Skip to main content

System information

5readings
0conditions
1themes fed
Livestatus

Machine identity and posture, including whether a reboot is pending.

Topic id: system_info.

Full inventory every hour. Supported changes are reported when the agent observes them.

Fields​

Device and operating-system identity, boot details and pending reboot indicators.

FieldTypeUnitMeaning
sparklogs.data.system_info.manufacturerstringWho made the machine, from SMBIOS.
sparklogs.data.system_info.modelstringThe machine's product name, from SMBIOS.
sparklogs.data.system_info.skustringThe manufacturer's SKU for the machine.
sparklogs.data.system_info.serial_numberstringHardware serial number for asset identification.
sparklogs.data.system_info.chassis_typestringWhat kind of enclosure the machine is in, such as desktop, laptop or server.
sparklogs.data.system_info.bios_versionstringThe firmware version string, as the machine reports it.
sparklogs.data.system_info.bios_datestringThe firmware's release date. SMBIOS MM/DD/YYYY or MM/DD/YY (two-digit years are 19xx) is stored as YYYY-MM-DD; any other spelling is kept as the firmware wrote it.
sparklogs.data.system_info.boot_modestringHow the machine boots: uefi, or legacy for a BIOS or compatibility-mode boot.
sparklogs.data.system_info.secure_bootboolWhether Secure Boot is enabled.
sparklogs.data.system_info.tpm_presentboolWhether the machine has a TPM available.
sparklogs.data.system_info.tpm_versionstringWhich TPM specification the module implements.
sparklogs.data.system_info.os_editionstringThe installed Windows edition.
sparklogs.data.system_info.os_display_versionstringThe feature-update version Windows shows to a user.
sparklogs.data.system_info.os_buildintegerThe Windows CurrentBuildNumber as an integer.
sparklogs.data.system_info.os_revisionintegerThe Windows Update Build Revision (UBR). Omitted when unreadable.
sparklogs.data.system_info.os_install_datestringtimestampWhen this Windows installation was first set up.
sparklogs.data.system_info.domain_joinedboolWhether the machine is joined to a domain rather than in a workgroup.
sparklogs.data.system_info.domain_or_workgroupstringThe domain the machine is joined to, or the workgroup it is in.
sparklogs.data.system_info.host_rolesstring_arrayDetected roles: dns_server, domain_controller, exchange, fslogix, hyper_v, sql_server. An empty array clears previously detected roles. Absent when detection has not run, preserving the previous result.
sparklogs.data.system_info.timezonestringThe time zone the machine is set to.
sparklogs.data.system_info.is_vmboolWhether the machine is virtual.
sparklogs.data.system_info.hypervisorstringWhich hypervisor a virtual machine runs on: hyperv, vmware, virtualbox, kvm, xen, aws, gce, parallels or ahv.
sparklogs.data.system_info.ram_total_bytesintegerbytesHow much physical memory the machine has installed.
sparklogs.data.system_info.cpu_modelstringThe processor's model name.
sparklogs.data.system_info.logical_coresintegercountHow many logical processors the machine has, which is what a per-core figure elsewhere is divided by.
sparklogs.data.system_info.page_file_configstringHow the page file is configured, in the spelling Windows stores: path, initial size and maximum size.
sparklogs.data.system_info.crash_dump_typestringConfigured bugcheck dump type, using the same values as crash_dump_config. Absent when the setting could not be read, which is not the same answer as none.
sparklogs.data.system_info.last_boot_timestringtimestampWhen the machine last started. Always present.
sparklogs.data.system_info.uptime_sintegersecondsHow long the machine has been up, in whole seconds. Always present.
sparklogs.data.system_info.reboot_pendingboolWhether the machine is waiting on a restart to finish applying something. Always present.
sparklogs.data.system_info.reboot_pending_sincestringtimestampWhen the pending restart was first witnessed. Present only while one is outstanding.
sparklogs.data.system_info.reboot_pending_reasonsstring_arrayWhat is waiting on the restart, from a closed vocabulary: cbs for servicing, wu for Windows Update, file_rename for a queued file replacement, rename for a computer rename. Always present, and empty when nothing is pending.

Changes​

This topic reports what the host looks like, so its news is what CHANGED between two reports. Each change below is a named fact you can ask about across the fleet.

ChangeWhat it means
reboot_pending_setreboot pending
secure_boot_changedSecure Boot state changed
tpm_changedTPM state changed
host_roles_changedhost roles changed
os_build_changedOS build changed

Example​

Inventory (every hour)

system identity; model Workstation 5000, build 26100.1742, up 4h00m.

sparklogs.data.system_info.bios_date: 2025-11-02
sparklogs.data.system_info.bios_version: 1.14
sparklogs.data.system_info.boot_mode: uefi
sparklogs.data.system_info.chassis_type: desktop
sparklogs.data.system_info.cpu_model: Contoso Core 8C
sparklogs.data.system_info.crash_dump_type: kernel
sparklogs.data.system_info.domain_joined: true
sparklogs.data.system_info.domain_or_workgroup: corp.example.com
sparklogs.data.system_info.is_vm: false
sparklogs.data.system_info.logical_cores: 8
sparklogs.data.system_info.manufacturer: Contoso
sparklogs.data.system_info.model: Workstation 5000
sparklogs.data.system_info.os_build: 26100
sparklogs.data.system_info.os_display_version: 24H2
sparklogs.data.system_info.os_edition: Windows 11 Pro
sparklogs.data.system_info.os_install_date: 2026-01-04T10:00:00Z
sparklogs.data.system_info.os_revision: 1742
sparklogs.data.system_info.page_file_config: C:\pagefile.sys 8192 16384
sparklogs.data.system_info.reboot_pending: false
sparklogs.data.system_info.reboot_pending_reasons: []
sparklogs.data.system_info.secure_boot: true
sparklogs.data.system_info.serial_number: SN-0000-0001
sparklogs.data.system_info.sku: professional
sparklogs.data.system_info.timezone: UTC
sparklogs.data.system_info.tpm_present: true
sparklogs.data.system_info.tpm_version: 2.0

SparkLogs: CONTEXT, Info, system_info: INVENTORY: system identity; model Workstation 5000, build 26100.1742, up 4h00m.