Concept and mechanism
A logging pipeline has several stages, and each control acts at one of them. In Ops Agent, defining a receiver is insufficient if no active pipeline references it. Connect collection to the flow and validate with representative events. Processors run in order; removing a field before parsing creates that field can leave it in final output. Also validate whether sensitive values remain in another representation, such as the original payload. After receipt, Log Router evaluates sinks. For non-intercepting sinks, each filter is independent: two sinks can route the same event. Do not treat configuration as a list where only the first match wins.
Guided application
In a fictional incident, the team creates a central destination after spending time finding logs. The new sink routes future logs; it does not automatically replay history. If history still exists at source, query it with suitable access or plan transfer through a supported mechanism. Aggregated interception changes descendant handling of matching logs, with the relevant exception of the origin _Required sink. Another distinction appears when sink exclusions reduce storage but entries.write pressure remains: the API received calls before those exclusions. To reduce emission, work at the producer or appropriate collection stage and measure impact. Do not remove evidence needed for the SLO, incident, or retention requirements merely to make a volume chart smaller.
A central destination empty before sink creation does not prove absence of source events.
Common pitfalls
Defined receiver as active; sink as backfill; exclusion as call reduction; transformation without order.
Related topics: Organization, identity, and visibility · Infrastructure, revisions, and environments · Pipelines, promotion, and recovery
Locate the problem stage before changing filters or retention.
Reference: Cloud Logging routing and sinks · Current linked guide; edition date unconfirmed (2026-09-30 inspection)