Every log entry passes through the Log Router first.
Only one of three audit log types is enabled by default.
Admin Activity
Config changes — always on, free, cannot be disabled
System Event
GCP-initiated changes — always on
Data Access
Reads/writes to data — NOT on by default, real volume/cost
A sink can route logs from every project under an org into one central security bucket — the mechanism behind org-wide audit visibility. Save a query the moment you'll plausibly need it again.