the required email-notification recipients.
  • Save the rule.

Reporting rules are widely available, but more advanced activity rules, automated actions and investigation capabilities require eligible editions.

6

Apply least-privilege access

Do not give every administrator full access to logs or response actions.

  • Go to Menu > Account > Admin roles.
  • Create or edit a delegated security role.
  • Grant only the required privileges, such as Reports, Audit and investigation, Alert Centre access, and Rules viewing or management.
  • Assign the role only to staff responsible for monitoring security.
  • Reserve the Super Administrator role for functions that genuinely require it.
7

Test the configuration

  • Perform a harmless test during an approved maintenance period.
  • Make a low-risk administrative change, such as updating the description of a test Google Group.
  • Wait for the event to be recorded.
  • Search Admin log events for the change.
  • Confirm that the log identifies who performed it, what was changed, when it occurred and relevant supporting information.
  • If the event matches a configured rule, confirm that an Alert Centre entry was created, every nominated recipient received the notification, the notification did not go to spam, and someone knows how to acknowledge and investigate it.
  • Reverse the test change if necessary and document the result.
8

Establish an ongoing review process

Recommended minimum practice:

  • Review high-severity alerts immediately.
  • Review open alerts and suspicious login activity daily.
  • Review administrator and OAuth activity weekly.
  • Review notification recipients and admin permissions quarterly.
  • Export important evidence during an incident.
  • Record the investigation, decisions and remedial action in your ticketing or incident-management system.
  • Consider forwarding logs to a properly secured SIEM or managed monitoring service if longer retention or continuous monitoring is required.

Important warnings

  • Audit logging does not prevent an attack. Logs provide evidence; alerts still require timely human review and response.
  • Logs may not appear immediately. Do not assume that a missing event proves an action did not occur.
  • Retention is limited. Retention periods vary by log type and Workspace edition. Export important evidence promptly and consider an external archival or SIEM solution if longer retention is required.
  • Licensing affects capability. Advanced investigation, automated response and activity rules may not be available with every edition.
  • Alerts can contain sensitive information. Limit access and do not forward them to unsecured personal accounts.
  • Poorly designed rules create noise. Too many notifications can result in important alerts being ignored.
  • Automated actions can disrupt users. A rule that suspends accounts or blocks activity may interrupt legitimate operations. Test carefully before enabling automated remediation.
  • Audit access is powerful. Apply least privilege and regularly review who can search, export or act on log data.
  • Do not rely on email alone. If the tenant or administrator mailbox is compromised, internal alert emails may be missed or deleted.

Google Workspace disclaimer

These instructions provide general security guidance and may not exactly match every Google Workspace edition, licensing arrangement or Admin console interface. Changing alert rules, administrator privileges or automated response settings can generate excessive notifications, expose sensitive information or interrupt legitimate business activity if configured incorrectly.

Before making changes, document the existing configuration, confirm that emergency administrator access is available, and test rules using a controlled account or organisational unit where practical. Organisations with regulatory, contractual or cyber-insurance obligations should have the configuration reviewed by a qualified Google Workspace security professional.

Netlogyx/Securemyemail accepts no responsibility for service interruption, missed alerts, data loss or other consequences arising from changes made without appropriate technical assessment and testing.