Endpoint monitor
Event store: monitor.endpoint.infoโ
This documentation provides a detailed description of all the fields collected from the endpoint monitor, split into logical categories for easy reference.
`getIndexConfidentialData` source="monitor.endpoint.info"
๐ฅ Hardware Informationโ
| Field | Description | Data Type | Unit | Example |
|---|---|---|---|---|
manufacturer | Manufacturer name | String | - | Dell Inc. |
model | Device model | String | - | XPS 9320 |
product_name | Product name | String | - | XPS 9320 |
product_uuid | Unique identifier for the device | String | - | 4C4C4544-0038-4410-804D-B5C04F4B5233 |
bios[].caption | BIOS caption/version | String | - | 2.30.0 |
bios[].release_date | BIOS release date | Integer | Epoch | 1776902400 |
cpu_model | CPU model | String | - | 12th Gen Intel Core i7-1260P |
cpu_clock_frequency | CPU base frequency | Integer | MHz | 2100 |
cpu_cores | Number of physical cores | Integer | Count | 12 |
cpu_logical_processors | Number of logical processors | Integer | Count | 16 |
memory_mb | Installed system memory | Integer | MB | 16384 |
๐ Operating System (OS)โ
| Field | Description | Data Type | Example |
|---|---|---|---|
os | Operating system name | String | Windows 11 Pro |
os_version | OS version | String | 22600.8893 |
os_codename | OS build codename | String | 25H2 |
os_install_date | Install date | Integer | 0 (epoch) |
last_boottime | Last boot time | Integer | 1785133343000 |
release_id | OS release ID | String | 2009 |
๐ Network Informationโ
| Field | Description | Data Type | Example |
|---|---|---|---|
connection_type | Current connection type | String | WiFi |
internal_ip | Internal IP address | String | 192.168.86.76 |
public_ip | Public IP address | String | 185.50.194.180 |
internal_mac_address | Primary MAC address | String | 04:cf:4b:fc:0f:e4 |
network_interfaces[] | List of network interfaces | Object | Detailed list of NICs |
๐ Power & Batteryโ
| Field | Description | Data Type | Unit | Example |
|---|---|---|---|---|
battery_count | Number of detected batteries | Integer | Count | 1 |
battery_device_name | Battery device name | String | - | DELL NXRKW24 |
battery_estimated_charge_remaining | Estimated remaining charge | Integer | % | 94 |
battery_estimated_runtime_sec | Estimated runtime | Integer | Seconds | 137 |
power_energy_saver_mode | Is energy saver mode enabled? | Boolean | - | 0 |
๐ Security & TPMโ
| Field | Description | Data Type | Example |
|---|---|---|---|
secure_boot_enabled | Secure Boot feature | Boolean | 1 |
secureboot.confidence_level | Secure Boot trust level | String | High Confidence |
tpm[].manufacturer_id_txt | TPM manufacturer | String | STM |
tpm[].spec_version | TPM specification version | String | 2.0 |
๐ฆ Storage (Pagefiles)โ
| Field | Description | Data Type | Example |
|---|---|---|---|
pagefiles[].drive | Drive letter for pagefile | String | C:\ |
pagefiles[].allocated_base_size | Base allocated size | Integer | 16000 |
pagefiles[].peak_usage | Peak usage in MB | Integer | 2433 |
๐ Virtualization Detailsโ
| Field | Description | Data Type | Example |
|---|---|---|---|
is_virtual_machine | Is device a VM? | Boolean | false |
virtual_machine_info.hypervisor | Hypervisor name | String | (empty) |
๐ต Multimedia (Sound & Video Devices)โ
| Field | Description | Example |
|---|---|---|
sound_devices[].name | Sound device name | Intelยฎ Smart Sound Technology |
video_devices[].caption | Video device description | Intel(R) Iris(R) Xe Graphics |
โ Additional Metadataโ
| Field | Description | Example |
|---|---|---|
lookup_key | Internal system ID key | b8513a96a1841bd64ede23 |
host | Splunk host identifier | b8513a96โฆ |
type | Device type | laptop |
vendor | Vendor name | Microsoft |
version | Agent or client version | 2026.04.17 |
KVStore: ux_nodesโ
KVStore ux_nodes is updated every 5 minutes via input script update_kvstore.py
Datamodel: UXM_Endpoint Endpointโ
TBDโ
| Field | Metric Store | Description | Data Type | Unit | Example | Available on platforms |
|---|---|---|---|---|---|---|
| version | Version of UXM Desktop agent | String | 2021.09.28 | Windows, Linux, MacOS | ||
| domain | String | testdomain.com | ||||
| hostname | String | DKTESTPC1 | Windows, Linux, MacOS | |||
| type | laptop, desktop, robot | String | laptop | |||
| cpu_cores | Number | 2 | Windows, Linux, MacOS | |||
| cpu_sockets | Number | 1 | Windows, Linux, MacOS | |||
| cpu_logical_processors | Number | 4 | Windows, Linux, MacOS | |||
| cpu_generation | String | Intel64 Family 6 Model 142 Stepping 9 | Windows | |||
| cpu_model | String | Intel Core i5 7200U, Intel Xeon | Windows, Linux, MacOS | |||
| cpu_clock_frequency | String | MHz | 2500 | Windows, Linux, MacOS | ||
| cpu_load | Move: Send at interval | Float | % | 55.4% | ||
| memory_mb | Number | MB | 24000 MB | |||
| manufacturer | String | Dell Inc. | Windows | |||
| model | String | Latitude 5480 | Windows | |||
| os | String | Windows 10 Pro, Ubuntu 18.04, Mac OS X Big sur | Windows, Linux, Mac OS | |||
| os_version | String | Windows 7:, Windows 10: 19042, Windows 11: 22000+, Linux (Kernel version): 5.4.0-1053-gcp, Mac OS X: 11.2.1 | Windows, Linux, Mac OS | |||
| os_codename | Friendly code name of the installed OS build. | String | Windows 10: 20H2, Linux Ubuntu: bionic, Mac OS X: Big Sur | Windows, Linux, Mac OS | ||
| product_identifying_number | Serial number or service code | String | 2C703M2 | Windows | ||
| product_name | String | Latitude 5480 | Windows | |||
| product_uuid | String | 4C4C4544-0043-3710-8030-B2C04F334D00 | Windows | |||
| last_boottime | Number | Timestamp | Windows | |||
| battery_wear_level | Float | % | 80% | Windows | ||
| batteries | Number | 1 | Windows | |||
| powerplan | Active power plan | String | Dell | Windows | ||
| powerplan_description | Active power plan description (Localised language) | String | Automatically balances performance with energy consumption on capable hardware. | Windows | ||
| powerplan_instance_id | Active power plan instance ID | String | 49ef8fc0-bb7f-488e-b6a0-f1fc77ec649b | Windows | ||
| windows_stability_index | Number | Windows |
Event store: Installed programs monitor.endpoint.programs_installedโ
Datamodel: UXM_Desktop Programs_Installed
Index: getIndexSessionData
Source type: monitor.endpoint.programs_installed
Dashboards visualizing data: endpoint_details?form.link=programs
Collected via Endpoint monitor
Collected: On start and daily
| Field | Display name | Description | Data Type | Unit | Example | Available on platforms |
|---|---|---|---|---|---|---|
| host | Endpoint node application is installed on, lookup hostname and info via ux_nodes_lookup. | String | 5d05ad82d053082a69343a52 | All | ||
| source | String | agent.programs.installed | All | |||
| sourcetype | String | uxm:json | All | |||
| timestamp_utc | UTC Timestamp from when data was collected. (Also stored in Splunk _time field) | 2019-12-19T10:08:27 | All | |||
| guid | GUID | String | Google Chrome | Windows | ||
| install_date | Install Date | 20210203 | Windows | |||
| install_source | Install Source | String | Windows | |||
| install_location | Install Location | String | C:\Program Files\Google\Chrome\Application | Windows | ||
| is_64_bit | Is 64 bit | 0 = Installed under Wow6432, 1 = Is 64 bit | String | 0 | Windows | |
| language | Language | String | 0 | Windows | ||
| major | Major | Windows | ||||
| major_version_parsed | Major version (Normalized) | Windows | ||||
| minor | Minor | Windows | ||||
| name | Name | String | Google Chrome | Windows, Linux, MacOS | ||
| name_parsed | Name (Normalized) | String | Google Chrome | Windows, Linux, MacOS | ||
| publisher | Publisher | String | Google LLC | Windows | ||
| version | Version | String | 88.0.4324.146 | Windows, Linux, MacOS | ||
| windows_installer | Is Windows Installer | Number | 0 | Windows |