Google Workspace connector reference

Important

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Google Workspace from the Previews page. See Manage Azure Databricks previews.

This page has reference information for the managed Google Workspace connector, including supported source tables and destination table schemas.

Supported source tables

The Google Workspace connector supports the following source tables, all under the default source schema. Each table uses lw_id as its primary key, syncs incrementally, and uses time as the cursor field.

Note

The gmail and drive tables contain Admin SDK Reports audit activity for those applications, not their content. To ingest Gmail mailbox contents or Google Drive files, use the dedicated Gmail connector or Google Drive connector.

Source table Description
gmail Gmail audit activity.
saml SAML audit activity.
token OAuth token audit activity.
calendar Google Calendar audit activity.
chat Google Chat audit activity.
rules Rules audit activity.
meet Google Meet audit activity.
chrome Chrome audit activity.
context_aware_access Context-Aware Access audit activity.
access_transparency Access Transparency audit activity.
mobile Mobile device audit activity.
user_accounts User account audit activity.
gcp Google Cloud Platform audit activity.
data_studio Looker Studio audit activity.
classroom Google Classroom audit activity.
keep Google Keep audit activity.
meet_hardware Google Meet hardware audit activity.
admin Administrator audit activity.
ldap Secure LDAP audit activity.
profile Profile audit activity.
access_evaluation Access Evaluation audit activity.
assignments Assignments audit activity.
contacts Contacts audit activity.
cloud_search Google Cloud Search audit activity.
data_migration Data migration audit activity.
directory_sync Directory Sync audit activity.
graduation Graduation audit activity.
vault Google Vault audit activity.
gemini_in_workspace_apps Gemini in Google Workspace apps audit activity.
tasks Google Tasks audit activity.
takeout Google Takeout audit activity.
drive Google Drive audit activity.
login Login audit activity.
groups Google Groups audit activity.
groups_enterprise Google Groups Enterprise audit activity.

All destination tables are liquid clustered on the time column.

Destination table schemas

The following sections describe the schema for each destination table that the Google Workspace connector writes.

Each row is one activity record from the Reports API. An activity can contain multiple events, which the connector stores in the events array instead of splitting them into separate rows. To get one row per event, use explode(events).

gmail

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

saml

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

token

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

calendar

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

chat

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

rules

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

meet

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

chrome

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

context_aware_access

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

access_transparency

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

mobile

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

user_accounts

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

gcp

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

data_studio

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

classroom

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

keep

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

meet_hardware

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

admin

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

ldap

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

profile

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

access_evaluation

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

assignments

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

contacts

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

cloud_search

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

data_migration

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

directory_sync

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

graduation

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

vault

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

gemini_in_workspace_apps

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

tasks

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

takeout

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

drive

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

login

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

groups

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

groups_enterprise

  • Primary key: lw_id
  • Cursor field: time
Field Data type
lw_id STRING
time TIMESTAMP
kind STRING
etag STRING
id STRUCT<time: STRING, uniqueQualifier: STRING, applicationName: STRING, customerId: STRING>
actor STRUCT<profileId: STRING, email: STRING, callerType: STRING, key: STRING, applicationInfo: STRUCT<oauthClientId: STRING, applicationName: STRING, impersonation: BOOLEAN>>
ownerDomain STRING
ipAddress STRING
isAgenticAction BOOLEAN
networkInfo STRUCT<ipAsn: ARRAY<INT>, regionCode: STRING, subdivisionCode: STRING>
events ARRAY<STRUCT<type: STRING, name: STRING, status: STRING, resourceIds: ARRAY<STRING>, parameters: ARRAY<STRUCT<name: STRING, value: STRING, intValue: STRING, boolValue: BOOLEAN, multiValue: ARRAY<STRING>, multiIntValue: ARRAY<STRING>, multiBoolValue: ARRAY<BOOLEAN>, messageValue: VARIANT, multiMessageValue: VARIANT>>>>
userDeviceInfo VARIANT
resourceDetails VARIANT

Note

This table does not support SCD type 2 because it has VARIANT columns.

Required OAuth permissions

The OAuth client must grant the following scope. See the Admin SDK Reports API reference.

Permission Required for
https://www.googleapis.com/auth/admin.reports.audit.readonly All tables

Required Google Workspace account permissions

The Google Workspace account used for ingestion must have the following permissions.

Permission Required for
Reports privilege All tables
Google Vault Access All Logs privilege vault table