Skip to main content

Event fields

Observation time, message and severity for each event.

FieldTypeUnitMeaning
tstringtimestampWhen the thing being reported was observed. For an occurrence this is when the fact happened, not when the agent found it.
messagestringA one-line summary of the event. Read detailed measurements under sparklogs.data.<topic>.
severitystringThe event severity.
native_severitystringSeverity before the configured reason ceiling reduced it. Present only when that limit applied.
__autoextract_disable_extract_fieldsboolDisables field extraction from the message. Measurements are already provided as structured data.