What's changed: Created Associate Google Workspace Administrator Chapter 6 (Domain 6 "Monitoring/troubleshooting": reports and audit logs = usage/security reports/admin-login-Drive-Gmail audit logs/BigQuery export; troubleshooting = Email Log Search/header analysis/investigation-tool cross-data investigation-bulk action/no-access isolation/GCDS checks).
6.1Reports and audit logs
Understand using Admin console reports (usage, security) and audit logs (admin actions, login, Drive, Gmail activity), exporting logs to BigQuery for long-term analysis, and tracking "who did what, when."
Safe, healthy operations require seeing "what is happening." The Admin console reports and audit logs provide this—the foundation for visibility and tracking.
6.1.1Reports and audit logs
Reports overview service usage (active users, storage, app use) and security (2SV adoption, external sharing, suspicious logins). Audit logs record activity in detail—admin actions (who changed a setting), login, Drive, Gmail, devices—so you can track "who did what, when." Map "overview usage/trends = reports" and "track individual actions = audit logs."
6.1.2Export for long-term analysis
To retain and analyze audit logs long-term, configure log export to BigQuery and analyze across data with SQL (useful beyond the console retention period and for complex correlation). Map "retain logs long-term and analyze with SQL = BigQuery export." For short-term/immediate checks, the console reports/audit logs suffice.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

