System information
5readings
0conditions
1themes fed
Livestatus
Machine identity and posture, including whether a reboot is pending.
Topic id: system_info.
Full inventory every hour. Supported changes are reported when the agent observes them.
Fields
Device and operating-system identity, boot details and pending reboot indicators.
| Field | Type | Unit | Meaning |
|---|---|---|---|
sparklogs.data.system_info.manufacturer | string | Who made the machine, from SMBIOS. | |
sparklogs.data.system_info.model | string | The machine's product name, from SMBIOS. | |
sparklogs.data.system_info.sku | string | The manufacturer's SKU for the machine. | |
sparklogs.data.system_info.serial_number | string | Hardware serial number for asset identification. | |
sparklogs.data.system_info.chassis_type | string | What kind of enclosure the machine is in, such as desktop, laptop or server. | |
sparklogs.data.system_info.bios_version | string | The firmware version string, as the machine reports it. | |
sparklogs.data.system_info.bios_date | string | The firmware's release date. SMBIOS MM/DD/YYYY or MM/DD/YY (two-digit years are 19xx) is stored as YYYY-MM-DD; any other spelling is kept as the firmware wrote it. | |
sparklogs.data.system_info.boot_mode | string | How the machine boots: uefi, or legacy for a BIOS or compatibility-mode boot. | |
sparklogs.data.system_info.secure_boot | bool | Whether Secure Boot is enabled. | |
sparklogs.data.system_info.tpm_present | bool | Whether the machine has a TPM available. | |
sparklogs.data.system_info.tpm_version | string | Which TPM specification the module implements. | |
sparklogs.data.system_info.os_edition | string | The installed Windows edition. | |
sparklogs.data.system_info.os_display_version | string | The feature-update version Windows shows to a user. | |
sparklogs.data.system_info.os_build | integer | The Windows CurrentBuildNumber as an integer. | |
sparklogs.data.system_info.os_revision | integer | The Windows Update Build Revision (UBR). Omitted when unreadable. | |
sparklogs.data.system_info.os_install_date | string | timestamp | When this Windows installation was first set up. |
sparklogs.data.system_info.domain_joined | bool | Whether the machine is joined to a domain rather than in a workgroup. | |
sparklogs.data.system_info.domain_or_workgroup | string | The domain the machine is joined to, or the workgroup it is in. | |
sparklogs.data.system_info.host_roles | string_array | Detected roles: dns_server, domain_controller, exchange, fslogix, hyper_v, sql_server. An empty array clears previously detected roles. Absent when detection has not run, preserving the previous result. | |
sparklogs.data.system_info.timezone | string | The time zone the machine is set to. | |
sparklogs.data.system_info.is_vm | bool | Whether the machine is virtual. | |
sparklogs.data.system_info.hypervisor | string | Which hypervisor a virtual machine runs on: hyperv, vmware, virtualbox, kvm, xen, aws, gce, parallels or ahv. | |
sparklogs.data.system_info.ram_total_bytes | integer | bytes | How much physical memory the machine has installed. |
sparklogs.data.system_info.cpu_model | string | The processor's model name. | |
sparklogs.data.system_info.logical_cores | integer | count | How many logical processors the machine has, which is what a per-core figure elsewhere is divided by. |
sparklogs.data.system_info.page_file_config | string | How the page file is configured, in the spelling Windows stores: path, initial size and maximum size. | |
sparklogs.data.system_info.crash_dump_type | string | Configured bugcheck dump type, using the same values as crash_dump_config. Absent when the setting could not be read, which is not the same answer as none. | |
sparklogs.data.system_info.last_boot_time | string | timestamp | When the machine last started. Always present. |
sparklogs.data.system_info.uptime_s | integer | seconds | How long the machine has been up, in whole seconds. Always present. |
sparklogs.data.system_info.reboot_pending | bool | Whether the machine is waiting on a restart to finish applying something. Always present. | |
sparklogs.data.system_info.reboot_pending_since | string | timestamp | When the pending restart was first witnessed. Present only while one is outstanding. |
sparklogs.data.system_info.reboot_pending_reasons | string_array | What is waiting on the restart, from a closed vocabulary: cbs for servicing, wu for Windows Update, file_rename for a queued file replacement, rename for a computer rename. Always present, and empty when nothing is pending. |
Changes
This topic reports what the host looks like, so its news is what CHANGED between two reports. Each change below is a named fact you can ask about across the fleet.
| Change | What it means |
|---|---|
reboot_pending_set | reboot pending |
secure_boot_changed | Secure Boot state changed |
tpm_changed | TPM state changed |
host_roles_changed | host roles changed |
os_build_changed | OS build changed |
Example
Inventory (every hour)
system identity; model Workstation 5000, build 26100.1742, up 4h00m.
sparklogs.data.system_info.bios_date: 2025-11-02
sparklogs.data.system_info.bios_version: 1.14
sparklogs.data.system_info.boot_mode: uefi
sparklogs.data.system_info.chassis_type: desktop
sparklogs.data.system_info.cpu_model: Contoso Core 8C
sparklogs.data.system_info.crash_dump_type: kernel
sparklogs.data.system_info.domain_joined: true
sparklogs.data.system_info.domain_or_workgroup: corp.example.com
sparklogs.data.system_info.is_vm: false
sparklogs.data.system_info.logical_cores: 8
sparklogs.data.system_info.manufacturer: Contoso
sparklogs.data.system_info.model: Workstation 5000
sparklogs.data.system_info.os_build: 26100
sparklogs.data.system_info.os_display_version: 24H2
sparklogs.data.system_info.os_edition: Windows 11 Pro
sparklogs.data.system_info.os_install_date: 2026-01-04T10:00:00Z
sparklogs.data.system_info.os_revision: 1742
sparklogs.data.system_info.page_file_config: C:\pagefile.sys 8192 16384
sparklogs.data.system_info.reboot_pending: false
sparklogs.data.system_info.reboot_pending_reasons: []
sparklogs.data.system_info.secure_boot: true
sparklogs.data.system_info.serial_number: SN-0000-0001
sparklogs.data.system_info.sku: professional
sparklogs.data.system_info.timezone: UTC
sparklogs.data.system_info.tpm_present: true
sparklogs.data.system_info.tpm_version: 2.0
SparkLogs: CONTEXT, Info, system_info: INVENTORY: system identity; model Workstation 5000, build 26100.1742, up 4h00m.