Use this page to learn how to view logs, monitor requests, and track distributed traces for traffic routed through your Agent Gateway deployment.
Logging
Agent Gateway logs are generated using the
networkservices.googleapis.com/Gateway monitored resource.
You can use these logs to monitor access requests to the gateway. This includes the logs created when Agent Gateway is deployed in dry-run mode.
View logs for a specific gateway
To view the logs for a specific gateway, complete the following steps.
Console query
In the Google Cloud console, go to the Logs Explorer page.
Click the Show query toggle.
Paste the following into the query field.
resource.type="networkservices.googleapis.com/Gateway" resource.labels.location="REGION" resource.labels.gateway_name="AGENT_GATEWAY_NAME"
Replace the following:
REGION: The region of your gateway.AGENT_GATEWAY_NAME: The name of your gateway.
Click Run query.
Agent Platform log names
To query specific types of log entries in the Logs Explorer, you can
filter your query by log name using the logName field. The following table
describes the primary log names generated by the Agent Gateway
and agent-side operations:
| Log name | Description |
|---|---|
projects/PROJECT_ID/logs/networkservices.googleapis.com%2Fgateway_requests |
Logs for gateway allow and deny decisions. |
projects/PROJECT_ID/logs/cloudaudit.googleapis.com%2Fdata_access |
Cloud Audit Logs for Identity-Aware Proxy (IAP) AuthorizeUser decisions. |
projects/PROJECT_ID/logs/aiplatform.googleapis.com%2Freasoning_engine_stderr |
Agent-side startup and execution errors (reasoning engine stderr). |
projects/PROJECT_ID/logs/aiplatform.googleapis.com%2Freasoning_engine_stdout |
Agent-side standard output (reasoning engine stdout). |
Replace PROJECT_ID with your Google Cloud project ID.
If you use Model Armor for content sanitization, those logs are emitted separately. For instructions on querying Model Armor logs, see View raw content security logs in Logs Explorer.
What is logged
Agent Gateway log entries contain information useful for monitoring and debugging traffic to and from your gateway.
| Field | Field format | Field type: Required or Optional | Description |
|---|---|---|---|
| severity insertID timestamp receiveTimestamp trace traceSampled logName |
LogEntry | Required | The general fields as described in a log entry. |
| httpRequest | HttpRequest | Required | A common protocol for logging HTTP requests. |
| resource | MonitoredResource | Required | The |
| jsonPayload | object (Struct format) | Required | The log entry payload that is expressed as a JSON object. The JSON object contains the following Agent Gateway fields:
|
Monitoring
Agent Gateway exports some Service Extensions metrics to Cloud Monitoring. If you're delegating authorization to Service Extensions, you can use these metrics to monitor traffic to and from your extension. For details, see Logging and monitoring for Cloud Load Balancing callouts.
Observability dashboard
Agent Gateway provides an observability dashboard that lets you monitor, audit, and debug traffic routed through your gateways:
- Scorecards: Track the total number of attempted authorizations, authorization failures, and requests per second.
- Charts: Visualize authorization failure rates (%) and requests per second over time.
- Egress traffic logs: Review detailed logs for egress queries, including
403denials, traffic to unregistered endpoints, and overall traffic trends.
Use the following steps to access the observability dashboard for a gateway in the Google Cloud console:
In the Google Cloud console, go to the Agent Gateway page.
Click the name of the gateway that you want to monitor.
Click the Observability tab.
Dashboard data requirements
The Agent Gateway observability dashboard uses
Observability Analytics to display data. If the dashboard isn't loading data,
ensure that you upgrade the _Default log bucket to use
Observability Analytics. The dashboard
retrieves data from the _Default bucket's _AllLogs
view.
Use Cloud Trace
Agent Gateway integrates with Cloud Trace to provide end-to-end request observability for agent workloads. Because Agent Gateway serves as the central control point for AI agents, enabling Trace gives you visibility into how requests travel from your agents through the gateway and across multiple Google Cloud services, tools, agents, and MCP servers. By tracking request flows across these service boundaries, Trace delivers complete distributed tracing for your agent architectures.
Using Trace, you can accomplish the following:
- Debug agent interactions with precision: Track the full journey of a request across service boundaries to isolate latency bottlenecks and failing backend calls.
- Honor upstream sampling decisions: Use parent-based sampling to maintain end-to-end trace continuity when upstream agents or clients initiate tracing, ensuring high-priority requests are fully captured without increasing baseline sampling rates for routine traffic.
- Unify observability with open standards: Built on OpenTelemetry and W3C TraceContext standards, traces seamlessly propagate context across your AI agents, Agent Gateway, target MCP servers or tools, and third-party monitoring platforms.
- Accelerate root-cause analysis: Correlate trace spans directly with
gateway request logs and metrics using
trace_idto troubleshoot production issues faster.
To learn more about Trace, see Cloud Trace overview.
Required roles
You must have the following Identity and Access Management (IAM) roles on your project:
- To configure and update a tracing policy: Compute Network Admin
(
roles/compute.networkAdmin) or Compute Admin (roles/compute.admin) - To view traces in the Google Cloud console: Cloud Trace User
(
roles/cloudtrace.user)
Additionally, to allow Agent Gateway to write trace spans to
Trace, you must grant the Cloud Trace Agent
role
(roles/cloudtrace.agent) to the following service accounts:
- Compute Engine service agent:
service-PROJECT_NUMBER@compute-system.iam.gserviceaccount.com - Network Security service agent:
service-PROJECT_NUMBER@gcp-sa-networksecurity.iam.gserviceaccount.com - Agent Gateway service agent:
service-PROJECT_NUMBER@gcp-sa-agentgateway.iam.gserviceaccount.com - Agent or client workload service account: If the calling AI agent or
client workload initiates the trace and exports its own parent spans to
Trace, then the workload's service account or the custom
service account attached to the agent must also be granted the
roles/cloudtrace.agentrole on the project. Otherwise, only the Agent Gateway child span is written and the parent span will be missing in Trace.
Replace PROJECT_NUMBER with your Google Cloud project number.
For more information about granting roles, see Manage access to projects, folders, and organizations.
Enable tracing
To enable tracing for Agent Gateway, create an observability policy YAML file and import it using the gcloud CLI.
Create a configuration file named
tracing-policy.yaml:name: "projects/PROJECT_ID/locations/REGION/telemetryPolicies/POLICY_NAME" targetTelemetry: resources: # You can attach a policy to multiple gateways - "//networkservices.googleapis.com/projects/PROJECT_ID/locations/REGION/agentGateways/AGENT_GATEWAY_NAME" displayName: "Tracing policy for Agent Gateway traffic" tracingConfiguration: samplingRate: SAMPLING_RATE parentBasedSampling: enabled: ENABLE_PARENT_BASED_SAMPLING samplingRate: PARENT_BASED_SAMPLING_RATEReplace the following:
PROJECT_ID: Your Google Cloud project ID.REGION: The region of your gateway (for example,europe-west1).POLICY_NAME: A name for the observability policy (for example,my-agw-tracing-policy).AGENT_GATEWAY_NAME: The name of your gateway.SAMPLING_RATE: The fraction of requests to trace. Set to a value from0.0to1.0. For high-traffic production environments, we recommend a rate of 1% (0.01) or 0.1% (0.001) to balance observability and ingestion costs.ENABLE_PARENT_BASED_SAMPLING: Controls whether to honor the sampled bit in incomingtraceparentheaders from upstream callers. Set totrueorfalse.PARENT_BASED_SAMPLING_RATE: The fraction of pre-sampled requests to trace. Set to a value from0.0to1.0. For example,1.0traces 100% of pre-sampled requests.
Import the observability policy:
gcloud beta network-services telemetry-policies import POLICY_NAME \ --source=tracing-policy.yaml \ --location=REGION
View traces
After enabling distributed tracing and sending traffic through your gateway, you can view trace details in the Google Cloud console:
-
In the Google Cloud console, go to the
Trace explorer page:
You can also find this page by using the search bar.
In the Filter bar, enter a trace filter expression (for example, to filter by latency threshold, HTTP status code, or request URI) or search by the specific trace ID.
To learn more about using the Trace explorer UI, see Find and explore traces.
Trace explorer
Trace explorer view in Trace Trace timeline view
Timeline view in Trace Trace graph view
Graph view in Trace
Correlate traces with logs and metrics
Agent Gateway provides seamless correlation between traces, logs, and metrics:
Log-trace correlation: every gateway request log entry written to Cloud Logging contains a
tracefield with the format:projects/PROJECT_ID/traces/TRACE_ID.- In the Logs Explorer, click the log entry and then select View trace details to navigate directly to the corresponding span in Trace.
- In Trace, click Show logs on the Trace Details pane to view all gateway request logs that are associated with that request.
Metric correlation: compare latency spikes observed in Cloud Monitoring metrics, such as
networkservices.googleapis.com/agentgateway/total_latencies, with trace span breakdowns to identify whether a latency spike occurred within the gateway or at the destination tool or server.
Troubleshooting
This section describes common issues and their resolutions.
Traces do not appear in Cloud Trace:
Verify that the Cloud Trace API (
cloudtrace.googleapis.com) is enabled on your project:gcloud services enable cloudtrace.googleapis.com --project=PROJECT_ID
Verify that the required Cloud Trace Agent IAM roles (
roles/cloudtrace.agent) have been granted to all the required service accounts.Verify that the observability policy exists in the correct region and that it references the appropriate Agent Gateway gateway:
gcloud beta network-services telemetry-policies describe POLICY_NAME \ --location=REGIONCheck the configured
samplingRate. If traffic volume is low or the sampling rate is low, traces might not be captured immediately. To confirm that tracing is functioning, you can temporarily update your policy to use 100% sampling (samplingRate: 1.00). Restore your production rate when you are finished testing.
Incomplete trace spans:
If trace spans appear as independent or disconnected root traces instead of child spans of your application requests, then do the following:
- Verify that
parentBasedSamplingis enabled (set totrue) in your observability policy. - Verify that the calling AI agent or workload's service account has been
granted the Cloud Trace Agent role (
roles/cloudtrace.agent) on the project so that parent spans can be exported to Trace. - Verify that your application uses an OpenTelemetry SDK that has
distributed tracing context propagation enabled so that the W3C
traceparentheader is propagated across service boundaries. For more information, see the OpenTelemetry TraceContext propagator documentation.
- Verify that
What's next
Codelab: Govern agentic workloads with Agent Platform
Learn how to govern agentic workloads with Agent Gateway on Gemini Enterprise Agent Platform.