Viewing audit logs

Audit logs are generated for modifications made using the Allowlisted Domains API, including the creation and deletion of domains in the allowlist. These actions are logged in the backend with specific activity types, such as Add trusted domains or Remove trusted domains. Administrators can check these audit logs to validate if a domain was added or deleted in the last 6 months.

To view audit logs, follow these steps:

  1. In the Google Admin console, go to Menu > Security > Security center > Investigation tool.
    Requires having the Security center administrator privilege.
  2. For Data source, select Admin log events.
  3. Click Add Condition.
  4. For the attribute, select Event, select Is as the operator, and choose Add trusted domains or Remove trusted domains.
  5. Click Search.