Cloud Cost Sense
Google Cloud Logging Cost: Ingestion, Retention, and Exclusions
Estimate Google Cloud Logging cost from log volume, bucket retention, network telemetry, duplicate routing, and destination charges.
Measure bytes stored instead of counting log lines
Cloud Logging storage is based on the volume streamed into the _Default and user-defined log buckets. Start with billable bytes by project and log bucket, then separate application logs, audit logs, and network telemetry. A request count alone is misleading because stack traces, structured payloads, and repeated labels can make entries very different sizes.
The _Required bucket stores specific audit logs without Logging storage or retention charges. Copies routed from _Required into another bucket can become billable, however. Check the current Google Cloud Observability pricing page for the monthly free allotment and rates rather than treating a saved estimate as a quote.
Add retention and every storage destination
The _Default and user-defined buckets use a 30-day default retention period. Keeping logs longer adds retention charges based on retained volume, while the _Required bucket has a fixed 400-day retention period without those charges. Match each bucket's retention to incident response, security, and compliance needs instead of extending every log equally.
Log Router itself has no additional charge, but destination services can charge for storage, processing, or transfer. Routing one entry into multiple log buckets also stores and bills multiple copies. Build the estimate as ingestion into each bucket, extended retention, and any Cloud Storage, BigQuery, or Pub/Sub destination cost.
Reduce noisy logs without losing evidence
Rank log sources by monthly bytes and usefulness before changing filters. Common candidates include duplicate request logs, successful health checks, verbose debug payloads, and high-volume network telemetry. VPC Flow Logs, Firewall Rules Logging, and Cloud NAT logs are vended network logs with distinct pricing, so estimate them separately from application logs.
Use sink exclusions or disable unnecessary generation at the source, but preserve security, audit, error, and recovery evidence. Exclusions reduce stored volume only after entries reach the Logging API, so they do not reduce write-request quotas. Validate a filter against sampled logs, monitor error visibility after rollout, and compare Logs Storage usage across equivalent periods.