Skip to main content

Field reference

Use these pages to find the stable path, type, and meaning of a field.

Event families​

FamilyWhat it carries
Event fieldsFields carried by every event.
SparkLogs event fieldsFields that identify a SparkLogs event's shape and classification.
Epoch fieldsFields that join state rows from the same reporting era.
Capture fieldsFields that identify the agent capture behind a state row.
Inventory fieldsFields that describe a complete state inventory.
Delta fieldsFields that connect consecutive state changes.
Episode fieldsFields that describe the life of an open or closed condition.
Occurrence fieldsFields that describe a discovered dated fact.
State row fieldsFields shared by rows under every state topic.
Configuration change fieldsFields that identify a changed configuration object and action.
Actor fieldsFields that identify the principal that initiated an action.
Running-as fieldsFields that identify a process's execution principal.
Target fieldsFields that identify the principal acted upon.
Member fieldsFields that identify the principal whose group membership changed.
Process fieldsFields that identify a process involved in an event.
Origin fieldsFields that identify the initiating network endpoint.
Destination fieldsFields that identify the receiving network endpoint.
Result fieldsFields that identify and interpret an event's main result code.

State topics​

Browse fields for every state topic.