The DNS Server service is present on the host.
A data feed is a stream of signals the agent collects from an endpoint and analyzes in realtime. Each is curated into named reasons and graded conditions with a stable meaning and a impact-based severity score, so investigations start from signal, not noise. The full event stream is still available for analysis.
The DNS Server service is present on the host.
The agent reports the domain controller host role for this machine.
The Hyper-V Virtual Machine Management or Host Compute service is present on the host.
The SQL Server and SQL Server Agent services are present on the host.
Microsoft Defender Antivirus detections, remediation outcomes and engine health from the Defender operational channel.
The Application channel: application crashes and hangs, database and VSS provider faults, certificate and identity-sync failures.
Application platform channels beyond the classic Application log: packaged-app deployment and readiness, the shell, application compatibility, and Office dialogs. Failures, cleanup residue, and lifecycle records are read from the provider payload.
Identity and security operational channels beyond the classic Security log: code integrity and application control, cloud identity and device registration, key and certificate stores, Group Policy, BitLocker posture and the endpoint sensor. The failures are read from the provider payload and the routine narration is held out of the attention bands.
Remote management, task scheduling, background transfer and configuration channels, with the transfer failures read and the routine narration held out of the attention bands.
Connectivity, DHCP, DNS, WLAN, firewall, SMB, RDP, and related channels. Failures, posture facts, and lifecycle records are read from the provider payload.
Kernel, boot, power, device, firmware, and hardware channels the System log does not carry. Device start and removal, boot measurement and TPM initialization failures, and OEM integrity-scan outcomes are read from the provider payload.
The Security channel: sign-in outcomes, privilege use, directory changes and audit policy changes.
The Setup channel: update and feature install outcomes as Windows itself records them.
The storage channels the System log does not carry: the port and class drivers, NTFS, partitions and volumes, and Storage Spaces. Bad blocks, controller resets, paging failures and volume mount failures are read from the driver payload.
The System channel: service, driver, disk, network, cluster and hardware faults from the operating system itself.
PowerShell engine and script-block channels, with whole script blocks reassembled and labelled for generated framework code, repeats and watchlisted commands.
Component-Based Servicing: what the servicing stack actually did to a package, and why it stopped.
DISM servicing operations: image and component-store maintenance and their failure detail.
A user or computer account in the directory or on the local host.
One subcategory of the Windows audit policy, which decides what the Security log records.
One setting of the endpoint protection product on the host.
One protection component of the endpoint protection product, such as real-time scanning.
A directory object that is neither an account nor a group, such as an organizational unit or a policy container.
The password and lockout policy of one domain.
One rule in the Windows Firewall, which decides what traffic the host accepts.
A security group, both the group itself and who belongs to it.
A right that decides how an account may sign in, such as locally at the keyboard or as a service.
A value in the Windows registry that auditing is turned on for.
A job Task Scheduler runs on a trigger or a clock.
A folder the host publishes on the network over SMB.
The clock of the host the event came from.
A background program the Service Control Manager starts and stops on the host.
What the SparkLogs agent stack itself costs the host: CPU, working set and handles.
The agent spool and delivery pipeline: how much is queued and when it last drained.
ReferencePer-collector health for the shipper the agent runs.
ReferenceWhether this host can write a usable crash dump when Windows or an application crashes.
Windows and application crashes with decoded error details and local dump analysis when available.
Every fixed volume: free space, fill trend, protection state and whether the filesystem is readable.
The device drivers installed on the host, and what changes about them between reports.
Per-feed health for the inputs the agent is shipping.
ReferenceThe installed-product inventory the agent reads from the host.
A rolled-up view of installed products, including protection-category coverage.
ReferenceWhole-host CPU and memory posture over a measured window.
Per-process cost: CPU, working set, handles and sustained growth.
Service configuration and run state, including automatic services that are not running.
Per-device IO posture, including a device that is busy but moving almost nothing.
The physical and virtual storage devices attached to the host.
ReferenceStorage throughput, queues and response time per volume.
Machine identity and posture, including whether a reboot is pending.
Processes selected by CPU, resident memory and read/write I/O, plus system CPU and an unlisted-process remainder.
ReferenceHow volumes map onto devices and partitions.
ReferenceShadow-copy storage allocation and how close it is to its cap.
VSS writer state, the canonical evidence behind a failed backup.
Whether this host is scanning, paused, or falling behind on updates.
Ship logs to SparkLogs with Grafana Alloy.
ReferenceShip logs to SparkLogs with Filebeat and the other Elastic Beats.
ReferenceShip logs to SparkLogs with Logstash.
ReferenceShip logs to SparkLogs with the OpenTelemetry Collector.
ReferenceShip logs and metrics to SparkLogs with Vector.
ReferenceSend events using the Elasticsearch bulk API shape.
ReferencePost JSON events to the SparkLogs ingest endpoint directly.
ReferenceSend events using the Loki push API shape.
ReferenceSend logs to SparkLogs over the OpenTelemetry protocol.
ReferenceSend syslog to SparkLogs from network devices and appliances.
ReferenceLearn how signals are curated into actionable insights and correlated with diagnostic themes and workloads.
Open the coverage wall