Skip to main content

Frequently Asked Questions

Why are Data Access audit logs disabled by default in GCP while Admin Activity logs aren't?

Data Access logs record every read and write of actual data (not just configuration changes), which for high-traffic services can generate enormous log volume and cost — so Google leaves them off by default for most services, BigQuery being a notable exception where some Data Access logging is always on. Admin Activity logs, covering things like IAM changes or resource creation, are comparatively low-volume and considered essential for accountability, so they're always enabled and can't be turned off.

What's a common mistake teams make with GCP audit logs during an incident investigation?

Assuming Data Access logs exist for a service after the fact — if they were never explicitly enabled before the incident, that history simply doesn't exist, and there's no way to retroactively recover who read what data. The practical fix is enabling Data Access logging proactively for sensitive services (especially anything handling regulated or customer data) as a standing policy, not something turned on only after a breach is already suspected.