How to Use Google Workspace Admin Console to Audit Drive File Sharing Events

In a large organization, maintaining visibility over who is sharing what is a critical security requirement. If an employee claims they didn’t leak a confidential spreadsheet to a competitor, or if you suspect an offboarding employee is downloading client lists to a personal Gmail account, you need hard data. The Google Workspace Admin Console includes a comprehensive audit log specifically designed to track every interaction with Google Drive files.

Note: Advanced audit logging features may require Google Workspace Business Standard, Enterprise, or Education tiers.

Step 1: Access the Drive Audit Log

  1. Log in to the Google Workspace Admin console (admin.google.com) using a Super Administrator account.
  2. On the left-hand navigation menu, go to Reporting > Audit and investigation > Drive log events.

By default, this page will display a chronological list of every action taken by every user in your domain across all of Google Drive. In an enterprise environment, this list updates with thousands of events per minute. You must filter the data to find what you need.

Step 2: Build a Search Query

The Drive log allows you to build complex filters based on conditions.

Scenario 1: Tracking a Suspicious User
If you suspect an employee (e.g., [email protected]) is downloading sensitive files before quitting:

  1. Click Add a condition.
  2. Select Actor.
  3. Type the employee’s email address.
  4. Click Add a condition again.
  5. Select Event Name.
  6. Select Download.
  7. Click Search. The log will now show every file that specific user has downloaded to their local hard drive.

Scenario 2: Tracing a Specific File
If you have a highly confidential document (e.g., “Q4 Merger Details”) and want to know exactly who has looked at it:

  1. Click Add a condition.
  2. Select Document Title (or Document ID for exact precision).
  3. Type the name of the file.
  4. Click Search. You will see a timeline of who viewed, edited, or printed the document.

Scenario 3: Finding Dangerous External Shares
To see if employees are granting access to personal Gmail accounts:

  1. Add a condition for Event Name = Change user access.
  2. Add a condition for Target User (the person receiving access).
  3. Change the operator to Does not contain and type your domain (e.g., @company.com).
  4. Click Search. This highlights every time an employee shared a file with an external email address.

Step 3: Analyze the Results

When you click on a specific row in the search results, a panel opens detailing the exact metadata of the event. Crucial fields include:

  • Actor: The email address of the person who took the action.
  • IP Address: The network IP from which the action occurred (useful for identifying compromised accounts logging in from unusual countries).
  • Item Visibility: Indicates if the file was private, shared with specific people, or made public with a link.
  • Timestamp: The exact date and time (adjusted to your local timezone).

Step 4: Exporting Data for HR or Legal

If you uncover evidence of a data breach or policy violation, you will likely need to share the logs with Human Resources or external legal counsel.

At the top of the search results table, click the Export icon (an arrow pointing down into a tray). You can export the filtered data to a Google Sheet (for easy sharing within the company) or download it as a CSV file for long-term secure archiving. Note: Large exports containing tens of thousands of rows may take several minutes to generate.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.