Instiq
Chapter 6 · Monitoring and troubleshooting·v1.0.0·Updated 6/15/2026·~13 min

What's changed: Created Associate Google Workspace Administrator Chapter 6 (Domain 6 "Monitoring/troubleshooting": reports and audit logs = usage/security reports/admin-login-Drive-Gmail audit logs/BigQuery export; troubleshooting = Email Log Search/header analysis/investigation-tool cross-data investigation-bulk action/no-access isolation/GCDS checks).

6.1Reports and audit logs

Key points

Understand using Admin console reports (usage, security) and audit logs (admin actions, login, Drive, Gmail activity), exporting logs to BigQuery for long-term analysis, and tracking "who did what, when."

Safe, healthy operations require seeing "what is happening." The Admin console reports and audit logs provide this—the foundation for visibility and tracking.

6.1.1Reports and audit logs

Reports overview service usage (active users, storage, app use) and security (2SV adoption, external sharing, suspicious logins). Audit logs record activity in detail—admin actions (who changed a setting), login, Drive, Gmail, devices—so you can track "who did what, when." Map "overview usage/trends = reports" and "track individual actions = audit logs."

6.1.2Export for long-term analysis

To retain and analyze audit logs long-term, configure log export to BigQuery and analyze across data with SQL (useful beyond the console retention period and for complex correlation). Map "retain logs long-term and analyze with SQL = BigQuery export." For short-term/immediate checks, the console reports/audit logs suffice.

Exam point

Common: requirement → means. E.g., "overview 2SV adoption or external-sharing trends" = reports; "track who changed a setting and when" = admin audit log; "who shared/viewed a file" = Drive audit log; "retain logs long-term and analyze with SQL" = export to BigQuery.

Warning

Watch the mix-ups: (1) Reports (trend overview) and audit logs (individual actions) have different roles. (2) Console log retention is time-limited; cover long-term with BigQuery export. (3) The place to look differs by log type (admin/login/Drive/Gmail).

Diagram of reports (overview usage/security trends), audit logs (track admin/login/Drive/Gmail actions), and BigQuery export for long-term retention and SQL analysis.
What is happening

6.1.3Section summary

  • Reports = overview usage/security trends
  • Audit logs = track "who did what, when" across admin/login/Drive/Gmail
  • Long-term retention and SQL analysis = export logs to BigQuery

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To overview org-wide 2SV adoption and external-sharing trends, what do you use?

Q2. To track who changed an admin setting and when, what do you use?

Q3. To retain audit logs long-term and analyze them across data with SQL, which best fits?

Q4. To track who shared/viewed which file, what do you use?

Q5. Which correctly contrasts reports and audit logs?

Q6. You need analysis beyond the console log-retention period. Which is most appropriate?

Check your understandingPractice questions for Chapter 6: Monitoring and troubleshooting

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.