Skip to main content

Field reference

Use these pages to find the stable path, type, and meaning of a field.

Event families​

FamilyWhat it carries
Event fieldsFields carried by every event.
SparkLogs event fieldsFields that identify a SparkLogs event's shape and classification.
Epoch fieldsInventory identity and subsequent changes for one device and topic.
Capture fieldsFields that identify the agent capture behind a state row.
Inventory fieldsFields that describe a complete state inventory.
Delta fieldsFields that connect consecutive state changes.
Episode fieldsFields that describe the life of an open or closed condition.
Occurrence fieldsFields that describe a discovered dated fact.
State row fieldsFields shared by rows under every state topic.
Configuration change fieldsFields that identify a changed configuration object and action.
Actor fieldsThe identity that initiated an action.
Running-as fieldsThe identity under which a process ran.
Target fieldsThe identity affected by an action.
Member fieldsThe identity added to or removed from a group.
Process fieldsFields that identify a process involved in an event.
Origin fieldsFields that identify the initiating network endpoint.
Destination fieldsFields that identify the receiving network endpoint.
Result fieldsFields that identify and interpret an event's main result code.

State topics​

Browse fields for every state topic.