Skip to main content

Data Feed Reference

A data feed is one stream the SparkLogs Agent collects from an endpoint, shaped so it can be asked about. Each page below lists the channels the feed binds and the curated reasons it scores, with the event ids and provider names behind each one.

A curated reason carries a stable reason code and a severity that reflects what the condition is worth to an engineer, so the same question answers the same way on every endpoint. A feed with no reasons yet is bound and collecting at the severity its providers state.

FeedWhat it coversChannelsCurated reasons
Microsoft Defender Antivirus event logWindows Defender/Operational event channel: malware detections and the remediation chain, protection disabled and re-enabled, configuration changes that resemble tampering213
Windows Application event logClassic Windows Event Log Application channel.144
Windows application platform event channelsApplication platform and user shell channels, bound as one feed: packaged-app deployment and readiness, the shell and modern app launch surface, application compatibility250
Windows identity and security event channelsIdentity, secrets, code integrity and policy channels, bound as one feed: LAPS, BitLocker, Code Integrity, AppLocker, Group Policy, certificate and key stores, biometrics and passkeys330
Windows management event channelsScheduled and remote management, servicing, backup, virtualization and print channels, bound as one feed: Task Scheduler, WMI, WinRM, Windows Update, BITS, VSS, Hyper-V, MDM and provisioning420
Windows network event channelsConnectivity, name resolution, file sharing and remote access channels, bound as one feed: DHCP, DNS client, WLAN, connectivity probes, the firewall and filtering platform, SMB client and server430
Windows platform event channelsKernel, boot, power, device and driver, hardware, clock and performance channels, bound as one feed.440
Windows Security event logClassic Windows Event Log Security channel, the host audit record.160
Windows Setup event logClassic Windows Event Log Setup channel: the package-servicing state machine (Microsoft-Windows-Servicing).12
Windows storage event channelsDisk, volume, filesystem, Storage Spaces and storage-housekeeping channels, bound as one feed: the storage port and class drivers, NTFS and its health-check arm, partitions and volumes220
Windows System event logClassic Windows Event Log System channel, the OS core.175
Windows PowerShell event channelsPowerShell engine and script-block channels, bound as one feed: the modern engine's operational and admin arms and the classic Windows PowerShell log.33
Windows CBS (Component-Based Servicing) logWindows servicing log (CBS.log / CbsPersist*.log).log file25
Windows DISM servicing logDISM.exe and DismApi sessions (dism.log).log file5

Channel counts are what the feed binds, not what a given endpoint has: a channel a Windows edition, role or OEM does not provide is absent there and the rest still collect.