GCPNAT

GCPNAT Schema #

Table description #

TableSection TableType TableSectionName Description
Usx Regular Microsoft Sentinel The Google Cloud Platform NAT data connector provides the capability to ingest Cloud NAT Audit logs and Cloud NAT Traffic logs into Microsoft Sentinel using the Compute Engine API. Refer the Product overview document for more details.

Table retention #

HotDays ColdDays TotalInteractiveDays
14 16 30

Schema #

Name Description Type
_BilledSize Double
_IsBillable String
AllocationStatus Status of the NAT IP address allocation. String
ASN Autonomous System Number (ASN) associated with the destination IP. String
City City of the destination IP address (geo-located). String
Continent Continent where the destination IP is located. String
Country Country of the destination IP address (geo-located). String
DestinationRegion Continent or larger geographical region of the destination. String
DestIp Destination external IP address the traffic was sent to. String
DestPort Destination port on the remote host. String
EndpointRegion Region of the destination endpoint. String
EndpointZone Zone of the destination endpoint if applicable. String
GatewayName Name of the Cloud NAT gateway instance. String
GCPResourceType Type of the monitored GCP resource (e.g., ‘router’, ‘gce_instance’). String
InsertId Unique identifier for the log entry within the GCP logging system. String
LogName Name of the log stream. String
NatIp Public NAT IP address assigned for this flow. String
NatPort Public NAT port assigned for this flow. String
ProjectId ID of the GCP project that generated the log entry. String
Protocol Network protocol used in the connection. String
ReceiveTimestamp The time the log entry was received by GCP Logging. DateTime
Region Region of the GCP resource involved in the NAT traffic. String
RouterId Identifier of the Cloud Router managing the NAT gateway. String
SourceSystem String
SrcIp Source internal IP address from which the traffic originated. String
SrcPort Source port on the internal VM or resource. String
TenantId Unique identifier of the tenant into which the data connector ingests data. String
TimeGenerated The timestamp when the log was ingested by Log Analytics. DateTime
Type The name of the table String
VmName Name of the virtual machine that initiated the NAT traffic. String

Schema changes #

Date Action
2026-01-02 Table added to tracking