Audit Logs for Small Business: What to Turn On and How Long to Keep Them

Ulises Paiz

Ulises Paiz is the owner and sole engineer at Ghosxt, a Salinas, CA managed IT and cybersecurity provider. He holds an M.S. in Cybersecurity and Information Assurance (WGU, 2026) and nine industry certifications including CompTIA SecurityX, CySA+, and Microsoft AZ-104, with prior DoD and federal contractor infrastructure experience. More about Ulises →

When a small business gets breached, the first two questions are always the same: how did they get in, and what did they take? Without logs, the honest answer to both is "we don't know." That uncertainty is expensive. It can turn a contained incident into a full notification, and it makes insurance claims harder.

Logging is not glamorous, but it is the difference between investigating a breach and guessing at one. Here is what to turn on, how long to keep it, and how to make sure someone actually looks.

Why audit logs matter before you need them

An audit log is a time-stamped record of who did what: who signed in and from where, who opened or shared a file, who changed a setting or created a rule. You cannot add logs after an incident. If logging was off or the records have already expired, that history is gone.

Logs also catch quiet attacks that never trigger an antivirus alert. A stolen password used from another country, a hidden email forwarding rule, or a departing employee downloading the client folder are all visible only in the audit trail. They are the evidence behind business email compromise cases and insider threat investigations.

1. Turn on the logs that answer real questions

You do not need to log everything. Start with the sources that tell you who accessed your data:

  • Microsoft 365: confirm the unified audit log is enabled in the Microsoft Purview portal, and that mailbox auditing is on. It is on by default for most tenants, but verify it. Our Microsoft 365 settings guide covers the neighboring controls.
  • Google Workspace: review the login, Drive, and admin audit reports under Reporting in the Admin console. See our Workspace security settings guide.
  • Windows computers and servers: enable security auditing for logons, account changes, and new services, and raise the Security log size above the small default, which can overwrite itself within days.
  • Firewall and VPN: keep connection and admin login logs, since edge devices are a favorite target.

If you run a point-of-sale or medical system, add its application logs too. Compliance programs such as PCI DSS and HIPAA expect audit controls.

2. Set retention long enough to matter

Default retention is often shorter than the time attackers stay hidden. Microsoft 365 Business Premium keeps standard audit records for 180 days, and most Google Workspace reports are kept for roughly six months. Windows event logs are limited by file size, not time.

Aim for 12 months of history. PCI DSS expects a year of logs with the latest three months readily available, and insurers and customers often ask for at least 90 days on a renewal application or security questionnaire.

Where the platform cannot keep that long, export or forward logs to separate storage. Keep a copy that administrators cannot quietly delete, because one of the first things an intruder with admin access does is clear the evidence.

3. Make sure someone is watching

A log nobody reads is a record of a breach you missed. You do not need a big security operations team. Pick a short list of events that deserve an alert:

  • Sign-ins from new countries, or impossible travel between two locations.
  • New mailbox forwarding or inbox rules.
  • Admin accounts created, or MFA removed from a user.
  • Large file downloads or sharing to personal accounts.
  • Repeated failed logins, a sign of password spraying.

Review those weekly, or hand the job to a managed detection and response service that watches around the clock. Write down what you do when an alert fires, and fold it into your incident response plan.

Common mistakes to avoid

  • Assuming logging is on without ever checking it.
  • Discovering the 90-day limit only after a breach is 120 days old.
  • Letting every admin account have permission to delete logs.
  • Collecting logs from every device but alerting on none of them.
  • Forgetting that employee monitoring has privacy limits. Tell staff what is logged in your acceptable use policy.

The takeaway

Logs are cheap insurance for the day something goes wrong. Verify that audit logging is on in Microsoft 365 or Google Workspace, raise retention toward 12 months, protect a copy from tampering, and decide who reads the alerts. An hour of setup now can save weeks of guesswork later.

Frequently asked questions

What is an audit log?

An audit log is a time-stamped record of who did what in a system: sign-ins, file access, setting changes, and email rules. It is the evidence you use to work out what happened after something goes wrong.

Does Microsoft 365 keep audit logs by default?

Microsoft 365 audit logging is on by default for most business tenants, and Business Premium keeps Standard audit records for 180 days. Longer retention, and some detailed events, need a higher license or an add-on, so check your plan before you need the data.

How long should a small business keep logs?

A practical target is 12 months. Attackers are often inside a network for weeks or months before anyone notices, and PCI DSS expects 12 months of log history with the most recent three months immediately available. Insurers and customers commonly ask for at least 90 days.

Where do I see Google Workspace audit logs?

In the Google Admin console, open Reporting, then Audit and investigation. You can search login, Drive, admin, and Gmail log events there. Most Workspace reports are kept for about six months, so export anything you need for longer.

Do I need a SIEM to do this?

No. Most small businesses need logging turned on, retention set, and a human or a managed detection and response service that actually reads the alerts. A SIEM adds central search across sources, but it is worthless if the underlying logs were never enabled.

Want logging turned on and someone watching it?

Ghosxt enables audit logging across Microsoft 365, Google Workspace, and your devices, sets retention, and reviews the alerts for you. You talk directly to the owner. See current pricing or our cybersecurity services.

Book your free assessment

Prefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.

Book free assessment Call (831) 204-0501