Every log entry passes through the Router before landing anywhere.
Only one of two audit log types is on by default.
_Default bucket
Configurable retention
_Required bucket
Fixed 400 days — not configurable, even by an org admin
Custom sink
BigQuery (Log Analytics) or Pub/Sub
Admin Activity audit logs: always on, can't be disabled. Data Access audit logs: off by default for most services due to volume — and can't be enabled retroactively to reconstruct past access.