Skip to main content

Frequently Asked Questions

How does Cloud Logging's default retention interact with long-term compliance or audit needs?

Cloud Logging retains most log types for a limited default window (commonly 30 days, longer for certain audit log categories), which is enough for operational debugging but not for compliance regimes requiring multi-year retention. Log Sinks solve this by routing matching logs — filtered by resource, severity, or specific fields using the query filter syntax — to BigQuery for queryable long-term analysis, Cloud Storage for cheap cold archival, or Pub/Sub for real-time downstream processing, decoupling retention duration from the default operational window entirely.

What's a common mistake when setting up Log Sinks for compliance retention?

Creating the sink after the compliance requirement is already in effect, rather than before, meaning historical logs from before the sink existed are unrecoverable once the default retention window expires — sinks only route logs generated after they're created. Teams also commonly under-scope the sink's filter, routing only a subset of resource types they think they need, then discover during an actual audit that a required log category was never captured because the filter excluded it from day one.