How to Export Google Workspace Audit Logs: Console, API, GAM
Export Google Workspace audit logs for an investigation: Admin console CSV, the Reports API (activities.list), GAM reports and Gmail settings, with limits.
TL;DR. Three routes, same underlying data. The Admin console (Reporting → Audit and investigation → export to CSV or Sheets) is fast for one account but capped at 100,000 rows. The Reports API (activities.list) gives full parameters and network info and scales. Gmail queries need ≤ 30-day windows. GAM wraps the API in one-line commands. Gmail filters, forwarding, delegates and send-as are not audit logs: export them separately with the Gmail API. All of these files can be dropped as-is into the in-browser analyzer.
Whatever you use, export early. Google keeps most log events for six months, and some sources lag by hours. You need a super admin, or an admin with the Audit & Investigation privilege for the console and the Reports API scope for API access.
Which logs, which period
| Log (console name) | Reports API applicationName | Why you need it |
|---|---|---|
| User log events (sign-ins) | login | Risky sign-ins, 2SV and recovery changes |
| User accounts | user_accounts | External forwarding enabled, 2SV / recovery changes |
| OAuth log events | token | Third-party app grants, API activity by app |
| Gmail log events | gmail | Delivery, auto-forward, archive/trash, sends |
| Drive log events | drive | Downloads, external sharing, visibility changes |
| Admin log events | admin | Admin roles, SSO, delegation, routing |
| SAML log events | saml | Sign-ins through a third-party IdP |
| Takeout log events | takeout | Full-account data exports |
| Groups log events | groups | External members added |
Period: at least 30 days before the suspicious email or first alert, up to now. For a single user, filter on that user. For admin-level questions, export the whole organization.
Route 1: Admin console "Audit and investigation" (CSV)
- Sign in at admin.google.com and open Reporting → Audit and investigation, then the log you want (for example User log events).
- Set the date range. The default is the last 7 days, which is almost never enough. Optionally add a filter on the actor.
- In Manage columns, add the network columns (IP address and the IP ASN column, if your console offers it) to the sign-in log. They are what reveal a hosting ASN.
- Click Export all, choose CSV or Google Sheets, and download the result. Google documents the export and its limits on each log's page, for example Admin log events: 100,000 rows in standard editions and 30 million with the security investigation tool.
- Repeat per log. Keep the original file names and the English column headers.
Watch out for: the column set depends on what you selected, the date format depends on your console and browser locale, and event names are display titles ("Successful login", "Download") rather than API names. The analyzer maps English titles back to API names. Other console languages are not mapped yet.
Route 2: the Reports API (activities.list)
The Admin SDK Reports API returns one JSON activity per record: time, actor, IP, networkInfo (ASN, region code) and the event with all its parameters. See the activities.list reference.
GET https://admin.googleapis.com/admin/reports/v1/activity/users/all/applications/login
?startTime=2026-08-15T00:00:00Z&maxResults=1000
Authorization: Bearer <token with admin.reports.audit.readonly>
Points that matter in an investigation:
- Paging. Follow
nextPageTokenuntil it disappears. Save each page as its own.jsonfile. Concatenated pages and JSON Lines also work in the analyzer. - Gmail window. Per the reference,
gmailrequests need bothstartTimeandendTime, at most 30 days apart. Loop month by month. - One user or all. Use
userKey=allfor the organization or an email address for one account. - Keep it raw. Don't flatten or "clean" the JSON. Nested parameters (Gmail
message_info, OAuthscope_data) carry the details.
This is the most complete input: network information is present on every record, so country-based checks such as impossible travel can run.
Route 3: GAM
GAM is the open-source command-line tool most Workspace admins already have. Its report command wraps activities.list and writes CSV:
gam report login user all range -30d today > login.csv
gam report token user all range -30d today > token.csv
gam report useraccounts user all range -30d today > user_accounts.csv
gam report gmail user claire@example.com range -30d today > gmail.csv
gam report drive user all range -30d today > drive.csv
gam report admin range -30d today > admin.csv
Name the files after the log (the analyzer also uses the file name as a hint). GAM CSVs keep API column names (id.time, actor.email, name) with parameters as extra columns. The analyzer reads them directly.
Gmail settings: the part the audit log doesn't have
Filters, forwarding addresses, the auto-forwarding setting, delegates and send-as aliases live in the mailbox's settings. The user accounts log does record email_forwarding_out_of_domain when forwarding is turned on. A filter that forwards or hides mail doesn't show up as a settings event anywhere in the audit logs. Use the Gmail API:
| Setting | Gmail API method | Save as |
|---|---|---|
| Filters | users.settings.filters.list | gmail-settings/<mailbox>/filters.json |
| Forwarding addresses | users.settings.forwardingAddresses.list | …/forwardingAddresses.json |
| Auto-forwarding | users.settings.getAutoForwarding | …/autoForwarding.json |
| Delegates | users.settings.delegates.list | …/delegates.json |
| Send-as | users.settings.sendAs.list | …/sendAs.json |
Reading another user's settings requires acting as that user, in practice a service account with domain-wide delegation (which is how GAM does it). The folder name tells the analyzer whose mailbox it is. GAM can print the same information for review (gam user <email> show filters, show forwards, show sendas, print delegates). The analyzer expects the Gmail API JSON responses. No API access? Sit with the user, open Settings → Filters and blocked addresses, Forwarding and POP/IMAP and Accounts, and take dated screenshots.
Preserve the evidence
- Keep originals untouched and compute a hash (
shasum -a 256 *) right after export. - Record who exported what, when, with which filters and from which tool.
- Store exports outside the compromised tenant. An attacker with admin access can read Drive.
- Export again a day later. OAuth events can lag "a couple of hours" and Takeout completion "up to many days", per Google's lag table.
For a broader treatment of extraction options, including Cloud Logging forwarding, SANS published a useful Google Workspace log extraction overview.
Next steps
- Analyze the exports: step-by-step analysis with the in-browser tool.
- Understand what's missing: audit log limitations.
- Short checklist version on the tool page: how to export these logs.
FAQ
Can I export Google Workspace audit logs to CSV?
Yes. In the Admin console, open Reporting → Audit and investigation, pick a log, run the search, then Export all to Google Sheets or CSV. Google caps exports at 100,000 rows (30 million with the security investigation tool).
What is the best way to export a lot of Workspace audit data?
The Admin SDK Reports API (activities.list), directly or through GAM. It returns every parameter plus network information (ASN, region), pages through large result sets and is easy to script. Gmail requests need a start and end time no more than 30 days apart.