The DNS Server service is present on the host.
A data feed is a stream of signals the agent collects from an endpoint and analyzes in realtime. Each is curated into named reasons and graded conditions with a stable meaning and a impact-based severity score, so investigations start from signal, not noise. The full event stream is still available for analysis.
The DNS Server service is present on the host.
The agent reports the domain controller host role for this machine.
The Hyper-V Virtual Machine Management service is present on the host.
The SQL Server and SQL Server Agent services are present on the host.
Microsoft Defender Antivirus detections, remediation outcomes and engine health from the Defender operational channel.
The Application channel: application crashes and hangs, database and VSS provider faults, certificate and identity-sync failures.
The Security channel: sign-in outcomes, privilege use, directory changes and audit policy changes.
The Setup channel: update and feature install outcomes as Windows itself records them.
The System channel: service, driver, disk, network, cluster and hardware faults from the operating system itself.
PowerShell engine and script-block channels, with whole script blocks reassembled and labelled for generated framework code, repeats and watchlisted commands.
Component-Based Servicing: what the servicing stack actually did to a package, and why it stopped.
DISM servicing operations: image and component-store maintenance and their failure detail.
Application platform channels beyond the classic Application log, collected for search and correlation.
Learn what is plannedIdentity and security operational channels beyond the classic Security log, collected for search and correlation.
Learn what is plannedRemote management, task scheduling and configuration channels, collected for search and correlation.
Learn what is plannedNetworking operational channels beyond the classic System log, collected for search and correlation.
Learn what is plannedCore platform operational channels, collected for search and correlation.
Learn what is plannedStorage operational channels beyond the classic System log, collected for search and correlation.
Learn what is plannedA user or computer account in the directory or on the local host.
One subcategory of the Windows audit policy, which decides what the Security log records.
One setting of the endpoint protection product on the host.
One protection component of the endpoint protection product, such as real-time scanning.
A directory object that is neither an account nor a group, such as an organizational unit or a policy container.
The password and lockout policy of one domain.
One rule in the Windows Firewall, which decides what traffic the host accepts.
A security group, both the group itself and who belongs to it.
A right that decides how an account may sign in, such as locally at the keyboard or as a service.
A value in the Windows registry that auditing is turned on for.
A job Task Scheduler runs on a trigger or a clock.
A folder the host publishes on the network over SMB.
The clock of the host the event came from.
A background program the Service Control Manager starts and stops on the host.
Per-collector health for the shipper the agent runs.
ReferenceEvery fixed volume: free space, fill trend, protection state and whether the filesystem is readable.
The device drivers installed on the host, and what changes about them between reports.
Per-feed health for the inputs the agent is shipping.
ReferenceThe installed-product inventory the agent reads from the host.
A rolled-up view of installed products, including protection-category coverage.
ReferencePer-device IO posture, including a device that is busy but moving almost nothing.
The physical and virtual storage devices attached to the host.
ReferenceStorage throughput, queueing and response time per device.
Machine identity and posture, including whether a reboot is pending.
How volumes map onto devices and partitions.
ReferenceShadow-copy storage allocation and how close it is to its cap.
VSS writer state, the canonical evidence behind a failed backup.
What the SparkLogs agent stack itself costs the host: CPU, working set and handles.
The agent spool and delivery pipeline: how much is queued and when it last drained.
Learn what is plannedWhether this host can produce a usable crash dump, and whether it recently did.
Whole-host CPU and memory posture over a measured window.
Per-process cost: CPU, working set, handles and sustained growth.
Service configuration and run state, including automatic services that are not running.
Whether this host is scanning, paused, or falling behind on updates.
Ship logs to SparkLogs with Grafana Alloy.
ReferenceShip logs to SparkLogs with Filebeat and the other Elastic Beats.
ReferenceShip logs to SparkLogs with Logstash.
ReferenceShip logs to SparkLogs with the OpenTelemetry Collector.
ReferenceShip logs and metrics to SparkLogs with Vector.
ReferenceSend events using the Elasticsearch bulk API shape.
ReferencePost JSON events to the SparkLogs ingest endpoint directly.
ReferenceSend events using the Loki push API shape.
ReferenceSend logs to SparkLogs over the OpenTelemetry protocol.
ReferenceSend syslog to SparkLogs from network devices and appliances.
ReferenceLearn how signals are curated into actionable insights and correlated with diagnostic themes and workloads.
Open the coverage wall