Cloud Logging
Google Cloud's service for collecting, storing, and querying log data from every GCP service and custom applications. Its query filter syntax lets logs be narrowed by resource, severity, and specific field values, and Log Sinks can route matching logs to BigQuery, Cloud Storage, or Pub/Sub for long-term retention beyond the default window.
Frequently Asked Questions
How does Cloud Logging's default retention interact with long-term compliance or audit needs?
Cloud Logging retains most log types for a limited default window (commonly 30 days, longer for certain audit log categories), which is enough for operational debugging but not for compliance regimes requiring multi-year retention. Log Sinks solve this by routing matching logs — filtered by resource, severity, or specific fields using the query filter syntax — to BigQuery for queryable long-term analysis, Cloud Storage for cheap cold archival, or Pub/Sub for real-time downstream processing, decoupling retention duration from the default operational window entirely.
What's a common mistake when setting up Log Sinks for compliance retention?
Creating the sink after the compliance requirement is already in effect, rather than before, meaning historical logs from before the sink existed are unrecoverable once the default retention window expires — sinks only route logs generated after they're created. Teams also commonly under-scope the sink's filter, routing only a subset of resource types they think they need, then discover during an actual audit that a required log category was never captured because the filter excluded it from day one.