Groups audit log
You can track changes to groups, group memberships, and group messages for users in your organization using the Google Groups audit log. You can also troubleshoot when users in your domain notice discrepancies and unexpected changes to their group activities. Entries usually appear within half an hour of the user action.
Types of changes you can track
- Group creation and deletion—You can verify that a group exists and was not recently deleted.
- Member addition and removal—If a user didn't receive a group message, you can check the audit log to see if the user is a group member. If the user was removed, the audit log also shows who removed them and when.
- Group posting permission changes—Users may unexpectedly receive a bounce message saying that they're not permitted to post. The audit log shows any changes to the posting permissions that would prevent the user to post.
- Spam moderation settings—If messages are sent to the moderation queue instead of being posted, the audit log will show if message moderation was a recent settings change.
The Groups audit log is only for the Google Groups interface. It logs both user and admin actions executed using the Google Groups interface. Google Groups actions performed by administrators using the Admin console or the Admin SDK directory API are only logged in the Admin audit logs.
Step 1: Open your Groups audit log
-
Sign in to your Google Admin console.
Sign in using your administrator account (does not end in @gmail.com).
-
From the Admin console Home page, go to Reports.
To see Reports, you might have to click More controls at the bottom.
- On the left, under Audit, click Groups.
- (Optional) Next to the columns, click Manage columns
and select the columns that you want to see or hide.
Step 2: Understand Groups audit log data
Data you can viewData Type | Description |
---|---|
Event Name | Action that was logged, such as adding or deleting groups, group invites, messages, or setting changes. |
|
A log entry for each time a user accepted an invitation to a group. |
|
A log entry for each time a user approved a request from another user. |
|
A log entry for each time a user joined a group. |
|
A log entry for each time a moderator changed a basic group setting. |
|
A log entry for each time a group was created. |
|
A log entry for each time a group was deleted. |
|
A log entry for each time group identity settings were modified. |
|
A log entry for each time a group information setting was added. |
|
A log entry for each time a group information setting was modified. |
|
A log entry for each time a group information setting was removed. |
|
A log entry for each time a new member restriction setting was updated. |
|
A log entry for each time a group permission setting was changed. |
|
A log entry for each time a post reply setting was modified. |
|
A log entry for each time a spam moderation setting was modified. |
|
A log entry for each time a group topic setting was modified. |
|
A log entry for each time a moderator approved or rejected a message. |
|
A log entry for each time a moderator attempted to allow all messages from a user to always be posted to a group. |
|
A log entry for each time a user was added to a group. |
|
A log entry for each time a moderator attempted to ban a user from a group during message moderation. |
|
A log entry for each time a user invitation was revoked from a group. |
|
A log entry for each time a user was invited to a group. |
|
A log entry for each time a moderator rejected a user request to join. |
|
A log entry for each time a user was reinvited to a group. |
|
A log entry for each time a user was removed from a group. |
Event description | Details of the event described in the Event name field. |
User | Email address of the user who triggered the event. |
Date | Date and time the event occurred (displayed in your browser's default time zone). |
Step 3: Customize and export your audit log data
Filter the audit log data by user or activity
You can narrow your audit log to show specific events or users. For example, find all log events for when users created or deleted a group, or find all group activity for a particular user.
- Open your Groups audit log as shown above.
- Click Add a filter.
- Select and enter the criteria for your filter and if needed, click Apply.
- (Optional) To filter by organizational unit, at the top right, click Organization filter, select the organizational unit, and click Apply.
- (Optional) To specify a date range to search, click Date range and select a period from the list or enter a start and end date and time. If needed, click Apply.
Filter by organizational unit
You can filter by organizational unit to compare statistics between child organizations in a domain.
- Open your Groups audit log as shown above.
- At the top, click Organization filter.
- Select an organizational unit and click Apply.
Filter by date
- At the top, click Date range.
- Select a period from the list or enter a start and end date and time.
- If needed, click Apply.
You can only filter the current organizational unit hierarchy, even when searching for older data. Data before December 20, 2018 will not appear in the filtered results.
Export your audit log data
You can export your audit log data to Google Sheets or download it to a CSV file.
- Open your audit log as shown above.
- (Optional) To change the data to include in your export, click Manage columns
, select or remove the columns that you want to export, and click Save.
- Click Download
.
- Under Select columns, click Currently selected columns or All columns.
- Under Select format, click Google Sheets or comma-separated values (CSV).
- Click Download.
You can export a maximum of 100,000 rows to Sheets or CSV.
How old is the data I'm seeing?
For details on exactly when data becomes available and how long it's retained, see Data retention and lag times.
Step 4: Set up email alerts
Track specific Groups activities by setting up alerts. For example, get an alert whenever someone creates or deletes a group.
Note: To get alerts on group-related actions performed in the Admin console, set up a custom alert in your admin audit log.
- Open your Groups audit log as shown above.
- Click Add a filter.
- Enter or select the criteria for your filter and click Create Alert.
- Enter a name for the alert.
- (Optional) To send the alert to all super administrators, under Recipients, click Turn on
.
- Enter the email addresses of alert recipients.
- Click Create.
To edit your custom alerts, see Administrator email alerts.