Gmail content compliance rules - logging?

Former Community Member
Not applicable

HI,

Where can I find logs for content compliance rules?

Cheers,

Arto

1 4 743
4 REPLIES 4

Hi , have you looked under the Audit > Rules tab?

Hi @jongunnarsson,

If it is in Rule logs then then what should be DataSource and Attribute

techdeepak_0-1659532694032.png

 

Hi @techdeepak , there are  attributes called rule id and rule name , you can experiment with a conditional of either of those.

I did some tests, and cannot find a specific section related to Gmail Compliance Rules, which is an unfortunate choice by Google.

Checking under the "Security Investigation tool > Rule log events" - these seem to only be the Rules-module Drive/DLP items, and not Gmail Compliance Rules (which are not managed within the Rules section).  I tried selecting 'Rule log events > Data source=Gmail', and no events are returned.

I also attempted "Security Investigation tool > Gmail log events" - no success.  There is an 'Event' option, but no options cover Compliance Rule execution/trigger.  You can select "Spam" and find if a custom rule flagged something spam, but this now appears to become a spam investigation.

It may be possible to use BigQuery; I have not attempted.  You can feed Gmail logs into BigQuery, so it may be that accessing these "raw" logs provides more data to be examined (including Compliance Rule trigger) then what Google makes available within the Security Investigation Tool UI.