이 문서에서는 Google 직원이 Google Workspace 리소스의 고객 콘텐츠에 액세스할 때 생성되는 액세스 투명성 로그를 보고 이해하는 방법을 설명합니다. Google Workspace의 고객 콘텐츠에는 Gmail, Google Docs, Google Sheets, Google Slides, 기타 Google Workspace 앱에 입력한 텍스트가 포함됩니다.
시작하기 전에
로그 뷰어(roles/logging.viewer) Identity and Access Management(IAM) 역할이 있는지 확인합니다. IAM 역할 부여에 대한 자세한 내용은 단일 역할 부여를 참조하세요.
Google Workspace에서 액세스 투명성을 사용하려면 Google Workspace 콘텐츠를 Google Cloud와 공유하도록 사용 설정해야 합니다. Google Workspace 콘텐츠를 Google Cloud와 공유하는 방법은 Google Cloud와 데이터 공유를 참조하세요.
Google Workspace의 액세스 투명성 로그 보기
Google Cloud 콘솔의 로그 탐색기를 사용하여 액세스 투명성 로그를 검색하고, 보고, 분석할 수 있습니다. 로그 탐색기 사용에 대한 자세한 내용은 로그 탐색기 사용을 참조하세요.
로그 탐색기를 사용하여 Google Workspace의 액세스 투명성 로그를 보려면 다음 안내를 따르세요.
{"insertId":"-6x8cuqc3rk","jsonPayload":{"activityId":{"uniqQualifier":"1720950322606095479","timeUsec":"1621441673703908"},"@type":"type.googleapis.com/ccc_hosted_reporting.ActivityProto","event":[{"status":{"success":true},"eventType":"GSUITE_RESOURCE","parameter":[{"multiStrValue":["GMAIL"],"name":"GSUITE_PRODUCT_NAME",},{"name":"RESOURCE_NAME","multiStrValue":["//googleapis.com/gmail/users/owner@example.com"],},{"name":"LOG_ID","value":"Qt8v90c0fAEy_SyaOplDvJc",},{"multiStrValue":["Google Initiated Service - For details, please refer to the documentation."],"name":"JUSTIFICATIONS",},{"name":"ACTOR_HOME_OFFICE","value":"US",},{"value":"owner@example.net","name":"OWNER_EMAIL",}],"eventName":"ACCESS"}]},"resource":{"type":"organization","labels":{"organization_id":"12345"}},"timestamp":"2021-05-19T16:27:53.703908Z","severity":"NOTICE","logName":"organizations/12345/logs/cloudaudit.googleapis.com%2Faccess_transparency","receiveTimestamp":"2021-05-19T16:28:52.867650088Z"}
Google 직원이 Google Workspace 리소스에 액세스할 때 생성되는 액세스 투명성 로그의 jsonPayload 필드에 표시될 수 있는 이벤트 및 매개변수에 대한 자세한 내용은 액세스 투명성 활동 이벤트를 참조하세요.
Google Workspace의 액세스 투명성 로그에 있는 다른 모든 필드에 대한 정보는 LogEntry를 참조하세요.
[[["이해하기 쉬움","easyToUnderstand","thumb-up"],["문제가 해결됨","solvedMyProblem","thumb-up"],["기타","otherUp","thumb-up"]],[["이해하기 어려움","hardToUnderstand","thumb-down"],["잘못된 정보 또는 샘플 코드","incorrectInformationOrSampleCode","thumb-down"],["필요한 정보/샘플이 없음","missingTheInformationSamplesINeed","thumb-down"],["번역 문제","translationIssue","thumb-down"],["기타","otherDown","thumb-down"]],["최종 업데이트: 2024-12-21(UTC)"],[[["\u003cp\u003eThis document details how to view Access Transparency logs, which are generated when Google personnel access customer content within Google Workspace applications like Gmail, Docs, Sheets, and Slides.\u003c/p\u003e\n"],["\u003cp\u003eTo access these logs, you must possess the Logs Viewer IAM role and enable sharing of Google Workspace content with Google Cloud.\u003c/p\u003e\n"],["\u003cp\u003eThe Logs Explorer in the Google Cloud console allows you to retrieve, view, and analyze these logs by using a specific query string that includes your organization's unique ID.\u003c/p\u003e\n"],["\u003cp\u003eAccess Transparency logs provide information about the events and parameters when Google personnel access resources in Google Workspace.\u003c/p\u003e\n"],["\u003cp\u003eAn example of a generated log is included, which includes details on the activity, such as the GSuite product name, the owner's email and other important information.\u003c/p\u003e\n"]]],[],null,["# Viewing Access Transparency logs for Google Workspace\n=====================================================\n\nThis document explains how you can view and understand the Access Transparency logs\ngenerated when Google personnel access Customer Data in Google Workspace\nresources. Customer Data in Google Workspace includes text that you\nhave entered into Gmail, Google Docs, Google Sheets, Google Slides, and other\nGoogle Workspace apps.\n\nBefore you begin\n----------------\n\n- Make sure that you have the Logs Viewer (`roles/logging.viewer`) Identity and Access Management\n (IAM) role. For information about granting an IAM\n role, see [Grant a single role](/iam/docs/granting-changing-revoking-access#grant-single-role).\n\n- To use Access Transparency with Google Workspace, you must enable sharing of\n Google Workspace content with Google Cloud. For information about sharing\n Google Workspace content with Google Cloud, see [Sharing data with\n Google Cloud](https://support.google.com/a/answer/9320190).\n\nView Access Transparency logs for Google Workspace\n--------------------------------------------------\n\nYou can use the [Logs Explorer](/logging/docs/view/logs-explorer-summary) in the Google Cloud console to\nretrieve, view, and analyze Access Transparency logs. For information about using\nthe Logs Explorer, see [Using the\nLogs Explorer](/logging/docs/view/logs-explorer-interface).\n\nTo view Access Transparency logs for Google Workspace using the Logs Explorer,\ndo the following:\n\n1. Go to the **Logs Explorer** page in the Google Cloud console.\n\n [Go to Logs Explorer](https://console.cloud.google.com/logs/query)\n2. Enter the following query in the Logs Explorer:\n\n logName=\"organizations/\u003cvar translate=\"no\"\u003eORG_ID\u003c/var\u003e/logs/cloudaudit.googleapis.com%2Faccess_transparency\"\n jsonPayload.@type=\"type.googleapis.com/ccc_hosted_reporting.ActivityProto\"\n\n Replace \u003cvar translate=\"no\"\u003eORG_ID\u003c/var\u003e with the unique identifier of your\n Google Cloud organization.\n3. Click **Run query** to execute the query.\n\n\nSample Access Transparency log for Google Workspace\n---------------------------------------------------\n\nThe following sample is an example of the Access Transparency log for\nGoogle Workspace. \n\n {\n \"insertId\": \"-6x8cuqc3rk\",\n \"jsonPayload\": {\n \"activityId\": {\n \"uniqQualifier\": \"1720950322606095479\",\n \"timeUsec\": \"1621441673703908\"\n },\n \"@type\": \"type.googleapis.com/ccc_hosted_reporting.ActivityProto\",\n \"event\": [\n {\n \"status\": {\n \"success\": true\n },\n \"eventType\": \"GSUITE_RESOURCE\",\n \"parameter\": [\n {\n \"multiStrValue\": [\n \"GMAIL\"\n ],\n \"name\": \"GSUITE_PRODUCT_NAME\",\n },\n {\n \"name\": \"RESOURCE_NAME\",\n \"multiStrValue\": [\n \"//googleapis.com/gmail/users/owner@example.com\"\n ],\n },\n {\n \"name\": \"LOG_ID\",\n \"value\": \"Qt8v90c0fAEy_SyaOplDvJc\",\n },\n {\n \"multiStrValue\": [\n \"Google Initiated Service - For details, please refer to the documentation.\"\n ],\n \"name\": \"JUSTIFICATIONS\",\n },\n {\n \"name\": \"ACTOR_HOME_OFFICE\",\n \"value\": \"US\",\n },\n {\n \"value\": \"owner@example.net\",\n \"name\": \"OWNER_EMAIL\",\n }\n ],\n \"eventName\": \"ACCESS\"\n }\n ]\n },\n \"resource\": {\n \"type\": \"organization\",\n \"labels\": {\n \"organization_id\": \"12345\"\n }\n },\n \"timestamp\": \"2021-05-19T16:27:53.703908Z\",\n \"severity\": \"NOTICE\",\n \"logName\": \"organizations/12345/logs/cloudaudit.googleapis.com%2Faccess_transparency\",\n \"receiveTimestamp\": \"2021-05-19T16:28:52.867650088Z\"\n }\n\nFor information about the event and parameters that can appear in the\n`jsonPayload` field of the Access Transparency logs generated when Google personnel\naccess Google Workspace resources, see [Access Transparency Activity Events](https://developers.google.com/admin-sdk/reports/v1/appendix/activity/access-transparency).\n\nFor information about all the other fields in the Access Transparency logs for\nGoogle Workspace, see [LogEntry](/logging/docs/reference/v2/rest/v2/LogEntry).\n\nWhat's next\n-----------\n\n- Learn more about [Access Transparency audit logs](https://support.google.com/a/answer/9230979).\n- Learn more about [Google Workspace audit logs](/logging/docs/audit/gsuite-audit-logging)."]]