Basic concepts

Cloud Logging is part of the Google Cloud's operations suite of products in Google Cloud. It includes storage for logs, a user interface called the Logs Viewer, and an API to manage logs programmatically. Logging lets you read and write log entries, query your logs, and control how you route your logs, including creating export sinks and logs-based metrics.


Logs are associated primarily with Google Cloud projects, although other Google Cloud resources, such as organizations, folders, and billing accounts, can also have logs.

Log entries

A log entry records status or an event. The entry might be created by Google Cloud services, AWS services, third-party applications, or your own applications. The "message" the log entry carries is called the "payload"; it can be a simple string or structured data.

Your project receives log entries when you begin to use the services that routinely produce log entries, like Compute Engine or BigQuery. You also get log entries when you connect Cloud Monitoring to AWS, when you install the Logging agent on your VM instances, and when you call the entries.write method in the Logging API.

For more information on log entry data formats, see the LogEntry type.


A log is a named collection of log entries within a Google Cloud resource. Each log entry includes the name of its log. A log name can be a simple identifier, like syslog, or a structured name including the log's writer, like Logs exist only if they contain log entries.

Retention period

Log entries are held in Cloud Logging for a limited time known as the retention period. After that, the entries are deleted. The retention periods for different types of logs are listed in Logging Quotas and limits.

You can configure the retention periods of some of your logs. For details, see Storing logs: Custom retention.

If you also want to back up your logs, export them outside of Cloud Logging.

Monitored resources

Each log entry indicates where it came from by including the name of a monitored resource. Examples include individual Compute Engine VM instances, Google Kubernetes Engine containers, database instances, and so on.

For a complete listing of monitored resource types, see Monitored resources and services.


A query is a filter expression in the Logging query language. It is used in the Logs Viewer and the Logging API to select log entries, such as those from a particular VM instance or those arriving in a particular time period with a particular severity level.

Logs Router

All logs, including audit logs, platform logs, and user logs, are sent to the Cloud Logging API where they pass through the Logs Router. The Logs Router checks each log entry against existing rules to determine which log entries to ingest (store), which log entries to include in exports, and which log entries to discard.

For more details, see Logs Router overview.

Exporting logs using sinks

Log entries received by Logging can be exported to Cloud Storage buckets, BigQuery datasets, and Pub/Sub topics.

You export logs by configuring log sinks, which then continue to export log entries as they arrive in Logging. A sink includes a destination and a query that selects the log entries to export.

For details, see Overview of logs exports.

Logs-based metrics

Metrics are a feature of Cloud Monitoring. A logs-based metric is a metric whose value is the number of log entries that match a query that you specify.

For details, see Overview of logs-based metrics

Log types

To learn about the types of logs available in Cloud Logging, see Available logs.

Access control

The ability to access Logging logs is controlled by granting Identity and Access Management permissions to members.

Most logs can be read by any member with the IAM Viewer role. To read Data Access audit logs or Access Transparency logs, the member requires either the IAM Owner role or a custom role with special permissions.

For more information on required permissions, see Access control.