GCPNATAudit

GCPNATAudit Schema #

Table description #

TableSection TableType TableSectionName Description
Usx Regular Microsoft Sentinel The Google Cloud Platform NAT data connector provides the capability to ingest Cloud NAT Audit logs and Cloud NAT Traffic logs into Microsoft Sentinel using the Compute Engine API. Refer the Product overview document for more details.

Table retention #

HotDays ColdDays TotalInteractiveDays
14 16 30

Schema #

Name Description Type
_BilledSize Double
_IsBillable String
AuthorizationInfo Details about the authorization. String
CallerIp IP address of the caller. String
EncryptedInterconnectRouter Whether the router uses encrypted interconnect. Boolean
GCPResourceName Name of the resource affected. String
GCPResourceType Type of the GCP resource. String
InsertId A unique ID for the log entry. String
LogName The name of the log stream. String
MethodName API method invoked. String
OperationFirst Indicates if this is the first operation in the series. Boolean
OperationId Identifier of the operation. String
OperationLast Indicates if this is the last operation in the series. Boolean
OperationProducer Producer of the operation. String
PayloadRequestNats NATs request payload. String
PayloadType Type of payload in the log. String
PrincipalEmail Email of the principal initiating the request. String
PrincipalSubject Subject or identity of the principal. String
ProjectId GCP Project ID where the event occurred. String
ReceiveTimestamp Time when the log was received. DateTime
RequestAttributeAuth Authorization details of the request. String
RequestAttributeDestination Destination details of the request. String
RequestAttributeTime Timestamp of the request attribute. DateTime
RequestId Unique ID of the request. String
RequestName Name of the request. String
RequestNetwork Network where the request was made. String
RequestRegion Region where the request originated. String
RequestSelfLink SelfLink URL of the request resource. String
RequestType Type of the request. String
ResourceLocation Geographic location of the resource. String
ResourceRegion Region of the GCP resource. String
ResponseErrorCode Error code if any error occurred. String
ResponseErrorMessage Error message returned, if any. String
ResponseErrors Details of any errors returned. String
ResponseId Identifier of the response. String
ResponseInsertTime Insert time of the response. DateTime
ResponseName Name of the response. String
ResponseOperationType Type of operation performed. String
ResponseProgress Progress status of the response. String
ResponseRegion Region associated with the response. String
ResponseSelfLink SelfLink URL of the response. String
ResponseSelfLinkWithId SelfLink URL with ID in the response. String
ResponseStartTime Start time of the response. DateTime
ResponseStatus Status of the response. String
ResponseTargetId Target ID in the response. String
ResponseTargetLink Target link in the response. String
ResponseType Type of the response returned. String
ResponseUser User returned in the response. String
RootTriggerId Root trigger ID of the operation. String
RouterId Identifier of the Cloud Router. String
ServiceName Name of the GCP service. String
Severity Severity level of the event. String
SourceSystem String
TenantId Unique identifier of the tenant into which the data connector ingests data. String
TimeGenerated The time at which the log was generated. DateTime
Type The name of the table String
UserAgent User agent string of the caller. String

Schema changes #

Date Action
2026-01-02 Table added to tracking