Skip to main content

Device drivers

3readings
0conditions
1themes fed
Livestatus

The device drivers installed on the host, and what changes about them between reports.

Topic id: drivers.

Full inventory every day. Supported changes are reported when the agent observes them.

Fields​

Installed driver packages and changes between observations.

FieldTypeUnitMeaning
sparklogs.data.drivers.packagestringThe package's stable identity: setup class, INF and provider, lowercased and joined.
sparklogs.data.drivers.classstringThe Windows setup class the package installs under, as the class key names it.
sparklogs.data.drivers.class_guidstringThe setup class key's own GUID.
sparklogs.data.drivers.infstringThe INF file that installed the package.
sparklogs.data.drivers.providerstringWho published the driver.
sparklogs.data.drivers.versionstringThe package version, as the registry spells it.
sparklogs.data.drivers.driver_datestringThe driver's date as a full RFC 3339 date. Omitted when the stored value is not a date this parser recognizes, so a reader of a date field always gets a date.
sparklogs.data.drivers.descriptionstringThe friendly name Windows shows for the package.
sparklogs.data.drivers.device_countintegercountHow many device instances on this machine use the package. At least one, and the measure of how much of the machine depends on a driver whose version just moved.

Changes​

This topic reports what the host looks like, so its news is what CHANGED between two reports. Each change below is a named fact you can ask about across the fleet.

ChangeWhat it means
driver_updateddriver updated
driver_addeddriver added
driver_removeddriver removed

Example​

Inventory (every day)

2 driver packages.

sparklogs.data.drivers.package: net/oem12.inf/contoso networks
sparklogs.data.drivers.driver_date: 2026-01-01
sparklogs.data.drivers.version: 10.1.2.3

SparkLogs: CONTEXT, Info, drivers: INVENTORY: 2 driver packages.