Data Feed Reference
A data feed is one stream the SparkLogs Agent collects from an endpoint, shaped so it can be asked about. Each page below lists the channels the feed binds and the curated reasons it scores, with the event ids and provider names behind each one.
A curated reason carries a stable reason code and a severity that reflects what the condition is worth to an engineer, so the same question answers the same way on every endpoint. A feed with no reasons yet is bound and collecting at the severity its providers state.
| Feed | What it covers | Channels | Curated reasons |
|---|---|---|---|
| Microsoft Defender Antivirus event log | Windows Defender/Operational event channel: malware detections and the remediation chain, protection disabled and re-enabled, configuration changes that resemble tampering | 2 | 13 |
| Windows Application event log | Classic Windows Event Log Application channel. | 1 | 44 |
| Windows application platform event channels | Application platform and user shell channels, bound as one feed: packaged-app deployment and readiness, the shell and modern app launch surface, application compatibility | 25 | 0 |
| Windows identity and security event channels | Identity, secrets, code integrity and policy channels, bound as one feed: LAPS, BitLocker, Code Integrity, AppLocker, Group Policy, certificate and key stores, biometrics and passkeys | 33 | 0 |
| Windows management event channels | Scheduled and remote management, servicing, backup, virtualization and print channels, bound as one feed: Task Scheduler, WMI, WinRM, Windows Update, BITS, VSS, Hyper-V, MDM and provisioning | 42 | 0 |
| Windows network event channels | Connectivity, name resolution, file sharing and remote access channels, bound as one feed: DHCP, DNS client, WLAN, connectivity probes, the firewall and filtering platform, SMB client and server | 43 | 0 |
| Windows platform event channels | Kernel, boot, power, device and driver, hardware, clock and performance channels, bound as one feed. | 44 | 0 |
| Windows Security event log | Classic Windows Event Log Security channel, the host audit record. | 1 | 60 |
| Windows Setup event log | Classic Windows Event Log Setup channel: the package-servicing state machine (Microsoft-Windows-Servicing). | 1 | 2 |
| Windows storage event channels | Disk, volume, filesystem, Storage Spaces and storage-housekeeping channels, bound as one feed: the storage port and class drivers, NTFS and its health-check arm, partitions and volumes | 22 | 0 |
| Windows System event log | Classic Windows Event Log System channel, the OS core. | 1 | 75 |
| Windows PowerShell event channels | PowerShell engine and script-block channels, bound as one feed: the modern engine's operational and admin arms and the classic Windows PowerShell log. | 3 | 3 |
| Windows CBS (Component-Based Servicing) log | Windows servicing log (CBS.log / CbsPersist*.log). | log file | 25 |
| Windows DISM servicing log | DISM.exe and DismApi sessions (dism.log). | log file | 5 |
Channel counts are what the feed binds, not what a given endpoint has: a channel a Windows edition, role or OEM does not provide is absent there and the rest still collect.