Logs table
The table in the Logs > Log search > Log discovery view lists records according to search and filtering criteria. The fields available for a record depend on the log source and how you process the data. However, all records contain the NXLog Agent core fields.
Core fields
NXLog Agent adds the following fields to every record it collects.
| Field | Type | Description |
|---|---|---|
|
The date and time that NXLog Agent received or collected the record.
The format is |
|
|
The IP address or hostname where the data originated. This field is displayed by default on the Log discovery view. |
|
|
The user-defined name of the NXLog Agent input module instance that collected the record. |
|
|
The type of NXLog Agent input module instance.
For example, |
Standard fields
Apart from the core fields described above, NXLog Agent contains a set of standard fields common to several modules.
| Field | Type | Description |
|---|---|---|
|
Internal unique identifier of the record. |
|
|
Name of the user who initiated the action described in the event. |
|
|
A number indicating the type of event. Error codes are vendor-specific and especially useful for event correlation. |
|
|
Windows Event ID. |
|
|
The date and time of the event.
The format is This field is displayed by default on the Log discovery view. |
|
|
The event message. In most cases, it contains user-friendly information about the recorded event. This field is displayed by default on the Log discovery view. |
|
|
The IP address of the remote host.
Available in network modules, such as |
|
|
The name of the module instance that generated the internal event.
This field is only used for NXLog Platform system logs.
If this field is used, the SourceModuleName field will identify the current |
|
|
The type of module, such as |
|
|
The ID of the process that generated the event. |
|
|
Severity name corresponding to the SeverityValue.
It can be one of |
|
|
NXLog Agent normalized severity value between 1 and 5. |
|
|
The application, service/daemon, or device that generated the event. |
|
|
Identifier of the span. This field is only used by OpenTelemetry event records. |
|
|
Name of the user who was the target of the action described in the event. |
|
|
Options for the trace. This field is only used by OpenTelemetry event records. |
|
|
Identifier of the trace. This field is only used for OpenTelemetry event records. |