Depending on your Google Workspace edition, you might have access to the security investigation tool, which has more advanced features. For example, super admins can identify, triage, and take action on security and privacy issues. Learn more
As your organization's administrator, you can run searches and take action on security issues related to Chat log events. For example, you can view a record of actions to monitor conversation and discussion activity in your organization. You can also see when a user starts a direct message or creates a space.
Before you begin
If you have Google Chat history turned off for your users, you won't see data for users who send direct messages, and you won't see data for the Direct message started event. To check your settings, go to Turn history on or off.
Run a search for log events
Your ability to run a search depends on your Google edition, your administrative privileges, and the data source. You can run a search on all users, regardless of their Google Workspace edition.
Attribute descriptions
For this data source, you can use the following attributes when searching log event data:
Attribute | Description |
---|---|
Actor | Email address of the user who performed the action |
Actor group name |
Group name of the actor. For more information, go to Filtering results by Google Group. To add a group to your filtering groups allowlist:
|
Actor organizational unit | Organizational unit of the actor |
Actor type | Role of the user who performed the action, such as Admin or Non-admin |
Attachment hash | SHA-256 hash of the chat attachment |
Attachment name | Name of the attachment sent in a Chat message |
Attachment status | Whether the message contains an attachment |
Attachment URL | Download URL of the attachment sent in a Chat message |
Conversation ownership |
Whether the conversation is owned by the customer (internally owned) or by other customers (externally owned) |
Conversation type |
Type of conversation, such as:
|
Data loss prevention scan status* | Using DLP for Chat , you can create data protection rules to prevent data leaks from Chat messages and attachments (uploaded files). DLP scan status includes values such as Failed, Partially scanned, and Scanned. |
Date | Date and time of the event (displayed in your browser's default time zone) |
Event | The logged event action, such as Message sent, Attachment uploaded, or Direct message started. |
External room* | Whether members outside the organization can be added to the chat room |
Message ID |
ID of the Chat message |
Message type |
Type of message, such as:
|
New role | New role type for recipients, such as Space manager or Member |
Recipients* | Recipients of a chat message. This attribute is logged when the following events occur:
|
Report ID | ID of the Chat message report |
Reporting category* | Category of the Chat message report, such as Spam, Confidential Information or Sensitive Information |
Room history setting | Whether Chat room history is turned on or off |
Room ID | Chat room ID |
Room name | Chat room name |
Note: If you gave a user a new name, you will not see query results with the user's old name. For example, if you rename OldName@example.com to NewName@example.com, you will not see results for events related to OldName@example.com.
Manage log event data
Take action based on search results
Manage your investigations
Supported editions for this feature: Frontline Standard; Enterprise Standard and Enterprise Plus; Education Standard and Education Plus; Enterprise Essentials Plus; Cloud Identity Premium. Compare your edition