Field reference
Use these pages to find the stable path, type, and meaning of a field.
Event families
| Family | What it carries |
|---|---|
| Event fields | Fields carried by every event. |
| SparkLogs event fields | Fields that identify a SparkLogs event's shape and classification. |
| Epoch fields | Inventory identity and subsequent changes for one device and topic. |
| Capture fields | Fields that identify the agent capture behind a state row. |
| Inventory fields | Fields that describe a complete state inventory. |
| Delta fields | Fields that connect consecutive state changes. |
| Episode fields | Fields that describe the life of an open or closed condition. |
| Occurrence fields | Fields that describe a discovered dated fact. |
| State row fields | Fields shared by rows under every state topic. |
| Configuration change fields | Fields that identify a changed configuration object and action. |
| Actor fields | The identity that initiated an action. |
| Running-as fields | The identity under which a process ran. |
| Target fields | The identity affected by an action. |
| Member fields | The identity added to or removed from a group. |
| Process fields | Fields that identify a process involved in an event. |
| Origin fields | Fields that identify the initiating network endpoint. |
| Destination fields | Fields that identify the receiving network endpoint. |
| Result fields | Fields that identify and interpret an event's main result code. |