Firewalld rich rule nflog: what is the source of group id?

Where does one obtain group ids for nflog of a rich rule?

It looks like the nftables rules end up getting written in /etc/nftables/ . I would start with main.nft, then checkout router and nat.

What are main.nft, router, and nat?