GCPFirewallLogs

GCPFirewallLogs Schema #

Table description #

TableSection TableType TableSectionName Description
Usx Regular Microsoft Sentinel The Google Cloud Platform (GCP) firewall logs, enable you to capture network inbound and outbound activity to monitor access and detect potential threats across Google Cloud Platform (GCP) resources.

Table retention #

HotDays ColdDays TotalInteractiveDays
14 16 30

Schema #

Name Description Type
_BilledSize Double
_IsBillable String
Action The Action that of the firewall rule. String
DestIp the IP address of the target device or service that incoming or outgoing network traffic is trying to reach. String
DestPort the Port of the target device or service that incoming or outgoing network traffic is trying to reach. String
Direction The direction of that the firewall rule applies. String
Disposition the final action taken on network traffic that matches a given rule. String
GCPResourceType The identifier of the type associated with this resource, such as ‘pubsub_subscription’. String
InsertId Optional. Providing a unique identifier for the log entry allows Logging to remove duplicate entries with the same timestamp and insertId in a single query result. String
InstanceProjectId the project ID associated with the instance that was involved in the firewall rule event. String
InstanceRegion the region associated with the instance that was involved in the firewall rule event. String
InstanceVmName the virtual machine name associated with the instance that was involved in the firewall rule event. String
InstanceZone the zone associated with the instance that was involved in the firewall rule event. String
IpPortInfo The information regarding the rule port and protocol. Object
LogName Information including a suffix identifying the log sub-type (e.g., admin activity, system access, data access) and where in the hierarchy the request was made. String
Priority The priority of the rule. String
ProjectId The identifier of the Google Cloud Platform (GCP) project associated with this resource, such as “my-project”. String
Protocol the protocol of the target device or service that incoming or outgoing network traffic is trying to reach. String
Referance The rule that triggered the log. String
RemoteLocationCity The city name based on the resource location. String
RemoteLocationContinent The continent name based on the resource location. String
RemoteLocationCountry The country name based on the resource location. String
RemoteLocationRegion The region name based on the resource location. String
ResourceLocation The resource location information. String
ResourceSubnetworkName The resource subnetwork name. String
SourceRange The range of the ip addresses that the rule applied to. Object
SourceSystem String
SrcIp the IP address of the source device or service that incoming or outgoing network traffic is trying to reach. String
SrcPort the Port of the source device or service that incoming or outgoing network traffic is trying to reach. String
SubnetworkId The resource subnetwork id. String
TenantId Unique identifier of the tenant into which the data connector ingests data. String
TimeGenerated The time the log entry was received by logging. DateTime
Timestamp The time the event described by the log entry occurred. DateTime
Type The name of the table String
VpcName The name of the Virtual Private Network(VPC) where the firewall rule applied. String
VpcProjectId The project id of the Virtual Private Network(VPC) where the firewall rule applied. String
VpcSubnetworkName The Subnetnetwork name of the Virtual Private Network(VPC) where the firewall rule applied. String

Schema changes #

Date Action
2026-01-02 Table added to tracking