GCPDNS

GCPDNS Schema #

Table description #

TableSection TableType TableSectionName Description
Usx Regular Microsoft Sentinel The Google Cloud Platform DNS data connector provides the capability to ingest Cloud DNS Query logs and Cloud DNS Audit logs into Microsoft Sentinel using the Google Cloud DNS API.

Table retention #

HotDays ColdDays TotalInteractiveDays
14 16 30

Schema #

Name Description Type
_BilledSize Double
_IsBillable String
AuthAnswer Indicates if the DNS response is authoritative. Boolean
AuthenticationInfoPrincipalEmail Email address of the user or service account performing the action. String
AuthenticationInfoPrincipalSubject The subject identifier for the principal (user or service account). String
AuthorizationInfo Details about the authorization decision for the request. String
DestinationIP Target IP address of the request. String
GCPResourceName Name of the resource being accessed or modified. String
GCPResourceType Type of the resource (e.g., compute instance, DNS record). String
InsertId A unique identifier assigned to each log entry. String
LogName The name of the log where this entry is stored. String
MethodName The API method or operation invoked in the request. String
PayloadType The format or type of the payload in the log entry. String
Protocol Protocol used (e.g., TCP, UDP). String
QueryName The domain name queried. String
QueryType DNS query type (RFC 1035 section 4.1.2). String
Rdata DNS answer in presentation format. String
ReqManZoneCloudLogConfigEnableLogging Indicates whether logging was enabled in the request for the managed zone. Boolean
ReqManZonePrivVisibConfigNetworks List of networks configured for private visibility of the managed zone. String
ReqmetaCallerSuppliedUserAgent User agent String provided by the caller. String
ReqmetaRequestAttributesTime Timestamp when the request was initiated. DateTime
RequestAPIType The type of API request being logged. String
RequestChangeAdditions Details of resource additions in the request. String
RequestChangeDeletions Details of resource deletions in the request. String
RequestManagedZone Details of the managed DNS zone in the request. String
RequestManagedZoneDescription Description of the managed DNS zone in the request. String
RequestManagedZoneDnsName The DNS name of the managed zone in the request. String
RequestManagedZoneName The name of the managed DNS zone in the request. String
RequestManagedZoneVisibility The visibility (public or private) of the managed zone in the request. String
RequestMetadataCallerIp IP address of the caller initiating the request. String
RequestName Name of the resource affected by the request. String
RequestProject Google Cloud project associated with the request. String
RequestType Type of the request (e.g., Create, Delete, Update). String
ResManZoneCloudLogConfigEnableLogging Indicates whether logging was enabled in the response for the managed zone. Boolean
ResourceLabelsLocation Location of the resource. String
ResourceLabelsPolicyName Represents the policy name associated with the DNS resource. String
ResourceLabelsProjectId Google Cloud project ID associated with the resource. String
ResourceLabelsSourceType Specifies the source type of the resource being modified String
ResourceLabelsTargetName The target resource name within Google Cloud DNS, such as the managed zone or DNS policy being modified. String
ResourceLabelsTargetType The type of DNS resource being acted upon String
ResourceLabelsZoneName The name of the managed DNS zone related to the operation. String
RespManZonePrivVisibConfigNetworks Lists networks associated with a private managed zone under private visibility configuration. String
ResponseChangeAdditions Represents additions made to DNS records (e.g., new A, AAAA, CNAME, or TXT records). String
ResponseChangeDeletions Details of deletions in the response. String
ResponseChangeId Identifier for the change request in the response. String
ResponseChangeStartTime Timestamp indicating when the change operation started. DateTime
ResponseChangeStatus Status of the change operation in the response. String
ResponseCode Response code for the operation. String
ResponseManagedZoneCreationTime Timestamp when the managed zone was created. DateTime
ResponseManagedZoneDescription Description of the managed zone returned in the response. String
ResponseManagedZoneDnsName DNS name of the managed zone returned in the response. String
ResponseManagedZoneFingerprint Fingerprint for detecting changes in the managed zone. String
ResponseManagedZoneId Unique identifier for the managed zone. String
ResponseManagedZoneName Name of the managed zone returned in the response. String
ResponseManagedZoneNameServers List of name servers associated with the managed zone. String
ResponseManagedZoneRrsetCount The total number of resource record sets (RRsets) within a managed zone. String
ResponseManagedZoneVisibility Visibility setting (public/private) of the managed zone. String
ResponseOperationId A unique identifier for the DNS operation performed. String
ResponseOperationStartTime The timestamp when the DNS operation started. DateTime
ResponseOperationStatus The status of the DNS operation String
ResponseOperationType The type of DNS operation executed (e.g., create, update, delete). String
ResponseOperationUser The user or service account that performed the DNS operation. String
ResponseOpZoneContextNewValue The new value after an operation modifies a DNS managed zone. String
ResponseOpZoneContextOldValue The previous value before an operation modified the DNS managed zone. String
ResponseType Type of response returned from the API. String
ServerLatency Measures the latency of the request to Google Cloud DNS. String
ServiceName Name of the Google Cloud service processing the request. String
Severity Log severity level (e.g., INFO, WARNING, ERROR). String
SourceIP IP address from which the query originated. String
SourceNetwork The originating network of the DNS request. String
SourceSystem String
StatusCode HTTP status code returned for the request. String
TenantId Unique identifier of the tenant into which the data connector ingests data. String
TimeGenerated The timestamp when the log entry was created. DateTime
Timestamp Timestamp when the log entry was recorded. DateTime
Type The name of the table String
VmInstanceId Compute Engine VM instance ID. String
VmInstanceIdString The VM instance ID (if applicable) associated with the request. String
VmInstanceName Compute Engine VM instance name. String
VmProjectId Google Cloud project ID of the network from which the query was sent. String
VmZoneName Name of the VM zone from which the query originated. String

Schema changes #

Date Action
2026-01-02 Table added to tracking