Ch 8 · Monitoring & Logging
Router & audit
35 / 38

Every log entry passes through the Log Router first.

Only one of three audit log types is enabled by default.

Admin Activity

Config changes — always on, free, cannot be disabled

System Event

GCP-initiated changes — always on

Data Access

Reads/writes to data — NOT on by default, real volume/cost

A sink can route logs from every project under an org into one central security bucket — the mechanism behind org-wide audit visibility. Save a query the moment you'll plausibly need it again.