Field reference
Use these pages to find the stable path, type, and meaning of a field.
Event families
| Family | What it carries |
|---|---|
| Event fields | Fields carried by every event. |
| SparkLogs event fields | Fields that identify a SparkLogs event's shape and classification. |
| Epoch fields | Fields that join state rows from the same reporting era. |
| Capture fields | Fields that identify the agent capture behind a state row. |
| Inventory fields | Fields that describe a complete state inventory. |
| Delta fields | Fields that connect consecutive state changes. |
| Episode fields | Fields that describe the life of an open or closed condition. |
| Occurrence fields | Fields that describe a discovered dated fact. |
| State row fields | Fields shared by rows under every state topic. |
| Configuration change fields | Fields that identify a changed configuration object and action. |
| Actor fields | Fields that identify the principal that initiated an action. |
| Running-as fields | Fields that identify a process's execution principal. |
| Target fields | Fields that identify the principal acted upon. |
| Member fields | Fields that identify the principal whose group membership changed. |
| Process fields | Fields that identify a process involved in an event. |
| Origin fields | Fields that identify the initiating network endpoint. |
| Destination fields | Fields that identify the receiving network endpoint. |
| Result fields | Fields that identify and interpret an event's main result code. |