Skip to main content

September 1, 2026

Experience Management for macOS and Windows

Use these Omnissa Workspace ONE Experience Management desktop telemetry data definitions and lists of available data fields to help you analyze Experience Management specific widgets in dashboards and in the Experience Management Solutions area in Omnissa Intelligence for your Windows and macOS devices that are managed by Omnissa Workspace ONE UEM.

Product information

Experience Management for macOS and Windows work on devices managed by the Omnissa Workspace ONE UEM product.

What category identifies Experience Management data?

When working in dashboard widgets in Intelligence, look for the Employee Experience category.

Update, sample, and transmission frequencies

Common fields

The common fields table lists the data that is common to all the Experience Management event types.

Friendly NamePropertyDefinitionTypeEvent SupportExamples
Device MakeDevice_MakeMake of the device.StringmacOS and WindowsLenovo
Device ModelDevice_ModelModel of the device.StringmacOS and Windows20XXS1ER00
Device Namedevice_nameName of the device.StringmacOS and WindowsPF2T16S2
Device Serial NumberDevice_Serial_NumberSerial number of the device.StringmacOS and WindowsVM8Kq4Oo513w
OS Major VersionOS_MajorThe major version number.IntegermacOS and Windows10
OS Minor VersionOS_MinorThe minor version number.IntegermacOS and Windows0
OS Name VersionOS_Name_VersionThe friendly name of the OS.StringmacOS and WindowsMicrosoft Windows 11 Enterprise
OS VersionOS_VersionThe operating system version.StringmacOS and Windows10.0.22631
PlatformplatformThe applicable platform.StringmacOS and WindowsWindows

App network

The App Network table lists available data concerning application access to networks in your Experience Management deployment.

  • Event category: App Network
  • Entity: app_net_event
    • New Connection - Identifies when an application initially connects to a network.
    • Failed Connection - Identifies when an application failed to connect to a network.
    • Closed Connection - Identifies when an application no longer remains connected to a network.
    • Connection Statistics - Gives metrics on an application's network connection.
  • Minimum agent version: Limited availability
Friendly NamePropertyDefinitionTypeNew ConnectionFailed ConnectionClosed ConnectionConnection StatisticsExamples
App VersionversionA number that identifies the application version.StringWindows onlyWindows onlyWindows onlyWindows only10.0.19041.4170
Application Pathapp_pathThe path where the app is installed on a device.StringWindows onlyWindows onlyWindows onlyWindows onlyC:\Windows\System32
Average Connection Establishment Timeavg_conn_millisAverage Connection Establishment time in milliseconds.DoubleWindows onlyNANANA260.5 milliseconds
BinaryapplicationThe name of the process holding the connection.StringWindows onlyWindows onlyWindows onlyWindows onlyctfmon.exe
Connections Countconnections_countThe number of connections in the last intervalIntegerWindows onlyNAWindows onlyWindows only100
DomaindomainAn internet address.StringWindows onlyWindows onlyWindows onlyWindows onlyDESKTOP-VAOF5MN
Event Nameevent_nameThe name of the event.StringWindows onlyWindows onlyWindows onlyWindows onlyNew Connection, Failed Connection, Closed Connection, Connection Statistics
Failure Descriptionfailure_descriptionA verbose description of the failure reasons (can be platform dependent).StringNAWindows onlyNANAConnection failed due to no service running on the target.
Failure Reasonfailure_reasonReason for a connection failure.StringNAWindows onlyNANARejected Connection
File DescriptionnameIndicates the application product name.StringWindows onlyWindows onlyWindows onlyWindows onlyHost Process for Windows Tasks
IP Protocol Versionip_protocol_versionIdentifies the IP protocol version as IPv4 or IPv6.StringWindows onlyWindows onlyWindows onlyWindows onlyIPv4
Is Loaded From App Volumesis_loaded_from_avIdentifies if the app is from App VolumesBooleanWindows onlyWindows onlyWindows onlyWindows onlyTrue
Local IP Addresslocal_ip_addressThe IP address of a local machine.StringNAWindows onlyNANA44.230.85.241
Local Portlocal_portThe local port number. This attribute is not mandatory.IntegerNAWindows onlyNANA8080
Network Protocol Typeprotocol_typeThe type of protocol as tcp or udp.StringWindows onlyWindows onlyWindows onlyWindows onlyTCP
Package PublisherpublisherThe publishing company of an app.StringWindows onlyWindows onlyWindows onlyWindows onlyIntel Corporation
Process IDprocess_idA unique number to identify a process.StringWindows onlyWindows onlyWindows onlyWindows only1134
Received Average Bytes Per Secondrx_avg_bpsThe received average speed in bytes per second in an event time frame.DoubleNANANAWindows only209,715,200
Received Bytesrx_bytesThe total data received from the socket connection in an event time frame (total data received in case of closed connection).DoubleNANAWindows onlyWindows only67995654
Received Packet Countrx_pkt_countthe number of packets received by the connection in an event time frame (total no of packets received in case of a closed connection).DoubleNANANAWindows only6521
Remote IP Addressremote_ip_addressThe remote IP address.StringWindows onlyWindows onlyWindows onlyWindows only44.230.85.241
Remote Portremote_portA remote port number.IntegerWindows onlyWindows onlyWindows onlyWindows only8800
Sent Average Bytes Per Secondtx_avg_bpsThe sent average speed in bytes per second in an event time frame.DoubleNANANAWindows only108,715,400
Sent Bytestx_bytesThe total data sent through the connection in an event time frame (total data sent in case of a closed connection).DoubleNANAWindows onlyWindows only987678543
Sent Packet Counttx_pkt_countThe number of packets sent through the connection in and event time frame (total number of packets sent in case of a closed connection).DoubleNANANAWindows only5431
Session IdentifiersessionA Windows session ID.StringWindows onlyWindows onlyWindows onlyWindows only2
UseruserThe user of an applicationStringWindows onlyWindows onlyWindows onlyWindows onlyTestUser
{.filterTable}

App performance

The App Performance and App Performance (High Frequency, LA, Windows only) table lists available data concerning how well and efficiently apps are running in your Experience Management deployment.

  • Event category: Performance
  • Entity: resource_consumption
    • app_resource_consumption - Identifies when an app is using too much CPU, memory, disk, and network.
  • Minimum agent version: 24.12 for app performance
  • Minimum agent version: 26.07 for app performance (high frequency), in limited availability, and for only Windows

Note: The schema for App Performance (High Frequency), currently in limited availability, is the same as App Performance except that it applies to Windows devices. The high frequency version collects raw application performance samples every 15 seconds and publishes aggregated events every 5 minutes, giving near-real-time visibility into resource consumption metrics including CPU, memory, disk, and GPU.

Friendly NamePropertyDefinitionTypeapp_resource_consumptionExamples
App VersionversionThe version of the Windows application.StringWindows only10.0.19041.4170
Application NameapplicationThe process binary name.StringmacOS and Windowsctfmon.exe
Average Disk Transfer per Seconddisk_io_bytes_secThe rate at which bytes transfer to the disk during IO operations.DoublemacOS and Windows2057 bps
Average Network Transfer per Secondnetwork_interface_bytes_secThe rate at which bytes transfer through the network interface.DoubleWindows only301 bps
From App Volumesis_loaded_from_avIdentifies whether an application was delivered by App Volumes or not.BooleanWindows onlyTRUE
GPU 0 Usagegpu_usage0The usage, as a percentage, of GPU #0 for an application.DoubleWindows only4.27%
GPU 1 Usagegpu_usage1The usage, as a percentage, of GPU #1 for an application.DoubleWindows only0.04%
GPU 2 Usagegpu_usage2The usage, as a percentage, of GPU #2 for an application.DoubleWindows only24.27%
Memory Usagememory_usage_percentageThe memory usage, as a percentage, of an application.DoublemacOS and Windows6.24%
Package NamenameThe friendly name of an application.StringmacOS and WindowsWindows PowerShell
Private Memoryprivate_commit_byteTotal memory reserved by a process (RAM + pagefile), not shared with others. Leaks show up as a steady increase in committed memory that never stabilizes, since allocations aren’t freed.LongWindows only2.29 MB
Process Countprocess_countThe process number that the application has consumed.IntegermacOS and Windows5
Processor Usageprocessor_usage_percentageThe processor usage, as a percentage, of an application.DoublemacOS and Windows25.41%
UseruserThe identified user of the session.StringmacOS and WindowsAdministrator
{.filterTable}

Apps

The Apps table lists data concerning characteristics and metadata for the apps in your Experience Management deployment.

  • Event category: Application
  • Entity: apps
    • Application Start - Identifies when an application begins process whether it is a service, a user, or UI process.
    • Application Exit - Identifies that an app has stopped running as expected because it was closed.
    • Application Foreground - Identifies that an app is displaying in the UI when the UI is in the foreground, or is the main focus of the user session.
    • Application Crash - Identifies that an app has stopped running, unexpectedly.
    • Application Hang - Identifies that an app is stuck in a process.
    • Application Unresponsive - Identifies that an app is not responding to user or resource inputs.
    • Application Change - Tracks the app as it is installed, removed, reconfigured, when an update is installed, and when an update is uninstalled.
    • Boot Degradation - Identifies that an application has reduced performance because of a restart. For example, the app took a long time to load during a system boot.
    • Shutdown Degradation- Identifies that an app has reduced performance while the system was shutting down.
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypeApplication StartApplication ExitApplication ForegroundApplication CrashApplication HangApplication UnresponsiveApplication ChangeBoot DegradationShutdown DegradationExamples
Activation Timeactivation_timeThe activation time for application focus.Date-TimeNANAmacOS and WindowsNANANANANANA2/13/2025 11:46:00 AM
Activity IDactivity_idThe activity id for a Windows event log.StringNANANANANANANAWindows onlyWindows onlyaaafff8b-ae3b-0001-6308-b1aa3baedb01
App Volumes Package IDav_package_idLists the ID of an App Volumes package.UUIDWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyNAWindows onlyWindows only08870c17-bca9-4558-9a4f-311f60e83439
Application End Timeend_timeThe time when the application stops.Date-TimeNAmacOS and WindowsNANANANANANANA2/13/2025 11:46:00 AM
Application Install Pathapp_pathThe installation path of the application.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS onlyWindows onlyWindows onlyC:\Windows\System32
Application NameapplicationNormalized app name or file description in Intelligence.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS onlyWindows onlyWindows onlyMicrosoft Windows Search Protocol Host
Create Timecreate_timeTime when the app was created.Date-TimemacOS and WindowsmacOS and WindowsmacOS and WindowsNANANANANANAFeb 14, 2025 11:15 AM
Degradation in Millisecondsload_degradation_time_millisReports the decrease of an app's performance.LongNANANANANANANAWindows onlyWindows only6744
DomaindomainIdentifies the domain of the session's user.StringWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyNANANADESKTOP-VAOF5MN
Duration in Millisecondsduration_millisThis field provides the total time an application was in the foreground in an application Foreground Event or an application remained unresponsive in an application Unresponsive Event. Use the Sum operator to know the total time of application usage.LongNANAmacOS and WindowsNAmacOS and WindowsmacOS and WindowsWindows onlyWindows onlyWindows only13.6 s
Event Statusevent_statusIdentifies the status of the application.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsWindows onlyWindows only"complete"
Exception Codeexception_codeException code in an application crash event.StringNANANAWindows onlyNANANANANA00000057
Exception Offsetexception_offsetThe offset of the crash module in the application. This field is applicable to Application Crash events.StringNANANAWindows onlyNANANANANA00000000000c837a
From App Volumesis_loaded_from_avIdentifies whether an application was delivered by App Volumes or not.BooleanWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyNAWindows onlyWindows onlyFALSE
GUIDguidLists the globally unique identifier for the app.StringNANANANANANAWindows onlyNANA7642522831597947940

12269795336078027775
MSI Pathmsi_pathThe file location of a MSI file.StringNANANANANANAWindows onlyNANAC:\ProgramData\AirWatchMDM\Apps\{5A821A77-BA32-4724-8BAB-2A83D3719FD4}\GlobalProtect64-6.1.4.msi
MethodmethodDetailed install action, for example Installation, Uninstall, or Reconfig.StringNANANANANANAmacOS and WindowsNANAReconfig
ModulemoduleThe module name within an application.StringNANANAmacOS and WindowsNANANANANAlibcoreclr.dylib
Module Pathmodule_pathThe module installation path.StringNANANAmacOS and WindowsNANANANANA/Library/Application Support/Workflow/libcoreclr.dylib
Module Timestampmodule_timestampThe time when the module was last modified.Date-TimeNANANAWindows onlyNANANANANAJan 28, 2025 1:09 PM
Module Versionmodule_versionThe module version.
This version can be different than the application version.
StringNANANAWindows onlyNANANANANA1307.2407.15032.0
Object Typeobject_typeThe type of the application. Values can be Application, Driver, and Service.StringNANANANANANANAWindows onlyNAApplication
Package Full NamepfnLists the application package family name.StringWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyNANANAMicrosoft.WindowsCalculator_8wekyb3d8bbwe
Package LanguagelocalityLists the application language identifier. For example, English is 0x409 (dec.1033).StringWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyNANANA1033
Package NamenameThe friendly name of the application.StringWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyWindows onlyConsole Window Host
Package PublisherpublisherThe application publisher name.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOs onlyWindows onlyWindows onlyMicrosoft Corporation
Package VersionversionThe application version.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOs onlyWindows onlyWindows only7.0.22621.4746
Process Identifierprocess_idIdentifies a unique ID for a running application.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsNANAmacOS and WindowsNANANA7456
Return Codereturn_codeThe application's exit code, and it indicates the application's exit status or reason.IntegerNAWindows onlyNANANANANANANA1168
SessionsessionLists the Windows session ID.StringWindows onlyWindows onlyWindows onlyNANAWindows onlyNANANA2
Timestampapp_timestampIndicates when the app waslast modified.Date-TimeNANANAWindows onlyNANANANANA(Timestamp) seconds (INT64) = 3013880354 nanos (INT32) = 0
Trigger Timetrigger_timeThe time when an event triggered.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsWindows onlyWindows only(Timestamp) seconds (INT64) = 1645402934 nanos (INT32) = 340502704
Transaction Identifiertransaction_idLists the unique ID assigned to a system transaction.StringNANANANANANAWindows onlyNANA17360517195459799390
Unresponsive Timeunresponsive_timeThe time when an app began to be unresponsive.Date-TimeNANANANANAWindows onlyNANANA(Timestamp) seconds (INT64) = 1699985579 nanos (INT32) = 797934221
Up Time in Millisecondsup_time_millisThe time the application is active, from when it starts to stops.LongNAmacOS and WindowsNANANANANANANA92 ms
UseruserIdentifies the user of the session.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsNANANATestUser
{.filterTable}

Asset information

The asset information table lists data concerning physical resources in your Experience Management deployment.

  • Event Category: Asset Info
  • Entity: asset_info - Identifies the device asset information, for example, CPU, physical disk, or BIOS.
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypeasset_infoExamples
BIOS Timestampbios_timestampIndicates that the asset's BIOS updated data at a specific timestamp.Date-TimeWindows onlyMay 21, 2023 3:00 PM
BIOS Versionbios_versionIndicates the version of the asset's BIOS.StringmacOS and Windows6.00
Logical Disk Free Space In Megabyteslogicaldisk_free_space_mbytesIndicates the Logical disk free space of the asset.DoublemacOS and Windows12877.000000
Logical Disk Free Space (%)logicaldisk_free_space_percentageIndicates the Logical disk free space of the asset as a percentage.DoublemacOS and Windows21.353724
Time Zonetime_zoneIndicates the time zone the asset is set to.StringmacOS and WindowsIndia Standard Time
{.filterTable}

Battery information

The battery information table lists data concerning device batteries in your Experience Management deployment.

  • Event category: Battery
  • Entity: battery_info - Reports the battery information, for example, charge cycle count, serial number, Initial and actual capacity of the battery in milliwatt-hour (mWh).
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypebattery_infoExamples
Actual Battery Capacityactual_charge_capacityActual current capacity of the battery, in milliwatt-hours (mWh).LongWindows only48600
Actual Battery Capacity Percentageactual_charge_capacity_percentActual current capacity of the battery, in percentages (%).DoubleWindows only87.93598443505908
Battery Cycle Countcharge_cycle_countCount of battery fully charged and discharged.LongWindows only110
Battery Manufacture Datemanufacture_dateManufacture date of the battery.Date-TimeWindows onlyFeb 1, 2020
(YEAR, MONTH, DAY)
Battery Manufacturer Namemanufacture_nameManufacturer name of the battery.StringWindows onlySMP
Battery Serial Numberserial_numberSerial number of the battery.StringWindows only7722
Designed Battery Capacitydesign_capacityInitial capacity of the battery in milliwatt-hour (mWh)LongWindows only84292
Is Battery Presentis_presentIdentifies if the battery is present or not.BooleanWindows only1
Is External Batteryis_external_batteryIdentifies if the battery is external or not.BooleanWindows only0
Last Removal Timelast_removal_timeThe removal time of a battery that is no longer present in the system.Date-TimeWindows only27-02-24 20:31
{.filterTable}

Device hardware

The device hardware table lists types, versions, manufacturers, identifying numbers, and other metadata for the hardware components in your Experience Management deployment.

  • Event category: Device Hardware
  • Entity: device_hardware - Identifies metrics concerning a device’s hardware, for example the driver version and the manufacturer.
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypedevice_hardwareExamples
Bus Typebus_typeType of bus.StringmacOS and WindowsUSB
PCI
Device Has Problemhas_problemIdentifies that the device has problem.BooleanWindows only0
Driver Published Datedriver_published_dateBuild date of the driver.Date-TimeWindows only(Timestamp) seconds (INT64) = 1698883200 nanos (INT32) = 0
Driver Versiondriver_versionVersion of the driver.StringWindows only10.0.22621.3672
Hardware Device IDhardware_idAn identifier that uniquely identifies a device.StringmacOS and Windows10868025185241700000
Hardware Device Manufacturerhardware_manufacturerManufacturer of the device.StringmacOS and WindowsRealtek
Hardware Device Namehardware_nameName of the device.StringmacOS and WindowsRealtek USB GbE Family Controller
Hardware Device Typehardware_typeType of device.StringmacOs and WindowsCamera
Is Presentis_presentIdentifies if the device is present or not.BooleanmacOS and Windows0
Last Removal Timelast_removal_timeThe removal time of a device that is no longer present in the system.Date-TimemacOS and Windows(Timestamp) seconds (INT64) = 1702294317 nanos (INT32) = 0
Platform Device IDplatform_device_idUnique device identifier for Windows.StringWindows onlyPCI\VEN_8086&DEV_A353&SUBSYS_09061028&REV_10\3&11583659&0&B8
Problem Codeproblem_codeCode of an identified problem on a Windows device.

This attribute is only applicable when a Windows device has a problem.
IntegerWindows only0
Problem Descriptionproblem_descriptionThe description of the problem.StringWindows only
{.filterTable}

Device performance

The device performance table lists available data concerning how well and efficiently devices are running in your Experience Management deployment.

  • Event category: NA
  • Entity: NA
    • Performance Counters - Identifies performance metrics for a device, for example the dedicated memory capacity or the battery status charge rate.
    • Power Consumption - Identifies performance metrics for a device’s power consumption, for example the display power consumption or the network power consumption.
  • Minimum agent version: 24.12
Friendly NameDefinitionPerformance CountersPower ConsumptionExamplesUnits
Average Total Power ConsumptionAverage total power in the duration time period.

avg_total_power = total_energy (converted to unit in Wh) / duration time (converted to unit in hour)
Windows onlyWindows only45.05Watts
Battery Status Charge RateThe rate at which the battery is charging.macOS and WindowsmacOS and Windows0Milliwatts
Battery Status Discharge RateThe rate at which the battery is discharging.macOS and WindowsmacOS and Windows0.Milliwatts
Battery Status Remaining CapacityThe amount of remaining battery capacity.macOS and WindowsmacOS and Windows75764Milliwatt-hours
CPU Power ConsumptionThe sum of the power consumed (in milliwatt-hours) by the CPU.

Transmitted based on the device performance transmit frequency for power data of 1 hour.

Use in dashboards to aggregate power consumed over any admin defined time range.
Windows onlyWindows only15470.04 mWhMilliwatt-hours
Disk Power ConsumptionThe sum of the power consumed (in milliwatt-hours) by the physical disk.

Transmitted based on the device performance transmit frequency for power data of 1 hour.

Use in dashboards to aggregate power consumed over any admin defined time range.
Windows onlyWindows only37.04 mWhMilliwatt-hours
Display Power ConsumptionThe sum of the power consumed (in milliwatt-hours) by the integrated display.

Transmitted based on the device performance transmit frequency for power data of 1 hour.

Use in dashboards to aggregate power consumed over any admin defined time range.
Windows onlyWindows only1707.04 mWhMilliwatt-hours
Display Power ConsumptionThe sum of the power consumed (in milliwatt-hours) by the integrated display.

Transmitted based on the device performance transmit frequency for power data of 1 hour.

Use in dashboards to aggregate power consumed over any admin defined time range.
Windows onlyWindows only1707.04 mWhMilliwatt-hours
Energy Consumption DurationThe period of time during which the energy consumption occurred (reported in milli seconds).macOS and WindowsmacOS and Windows1 minms/s/min
GPU 0 Dedicated Memory CapacityThe maximum RAM allocated for the graphics processing unit (GPU) #0.Windows onlyWindows only128 MBBytes
GPU 0 Dedicated Memory UsageThe maximum RAM that GPU #0 can use.Windows onlyWindows only0 bytesBytes
GPU 0 ManufacturerThe name of the company that manufactured GPU #0.Windows onlyWindows onlyIntel CorporationNA
GPU 0 NameThe name of GPU #0.macOS and WindowsmacOS and WindowsIntel(R) UHD Graphics 630NA
GPU 0 Shared Memory UsageThe shared RAM used by GPU #0.Windows onlyWindows only6494 MBBytes
GPU 0 UsageThe usage as a percentage of GPU #0.macOS and WindowsmacOS and Windows0.12%Percentage
GPU 1 Dedicated Memory CapacityThe maximum RAM allocated for GPU #1.Windows onlyWindows only3.87 GBBytes
GPU 1 Dedicated Memory UsageThe maximum RAM that GPU #1 can use.Windows onlyWindows only0 bytesBytes
GPU 1 ManufacturerThe name of the company that manufactured GPU #1.Windows onlyWindows onlyIntel CorporationNA
GPU 1 NameThe name of GPU #1.macOS and WindowsmacOS and WindowsNVIDIA Quadro T1000NA
GPU 1 Shared Memory UsageThe shared RAM used by GPU #1.Windows onlyWindows only256 KBBytes
GPU 1 UsageThe usage as a percentage of GPU #1.macOS and WindowsmacOS and Windows0%Percentage
GPU 2 Dedicated Memory CapacityThe maximum RAM allocated for GPU #2.Windows onlyWindows only3.87 GBBytes
GPU 2 Dedicated Memory UsageThe maximum RAM that GPU #2 can use.Windows onlyWindows only0 bytesBytes
GPU 2 ManufacturerThe name of the company that manufactured GPU #2.Windows onlyWindows onlyIntel CorporationNA
GPU 2 NameThe name of GPU #2.macOS and WindowsmacOS and WindowsIntel(R) UHD Graphics 630NA
GPU 2 Shared Memory UsageThe shared RAM used by GPU #2.Windows onlyWindows only256 KBBytes
GPU 2 UsageThe usage as a percentage of GPU #2.macOS and WindowsmacOS and Windows0%Percentage
GPU Shared Memory CapacityThe maximum RAM allocated for GPUs to share with other components.Windows onlyWindows only15.84GBBytes
Logicaldisk Free Space (Megabytes)The hard disk free space in megabytes.macOS and WindowsmacOS and Windows11421MB
Memory Cache Faults per secThe memory cache faults per seconds. Cache Faults is a type of Page Fault.Windows onlyWindows only68.287961Cache faults/sec
Memory Committed Bytes in useThe ratio of Memory\\Committed Bytes to the Memory\\Commit Limit.macOS and WindowsmacOS and Windows26.38%Percentage
Memory Page Faults per secThe total page faults including soft and hard.

Average number of pages faulted per second.
Windows onlyWindows only9651.298229Page faults/sec
Memory Page Reads per secThe rate at which the disk was read to resolve hard page faults.Windows onlyWindows only435.24747Page reads/sec
Memory Page Writes per secThe rate at which page data is written to the disk.Windows onlyWindows only0.02Page reads/sec
Memory Pages per secThe rate at which pages are read or written to the disk to resolve hard faults.Windows onlyWindows only23.54Number of pages per second
Memory Transition Faults per secThis field provides the rate at which page faults are resolved by recovering the pages shared by other processes.Windows onlyWindows only1570.952333Transition faults/sec
Memory Usage PercentageThe overall memory usage as a percentage of the device.macOS and WindowsmacOS and Windows34.0944%Percentage
Network Interface Packets Outbound ErrorsThe number of outbound packets that did not transmit because of errors.macOS and WindowsmacOS and Windows0NA
Network Interface Packets Received ErrorsThe number of inbound packets that contained errors.macOS and WindowsmacOS and Windows7NA
Network Power ConsumptionThe sum of the power consumed (in milliwatt-hours) by the network adapters.

Transmitted based on the device performance transmit frequency for power data of 1 hour.

Use in dashboards to aggregate power consumed over any admin defined time range.
Windows onlyWindows only490.04 mWhMilliwatt-hours
Paging File UsageThe percentage value of page file usages.macOS and WindowsmacOS and Windows6.1822%Percentage
Physical Disk Avg Disk Bytes Queue LengthThe average number of IO requests in the queue waiting to be sent to the storage system.Windows onlyWindows only903 bytesBytes
Physical Disk Avg Disk Bytes ReadThe average number of bytes transferred to the disk during read operations.macOS and WindowsmacOS and Windows146.84 KBKB
Physical Disk Avg Disk Bytes TransferAverage number of bytes transferred to the disk during read/write operations.Windows onlyWindows only74.93 KBKB
Physical Disk Avg Disk Bytes WriteThe average number of bytes transferred to the disk during write operations.Windows onlyWindows only67.42 KBKB
Physical Disk Avg Disk Read per secThe rate at which bytes are read to the disk during read operations.macOS and WindowsmacOS and Windows0.000494Second
Physical Disk Avg Disk Read Queue LengthThe average number of read IO requests in the queue waiting to be sent to the storage system.Windows onlyWindows only9.09Average number of read requests in the queue
Physical Disk Avg Disk Read TimeIt is a performance metric that measures the average time, in milliseconds, that it takes to read data from a physical disk.

This metric provides insight into the responsiveness of the disk when performing read operations.
Windows onlyWindows only0.03Percentage
Physical Disk Avg Disk Transfer per secThe rate at which of bytes transferred to the disk during IO operations.Windows onlyWindows only0.00049Second
Physical Disk Avg Disk Write per secThe rate at which bytes are written to the disk during write operations.macOS and WindowsmacOS and Windows0.000494Second
Physical Disk Avg Disk Write Queue LengthThe average number of write IO requests in the queue waiting to be sent to the storage system.Windows onlyWindows only2.91Average number of write requests in the queue
Physical Disk Avg Disk Write TimeIt is a performance metric that measures the average time, in milliseconds, that it takes to write data to a physical disk.

This metric is crucial for understanding the responsiveness and efficiency of the disk when handling write operations.
Windows onlyWindows only0.04Percentage
Physical Disk Idle TimeIt is a performance metric that measures the percentage of time during which the physical disk is not processing any read or write requests.

It essentially indicates how much of the time the disk is idle, meaning it is not being used actively by any applications or processes.
macOS and WindowsmacOS and Windows99.72Percentage
Physical Memory in BytesThe physical memory of the device.macOS and WindowsmacOS and Windows16.00 GBGB
Processor Total C1 TimeRefers to the time a CPU core spends in the C1 state, which is one of the "C-states" or "power states" in modern processors C1 (Halt).

The first idle state where the CPU is still active but not executing instructions.

It can quickly return to C0 (active state - The CPU is fully operational, executing instructions).

It's the lightest sleep state with minimal power saving.
Windows onlyWindows only6.87%Percentage
Processor Total C2 TimeRefers to the time a CPU core spends in the C2 state.

C2 - Stop-Clock: A deeper idle state than C1, which reduces power consumption further, but takes a bit longer to return to C0 (active state - The CPU is fully operational, executing instructions).

In scenarios where power saving is critical, higher total times in C2 or C3 might be desired, as they indicate the processor is spending more time in low-power states.
Windows onlyWindows only4.99%Percentage
Processor Total C3 TimeRefers to the time a CPU core spends in the C3 state.

C3 - Sleep: A deeper sleep state where more of the CPU's functions are powered down.

This state saves more power but takes even longer to wake up and return to C0 (active state - The CPU is fully operational, executing instructions).
Windows onlyWindows only61.57%Percentage
Processor Total DPC TimeThis is the cumulative amount of time the CPU spends in an idle state.

Monitoring idle time is important for understanding system utilization.

A high idle time generally indicates that the CPU is not heavily loaded and has sufficient capacity to handle more tasks.
Windows onlyWindows only0.08%Percentage
Processor Total Idle TimeThis is the cumulative amount of time the CPU spends in an idle state.

Monitoring idle time is important for understanding system utilization.

A high idle time generally indicates that the CPU is not heavily loaded and has sufficient capacity to handle more tasks.
macOS and WindowsmacOS and Windows73.41%Percentage
Processor Total Interrupt TimeThe percentage time the processor spends in receiving and servicing hardware interruptions during sample intervals.

A high percentage of interruptions can indicate a problem with a hardware device.
Windows onlyWindows only0.21%Percentage
Processor Total Interrupts per secThe total interruptions per second.Windows onlyWindows only6712.42NA
Processor Total Privileged TimeThe percentage of time that the processor is spent executing in Kernel (or Privileged) mode.macOS and WindowsmacOS and Windows5.4%Percentage
Processor Total Processor TimeThe percentage of elapsed time that the processor spends executing non-idle threads.macOS and WindowsmacOS and Windows10.58%Percentage
Processor Total User TimeThe percentage of time that the processor spends executing in User mode.macOS and WindowsmacOS and Windows3.45%Percentage
System On Chip Power ConsumptionThe sum of the power consumed (in milliwatt-hours) by the integrated circuit.

Transmitted based on the device performance transmit frequency for power data of 1 hour.

Use in dashboards to aggregate power consumed over any admin defined time range.
Windows onlyWindows only0Milliwatt-hours
Thermal Zone Information Throttle ReasonThe reasons why the thermal zone is limiting.Windows onlyWindows only0NA
Thermal Zone Information Zone TemperatureThe CPU core temperature.macOS and WindowsmacOS and Windows24.85Celsius
Total Power ConsumptionThe sum of the power consumed (in milliwatt-hours) by all hardware components.

Transmitted based on the device performance transmit frequency for power data of 1 hour.

Use in dashboards to aggregate power consumed over any admin defined time range.
Windows onlyWindows only58391.17 mWhMilliwatt-hours
{.filterTable}

Devices

The devices table lists data concerning systems, components, and metadata for the devices in your Experience Management deployment.

  • Event category: Device
  • Entity: devices
    • Boot - Identifies metrics concerning a device’s boot functions, for example boot end time or boot drive load time.
    • Shutdown - Identifies metrics for a device’s shutdown functions like duration time or preshutdown time.
    • System Crash - Identifies metrics concerning a device system’s unexpected and complete stoppage, for example an error code or a crash path.
    • Unexpected Shutdown - Identifies metrics concerning a device’s unexpected shutdown, for example performance degradation or kernel load in time.
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypeBootShutdownSystem CrashUnexpected ShutdownExamples
Activity IDactivity_idThe unique ID for a windows event log.

You can use this to correlate Boot and Shutdown events with Employee Experience > Apps where the event name = Boot Degradation events.
StringWindows onlyWindows onlyNANAaaafff8b-ae3b-0001-6308-b1aa3baedb01
Autochk Duration in Millisecondsautochk_millisThe process involves the autochk.exe utility running at startup to check the logical integrity of NTFS file systems, typically on volumes flagged as "dirty" after an improper shutdown.LongWindows onlyNANANA
Boot Device Duration in Millisecondsdevice_init_millisThe boot device, such as a hard drive or USB, contains the bootloader which in turn loads the operating system's kernel (ntoskrnl.exe), essential drivers, and the Windows kernel (ntoskrnl.exe) into RAM. This initializes the system and prepares it for user login.LongWindows onlyNANANA
Boot Driver Load Duration in Millisecondsboot_driverload_duration_millisLoads the Windows kernel (ntoskrnl.exe) and essential drivers into memory. This kernal and drivers are necessary to start the operating system and interact with hardware.

These drivers, known as boot-start drivers, are automatically installed by Windows during the initial setup to ensure fundamental hardware functionality.
LongWindows onlyNANANA298
Boot End Timeboot_end_timeBoot end time.File Date-TimeWindows onlyNANANAJan 26, 2025 10:18 PM
Boot PNP Duration in Millisecondspnp_init_millisThe process is the phase of the Windows startup sequence where the PnP manager, a key component of the operating system, identifies and configures hardware devices by loading their drivers and allocating system resources like memory and interrupts.LongWindows onlyNANANA
Boot Prefetch Service Durationboot_prefetchinit_duration_millisOfficially known as SuperFetch (now part of SysMain in modern Windows versions), this property improves the Windows boot process by pre-loading frequently used application files and data into RAM during startup to make subsequent boots and application launches faster.LongWindows onlyNANANA85
Crash Addresscrash_addressMemory address of the system crash.StringNANAWindows onlyNA0xfffff80377614f10
Crash Parameters ListparametersBugCheck description of parameters.File Date-TimeNANAWindows onlyWindows only0x00000000c0000005,0xfffff8037b9c5050,0xffffdd8369b2daa0,0x0000000000000000
Crash Pathcrash_pathWindows dump file location.StringNANAmacOS and WindowsNAC:\Windows\Minidump\012725-20890-01.dmp
Crashdump Typecrashdump_typeWindows crash dump type.StringNANANAWindows only7
Critical Services Initialization Duration in Millisecondscritical_services_init_millisA key phase of the Windows boot process where the operating system loads and starts essential system services and drivers.LongWindows onlyNANANA
Duration in Millisecondsduration_millisBoot and Shutdown duration.LongWindows onlyWindows onlyNANA43783
End Timeend_timeThe time boot ends.File Date-TimemacOS and WindowsmacOS and WindowsNANA(Timestamp) seconds (INT64) = 1710936457 nanos (INT32) = 572000000
ErrorerrorThe BugCheck code.StringNANAWindows onlyWindows only0x000000d1
Event Statusevent_statusIdentifies the status of a process.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsComplete
Exception Codeerror_codeA string that represents an error.StringNANAWindows onlyNA0x80000003
Explorer Initialization Duration in Millisecondsexplorer_init_millisThe stage of the Windows boot sequence after user login but before the desktop is fully responsive.LongWindows onlyNANANA
Kernel Initialization Duration in Millisecondskernel_init_millisThe process involves the OS loader loading the core Windows kernel (ntoskrnl.exe) into memory, followed by the initialization of the Hardware Abstraction Layer (HAL) and essential "boot critical" device drivers.LongWindows onlyNANANA2.803
Kernel Load Duration in Millisecondskernel_millisPart of the Shutdown event.LongNAWindows onlyNANA1126
Machine Profile Processing Duration in Millisecondsmachine_profile_processing_millisRefers to the operating system initializing and loading user-specific settings and profiles after the core system has started and the user has logged in.LongWindows onlyNANANA
Main Path Load Duration in Millisecondsmain_pathload_duration_millisThe main path for the Windows boot process depends on the system's firmware; either the traditional BIOS or the newer UEFI. Both paths involve firmware initializing hardware, a boot manager, and a bootloader that loads the Windows kernel and essential drivers.LongWindows onlyNANANA10483
ModulemoduleCrashed module in a system crash event.StringNANAWindows onlyNAwin32kbase
Numbers of Startup Appsnum_startup_appsThe number of startup programs for each computer and user, depending on the installed software and user preferences.

You can view and manage these apps through the Task Manager's Startup tab or the Settings app under Apps > Startup to control which applications launch automatically when you sign in. This property impacts boot time and system performance. 
LongWindows onlyNANANA12
OS Loader Duration in Millisecondsos_loader_millisAlso called the Boot Manager (bootmgr.exe), it is a critical part of the Windows boot process that takes over after the UEFI/BIOS performs its Power-On Self-Test (POST) and firmware checks.LongWindows onlyNANANA
Other Kernel Initialization Duration in Millisecondsother_kernel_init_millisThe process involves the operating system kernel (ntoskrnl.exe) taking full control after the bootloader loads it into memory, establishing the essential hardware abstraction layer (HAL) for hardware communication, loading the Windows Registry and essential drivers, setting up core services like the system pagefile, and then launching the first user-mode processes, such as the Session Manager (smss.exe). This process prepares the system for user interaction.LongWindows onlyNANANA
Other Logon Initial Activity Duration in Millisecondsother_logon_init_activity_millisPart of Logon and is a Windows boot performance metric that measures the total time spent on logon-related tasks not covered by other specific metrics, such as profile or Group Policy loading.

The property accounts for a collection of background processes and scripts that run during a user's sign-in to the desktop.
LongWindows onlyNANANA
Performance Degradationperf_degradationIndicates that boot or shutdown was degraded.BooleanWindows onlyWindows onlyNANATRUE
Post Boot Duration in Millisecondspost_boot_millisThe POST (Power-On Self-Test) is a hardware diagnostic routine that runs immediately after a computer is powered on, before the Windows operating system loads. It verifies the functionality of crucial hardware components like the CPU, RAM, hard drive, and other peripherals.

If POST detects a hardware error, it typically halts the boot process and may signal the problem with a specific beep pattern or error message.
LongWindows onlyNANANA
Preshutdown Duration in Millisecondspreshutdown_millisA timeout period during the Windows shutdown process that gives critical services an initial opportunity to stop gracefully.

By default, this period is 3 minutes (180 seconds), but services can request an extension or developers can adjust it to a maximum of 3600 seconds.
LongNAWindows onlyNANA572
ProcessprocessCrashed process in a system crash.IntegerNANAmacOS and WindowsNAntkrnlmp.exe
ReasonreasonThe reason for unexpected shutdown, for example ColdReboot or SystemCrash.StringNANANAmacOS and WindowsSystemCrash
Reboot After Installreboot_after_installThe reboot after install flag in a Windows boot event indicates that the system has restarted to complete the installation of an application, a driver, or a Windows update.BooleanWindows onlyNANANAFalse
ResultresultThe result of a process.StringmacOS and WindowsmacOS and WindowsNANASuccess
SMSS Initialization Duration in Millisecondssmss_init_millisThe crucial first step where Windows' smss.exe starts after the kernel loads, creating and managing user and system sessions.LongWindows onlyNANANA
Services Duration in Millisecondsservices_millisInvolves the Service Control Manager (SCM) sending a shutdown signal to all running services, which have a default time limit to respond and shut down gracefully.LongNAWindows onlyNANA85
Session 0 Initialization Duration in Millisecondssession0_init_millisA critical stage in the Windows boot process where the foundational, non-interactive system services are started before any user logs on.LongWindows onlyNANANA
Session 1 Initialization Duration in Millisecondssession1_init_millisIt is a phrase often seen in a "SESSION1_INITIALIZATION_FAILED" BSOD (Blue Screen of Death) error message<0xC2><0xA0> that indicates a critical error preventing Windows from starting.LongWindows onlyNANANA
Session Initialization Other Duration in Millisecondssession_init_other_millisPart of the Boot Event.LongWindows onlyNANANA
Stack Tracestack_traceList of the method calls that the resource was in the middle of when an Exception was thrown.StringNANAmacOS and WindowsNAnt!KeBugCheckEx+0x0(0xfffff802033fd890),(0xfffff80203411e29),(0xfffff8020340d8a3),(0xfffff8021bcf1981),(0xfffff8021bcf1d3d),(0xfffff8021bcf1ea1),(0xfffff80203235cf5),(0xfffff8020364599c),(0xfffff802036455f3),(0xfffff802036448c6)'
System PNP Duration in Millisecondspnp_load_duration_millisA critical part of Windows startup where the PnP manager identifies and configures hardware devices by loading the correct device drivers.LongWindows onlyNANANA263
System Session Duration in Millisecondssystem_session_millisA coordinated series of steps that ends this session and powers down the computer.

The duration of this process can vary based on several factors, with the most significant one being the "Fast Startup" feature
LongNAWindows onlyNANA10483
Time Change in Millisecondstimechange_millisThe shutdown time change.LongNAWindows onlyNANA448
Total Boot Duration in Millisecondstotal_boot_millisThe total time it takes for a computer to go from being powered off to being fully functional and ready for user interaction. In this case, from the power button press until the Windows logon screen.LongWindows onlyNANANA
Trigger Timetrigger_timeReports the boot start time.File Date-TimemacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and Windows(Timestamp) seconds (INT64) = 1645402934 nanos (INT32) = 340502704
User Logon Wait Duration in Millisecondsuser_logon_wait_millisRefers to the time it takes for a user's profile and desktop environment to fully load and become responsive after the user enters their credentials.

This duration is influenced by factors like startup applications, disk activity, and Group Policy processing.
LongWindows onlyNANANA
User Policy Duration in Millisecondsuser_policy_millisRefers to the maximum amount of time the system will wait for Group Policy scripts to finish executing before forcing a shutdown.LongNAWindows onlyNANA298
User Profiles Duration in Millisecondsuser_profiles_millisThe time it takes to properly unload a user's session and all related processes.

While there is no single "duration," a normal shutdown involving user profiles should be very fast.

Delays indicate a problem with a specific application or process that is preventing the session from closing.
LongNAWindows onlyNANA10483
User Profile Processing Duration in Millisecondsuser_profile_processing_millisLoads the settings, preferences, and data for a specific user after they have entered their credentials.

This critical phase is managed by the User Profile Service (ProfSvc), and delays or errors during this process can prevent a user from signing in.
LongWindows onlyNANANA
User Session Duration in Millisecondsuser_session_millisRefers to the time it takes to properly close all user-related applications and services before the system shuts down.

During this period, Windows sends specific messages to processes to trigger an orderly exit, allowing applications to save data and terminate gracefully. 
LongNAWindows onlyNANA298
VersionversionOS version.StringNANAmacOS and WindowsNA10.0.19041
{.filterTable}

Display

The display table lists data concerning the resource screens showing electronic media in your Experience Management deployment.

  • Event category: Display
  • Entity: display
    • Screen Saver Off - Identifies that a resource stopped using or does not use a screen saver.
    • Screen Saver On - Identifies that a resource used a screen saver.
    • Sleep - Identifies metrics concerning a resource in the sleep state.
    • Wake - Identifies metrics concerning a resource in the wake state.
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypeScreen Saver OffScreen Saver OnSleepWakeExamples
DomaindomainDomain of the display.StringWindows onlyWindows onlyNANADTEST-WIN10-1
Duration in Millisecondsduration_millisWake or sleep duration.LongNANAWindows onlyWindows only641
Event Statusevent_statusFor an OS start trigger, the status is Request. For an OS start complete, the status is Complete.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsComplete
Trigger Timetrigger_timeIdentifies the boot start time.File Date-TimemacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and Windows(Timestamp) seconds (INT64) = 1645402934 nanos (INT32) = 340502704
UseruserThe user of the display.StringmacOS and WindowsmacOS and WindowsNANAAdministrator
{.filterTable}

Network

The network table lists data concerning components in the system that connects and facilitates communication between the devices and resources in your Experience Management deployment.

  • Event category: Network

  • Entity: net_event

    • net_event_l2_connected - Identifies that the resource is connected to the network.
    • net_event_l2_disconnected - Identifies that the resource is not connected to the network.
    • net_event_l2_reconfigured - Identifies that the network on the resource has been reconfigured.
    • net_event_l2_statistic - Identifies metrics pertaining to the network.
    • lan_gw_latency - Identifies that the network has a LAN latency issue.
    • wan_dns_latency - Identifies that the network has a WAN latency issue.
    • Public IP - Identifies location data such as address, city, country, region, longitude, latitude, and geolocation ID of a public IP. This event requires the device to have network access to the following domains: ts.awmdm.com, ts4.awmdm.com, and ts6.awmdm.com.
  • Minimum agent version: Use 25.09 to use the Public IP event and 24.12 for all other events.

Friendly NamePropertyDefinitionTypenet_event_l2_connectednet_event_l2_disconnectednet_event_l2_reconfigurednet_event_l2_statisticlan_gw_latencywan_dns_latencyPublic IPExamples
Dot11 Auth Typedot11_auth_typeLists the authentication type used to establish a connection.StringWindows onlyNAWindows onlyNANANANAWPA2 RSNA
Dot11 Available Modesdot11_available_modesLists modes supported by an adapter. What displays in this list depends on the adapter’s configuration settings.

Possible values are 802.11, +, and a/b/g/n/ac/ad/ax.
String ListWindows onlyNAWindows onlyNANANANA802.11b
802.11g
802.11n
802.11a
802.11ac
802.11ax
Dot11 BSS Available Modesdot11_bss_available_modesLists the available 802.11 modes on the access point that the adapter is connected to.String ListWindows onlyNAWindows onlyNANANANA802.11ax
Dot11 BSS IPv4addressdot11_bss_ipv4addressLists the IPv4 address of the access point that the adapter is connected to.StringWindows onlyNAWindows onlyNANANANA0.0.0.0
Dot11 BSS WiFi Generationdot11_bss_wifi_generationLists the latest WiFi generation supported by the access point that the adapter is connected to.StringWindows onlyNAWindows onlyNANANANAWi-Fi 6
Dot11 BSS WPS Enableddot11_bss_wps_enabledLists the WiFi protected setup (WPS) activated on an access point that the adapter is connected to.BooleanWindows onlyNAWindows onlyNANANANATRUE
Dot11 BSS WPS Modesdot11_bss_wps_modesLists the WiFi protected setup modes activated on the access point that the adapter is connected to.String ListWindows onlyNAWindows onlyNANANANAPrivacy
WPS
Push Button
Pin
Dot11 BSSIDdot11_bssidLists the MAC address of an access point.StringWindows onlyNAWindows onlyNANANANAa8:5b:f7:fc:6e:11
Dot11 Channeldot11_channelLists the WiFi channel used by a connection.IntegermacOS and WindowsNAmacOS and WindowsNANANANA64
Dot11 Encryptiondot11_encryptionLists the encryption algorithm used by this connection.

Possible values:
None
WEP-RC4-40
WEP-RC4-104
WEP-RC4-ANY
TKIP-RC4 WPA-USE-GROUP
CCMP-AES-128
CCMP-AES-256
BIP-CMAC-128
BIP-CMAC-256
BIP-GMAC-128
BIP-GMAC-256
GCMP-AES-128
GCMP-AES-256
IHV
StringWindows onlyNAWindows onlyNANANANACCMP-AES-128
Dot11 Frequencydot11_frequencyLists the values as 2.4 or 5 GHz.FloatmacOS and WindowsNAmacOS and WindowsNANANANA5.320000172
Dot11 Modedot11_modeLists the 802.11 mode.

Possible values are 802.11, +, and a/b/g/n/ac/ad/ax.
StringmacOS and WindowsNAmacOS and WindowsNANANANA802.11ax
Dot11 RSSIdot11_rssiLists the signal strength in decibels-milliwatts (dBm).IntegermacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsNANANA-39
Dot11 Security Standarddot11_security_standardIndicates the security standard used to establish a connection.

Possible values are:
Unknown
Open
WP
WPA Personal
WPA Enterprise
WPA2 Personal
WPA2 Enterprise
WPA3 Personal
WPA3 Enterpriser
IHV
StringmacOS and WindowsNAmacOS and WindowsNANANANAWPA2 Enterprise
Dot11 Signal Qualitydot11_signal_qualityIndicates the signal quality, as a percentage, provided by Microsoft Windows.IntegermacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsNANANA85
Dot11 SSIDdot11_ssidLists the wireless network name.StringmacOS and WindowsNAmacOS and WindowsmacOS and WindowsNANANAAcme
Dot11 WiFi Generationdot11_wifi_generationLists the latest WiFi generation supported by the adapter.

Possible values are Wifi-1..6 and 6E.
StringWindows onlyNAWindows onlyNANANANAWi-Fi 6
Event Friendly Nameevent_friendly_nameA human readable name of the event.StringNANANANANANAWindows onlyPublic IP
Geolocation IPv4 Addressgeolocation_ipv4_addressIdentifies an IPv4 address mapped to a location.StringNANANANANANAWindows only192.30.67.11
Geolocation IPv6 Addressgeolocation_ipv6_addressIdentifies an IPv6 address mapped to a locationStringNANANANANANAWindows only2600:1700:1dd0:1b90:80bf:fab:78e0:4029%0
IPv4 Addressesipv4_addressesLists the IPv4 addresses and subnet lengths.

For example, 10.20.30.40/22.
String ListmacOS and WindowsNAmacOS and WindowsNANANAWindows only10.4.137.89/21
IPv4 Cityipv4_cityIdentifies the city to which a public IP is mapped.StringNANANANANANAWindows onlyAtlanta
IPv4 Countryipv4_countryIdentifies the country to which a public IP is mapped.StringNANANANANANAWindows onlyUnited States (US)
IPv4 DHCP Enabledipv4_dhcp_enabledIndicates that IPv4 DHCP is activated for a connection.BooleanWindows onlyNAWindows onlyNANANANATRUE
IPv4 DHCP Serveripv4_dhcp_serverLists the IP address of the IPv4 DHCP server that issued the connection’s IP address.StringWindows onlyNAWindows onlyNANANANA192.168.133.254
IPv4 DNS Serversipv4_dns_serversLists the IPv4 DNS servers.String ListWindows onlyNAWindows onlyNANANANA10.117.0.1
10.111.0.1
10.112.16.131
IPv4 Enabledipv4_enabledIndicates that IPv4 is activated for a connection.BooleanmacOS and WindowsNAmacOS and WindowsNANANANATRUE
IPv4 Gatewaysipv4_gatewaysLists the IPv4 gateways.String ListWindows onlyNAWindows onlyNANANANA10.4.143.253
IPv4 Geolocation IDipv4_geolocation_idA value that represents the geographic data assigned to a public IP.StringNANANANANANAWindows only192.30.67.11
IPv4 LAN Average Latencyipv4_gw_avg_respIndicates the average latency for IPv4 gateway in milliseconds.DoubleNANANANAmacOS and WindowsNANA564.0000000
IPv4 LAN Gateway Addressipv4_gw_addrLists the IP address of the IPv4 gateway.StringNANANANAmacOS and WindowsNANA10.185.111.254
IPv4 LAN Packet Loss Rateipv4_gw_packet_loss_rateIndicates the percentage of packet loss rate for IPv4 gateway.DoubleNANANANAmacOS and WindowsNANA0.0000000
IPv4 Latitudeipv4_latitudeLists the latitudinal quardinates to which a public IP is mapped.StringNANANANANANAWindows only33.74
IPv4 Longitudeipv4_longitudeLists the longitudinal quardinates to which a public IP is mapped.StringNANANANANANAWindows only-84.38798
IPv4 Regionipv4_regionIdentifies the region to which a public IP is mapped.StringNANANANANANAWindows onlyGeorgia
IPv4 WAN Average Latencyipv4_wan_dns_avg_respIndicates the average latency for IPv4 WAN DNS in milliseconds.DoubleNANANANANAmacOS and WindowsNA814.000000
IPv4 WAN DNS Target Addressipv4_wan_dns_target_addrLists the IP address of the IPv4 WAN DNS address.StringNANANANANAmacOS and WindowsNA8.8.8.8
IPv4 WAN Packet Loss Rateipv4_wan_dns_packet_loss_rateIndicates the percentage of packet loss rate for IPv4 WAN DNS.DoubleNANANANANAmacOS and WindowsNA0
IPv6 Addressesipv6_addressesLists the IPv6 addresses and subnet lengths.String ListmacOS and WindowsNAmacOS and WindowsNANANAWindows onlyfe80::50:56ff:fe56:4453
IPv6 Cityipv6_cityIdentifies the city to which a public IP is mapped.StringNANANANANANAWindows onlyAtlanta
IPv6 Countryipv6_countryIdentifies the country to which a public IP is mapped.StringNANANANANANAWindows onlyUnited States (US)
IPv6 DNS Serversipv6_dns_serversList the IPv6 DNS servers.String ListWindows onlyNAWindows onlyNANANANAfec0:0:0:ffff::1%1
fec0:0:0:ffff::2%1
fec0:0:0:ffff::3%1
IPv6 Enabledipv6_enabledIndicates that IPv6 is activated for a connection.BooleanmacOS and WindowsNAmacOS and WindowsNANANANATRUE
IPv6 Gatewaysipv6_gatewaysLists the IPv6 gateways.String ListWindows onlyNAWindows onlyNANANANA
IPv6 Geolocation IDipv6_geolocation_idA value that represents the geographic data assigned to a public IP.StringNANANANANANAWindows only2600:1700:1dd0:1b90:80bf:fab:78e0:4029%0
IPv6 LAN Average Latencyipv6_gw_avg_respIndicates the average latency for IPv6 gateway in milliseconds.DoubleNANANANAmacOS and WindowsNANA814.00000000
IPv6 LAN Gateway Addressipv6_gw_addrLists the IP address of the IPv6 gateway.StringNANANANAmacOS and WindowsNANAfe80::50:56ff:fe56:4453
IPv6 LAN Packet Loss Rateipv6_gw_packet_loss_rateIndicates the percentage of packet loss rate for IPv6 gateway.DoubleNANANANAmacOS and WindowsNANA0.0000000
IPv6 Latitudeipv6_latitudeLists the latitudinal quardinates to which a public IP is mapped.StringNANANANANANAWindows only33.74
IPv6 Longitudeipv6_longitudeLists the longitudinal quardinates to which a public IP is mapped.StringNANANANANANAWindows only-84.38798
IPv6 Regionipv6_regionIdentifies the region to which a public IP is mapped.StringNANANANANANAWindows onlyGeorgia
IPv6 WAN Average Latencyipv6_wan_dns_avg_respIndicates the average latency for IPv6 WAN DNS in milliseconds.DoubleNANANANANAmacoS and WindowsNA29.000000
IPv6 WAN DNS Target Addressipv6_wan_dns_target_addrLists the IP address of the IPv6 WAN DNS address.StringNANANANANAmacOS and WindowsNAfe80::50:56ff:fe56:4453
IPv6 WAN Packet Loss Rateipv6_wan_dns_packet_loss_rateIndicates the percentage of packet loss rate for IPv6 WAN DNS.DoubleNANANANANAmacOS and WindowsNA0.0000000
L2 Avg Recv Bpsl2_rx_avg_bpsIndicates the average received bytes per second over a sample period.LongNANANAmacOS and WindowsNANANA4738.00
L2 Avg Tx Bpsl2_tx_avg_bpsIndicates the average transmitted bytes per second over sample period.LongNANANAmacOS and WindowsNANANA4785.00
L2 Connection Breadcrumbl2_connection_breadcrumbTo link events together, the system generates a unique connection GUID for each connection event as indicated by the event net_event_l2_connected.

The system uses the generated GUID in subsequent events (lan_gw_latency and wan_dns_latency,net_event_l2_disconnected, net_event_l2_reconfigured, and net_event_l2_statistics) that are associated with a connection.
StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsNAd6e7de41-49f2-4995-aeef-021290d1ad67
L2 Recv Bpsl2_rx_link_speed_bits_psLists the current received link speed in bits per second.LongNANANAmacOS and WindowsNANANA310000000.00
L2 Tx Bpsl2_tx_link_speed_bits_psLists the current transmitted link speed in bits per second.LongNANANAmacOS and WindowsNANANA542000000.00
NIC Descriptionnic_descriptionIdentifies the network interface card.

lan_gw_latency
net_event_l2_connected
net_event_l2_disconnected
net_event_l2_reconfigured
net_event_l2_statistics
wan_dns_latency
StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsNAIntel(R) 82574L Gigabit Network Connection
NIC Typenic_typeIndicates that the network is a wired Ethernet 802.1 or a wireless 802.1.

Possible values are Ethernet and Wireless.
StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsNAWireless
Physical Addressphysical_addressLists the MAC address.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsNA02:00:72:24:e4:b2
{.filterTable}

Network adapters

The network adapter table lists data concerning the cards in devices and resources that facilitate connection to the network and that allow communication with the network and the internet in your Experience Management deployment.

  • Event category: Network
  • Entity: device_network_adapter - Lists the device network adapter information, for example, NIC type and description, MAC address, or driver name.
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypedevice_network_adapterExamples
Driver Install Datedriver_install_dateIndicates the date a driver was installed or updated.Date-TimeWindows onlyFriday, October 4, 2024
Driver Namedriver_nameLists the installed driver name.StringWindows onlyIntel(R) Wireless-AC 9560 160MHz
Driver Problemdriver_problemA flag that indicates that the system found an issue with a driver.BooleanWindows onlyFALSE
Driver Problem Descriptiondriver_problem_descriptionLists the problem with a driver.StringWindows onlyA description of the driver problem.
Driver Providerdriver_providerLists the author of an installed driver.StringWindows onlyIntel
Driver Published Datedriver_published_dateIndicates the date a driver was published.

On Windows, this value is the DriverVer from the INF file.
Date-TimeWindows onlyTuesday, April 30, 2024
Driver Versiondriver_versionLists the installed driver version.StringWindows only23.60.1.2
NIC Descriptionnic_descriptionDescribes the unique adapter.StringmacOS and WindowsIntel(R) Wireless-AC 9560 160MHz
NIC Manufacturernic_manufacturerIndicates the manufacturer. An example is Intel.StringmacOS and WindowsIntel Corporation
NIC Modelnic_modelLists the model name of an adapter.StringmacOS and WindowsIntel(R) Wireless-AC 9560 160MHz
NIC Typenic_typeIndicates that the adapter is a wired Ethernet 802.1 or a wireless 802.11.

Possible values are Ethernet and Wireless.
StringmacOS and WindowsWireless
Physical Addressphysical_addressList the MAC address of an adapter.StringmacOS and Windows04:ed:33:79:3c:c2
{.filterTable}

OS Updates

The OS updates table lists data concerning the updates, which can include new features, security enhancements, and performance improvements, pushed to resource operating systems in your Experience Management deployment.

  • Event category: OS Updates
  • Entity: os_updates
    • Patch Install - Identifies metrics pertaining to a resources’s patch installation, for example the duration and the patch title.
    • Patch Uninstall - Identifies metrics pertaining to a resources’s patch uninstallation, for example the GUID and the error code.
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypePatch InstallPatch UninstallExamples
Duration in Millisecondsduration_millisThe OS updated installation duration.LongWindows onlyWindows only593
ErrorerrorAn error code in the event log.StringNAWindows only0x80070013
Event Statusevent_statusReports the status of the event as complete, request, and failed.StringmacOS and WindowsmacOS and WindowsComplete
GUIDguidThe globally unique identifier of the OS update.UUIDWindows onlyWindows only32505c-a41c-aff0-babe-01963daa4da0
Revision Numberrevision_numberA unique ID that indicates a change or a revision of an OS update.StringmacOS and WindowsmacOS and Windows2949172
TitletitleThe title of the OS update.StringmacOS and WindowsmacOS and WindowsSecurity Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.361.786.0)
Transaction Identifiertransaction_idA unique ID that identifies the OS update transaction.StringWindows onlyWindows only10975597789300736267
Trigger Timetrigger_timeThe time an event triggeredFile Date-TimemacOS and WindowsmacOS and Windows(Timestamp) seconds (INT64) = 1645402934 nanos (INT32) = 340502704
{.filterTable}

Service inventory

The Service Inventory table lists data about Windows services running on endpoint devices in your Experience Management deployment.

  • Event category: Service inventory
  • Entity: service_inventory
  • Minimum agent version: 26.07
Friendly NamePropertyDefinitionTypeExamples
App Volumes Package IDav_package_idThe App Volumes package identifier associated with the service.Uuid08870c17-bca9-4558-9a4f-311f60e83439
From App Volumesis_loaded_from_avIndicates whether the service is delivered from App Volumes.Booleantrue
Process Nameimage_nameThe name of the process hosting the service.Stringsvchost.exe
Process Versionimage_versionThe version of the process hosting the service.String10.0.26100.5074
Service Auto Recoveryauto_recoveryIndicates whether auto recovery is configured for the service.Booleantrue
Service DescriptiondescriptionThe description of the service.StringOmnissa Experience Management Service collects telemetry for use with the Omnissa Digital Employee Experience Management Solution
Service Display Namedisplay_nameThe display name of the service.StringOmnissa Experience Management Service
Service Dll Namedll_nameThe name of the DLL associated with the service. On Windows, many services run inside a shared host process; this attribute captures the service DLL name.Stringztdhelper.dll
Service Dll Versiondll_versionThe version of the DLL associated with the service.String10.0.26100.6725
Service Idservice_idThe unique identifier of the service. On Windows, this is a hash of the service name.String5086996434635914803
Service Logon Account Domainaccount_domainThe domain of the user account under which the service runs. Affects service permissions and access.StringTestdomain
Service Logon Account Useraccount_userThe user account under which the service runs. Affects service permissions and access. Allowed values: Local System, Local Service, Network Service.StringLocal System
Service NamenameThe name of the service.Stringws1etlm
Service Startup Typestartup_typeThe startup type of the service, which defines how and when the service starts. Allowed values: Automatic, Manual, Disabled.StringAutomatic
Service StatusstatusThe current status of the service. Allowed values: Running, Stopped.StringRunning
Service TypetypeThe type of service. Allowed values: System, User, User_Instance.StringSystem
Session Domainsession_domainThe session domain for a User service instance.Stringtestdomain
Session Idsession_idThe session identifier for a User service instance.String2
Session Usersession_user_nameThe session user name for a User service instance.Stringtestuser
{.filterTable}

Service inventory change event

In addition to the Service Inventory snapshot entity, Omnissa Intelligence creates two derived timeseries entities that track historical changes to service inventory data over time.

  • Service Inventory Change Event that tracks changes to service_inventory data for UEM-managed Windows devices.
  • Service Inventory Change Event (Horizon) that tracks changes to horizon_service_inventory data for Horizon-managed devices.

The Service Inventory snapshot entity captures a point-in-time inventory of all services on a device at each reporting cycle. However, snapshot data alone doesn't tell you what changed and when it changed. The Inventory Change Event entity does tell you what changed and when it changed.

Each time a new snapshot arrives for a specific service on a given device, Intelligence compares the current and previous attribute values for each service. If any attribute changes - service status, startup type, account user, display name, or any other tracked field - Intelligence automatically creates a timeseries entry recording that change. You now have a queryable history of changes.

Example use case

An IT admin wants to know when a specific service stops running across their fleet, and wants to be alerted to it - not just see the current state.

  • The snapshot entity shows the current inventory.
  • The change event entity activates automations and alerts that are triggered when a service transitions from Running to Stopped (or any other state change).

Allowed values

Service Status values

ValueDescription
RunningThe service is currently active and running.
StoppedThe service is not running.

Service Startup Type values

ValueDescription
AutomaticThe service starts automatically when the system starts.
ManualThe service starts only when explicitly started by a user or application.
DisabledThe service is disabled and cannot be started.
SystemThe service is loaded during kernel initialization, early in system startup.

Service Type values

ValueDescription
SystemA service that runs in a shared host process (e.g. svchost.exe).
UserA per-user service instance.
User InstanceA specific instance of a per-user service.

Service Logon Account User values

ValueDescription
Local SystemA highly privileged built-in account used by the operating system.
Loacl ServiceA built-in account with reduced privileges for services that do not need network access.
Network ServiceA built-in account that has network access but reduced local privileges.
User AccountA specific user or domain account under which the service runs, using that account's credentials and permissions.

For services running under a specific user account (for example domain\user), the system splits the value and populates either the Service Logon Account User and the Service Logon Account Domain attribute accordingly.

Services

The services table lists data concerning the Omnissa App Volumes service and other services in your Experience Management deployment.

  • Event category: Services
  • Entity: services
    • Service Installed - Identifies metrics pertaining to the installation of a service.
    • Service Removed - Identifies metrics pertaining to the removal of a service.
    • Service Start - Identifies metrics pertaining to the start of a service on a Windows resource, for example the App Volumes package ID.
    • Service Stop - Identifies metrics pertaining to the stoppage of a service on a Windows resource, for example the process ID.
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypeService InstalledService RemovedService StartService StopExamples
App Volumes Package IDav_package_idLists the ID of an App Volumes package.UUIDNANAWindows onlyWindows only08870c17-bca9-4558-9a4f-311f60e83439
Duration in Millisecondsduration_millisIndicates how long it takes to start or stop the service successfully.LongNANAWindows onlyWindows only72
Event Statusevent_statusThe status of the service event.StringmacOS onlymacOS onlyWindows onlyWindows onlyComplete
From App Volumesis_loaded_from_avIdentifies whether an application was delivered by App Volumes or not.BooleanNANAWindows onlyWindows onlyFALSE
Image Nameimage_nameLists the executable of the service.StringmacOS onlymacOS onlyWindows onlyWindows onlysppsvc.exe
Process IDprocess_idLists the process ID of the service.StringNANAWindows onlyWindows only11516
Service Display Nameservice_display_nameLists the service long name.StringmacOS onlymacOS onlyWindows onlyWindows onlySoftware Protection
Service Nameservice_namemacOS: This data field lists the identifier of the service.

Windows: This data field lists the service short name.
StringmacOS onlymacOS onlyWindows onlyWindows onlyTrustedInstaller
Trigger Timetrigger_timeThe time a service event triggered.File Date-TimemacOS onlymacOS onlyWindows onlyWindows only(Timestamp) seconds (INT64) = 1645402934 nanos (INT32) = 340502704
UseruserLists the service owner.StringmacOS onlymacOS onlyNANAadmin
{.filterTable}

Software metering

The software metering table lists data concerning the software metering solution, which monitors desktops, measures usage, and works with workflows to automate actions for productivity and security applications, in your Experience Management deployment.

  • Event category: NA
  • Entity: NA
  • Minimum agent version: 24.12
Friendly NameDefinitionSourceSupported on WindowsSupported on macOS
Active ApplicationsCount of device with last application foreground time within 14, 30, 45, 60, 90, or 120 days (count of devices).

Active Apps = Total Device Count with app installed - Inactive Device Count
App ActivityYesYes
App Create DateDate the application was initially installed in your environment on a device, ignoring versioning.Software Metering

UEM
YesYes
App StatusIdentifies if the app is managed or unmanaged.UEMYesYes
Application NameParent name for all applications mapped to single identifier.Software Application CatalogYesYes
Average Foreground TimeCalculated based on Total Foreground Time during set time period / Count of Foreground Launch events during set time period.Employee ExperienceYesYes
CategoryCategory allows the grouping of similar software applications for easy comparison.Software Application CatalogYesYes
Device ModelThe model of the device.UEMYesYes
Device NameThe friendly name of the device.UEMYesYes
Foreground ActivityThe user selected foreground activity for calculating metrics on the dashboard.Software MeteringYesYes
Inactive ApplicationsCount of devices with last application foreground time not within 14, 30, 45, 60, 90, or 120 days.

Inactive Apps = Total devices with app installed - Active Device Count
App Activity

Employee Experience
YesYes
Last SeenThe last date the device had an event with the applications.UEMYesYes
OS VersionCurrent version of the operating system.UEMYesYes
PlatformSpecific platform.UEMYesYes
PlatformsList of all platforms associated with the software applications.App Activity

Employee Experience
YesYes
Product Last Foreground XX daysThe last time the product was interacted with within a selected time range (14, 30, 45, 60, 90, or 120 days).Software MeteringYesYes
Product URLThe URL to the publisher product page.Software Application CatalogYesYes
PublisherThe parent company that owns the application.Software Application CatalogYesYes
StatusManage and unmanaged status imported from UEM.UEMYesYes
Total ApplicationsThe total count of devices with the application currently installed.App ActivityYesYes
Total Foreground TimeSum of foreground time across all applications within a set time period.Employee ExperienceYesYes
{.filterTable}

Storage information

The storage information table lists data concerning the components that store information and house saved data for resources to access in your Experience Management deployment.

  • Event category: Storage information
  • Entity: NA
    • disk_info - Lists the disk information, for example, disk name, media type, protocol type, or bus type.
    • volume_info - Lists the volume information, for example, mount path, drive letter, or capacity.
  • Minimum agent version: 24.12
Friendly NameDefinitiondisk_infovolume_infoExamples
Disk NameThe disk name that was returned by the Windows OS.Windows onlyWindows onlyMicron 2300 NVMe 1024GB
Disk SizeTotal space of the disk, and it includes reserved space and available space.

Reserved space is the space reserved by the operating system or hardware that can not be assigned to volumes.

Available space is the space that can be assigned to volumes.
Windows onlyWindows only5000.0 (Megabytes)
Drive LetterLetter of the drive, which can be C, D, E, or F.Windows onlyWindows onlyC
FailedIndicates a failure during the collection of disk information, like an inaccessible USB disk.Windows onlyWindows onlyTrue
False
Free SpaceThe free space of the volume as reported by the filesystem.Windows onlyWindows only1000.0 (Megabytes)
Health StatusThe disk’s health status, which is based on S.M.A.R.T. (Self-Monitoring, Analysis, and Reporting Technology), Hardware Error, and Transient Error.Windows onlyWindows onlyUnknown
Unhealthy
Warning
Healthy
Information TypeThe type of information.Windows onlyWindows onlyDisk
Volume
Is Active System DriveIndicates whether the volume contains the running operating system.Windows onlyWindows onlyTrue
False
Is PresentIndicates that the disk is present, if the disk is unplugged, or if it is set to false.

By default, the system reports disk removal for up to seven days.
Windows onlyWindows onlyTrue
False
Is RemovableIndicates that the disk is removable, like a USB drive.Windows onlyWindows onlyTrue
False
Last Removal TimeWhen combined with Is Present, displays the last removal time.

By default, the system reports disk removal for up to seven days.
Windows onlyWindows only2/27/2024 20:31
Manufacturer NameThe name of the storage manufacturer.Windows onlyWindows onlyMicron
Media TypeIdentifies the solid state drives (SSDs).

Provided as an ENUM (enumerated type).
Windows onlyWindows onlySSD
HDD
Other
Unallocated SpaceThe unallocated disk space not assigned to volumes.Windows onlyWindows only1000.0 (Megabytes)
Unique IdentifierAn identifier that is locally generated to uniquely identify the device.Windows onlyWindows only18026096556741400000
Used Space PercentageThe used volume space percentage that is reported by the filesystem.Windows onlyWindows only40.0%
Volume SizeThe size of the volume.Windows onlyWindows only5000.0 (Megabytes)
Volume TypeIndicates the volume type as data, recovery, or other.

Data: Indicates that the volume is used to save files.

Recovery: Indicates that the recovery volume is used for system recovery and troubleshooting.

Other: Indicates other types of volumes besides data and recovery.
Windows onlyWindows onlyData
Recovery
Other
{.filterTable}

Synthetic URL monitoring

The synthetic URL monitoring table lists data concerning the synthetic URL monitoring solution, which monitors specific web applications and URLs to identify network performance issues and availability, in your Experience Management deployment.

  • Event category:
  • Entity: synthetic_url_monitoring
    • http_https_url_test - Identifies metrics for or a web application or a URL experiencing network performance issues, for example a reason for failure or a protocol version.
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypehttp_https_url_testExamples
Certification Valid Fromcert_valid_from_timeThe secure connection certificate start date.Date-TimeWindows only(Timestamp) seconds (INT64) = 1701293404 nanos (INT32) = 0
Certification Valid Tocert_valid_to_timeThe secure connection certificate end date.Date-TimeWindows only(Timestamp) seconds (INT64) = 1709069403 nanos (INT32) = 0
Configured IP Protocolconfigured_ip_protocolAdministrator configured IP (Internet Protocol) to run tests.

The possible IP protocols are IPv4, IPv6, and Auto.
StringWindows onlyIPv4
Fail Reasonfail_reasonThe reason a connection failed.StringWindows onlyResolving timed out after 1006 milliseconds/ Could not resolve host: bad_host/ Request failed with status code: 404
HTTP Response Time in Millisecondshttp_resp_millisThe time it takes for the data transfer to complete.DoubleWindows only270.770000
HTTP Status Codehttp_status_codeHTTP/S code connection.

Empty status indicates failure.
IntegerWindows only404
IP Protocol Versionip_protocol_versionIP protocol used in testing.StringWindows onlyIPv4
Is Secure Protocolis_secure_protocolTrue if there is a secure TLS/SSL connection, and False otherwise.BoolenWindows only1
Is Successis_successIndicates whether the connection is a success.BooleanWindows only1
Name Response Time in Millisecondsname_res_millisThe time it takes for the name to resolve.DoubleWindows only26.856000
Socket Connection Time in Millisecondssocket_conn_millisThe time it takes to connect to the remote host (or proxy).DoubleWindows only374.133000
TLS Setup Time in Millisecondstls_setup_millisThe time it takes for the SSL connect or handshake with the remote host.DoubleWindows only24.610000
Target Addresstarget_addressThe target URL to test.StringWindows onlyhttps://example-102303.com
Target IP Addresstarget_ip_addressResolved IP address of the target address.StringWindows only44.230.85.241
Test IDtest_idA UUID for each synthetic test.StringWindows only156d003e-fe38-4640-a56e-dbcd0bd5df99
Test Typetest_typeSynthetic test type.StringWindows onlyHttp/s
Total Response Time in Millisecondstotal_resp_millisTotal HTTP/S connection time.DoubleWindows only129.750000
{.filterTable}

User actions

The user actions table lists data concerning who interacts with your resources and from where in your Experience Management deployment.

  • Event category: User Actions
  • Entity: user_actions
    • Logon - Identifies metrics concerning user actions while logging on to a resource, for example logon type or the user name.
    • Logout - Identifies metrics concerning user actions while logging out of a resource, for example if the logging out failed.
    • Lock - Identifies metrics concerning user actions while locking a resource, for example the computer domain name.
    • Unlock - Identifies metrics concerning user actions while unlocking a resource, for example if the unlock was successful.
  • Minimum agent version: 24.12
Friendly NamePropertyDefinitionTypeLogonLogoutLockUnlockExamples
DomaindomainThe computer domain name.StringWindows onlyWindows onlyWindows onlyWindows onlyDTEST-WIN10-1
Event Statusevent_statusThe status of the user action.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsComplete
Logon Typelogon_typeThe type of log on. For example, Interactive.StringWindows onlyNAWindows onlyWindows onlyInteractive
ResultresultThe result of a user action.StringmacOS and WindowsWindows onlyWindows onlyWindows onlySuccess
SessionsessionThe user session ID.IntegerNAWindows onlyWindows onlyWindows only2
Trigger Timetrigger_timeThe time a user action event triggered.File Date-TimemacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and Windows(Timestamp) seconds (INT64) = 1645402934 nanos (INT32) = 340502704
UseruserThe logon user name.StringmacOS and WindowsmacOS and WindowsmacOS and WindowsmacOS and WindowsAdministrator
{.filterTable}

Web apps

The web apps table lists data concerning the web app monitoring solution, which collects data on web apps using the Omnissa Experience Management browser extension, in your Experience Management deployment.

  • Event category: Web App Metrics
  • Entity: web_app_metrics
    • web_app_speed - Identifies metrics for an internet session.
    • web_app_error - The error when a page load failed and it includes two types of errors: HTTP error and Browser error.
  • Minimum agent version: 25.03
Friendly NamePropertyDefinitionTypeweb_app_speedweb_app_errorExamples
Browserbrowser_nameThe name of the browser.StringmacOS and WindowsmacOS and WindowsMicrosoft Edge, Google Chrome
Browser Versionbrowser_versionThe version of the browser.StringmacOS and WindowsmacOS and Windows122.0.6261.129
Connection Setup Duration in Millisecondsconnect_durationThe time to establish socket connection between browser and web server.DoublemacOS and WindowsNA100
DNS Lookup Duration in Millisecondsdns_durationThe time to resolve domain names.DoublemacOS and WindowsNA100
DOM Content Load Durationdom_content_load_durationThe time when the HTML structure of a page is fully parsed, allowing JavaScript to execute and other elements to load.

This is a metric for understanding how quickly a webpage becomes interactive.
DoublemacOS and WindowsNA100
DOM Processing Durationdom_processing_durationThe time for the browser to understand and build the structure of the page.

This duration is a key factor in overall page load time and user experience.
DoublemacOS and WindowsNA100
ErrorerrorThe error when a page load failed. Errors include HTTP error and Browser error.StringNAmacOS and WindowsHTTP ERROR 404

net::ERR_FAILED
Extension Versionextension_versionThe version of the browser extensionStringmacOS and WindowsmacOS and Windows24.10.0.278
Host of Target URLtarget_url_hostThe host of the target URL.StringmacOS and WindowsmacOS and Windowshttps://example.com
HTTP ProtocolprotocolThe protocol version of HTTP.StringmacOS and WindowsNAhttp1.1/h2/h3
HTTP Request Duration in Millisecondsrequest_durationThe time until first byte of document response is received.DoublemacOS and WindowsNA100
HTTP Response Duration in Millisecondsresponse_durationThe time to download the document response.DoublemacOs and WindowsNA100
Load Duration in Millisecondsload_durationThe time to load the web app.DoublemacOS and WindowsNA100
Redirect Duration in Millisecondsredirect_durationThe time for the HTTP redirect if there is one .DoublemacOS and WindowsNA100
Relative Reference of Target URLtarget_url_relativeThe other part of the target URL.StringmacOS and WindowsmacOS and Windows/path?query#anchor
TLS Negotiation Duration in Millisecondstls_durationThe time to establish a secure socket connection between browser and web server.DoublemacOS and WindowsNA100
Total Load Duration in Millisecondstotal_load_durationThe time for a web page to fully load and become interactive, from the initial user request to the final rendering of all its content in the browser.DoublemacOS and WindowsNA1000
Unload Durationunload_durationThe time when a document or a child resource is being unloaded, such as when a user navigates away from a page, closes a tab, or refreshes the page.DoublemacOS and WindowsNA100
{.filterTable}

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…