Use these Omnissa Workspace ONE Experience Management desktop telemetry data definitions and lists of available data fields to help you analyze Experience Management for Horizon specific widgets in dashboards and in the Experience Management Solutions area in Omnissa Intelligence.
Product information and supported platform
Experience Management for Horizon works on the Omnissa Horizon product run on the Windows platform.
Supported desktop models
Experience Management for Horizon supports the virtual desktop infrastructure (VDI) and remote desktop session host (RDSH) models.
What Category identifies Experience Management data?
When working in dashboard widgets in Intelligence, look for the Employee Experience category.
Update, sample, and transmission frequencies
- Updates: See How often does Experience Management data update?.
- Sample and transmission: See What are the sample and transmission frequencies?.
Common fields
The common fields table lists the data that is common to all the Experience Management for Horizon event types.
| Friendly Name | Property | Definition | Type | Event Support | Examples |
|---|---|---|---|---|---|
| Device Make | Device_Make | Make of the device. | String | Windows only | Lenovo |
| Device Model | Device_Model | Model of the device. | String | Windows only | 20XXS1ER00 |
| Device Name | device_name | Name of the device. | String | Windows only | PF2T16S2 |
| Device Serial Number | Device_Serial_Number | Serial number of the device. | String | Windows only | VM8Kq4Oo513w |
| Horizon Session UUID | session_uuid | The unique session UUID for a Horizon session. | String | Windows only | 37A60EF4-1482-49AA-9835-E3FE5664CF10 |
| Horizon Session User Name | horizon_session_user | The name of a Horizon session user. | String | Windows only | aabdulaziz |
| OS Major Version | OS_Major | The major version number. | Integer | Windows only | 10 |
| OS Minor Version | OS_Minor | The minor version number. | Integer | Windows only | 0 |
| OS Name Version | OS_Name_Version | The friendly name of the OS. | String | Windows only | Microsoft Windows 11 Enterprise |
| OS Version | OS_Version | The operating system version. | String | Windows only | 10.0.22631 |
| Platform | platform | The applicable platform. | String | Windows only | Windows |
| Pool ID | template_id | The pool or template ID. | String | Windows only | 64f7a6c7c03e7f07d5a85a19 |
| Pool Name | template_name | The name of a pool or template. | String | Windows only | C5-SL-Standard-2 |
| Unique Session Identifier | session_identifier | The unique session id generated by TLM driver. | String | Windows only | 0000011d-0000-0015-f00b-aef601000000 |
App network
The App Network table lists available data concerning application access to networks in your Experience Management deployment.
- Event category: App Network
- Entity: app_net_event
- New Connection - Identifies when an application initially connects to a network.
- Failed Connection - Identifies when an application failed to connect to a network.
- Closed Connection - Identifies when an application no longer remains connected to a network.
- Connection Statistics - Gives metrics on an application's network connection.
- Minimum agent version: 2509
| Friendly Name | Property | Definition | Type | New Connection | Failed Connection | Closed Connection | Connection Statistics | Examples |
|---|---|---|---|---|---|---|---|---|
| App Version | version | A number that identifies the application version. | String | Windows only | Windows only | Windows only | Windows only | 10.0.19041.4170 |
| Application Path | app_path | The path where the app is installed on a device. | String | Windows only | Windows only | Windows only | Windows only | C:\Windows\System32 |
| Average Connection Establishment Time | avg_conn_millis | Average Connection Establishment time in milliseconds. | Double | Windows only | NA | NA | NA | 260.5 milliseconds |
| Binary | application | The name of the process holding the connection. | String | Windows only | Windows only | Windows only | Windows only | ctfmon.exe |
| Connections Count | connections_count | The number of connections in the last interval | Integer | Windows only | NA | Windows only | Windows only | 100 |
| Domain | domain | An internet address. | String | Windows only | Windows only | Windows only | Windows only | DESKTOP-VAOF5MN |
| Event Name | event_name | The name of the event. | String | Windows only | Windows only | Windows only | Windows only | New Connection, Failed Connection, Closed Connection, Connection Statistics |
| Failure Description | failure_description | A verbose description of the failure reasons (can be platform dependent). | String | NA | Windows only | NA | NA | Connection failed due to no service running on the target. |
| Failure Reason | failure_reason | Reason for a connection failure. | String | NA | Windows only | NA | NA | Rejected Connection |
| File Description | name | Indicates the application product name. | String | Windows only | Windows only | Windows only | Windows only | Host Process for Windows Tasks |
| IP Protocol Version | ip_protocol_version | Identifies the IP protocol version as IPv4 or IPv6. | String | Windows only | Windows only | Windows only | Windows only | IPv4 |
| Is Loaded From App Volumes | is_loaded_from_av | Identifies if the app is from App Volumes | Boolean | Windows only | Windows only | Windows only | Windows only | True |
| Local IP Address | local_ip_address | The IP address of a local machine. | String | NA | Windows only | NA | NA | 44.230.85.241 |
| Local Port | local_port | The local port number. This attribute is not mandatory. | Integer | NA | Windows only | NA | NA | 8080 |
| Network Protocol Type | protocol_type | The type of protocol as tcp or udp. | String | Windows only | Windows only | Windows only | Windows only | TCP |
| Package Publisher | publisher | The publishing company of an app. | String | Windows only | Windows only | Windows only | Windows only | Intel Corporation |
| Process ID | process_id | A unique number to identify a process. | String | Windows only | Windows only | Windows only | Windows only | 1134 |
| Received Average Bytes Per Second | rx_avg_bps | The received average speed in bytes per second in an event time frame. | Double | NA | NA | NA | Windows only | 209,715,200 |
| Received Bytes | rx_bytes | The total data received from the socket connection in an event time frame (total data received in case of closed connection). | Double | NA | NA | Windows only | Windows only | 67995654 |
| Received Packet Count | rx_pkt_count | the number of packets received by the connection in an event time frame (total no of packets received in case of a closed connection). | Double | NA | NA | NA | Windows only | 6521 |
| Remote IP Address | remote_ip_address | The remote IP address. | String | Windows only | Windows only | Windows only | Windows only | 44.230.85.241 |
| Remote Port | remote_port | A remote port number. | Integer | Windows only | Windows only | Windows only | Windows only | 8800 |
| Sent Average Bytes Per Second | tx_avg_bps | The sent average speed in bytes per second in an event time frame. | Double | NA | NA | NA | Windows only | 108,715,400 |
| Sent Bytes | tx_bytes | The total data sent through the connection in an event time frame (total data sent in case of a closed connection). | Double | NA | NA | Windows only | Windows only | 987678543 |
| Sent Packet Count | tx_pkt_count | The number of packets sent through the connection in and event time frame (total number of packets sent in case of a closed connection). | Double | NA | NA | NA | Windows only | 5431 |
| Session Identifier | session | A Windows session ID. | String | Windows only | Windows only | Windows only | Windows only | 2 |
| User | user | The user of an application | String | Windows only | Windows only | Windows only | Windows only | TestUser |
| {.filterTable} |
App performance
The App Performance and App Performance (High Frequency, LA) table lists available data concerning how well and efficiently apps are running in your Experience Management deployment.
- Event category: Performance
- Entity: resource_consumption
- app_resource_consumption - Identifies when an app is using too much CPU, memory, disk, and network.
- Minimum agent version: 24.12
- Minimum agent version: 26.07 for app performance (high frequency), in limited availability
Note: The schema for App Performance (High Frequency), currently in limited availability, is the same as App Performance. The high frequency version collects raw application performance samples every 15 seconds and publishes aggregated events every 5 minutes, giving near-real-time visibility into resource consumption metrics including CPU, memory, disk, and GPU.
| Friendly Name | Property | Definition | Type | app_resource_consumption | Examples |
|---|---|---|---|---|---|
| Average Disk Transfer per Second | disk_io_bytes_sec | The rate at which bytes transfer to the disk during IO operations. | Double | Windows only | 2057 bps |
| Average Network Transfer per Second | network_interface_bytes_sec | The rate at which bytes transfer through the network interface. | Double | Windows only | 301 bps |
| From App Volumes | is_loaded_from_av | Identifies whether an application was delivered by App Volumes or not. | Boolean | Windows only | TRUE |
| Memory Usage | memory_usage_percentage | The memory usage, as a percentage, of an application. | Double | Windows only | 6.24% |
| Package Name | name | The friendly name of an application. | String | Windows only | Windows PowerShell |
| Private Memory | private_commit_byte | Total memory reserved by a process (RAM + pagefile), not shared with others. Leaks show up as a steady increase in committed memory that never stabilizes, since allocations aren’t freed. | Long | Windows only | 2.29 MB |
| Process Count | process_count | The process number that the application has consumed. | Integer | Windows only | 5 |
| Processor Usage | processor_usage_percentage | The processor usage, as a percentage, of an application. | Double | Windows only | 25.41% |
| {.filterTable} |
Apps
The Apps table lists data concerning characteristics and metadata for the apps in your Experience Management deployment.
- Event category: Application
- Entity: apps
- Application Crash - Identifies that an app has stopped running, unexpectedly.
- Application Exit - Identifies that an app has stopped running as expected because it was closed.
- Application Foreground - Identifies that an app is displaying in the UI when the UI is in the foreground, or is the main focus of the user session.
- Application Hang - Identifies that an app is stuck in a process.
- Application Start - Identifies when an application begins process whether it is a service, a user, or UI process.
- Minimum agent version: 24.12
| Friendly Name | Property | Definition | Type | Application Start | Application Exit | Application Foreground | Application Crash | Application Hang | Examples |
|---|---|---|---|---|---|---|---|---|---|
| Activation Time | activation_time | The activation time for application focus. | Date-Time | NA | NA | Windows only | NA | NA | 2/13/2025 11:46:00 AM |
| App Volumes Package ID | av_package_id | Lists the ID of an App Volumes package. | UUID | Windows only | Windows only | Windows only | Windows only | Windows only | 08870c17-bca9-4558-9a4f-311f60e83439 |
| Application End Time | end_time | The time when the application stops. | Date-Time | NA | Windows only | NA | NA | NA | 2/13/2025 11:46:00 AM |
| Application Install Path | app_path | The installation path of the application. | String | Windows only | Windows only | Windows only | Windows only | Windows only | C:\Windows\System32 |
| Application Name | application | Normalized app name or file description in Intelligence. | String | Windows only | Windows only | Windows only | Windows only | Windows only | Microsoft Windows Search Protocol Host |
| Duration in Milliseconds | duration_millis | This field provides the total time an application was in the foreground in an application Foreground Event or an application remained unresponsive in an application Unresponsive Event. Use the Sum operator to know the total time of application usage. | Long | NA | NA | Windows only | NA | Windows only | 13.6 s |
| Exception Code | exception_code | Exception code in an application crash event. | String | NA | NA | NA | Windows only | NA | 00000057 |
| Exception Offset | exception_offset | The offset of the crash module in the application. This field is applicable to Application Crash events. | String | NA | NA | NA | Windows only | NA | 00000000000c837a |
| From App Volumes | is_loaded_from_av | Identifies whether an application was delivered by App Volumes or not. | Boolean | Windows only | Windows only | Windows only | Windows only | Windows only | FALSE |
| Module | module | The module name within an application. | String | NA | NA | NA | Windows only | NA | libcoreclr.dylib |
| Module Path | module_path | The module installation path. | String | NA | NA | NA | Windows only | NA | /Library/Application Support/Workflow/libcoreclr.dylib |
| Module Version | module_version | The module version. This version can be different than the application version. | String | NA | NA | NA | Windows only | NA | 1307.2407.15032.0 |
| Package Name | name | The friendly name of the application. | String | Windows only | Windows only | Windows only | Windows only | Windows only | Console Windows Host |
| Package Publisher | publisher | The application publisher name. | String | Windows only | Windows only | Windows only | Windows only | Windows only | Microsoft Corporation |
| Package Version | version | The application version. | String | Windows only | Windows only | Windows only | Windows only | Windows only | 7.0.22621.4746 |
| Up Time in Milliseconds | up_time_millis | The time the application is active, from when it starts to stops. | Long | NA | Windows only | NA | NA | NA | 92 ms |
| {.filterTable} |
Network
The network table lists data concerning components in the system that connects and facilitates communication between the devices and resources in your Experience Management deployment.
- Event category: Network
- Entity: net_event
- Public IP - Identifies location data such as address, city, country, region, longitude, latitude, and geolocation ID of a public IP. This event requires the device to have network access to the following domains:
ts.awmdm.com,ts4.awmdm.com, andts6.awmdm.com.
- Public IP - Identifies location data such as address, city, country, region, longitude, latitude, and geolocation ID of a public IP. This event requires the device to have network access to the following domains:
- Minimum agent version: 25.09
| Friendly Name | Property | Definition | Type | Public IP | Examples |
|---|---|---|---|---|---|
| Event Friendly Name | event_friendly_name | A human readable name of the event. | String | Windows only | Public IP |
| Geolocation IPv4 Address | geolocation_ipv4_address | Identifies an IPv4 address mapped to a location. | String | Windows only | 192.30.67.11 |
| Geolocation IPv6 Address | geolocation_ipv6_address | Identifies an IPv6 address mapped to a location | String | Windows only | 2600:1700:1dd0:1b90:80bf:fab:78e0:4029%0 |
| IPv4 Addresses | ipv4_addresses | Lists the IPv4 addresses and subnet lengths. For example, 10.20.30.40/22. | String List | Windows only | 10.4.137.89/21 |
| IPv4 City | ipv4_city | Identifies the city to which a public IP is mapped. | String | Windows only | Atlanta |
| IPv4 Country | ipv4_country | Identifies the country to which a public IP is mapped. | String | Windows only | United States (US) |
| IPv4 Geolocation ID | ipv4_geolocation_id | A value that represents the geographic data assigned to a public IP. | String | Windows only | 192.30.67.11 |
| IPv4 Latitude | ipv4_latitude | Lists the latitudinal quardinates to which a public IP is mapped. | String | Windows only | 33.74 |
| IPv4 Longitude | ipv4_longitude | Lists the longitudinal quardinates to which a public IP is mapped. | String | Windows only | -84.38798 |
| IPv4 Region | ipv4_region | Identifies the region to which a public IP is mapped. | String | Windows only | Georgia |
| IPv6 Addresses | ipv6_addresses | Lists the IPv6 addresses and subnet lengths. | String List | Windows only | fe80::50:56ff:fe56:4453 |
| IPv6 City | ipv6_city | Identifies the city to which a public IP is mapped. | String | Windows only | Atlanta |
| IPv6 Country | ipv6_country | Identifies the country to which a public IP is mapped. | String | Windows only | United States (US) |
| IPv6 Geolocation ID | ipv6_geolocation_id | A value that represents the geographic data assigned to a public IP. | String | Windows only | 2600:1700:1dd0:1b90:80bf:fab:78e0:4029%0 |
| IPv6 Latitude | ipv6_latitude | Lists the latitudinal quardinates to which a public IP is mapped. | String | Windows only | 33.74 |
| IPv6 Longitude | ipv6_longitude | Lists the longitudinal quardinates to which a public IP is mapped. | String | Windows only | -84.38798 |
| IPv6 Region | ipv6_region | Identifies the region to which a public IP is mapped. | String | Windows only | Georgia |
Service inventory
The Service Inventory table lists data about Windows services running on endpoint devices in your Experience Management deployment.
- Event category: Service inventory
- Entity: service_inventory
- Minimum agent version: 26.07
| Friendly Name | Property | Definition | Type | Examples |
|---|---|---|---|---|
| App Volumes Package ID | av_package_id | The App Volumes package identifier associated with the service. | Uuid | 08870c17-bca9-4558-9a4f-311f60e83439 |
| From App Volumes | is_loaded_from_av | Indicates whether the service is delivered from App Volumes. | Boolean | true |
| Process Name | image_name | The name of the process hosting the service. | String | svchost.exe |
| Process Version | image_version | The version of the process hosting the service. | String | 10.0.26100.5074 |
| Service Auto Recovery | auto_recovery | Indicates whether auto recovery is configured for the service. | Boolean | true |
| Service Description | description | The description of the service. | String | Omnissa Experience Management Service collects telemetry for use with the Omnissa Digital Employee Experience Management Solution |
| Service Display Name | display_name | The display name of the service. | String | Omnissa Experience Management Service |
| Service Dll Name | dll_name | The name of the DLL associated with the service. On Windows, many services run inside a shared host process; this attribute captures the service DLL name. | String | ztdhelper.dll |
| Service Dll Version | dll_version | The version of the DLL associated with the service. | String | 10.0.26100.6725 |
| Service Id | service_id | The unique identifier of the service. On Windows, this is a hash of the service name. | String | 5086996434635914803 |
| Service Logon Account Domain | account_domain | The domain of the user account under which the service runs. Affects service permissions and access. | String | Testdomain |
| Service Logon Account User | account_user | The user account under which the service runs. Affects service permissions and access. Allowed values: Local System, Local Service, Network Service. | String | Local System |
| Service Name | name | The name of the service. | String | ws1etlm |
| Service Startup Type | startup_type | The startup type of the service, which defines how and when the service starts. Allowed values: Automatic, Manual, Disabled. | String | Automatic |
| Service Status | status | The current status of the service. Allowed values: Running, Stopped. | String | Running |
| Service Type | type | The type of service. Allowed values: System, User, User_Instance. | String | System |
| Session Domain | session_domain | The session domain for a User service instance. | String | testdomain |
| Session Id | session_id | The session identifier for a User service instance. | String | 2 |
| Session User | session_user_name | The session user name for a User service instance. | String | testuser |
| {.filterTable} |
Service inventory change event
In addition to the Service Inventory snapshot entity, Omnissa Intelligence creates two derived timeseries entities that track historical changes to service inventory data over time.
- Service Inventory Change Event that tracks changes to
service_inventorydata for UEM-managed Windows devices. - Service Inventory Change Event (Horizon) that tracks changes to
horizon_service_inventorydata for Horizon-managed devices.
The Service Inventory snapshot entity captures a point-in-time inventory of all services on a device at each reporting cycle. However, snapshot data alone doesn't tell you what changed and when it changed. The Inventory Change Event entity does tell you what changed and when it changed.
Each time a new snapshot arrives for a specific service on a given device, Intelligence compares the current and previous attribute values for each service. If any attribute changes - service status, startup type, account user, display name, or any other tracked field - Intelligence automatically creates a timeseries entry recording that change. You now have a queryable history of changes.
Example use case
An IT admin wants to know when a specific service stops running across their fleet, and wants to be alerted to it - not just see the current state.
- The snapshot entity shows the current inventory.
- The change event entity activates automations and alerts that are triggered when a service transitions from Running to Stopped (or any other state change).
Allowed values
Service Status values
| Value | Description |
|---|---|
| Running | The service is currently active and running. |
| Stopped | The service is not running. |
Service Startup Type values
| Value | Description |
|---|---|
| Automatic | The service starts automatically when the system starts. |
| Manual | The service starts only when explicitly started by a user or application. |
| Disabled | The service is disabled and cannot be started. |
| System | The service is loaded during kernel initialization, early in system startup. |
Service Type values
| Value | Description |
|---|---|
| System | A service that runs in a shared host process (e.g. svchost.exe). |
| User | A per-user service instance. |
| User Instance | A specific instance of a per-user service. |
Service Logon Account User values
| Value | Description |
|---|---|
| Local System | A highly privileged built-in account used by the operating system. |
| Loacl Service | A built-in account with reduced privileges for services that do not need network access. |
| Network Service | A built-in account that has network access but reduced local privileges. |
| User Account | A specific user or domain account under which the service runs, using that account's credentials and permissions. For services running under a specific user account (for example domain\user), the system splits the value and populates either the Service Logon Account User and the Service Logon Account Domain attribute accordingly. |
User actions
The User Actions table lists data concerning user actions when logging on and when processing client-side extensions and group policy objects.
- Event category: User Actions
- Entity: user_actions
- user_gpo_cse_details - Provides processing details for a client-side extension.
- user_gpo_details - Provides processing details for a group policy object.
- user_gpo_summary - Provides processing details for applying user group policies during a user logon.
- Minimum agent version: 24.12
| Friendly Name | Definition | user_gpo_cse_details | user_gpo_details | user_gpo_summary |
|---|---|---|---|---|
| Asynchronous Processing | For the user_gpo_cse_details event, this field indicates if a client-side extension does or does not require synchronous processing to apply new settings.For the user_gpo_summary event, this field indicates whether the Group Policy service applies policy settings asynchronously. | Windows only | NA | Windows only |
| CSE Name List | Lists the client-side extensions used to process a GPO with the user_gpo_details event. | NA | Windows only | NA |
| Domain | Lists the Windows domain name using the user_gpo_cse_details, user_gpo_details, and user_gpo_summary events. | Windows only | Windows only | Windows only |
| Duration in Milliseconds | For the user_gpo_cse_details event, this field provides the processing time of a client-side extension. For the user_gpo_details event, this field provides the time used to process a GPO. For the user_gpo_summary event, this field provides the total time used to apply user group policies during user logon. | Windows only | Windows only | Windows only |
| End Time | For the user_gpo_cse_details event, this field provides the time when the processing of the client-side extension ended.For the user_gpo_summary event, this field provides the time when the user logon group policy processing ended. | Windows only | NA | Windows only |
| GPO Name List | Lists the GPOs processed by a client-side extension with the user_gpo_cse_details event. | Windows only | NA | NA |
| Name | For the user_gpo_cse_details event, this field provides the name of the client-side extension. For the user_gpo_details event, this field provides the name of the GPO. | Windows only | Windows only | NA |
| Preprocessing Duration in Milliseconds | Lists the time used to complete preprocessing operations when applying user group policies during user logon using the user_gpo_summary event. | NA | NA | Windows only |
| Result | Lists the execution results of the client-side extension using the user_gpo_cse_details event. Values are Success, Warning, and Error. | Windows only | NA | NA |
| Start Time | For the user_gpo_cse_details event, this field provides the time when the processing of a client-side extension started. For the user_gpo_summary event, this field provides the time when an instance of the user logon group policy processing started. | Windows only | NA | Windows only |
| User | Lists the logon user name using the user_gpo_cse_details, user_gpo_details, and user_gpo_summary events. | Windows only | Windows only | Windows only |
| {.filterTable} |
Was this page helpful?