GCPVPCFlow

GCPVPCFlow Schema #

Table description #

TableSection TableType TableSectionName Description
Usx Regular Microsoft Sentinel The Google Cloud Platform (GCP) VPC Flow Logs enable you to capture network traffic activity at the VPC level, allowing you to monitor access patterns, analyze network performance, and detect potential threats across GCP resources.

Table retention #

HotDays ColdDays TotalInteractiveDays
14 16 30

Schema #

Name Description Type
_BilledSize Double
_IsBillable String
BytesSent Amount of bytes sent from the source to the destination. String
DestGatewayInterconnectName If the type of the gateway is INTERCONNECT_ATTACHMENT, this field is populated with the name of the Cloud Interconnect connection on which the VLAN attachment is configured. String
DestGatewayInterconnectProjectNumber If the type of the gateway is INTERCONNECT_ATTACHMENT, this field is populated with the Google Cloud project number of the Cloud Interconnect connection on which the VLAN attachment is configured. String
DestGatewayLocation Region of the destination gateway String
DestGatewayName Name of the destination gateway String
DestGatewayProjectId Google Cloud project ID of the destination gateway String
DestGatewayType Type of the destination gateway. Can be INTERCONNECT_ATTACHMENT or VPN_TUNNEL. String
DestGatewayVpc VPC network details of the gateway Object
DestGkeClusterLocation Location of the destination cluster. This can be a zone or a region depending if the cluster is zonal or regional. String
DestGkeClusterName Destination GKE cluster name. String
DestGkePodName Name of the destination Pod String
DestGkePodNamespace Namespace of the destination Pod String
DestGkePodWorkloadName Name of the top-level destination workload controller String
DestGkePodWorkloadType Type of the top-level destination workload controller. String
DestGkeService Destination GKE Service name. Object
DestGoogleServiceType This field is set to GOOGLE_API if the destination is a Google API service. String
DestInstanceGroupName Name of the instance group String
DestInstanceGroupRegion If the instance group is regional, this field is populated with the region of the instance group. String
DestInstanceGroupZone If the instance group is zonal, this field is populated with the zone of the instance group. String
DestInstanceProjectId ID of the Google Cloud project that contains the VM resource String
DestInstanceRegion Region of the VM String
DestInstanceVmName Instance name of the VM String
DestInstanceZone Zone of the VM String
DestIp Destination IP address String
DestLocationAsn The ASN of the external destination network to which this endpoint belongs. String
DestLocationCity City for external destination endpoints. String
DestLocationContinent Continent for external destination endpoints. String
DestLocationCountry Country for external destination endpoints. String
DestLocationRegion Region for external destination endpoints. String
DestPort Destination port String
DestVpcName Name of the network String
DestVpcProjectId ID of the Google Cloud project containing the VPC String
DestVpcSubnetworkName Name of the subnet String
DestVpcSubnetworkRegion Region of the subnet String
EndTime Timestamp of the last observed packet during the aggregated time interval. DateTime
GCPResourceType Type of the resource (e.g., compute instance, DNS record). String
InsertId A unique identifier assigned to each log entry. String
InternetRoutingDetailsEgressAsn List of relevant AS paths. If there are multiple AS paths available to the flow, the field might contain more than one AS path. String
LbBackendGroupLocation Location of the backend group String
LbBackendGroupName Name of the backend group String
LbBackendGroupType Type of the backend group String
LbBackendServiceName Name of the backend service. String
LbForwardingRuleName Name of the forwarding rule String
LbForwardingRuleProjectId Google Cloud project ID of the forwarding rule String
LbReporter Cloud Load Balancing reporter. Can be either CLIENT or BACKEND String
LbScheme Load balancer scheme String
LbType Load balancer type. String
LbUrlMapName Name of the URL map. Populated if the type of the load balancer is APPLICATION_LOAD_BALANCER. String
LbVpc VPC network details of the load balancer Object
Location Location of the resource. String
LogName The name of the log where this entry is stored. String
NetworkServiceDscp If the Differentiated Services field is present in packet headers, this field is populated with the DSCP value. String
PacketsSent Number of packets sent from the source to the destination. String
ProjectId ProjectId of the resource. String
Protocol The IANA protocol number String
PscAttachmentProjectId Google Cloud project ID of the service attachment String
PscAttachmentRegion Region of the service attachment String
PscAttachmentVpc VPC network details of the service attachment Object
PscEndpointConnectionId Private Service Connect connection ID String
PscEndpointProjectId Google Cloud project ID of the Private Service Connect endpoint String
PscEndpointRegion Region of the endpoint. Not populated if the target service type is GLOBAL_GOOGLE_APIS. String
PscEndpointTargetServiceType Target service type. Can be either GLOBAL_GOOGLE_APIS or PUBLISHED_SERVICE. String
PscEndpointVpc VPC network details of the Private Service Connect endpoint Object
ReceiveTimestamp Timestamp of the event when it was received by the logging service. DateTime
Reporter The side which reported the flow. String
Rttmsec The measured latency is the time elapsed between sending a SEQ and receiving a corresponding ACK. String
SourceSystem String
SrcGatewayInterconnectName If the type of the gateway is INTERCONNECT_ATTACHMENT, this field is populated with the name of the Cloud Interconnect connection on which the VLAN attachment is configured. String
SrcGatewayInterconnectProjectNumber If the type of the gateway is INTERCONNECT_ATTACHMENT, this field is populated with the Google Cloud project number of the Cloud Interconnect connection on which the VLAN attachment is configured. String
SrcGatewayLocation Region of the gateway String
SrcGatewayName Name of the gateway String
SrcGatewayProjectId Google Cloud project ID of the gateway String
SrcGatewayType Type of the gateway. Can be INTERCONNECT_ATTACHMENT or VPN_TUNNEL. String
SrcGatewayVpc VPC network details of the gateway Object
SrcGkeClusterLocation Location of the source cluster. This can be a zone or a region depending if the cluster is zonal or regional. String
SrcGkeClusterName Source GKE cluster name. String
SrcGkePodName Name of the source Pod String
SrcGkePodNamespace Namespace of the source Pod String
SrcGkePodWorkloadName Name of the top-level source workload controller String
SrcGkePodWorkloadType Type of the top-level source workload controller. String
SrcGkeService Source GKE Service name. Object
SrcGoogleServiceType This field is set to GOOGLE_API if the source is a Google API service. String
SrcInstanceGroupName Name of the source instance group String
SrcInstanceGroupRegion If the source instance group is regional, this field is populated with the region of the source instance group. String
SrcInstanceGroupZone If the source instance group is zonal, this field is populated with the zone of the source instance group. String
SrcInstanceProjectId ID of the Google Cloud project that contains the source VM resource String
SrcInstanceRegion Region of the source VM String
SrcInstanceVmName Instance name of the source VM String
SrcInstanceZone Zone of the source VM String
SrcIp Source IP address String
SrcLocationAsn The ASN of the external source network to which this endpoint belongs. String
SrcLocationCity City for external source endpoints. String
SrcLocationContinent Continent for external source endpoints. String
SrcLocationCountry Country for external source endpoints. String
SrcLocationRegion Region for external source endpoints. String
SrcPort Source port String
SrcVpcName Name of the source network String
SrcVpcProjectId ID of the Google Cloud project containing the VPC String
SrcVpcSubnetworkName Name of the source subnet, String
SrcVpcSubnetworkRegion Name of the source region String
StartTime Timestamp of the first observed packet during the aggregated time interval. DateTime
SubnetworkId ID of the Google Cloud project containing the VPC String
SubnetworkName Name of the subnet String
TenantId Unique identifier of the tenant into which the data connector ingests data. String
TimeGenerated The time the log entry was received by logging. DateTime
Timestamp Timestamp of the log entry. DateTime
Type The name of the table String

Schema changes #

Date Action
2026-01-02 Table added to tracking