I'm currently validating our Drive sharing settings so that we can place more restrictive trust rules in place, our current rules only restrict Shared Drives from sharing externally, 'My Drive' is not inhibited. Currently filtering the drive audit log with `Visibility>Is>Shared Externally` this yields a ton of files that don't have any external users, groups, shared with (that I can see) yet are marked as shared externally. Any reasons as to why it would log it like that?
one possible explanation is that if you turn off external sharing and a user shared a resource with a group that allows external users, that would still count as "shared externally."
So even though external users in the group can't access the data itself, you'll see that logged. This also applies even if the group doesn't have any external users.