Skip to main content

September 1, 2026

Experience Management for Horizon

Use these Omnissa Workspace ONE Experience Management desktop telemetry data definitions and lists of available data fields to help you analyze Experience Management for Horizon specific widgets in dashboards and in the Experience Management Solutions area in Omnissa Intelligence.

Product information and supported platform

Experience Management for Horizon works on the Omnissa Horizon product run on the Windows platform.

Supported desktop models

Experience Management for Horizon supports the virtual desktop infrastructure (VDI) and remote desktop session host (RDSH) models.

What Category identifies Experience Management data?

When working in dashboard widgets in Intelligence, look for the Employee Experience category.

Update, sample, and transmission frequencies

Common fields

The common fields table lists the data that is common to all the Experience Management for Horizon event types.

Friendly NamePropertyDefinitionTypeEvent SupportExamples
Device MakeDevice_MakeMake of the device.StringWindows onlyLenovo
Device ModelDevice_ModelModel of the device.StringWindows only20XXS1ER00
Device Namedevice_nameName of the device.StringWindows onlyPF2T16S2
Device Serial NumberDevice_Serial_NumberSerial number of the device.StringWindows onlyVM8Kq4Oo513w
Horizon Session UUIDsession_uuidThe unique session UUID for a Horizon session.StringWindows only37A60EF4-1482-49AA-9835-E3FE5664CF10
Horizon Session User Namehorizon_session_userThe name of a Horizon session user.StringWindows onlyaabdulaziz
OS Major VersionOS_MajorThe major version number.IntegerWindows only10
OS Minor VersionOS_MinorThe minor version number.IntegerWindows only0
OS Name VersionOS_Name_VersionThe friendly name of the OS.StringWindows onlyMicrosoft Windows 11 Enterprise
OS VersionOS_VersionThe operating system version.StringWindows only10.0.22631
PlatformplatformThe applicable platform.StringWindows onlyWindows
Pool IDtemplate_idThe pool or template ID.StringWindows only64f7a6c7c03e7f07d5a85a19
Pool Nametemplate_nameThe name of a pool or template.StringWindows onlyC5-SL-Standard-2
Unique Session Identifiersession_identifierThe unique session id generated by TLM driver.StringWindows only0000011d-0000-0015-f00b-aef601000000

App network

The App Network table lists available data concerning application access to networks in your Experience Management deployment.

  • Event category: App Network
  • Entity: app_net_event
    • New Connection - Identifies when an application initially connects to a network.
    • Failed Connection - Identifies when an application failed to connect to a network.
    • Closed Connection - Identifies when an application no longer remains connected to a network.
    • Connection Statistics - Gives metrics on an application's network connection.
  • Minimum agent version: 2509
Friendly NamePropertyDefinitionTypeNew ConnectionFailed ConnectionClosed ConnectionConnection StatisticsExamples
App VersionversionA number that identifies the application version.StringWindows onlyWindows onlyWindows onlyWindows only10.0.19041.4170
Application Pathapp_pathThe path where the app is installed on a device.StringWindows onlyWindows onlyWindows onlyWindows onlyC:\Windows\System32
Average Connection Establishment Timeavg_conn_millisAverage Connection Establishment time in milliseconds.DoubleWindows onlyNANANA260.5 milliseconds
BinaryapplicationThe name of the process holding the connection.StringWindows onlyWindows onlyWindows onlyWindows onlyctfmon.exe
Connections Countconnections_countThe number of connections in the last intervalIntegerWindows onlyNAWindows onlyWindows only100
DomaindomainAn internet address.StringWindows onlyWindows onlyWindows onlyWindows onlyDESKTOP-VAOF5MN
Event Nameevent_nameThe name of the event.StringWindows onlyWindows onlyWindows onlyWindows onlyNew Connection, Failed Connection, Closed Connection, Connection Statistics
Failure Descriptionfailure_descriptionA verbose description of the failure reasons (can be platform dependent).StringNAWindows onlyNANAConnection failed due to no service running on the target.
Failure Reasonfailure_reasonReason for a connection failure.StringNAWindows onlyNANARejected Connection
File DescriptionnameIndicates the application product name.StringWindows onlyWindows onlyWindows onlyWindows onlyHost Process for Windows Tasks
IP Protocol Versionip_protocol_versionIdentifies the IP protocol version as IPv4 or IPv6.StringWindows onlyWindows onlyWindows onlyWindows onlyIPv4
Is Loaded From App Volumesis_loaded_from_avIdentifies if the app is from App VolumesBooleanWindows onlyWindows onlyWindows onlyWindows onlyTrue
Local IP Addresslocal_ip_addressThe IP address of a local machine.StringNAWindows onlyNANA44.230.85.241
Local Portlocal_portThe local port number. This attribute is not mandatory.IntegerNAWindows onlyNANA8080
Network Protocol Typeprotocol_typeThe type of protocol as tcp or udp.StringWindows onlyWindows onlyWindows onlyWindows onlyTCP
Package PublisherpublisherThe publishing company of an app.StringWindows onlyWindows onlyWindows onlyWindows onlyIntel Corporation
Process IDprocess_idA unique number to identify a process.StringWindows onlyWindows onlyWindows onlyWindows only1134
Received Average Bytes Per Secondrx_avg_bpsThe received average speed in bytes per second in an event time frame.DoubleNANANAWindows only209,715,200
Received Bytesrx_bytesThe total data received from the socket connection in an event time frame (total data received in case of closed connection).DoubleNANAWindows onlyWindows only67995654
Received Packet Countrx_pkt_countthe number of packets received by the connection in an event time frame (total no of packets received in case of a closed connection).DoubleNANANAWindows only6521
Remote IP Addressremote_ip_addressThe remote IP address.StringWindows onlyWindows onlyWindows onlyWindows only44.230.85.241
Remote Portremote_portA remote port number.IntegerWindows onlyWindows onlyWindows onlyWindows only8800
Sent Average Bytes Per Secondtx_avg_bpsThe sent average speed in bytes per second in an event time frame.DoubleNANANAWindows only108,715,400
Sent Bytestx_bytesThe total data sent through the connection in an event time frame (total data sent in case of a closed connection).DoubleNANAWindows onlyWindows only987678543
Sent Packet Counttx_pkt_countThe number of packets sent through the connection in and event time frame (total number of packets sent in case of a closed connection).DoubleNANANAWindows only5431
Session IdentifiersessionA Windows session ID.StringWindows onlyWindows onlyWindows onlyWindows only2
UseruserThe user of an applicationStringWindows onlyWindows onlyWindows onlyWindows onlyTestUser
{.filterTable}

App performance

The App Performance and App Performance (High Frequency, LA) table lists available data concerning how well and efficiently apps are running in your Experience Management deployment.

  • Event category: Performance
  • Entity: resource_consumption
    • app_resource_consumption - Identifies when an app is using too much CPU, memory, disk, and network.
  • Minimum agent version: 24.12
  • Minimum agent version: 26.07 for app performance (high frequency), in limited availability

Note: The schema for App Performance (High Frequency), currently in limited availability, is the same as App Performance. The high frequency version collects raw application performance samples every 15 seconds and publishes aggregated events every 5 minutes, giving near-real-time visibility into resource consumption metrics including CPU, memory, disk, and GPU.

Friendly NamePropertyDefinitionTypeapp_resource_consumptionExamples
Average Disk Transfer per Seconddisk_io_bytes_secThe rate at which bytes transfer to the disk during IO operations.DoubleWindows only2057 bps
Average Network Transfer per Secondnetwork_interface_bytes_secThe rate at which bytes transfer through the network interface.DoubleWindows only301 bps
From App Volumesis_loaded_from_avIdentifies whether an application was delivered by App Volumes or not.BooleanWindows onlyTRUE
Memory Usagememory_usage_percentageThe memory usage, as a percentage, of an application.DoubleWindows only6.24%
Package NamenameThe friendly name of an application.StringWindows onlyWindows PowerShell
Private Memoryprivate_commit_byteTotal memory reserved by a process (RAM + pagefile), not shared with others. Leaks show up as a steady increase in committed memory that never stabilizes, since allocations aren’t freed.LongWindows only2.29 MB
Process Countprocess_countThe process number that the application has consumed.IntegerWindows only5
Processor Usageprocessor_usage_percentageThe processor usage, as a percentage, of an application.DoubleWindows only25.41%
{.filterTable}

Apps

The Apps table lists data concerning characteristics and metadata for the apps in your Experience Management deployment.

  • Event category: Application
  • Entity: apps
    • Application Crash - Identifies that an app has stopped running, unexpectedly.
    • Application Exit - Identifies that an app has stopped running as expected because it was closed.
    • Application Foreground - Identifies that an app is displaying in the UI when the UI is in the foreground, or is the main focus of the user session.
    • Application Hang - Identifies that an app is stuck in a process.
    • Application Start - Identifies when an application begins process whether it is a service, a user, or UI process.
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypeApplication StartApplication ExitApplication ForegroundApplication CrashApplication HangExamples
Activation Timeactivation_timeThe activation time for application focus.Date-TimeNANAWindows onlyNANA2/13/2025 11:46:00 AM
App Volumes Package IDav_package_idLists the ID of an App Volumes package.UUIDWindows onlyWindows onlyWindows onlyWindows onlyWindows only08870c17-bca9-4558-9a4f-311f60e83439
Application End Timeend_timeThe time when the application stops.Date-TimeNAWindows onlyNANANA2/13/2025 11:46:00 AM
Application Install Pathapp_pathThe installation path of the application.StringWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyC:\Windows\System32
Application NameapplicationNormalized app name or file description in Intelligence.StringWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyMicrosoft Windows Search Protocol Host
Duration in Millisecondsduration_millisThis field provides the total time an application was in the foreground in an application Foreground Event or an application remained unresponsive in an application Unresponsive Event. Use the Sum operator to know the total time of application usage.LongNANAWindows onlyNAWindows only13.6 s
Exception Codeexception_codeException code in an application crash event.StringNANANAWindows onlyNA00000057
Exception Offsetexception_offsetThe offset of the crash module in the application. This field is applicable to Application Crash events.StringNANANAWindows onlyNA00000000000c837a
From App Volumesis_loaded_from_avIdentifies whether an application was delivered by App Volumes or not.BooleanWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyFALSE
ModulemoduleThe module name within an application.StringNANANAWindows onlyNAlibcoreclr.dylib
Module Pathmodule_pathThe module installation path.StringNANANAWindows onlyNA/Library/Application Support/Workflow/libcoreclr.dylib
Module Versionmodule_versionThe module version.
This version can be different than the application version.
StringNANANAWindows onlyNA1307.2407.15032.0
Package NamenameThe friendly name of the application.StringWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyConsole Windows Host
Package PublisherpublisherThe application publisher name.StringWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyMicrosoft Corporation
Package VersionversionThe application version.StringWindows onlyWindows onlyWindows onlyWindows onlyWindows only7.0.22621.4746
Up Time in Millisecondsup_time_millisThe time the application is active, from when it starts to stops.LongNAWindows onlyNANANA92 ms
{.filterTable}

Network

The network table lists data concerning components in the system that connects and facilitates communication between the devices and resources in your Experience Management deployment.

  • Event category: Network
  • Entity: net_event
    • Public IP - Identifies location data such as address, city, country, region, longitude, latitude, and geolocation ID of a public IP. This event requires the device to have network access to the following domains: ts.awmdm.com, ts4.awmdm.com, and ts6.awmdm.com.
  • Minimum agent version: 25.09
Friendly NamePropertyDefinitionTypePublic IPExamples
Event Friendly Nameevent_friendly_nameA human readable name of the event.StringWindows onlyPublic IP
Geolocation IPv4 Addressgeolocation_ipv4_addressIdentifies an IPv4 address mapped to a location.StringWindows only192.30.67.11
Geolocation IPv6 Addressgeolocation_ipv6_addressIdentifies an IPv6 address mapped to a locationStringWindows only2600:1700:1dd0:1b90:80bf:fab:78e0:4029%0
IPv4 Addressesipv4_addressesLists the IPv4 addresses and subnet lengths.

For example, 10.20.30.40/22.
String ListWindows only10.4.137.89/21
IPv4 Cityipv4_cityIdentifies the city to which a public IP is mapped.StringWindows onlyAtlanta
IPv4 Countryipv4_countryIdentifies the country to which a public IP is mapped.StringWindows onlyUnited States (US)
IPv4 Geolocation IDipv4_geolocation_idA value that represents the geographic data assigned to a public IP.StringWindows only192.30.67.11
IPv4 Latitudeipv4_latitudeLists the latitudinal quardinates to which a public IP is mapped.StringWindows only33.74
IPv4 Longitudeipv4_longitudeLists the longitudinal quardinates to which a public IP is mapped.StringWindows only-84.38798
IPv4 Regionipv4_regionIdentifies the region to which a public IP is mapped.StringWindows onlyGeorgia
IPv6 Addressesipv6_addressesLists the IPv6 addresses and subnet lengths.String ListWindows onlyfe80::50:56ff:fe56:4453
IPv6 Cityipv6_cityIdentifies the city to which a public IP is mapped.StringWindows onlyAtlanta
IPv6 Countryipv6_countryIdentifies the country to which a public IP is mapped.StringWindows onlyUnited States (US)
IPv6 Geolocation IDipv6_geolocation_idA value that represents the geographic data assigned to a public IP.StringWindows only2600:1700:1dd0:1b90:80bf:fab:78e0:4029%0
IPv6 Latitudeipv6_latitudeLists the latitudinal quardinates to which a public IP is mapped.StringWindows only33.74
IPv6 Longitudeipv6_longitudeLists the longitudinal quardinates to which a public IP is mapped.StringWindows only-84.38798
IPv6 Regionipv6_regionIdentifies the region to which a public IP is mapped.StringWindows onlyGeorgia

Service inventory

The Service Inventory table lists data about Windows services running on endpoint devices in your Experience Management deployment.

  • Event category: Service inventory
  • Entity: service_inventory
  • Minimum agent version: 26.07
Friendly NamePropertyDefinitionTypeExamples
App Volumes Package IDav_package_idThe App Volumes package identifier associated with the service.Uuid08870c17-bca9-4558-9a4f-311f60e83439
From App Volumesis_loaded_from_avIndicates whether the service is delivered from App Volumes.Booleantrue
Process Nameimage_nameThe name of the process hosting the service.Stringsvchost.exe
Process Versionimage_versionThe version of the process hosting the service.String10.0.26100.5074
Service Auto Recoveryauto_recoveryIndicates whether auto recovery is configured for the service.Booleantrue
Service DescriptiondescriptionThe description of the service.StringOmnissa Experience Management Service collects telemetry for use with the Omnissa Digital Employee Experience Management Solution
Service Display Namedisplay_nameThe display name of the service.StringOmnissa Experience Management Service
Service Dll Namedll_nameThe name of the DLL associated with the service. On Windows, many services run inside a shared host process; this attribute captures the service DLL name.Stringztdhelper.dll
Service Dll Versiondll_versionThe version of the DLL associated with the service.String10.0.26100.6725
Service Idservice_idThe unique identifier of the service. On Windows, this is a hash of the service name.String5086996434635914803
Service Logon Account Domainaccount_domainThe domain of the user account under which the service runs. Affects service permissions and access.StringTestdomain
Service Logon Account Useraccount_userThe user account under which the service runs. Affects service permissions and access. Allowed values: Local System, Local Service, Network Service.StringLocal System
Service NamenameThe name of the service.Stringws1etlm
Service Startup Typestartup_typeThe startup type of the service, which defines how and when the service starts. Allowed values: Automatic, Manual, Disabled.StringAutomatic
Service StatusstatusThe current status of the service. Allowed values: Running, Stopped.StringRunning
Service TypetypeThe type of service. Allowed values: System, User, User_Instance.StringSystem
Session Domainsession_domainThe session domain for a User service instance.Stringtestdomain
Session Idsession_idThe session identifier for a User service instance.String2
Session Usersession_user_nameThe session user name for a User service instance.Stringtestuser
{.filterTable}

Service inventory change event

In addition to the Service Inventory snapshot entity, Omnissa Intelligence creates two derived timeseries entities that track historical changes to service inventory data over time.

  • Service Inventory Change Event that tracks changes to service_inventory data for UEM-managed Windows devices.
  • Service Inventory Change Event (Horizon) that tracks changes to horizon_service_inventory data for Horizon-managed devices.

The Service Inventory snapshot entity captures a point-in-time inventory of all services on a device at each reporting cycle. However, snapshot data alone doesn't tell you what changed and when it changed. The Inventory Change Event entity does tell you what changed and when it changed.

Each time a new snapshot arrives for a specific service on a given device, Intelligence compares the current and previous attribute values for each service. If any attribute changes - service status, startup type, account user, display name, or any other tracked field - Intelligence automatically creates a timeseries entry recording that change. You now have a queryable history of changes.

Example use case

An IT admin wants to know when a specific service stops running across their fleet, and wants to be alerted to it - not just see the current state.

  • The snapshot entity shows the current inventory.
  • The change event entity activates automations and alerts that are triggered when a service transitions from Running to Stopped (or any other state change).

Allowed values

Service Status values

ValueDescription
RunningThe service is currently active and running.
StoppedThe service is not running.

Service Startup Type values

ValueDescription
AutomaticThe service starts automatically when the system starts.
ManualThe service starts only when explicitly started by a user or application.
DisabledThe service is disabled and cannot be started.
SystemThe service is loaded during kernel initialization, early in system startup.

Service Type values

ValueDescription
SystemA service that runs in a shared host process (e.g. svchost.exe).
UserA per-user service instance.
User InstanceA specific instance of a per-user service.

Service Logon Account User values

ValueDescription
Local SystemA highly privileged built-in account used by the operating system.
Loacl ServiceA built-in account with reduced privileges for services that do not need network access.
Network ServiceA built-in account that has network access but reduced local privileges.
User AccountA specific user or domain account under which the service runs, using that account's credentials and permissions.

For services running under a specific user account (for example domain\user), the system splits the value and populates either the Service Logon Account User and the Service Logon Account Domain attribute accordingly.

User actions

The User Actions table lists data concerning user actions when logging on and when processing client-side extensions and group policy objects.

  • Event category: User Actions
  • Entity: user_actions
    • user_gpo_cse_details - Provides processing details for a client-side extension.
    • user_gpo_details - Provides processing details for a group policy object.
    • user_gpo_summary - Provides processing details for applying user group policies during a user logon.
  • Minimum agent version: 24.12
Friendly NameDefinitionuser_gpo_cse_detailsuser_gpo_detailsuser_gpo_summary
Asynchronous ProcessingFor the user_gpo_cse_details event, this field indicates if a client-side extension does or does not require synchronous processing to apply new settings.

For the user_gpo_summary event, this field indicates whether the Group Policy service applies policy settings asynchronously.
Windows onlyNAWindows only
CSE Name ListLists the client-side extensions used to process a GPO with the user_gpo_details event.NAWindows onlyNA
DomainLists the Windows domain name using the user_gpo_cse_details, user_gpo_details, and user_gpo_summary events.Windows onlyWindows onlyWindows only
Duration in MillisecondsFor the user_gpo_cse_details event, this field provides the processing time of a client-side extension.

For the user_gpo_details event, this field provides the time used to process a GPO.

For the user_gpo_summary event, this field provides the total time used to apply user group policies during user logon.
Windows onlyWindows onlyWindows only
End TimeFor the user_gpo_cse_details event, this field provides the time when the processing of the client-side extension ended.

For the user_gpo_summary event, this field provides the time when the user logon group policy processing ended.
Windows onlyNAWindows only
GPO Name ListLists the GPOs processed by a client-side extension with the user_gpo_cse_details event.Windows onlyNANA
NameFor the user_gpo_cse_details event, this field provides the name of the client-side extension.

For the user_gpo_details event, this field provides the name of the GPO.
Windows onlyWindows onlyNA
Preprocessing Duration in MillisecondsLists the time used to complete preprocessing operations when applying user group policies during user logon using the user_gpo_summary event.NANAWindows only
ResultLists the execution results of the client-side extension using the user_gpo_cse_details event.

Values are Success, Warning, and Error.
Windows onlyNANA
Start TimeFor the user_gpo_cse_details event, this field provides the time when the processing of a client-side extension started.

For the user_gpo_summary event, this field provides the time when an instance of the user logon group policy processing started.
Windows onlyNAWindows only
UserLists the logon user name using the user_gpo_cse_details, user_gpo_details, and user_gpo_summary events.Windows onlyWindows onlyWindows only
{.filterTable}

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…