enTrail

Box

Every event field Built

140 fields. Five are required, one more is on by default, and everything else is optional. You never have to use a field you do not need, and a field we do not know is kept rather than dropped.

ContractValue
Version1.0.0-rc.5
Fields140, of which 65 carry an OpenTelemetry name
Requiredaction actor.type actor.id outcome ts
Size limits256 KiB an event, 5 MiB or 1000 events a batch

How to read this

You do not have to rename your data to use these names. A mapping profile translates your field names to ours on the way in, and the raw payload is sealed byte for byte regardless. See send events.

On this page

Core

The shape of every event: what happened, and how it ended.

FieldAcceptsConstraintsNotes
actionRequiredtext
  • 1–128 characters
  • Dotted action name (user.login, rx.recommend); legacy single-word actions also pass.
  • Exact pattern^[A-Za-z0-9_:-]+(?:\.[A-Za-z0-9_:-]+)*$
What happened, as dotted noun.verb (user.login, record.delete, rx.recommend).
correlation_idtext
  • Up to 128 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Groups related events (an AI recommendation and its human approval; open-edit-move of one file).
event.categorytext
  • Up to 64 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Area of the application (auth, billing, records).
event.client_idtext
  • Up to 128 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Client-supplied idempotency key; a retry with the same value is not sealed twice.
event.descriptionOn by defaulttext
  • Up to 2000 characters
  • Free text, may span lines: tab, LF and CR allowed, other control characters rejected.
  • Exact pattern^[^\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F-\u009F]*$
Human-readable description of what happened. Required by default; a project may switch it to optional in its field policy.
event.duration_mswhole number
  • 0 or greater
How long the action took, in milliseconds.
event.timezonetext
  • Up to 64 characters
  • IANA time zone name (America/New_York, Asia/Kolkata, UTC). Abbreviations such as EST are not accepted: they are ambiguous.
  • Exact pattern^(?:UTC|[A-Za-z][A-Za-z0-9_+-]*(?:/[A-Za-z0-9_+-]+){1,2})$
IANA time zone the event happened in, as claimed by the client. An offset alone cannot identify the zone or whether daylight saving applied; this can.
outcomeRequiredone of a fixed set
  • Must be one of: success failure denied error partial pending
Result of the action.
parent_event_idtext
  • Up to 128 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Event that directly caused this one.
severityone of a fixed set
  • Must be one of: trace debug info warn error fatal
Significance of the event. Values are the OpenTelemetry log SeverityText names in lower case (trace < debug < info < warn < error < fatal).
tsRequiredRFC 3339 timestamp
  • RFC 3339, with an explicit Z or numeric offset — not a bare local time
  • RFC 3339 timestamp with explicit Z or offset.
  • Exact pattern^[0-9]{4}-(?:0[1-9]|1[0-2])-(?:0[1-9]|[12][0-9]|3[01])[Tt](?:[01][0-9]|2[0-3]):[0-5][0-9]:(?:[0-5][0-9]|60)(?:\.[0-9]+)?(?:[Zz]|[+-](?:[01][0-9]|2[0-3]):[0-5][0-9])$
When the client says the event happened: RFC 3339 with an explicit Z or numeric offset. Recorded as a claim; chain order never uses it. Stored normalized to UTC together with the original offset, so both the UTC instant and the local wall-clock time the event claimed are always available.

Actor

Who or what did it. Service accounts, machines and AI agents are actors too.

FieldAcceptsConstraintsNotes
actor.auth_methodone of a fixed set
  • Must be one of: password sso mfa api_key certificate token none
How the actor authenticated for this action.
actor.display_nametext
  • Up to 256 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Human-readable label (Jane Doe). Not unique, may change; often absent for machines and service accounts. Personal data. Can be sent hashed instead.
actor.domaintext
  • Up to 256 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Tenant, domain or realm of the identity (CORP, acme.onmicrosoft.com).
actor.emailtext
  • Up to 320 characters
  • Email address (WHATWG form, domain must contain a dot).
  • Exact pattern^[A-Za-z0-9.!#$%&'*+/=?^_`{|}~-]+@[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?(?:\.[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?)+$
Actor's email address; also the TRACE identifier. Personal data. Can be sent hashed instead.
actor.idRequiredtext
  • 1–512 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Stable unique identifier of the principal (user ID, ARN, SID, db-account@host).
actor.identity_providertext
  • Commonly: okta entra_id active_directory aws_iam gcp_iam postgres mysql local . Others accepted.
  • Up to 64 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Where the identity is defined.
actor.nametext
  • Up to 256 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Identity name the principal authenticates as (jdoe, svc-backup, app_rw, build-agent-03). Unique within its identity provider and stable over time. Not a display label. Personal data. Can be sent hashed instead.
actor.on_behalf_of.idtext
  • Up to 512 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Identifier of the principal the actor acted for.
actor.on_behalf_of.typeone of a fixed set
  • Must be one of: user service_account machine db_account ai_agent api_key system
Kind of principal the actor acted for (delegation or impersonation).
actor.roletext
  • Up to 64 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Role of the actor (admin, physician, readonly).
actor.typeRequiredone of a fixed set
  • Must be one of: user service_account machine db_account ai_agent api_key system
Kind of principal that performed the action. The actor is WHO did it; the device is WHAT it was done from.

Target and change

What was acted on, and what changed about it.

FieldAcceptsConstraintsNotes
change.aftertextNo constraint beyond its type.Values of the changed fields after the change, keyed by field name (absent for delete). Serialized size up to 64 KB. Personal data. Can be sent hashed instead.
change.beforetextNo constraint beyond its type.Values of the changed fields before the change, keyed by field name (absent for create). Serialized size up to 64 KB. Personal data. Can be sent hashed instead.
change.fieldsarrayNo constraint beyond its type.Names of the target's fields that changed. change.before and change.after contain only these fields.
change.kindone of a fixed set
  • Must be one of: create update delete transition permission config link unlink content
What sort of change was made to the target.
change.state_hash.aftertext
  • SHA-256 digest, lowercase hex.
  • Exact pattern^[a-f0-9]{64}$
SHA-256 of the target's entire state after the change.
change.state_hash.beforetext
  • SHA-256 digest, lowercase hex.
  • Exact pattern^[a-f0-9]{64}$
SHA-256 of the target's entire state before the change (for a file: its content). Should equal the previous event's state_hash.after for the same target; a mismatch means an unrecorded change.
file.content_sha256text
  • SHA-256 digest, lowercase hex.
  • Exact pattern^[a-f0-9]{64}$
SHA-256 of the file contents at the moment of a non-changing operation (proves exactly what was opened or downloaded).
file.nametext
  • Up to 255 characters
  • File name without directory separators or control characters.
  • Exact pattern^[^\u0000-\u001F\u007F/\\]+$
Name of the file including the extension, without the directory. OpenTelemetry: file.name. Personal data. Can be sent hashed instead.
file.operationone of a fixed set
  • Must be one of: open read create modify move copy delete download upload permission_change
Shared file vocabulary. Changing operations also carry change.*; non-changing ones (open, read, download) carry file.content_sha256.
file.pathtext
  • Up to 4096 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Full path of the file at the time of the event. For moves and renames use change.before/after with field 'path' instead. OpenTelemetry: file.path. Personal data. Can be sent hashed instead.
file.sizewhole number
  • 0 or greater
File size in bytes. OpenTelemetry: file.size.
file.typetext
  • Up to 128 characters
  • Media type, type/subtype.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9!#$&^_.+-]{0,126}/[A-Za-z0-9][A-Za-z0-9!#$&^_.+-]{0,126}$
File media type.
target.idtext
  • Up to 512 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Stable identifier of the object acted on; should survive renames and moves.
target.nametext
  • Up to 256 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Display name of the object acted on. Personal data. Can be sent hashed instead.
target.typetext
  • Up to 64 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Kind of object acted on (patient_record, invoice, file, user, environment). 'Target' is the object of the action.

Access

Emergency, elevated, impersonated and delegated access, with its justification.

FieldAcceptsConstraintsNotes
access.approver.idtext
  • Up to 512 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Identifier of the approver.
access.approver.typeone of a fixed set
  • Must be one of: user service_account machine db_account ai_agent api_key system
Kind of principal that approved the access, if any.
access.expires_atRFC 3339 timestamp
  • RFC 3339, with an explicit Z or numeric offset — not a bare local time
  • RFC 3339 timestamp with explicit Z or offset.
  • Exact pattern^[0-9]{4}-(?:0[1-9]|1[0-2])-(?:0[1-9]|[12][0-9]|3[01])[Tt](?:[01][0-9]|2[0-3]):[0-5][0-9]:(?:[0-5][0-9]|60)(?:\.[0-9]+)?(?:[Zz]|[+-](?:[01][0-9]|2[0-3]):[0-5][0-9])$
When the elevated or break-glass access ends.
access.justificationtext
  • Up to 2000 characters
  • Free text, may span lines: tab, LF and CR allowed, other control characters rejected.
  • Exact pattern^[^\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F-\u009F]*$
Reason given for break-glass or elevated access.
access.modeone of a fixed set
  • Must be one of: normal break_glass elevated impersonation delegated
How access was obtained. break_glass = emergency access that bypassed normal controls; elevated = temporary privilege raise (sudo, JIT admin); impersonation = acting as another principal; delegated = acting with granted authority. Anything but normal is always surfaced.
access.referencetext
  • Up to 128 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Incident, ticket or change reference authorising the access.

AI and generative AI

The prompt, the model, its reasoning, and whether a human was in the loop.

FieldAcceptsConstraintsNotes
ai.autonomyone of a fixed set
  • Must be one of: advisory supervised autonomous
advisory = the AI recommended and a human decided; supervised = the AI acted after human approval; autonomous = the AI acted with no human in the loop. Autonomous actions are always surfaced.
ai.confidencenumber
  • 0 or greater
  • 1 or less
Model confidence, 0 to 1.
ai.decisiontext
  • Up to 2000 characters
  • Free text, may span lines: tab, LF and CR allowed, other control characters rejected.
  • Exact pattern^[^\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F-\u009F]*$
What the AI decided or recommended.
ai.explanationtext
  • Up to 4000 characters
  • Free text, may span lines: tab, LF and CR allowed, other control characters rejected.
  • Exact pattern^[^\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F-\u009F]*$
The AI's own plain-language explanation of its decision, written for the audit trail (what a reviewer should read).
ai.guardrail.actionone of a fixed set
  • Must be one of: blocked modified flagged allowed
Most severe action taken by the guardrails.
ai.guardrail.categoriesarray
  • Commonly: pii toxicity prompt_injection jailbreak policy off_topic hallucination unsafe_action . Others accepted.
Categories of the guardrails that fired.
ai.guardrail.detailstext
  • Up to 2000 characters
  • Free text, may span lines: tab, LF and CR allowed, other control characters rejected.
  • Exact pattern^[^\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F-\u009F]*$
What the guardrail found.
ai.guardrail.namesarrayNo constraint beyond its type.Guardrails that fired, by name.
ai.guardrail.triggeredtrue or falseNo constraint beyond its type.Whether any guardrail fired on the input or output.
ai.human_reviewone of a fixed set
  • Must be one of: required not_required completed
Human review status; the approval itself is a separate event linked by correlation_id.
ai.model.digesttext
  • SHA-256 digest, lowercase hex.
  • Exact pattern^[a-f0-9]{64}$
SHA-256 of the model weights or manifest (self-hosted models), proving exactly which model ran.
ai.model.hostone of a fixed set
  • Must be one of: vendor_api self_hosted on_device
Where inference ran.
ai.model.quantizationtext
  • Commonly: none fp16 bf16 fp8 int8 int4 q4_k_m q8_0 awq gptq . Others accepted.
  • Up to 32 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Weight quantization of the model that served the request.
ai.model.versiontext
  • Up to 128 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Model version or snapshot date when not part of the model name.
ai.prompt.sha256text
  • SHA-256 digest, lowercase hex.
  • Exact pattern^[a-f0-9]{64}$
SHA-256 of the exact rendered prompt bytes sent to the model. Proves what the model was asked without storing the prompt.
ai.prompt.versiontext
  • Up to 64 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Version of the prompt template named by gen_ai.prompt.name.
ai.reasoningtext
  • Up to 65536 characters
  • Free text, may span lines: tab, LF and CR allowed, other control characters rejected.
  • Exact pattern^[^\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F-\u009F]*$
Raw rationale or chain of thought as produced by the model. Can be sent hashed instead.
ai.tonetext
  • Commonly: neutral formal empathetic assertive cautious . Others accepted.
  • Up to 64 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Tone the model was instructed to use or self-reported.
gen_ai.agent.descriptiontext
  • Up to 2000 characters
  • Free text, may span lines: tab, LF and CR allowed, other control characters rejected.
  • Exact pattern^[^\u0000-\u0008\u000B\u000C\u000E-\u001F\u007F-\u009F]*$
The agent's purpose. OpenTelemetry: gen_ai.agent.description.
gen_ai.agent.idtext
  • Up to 256 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Unique identifier of the agent. For an ai_agent actor this normally equals actor.id. OpenTelemetry: gen_ai.agent.id.
gen_ai.agent.nametext
  • Up to 256 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Human-readable agent name. OpenTelemetry: gen_ai.agent.name.
gen_ai.agent.versiontext
  • Up to 64 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Agent version. OpenTelemetry: gen_ai.agent.version.
gen_ai.conversation.idtext
  • Up to 256 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Conversation or thread identifier. OpenTelemetry: gen_ai.conversation.id.
gen_ai.data_source.idtext
  • Up to 256 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Data source used for retrieval. OpenTelemetry: gen_ai.data_source.id.
gen_ai.input.messagesarrayNo constraint beyond its type.The input prompt: chat history provided to the model, in OpenTelemetry message form ({role, parts:[{type, content}]}). Large: counts toward event_max_bytes; ai.prompt.sha256 proves it without storing it. OpenTelemetry: gen_ai.input.messages. Personal data. Can be sent hashed instead.
gen_ai.operation.nametext
  • Commonly: chat text_completion embeddings generate_content retrieval create_agent invoke_agent invoke_workflow execute_tool . Others accepted.
  • Up to 64 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
The operation performed. OpenTelemetry: gen_ai.operation.name.
gen_ai.output.messagesarrayNo constraint beyond its type.Messages generated by the model, in OpenTelemetry message form. OpenTelemetry: gen_ai.output.messages. Personal data. Can be sent hashed instead.
gen_ai.output.typetext
  • Commonly: text json image speech . Others accepted.
  • Up to 32 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Kind of output requested. OpenTelemetry: gen_ai.output.type.
gen_ai.prompt.nametext
  • Up to 256 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Reference identifier of the prompt template in the customer's prompt registry (the prompt the agent's output was produced against). OpenTelemetry: gen_ai.prompt.name.
gen_ai.provider.nametext
  • Commonly: openai anthropic aws.bedrock azure.ai.openai gcp.vertex_ai gcp.gemini cohere mistral_ai deepseek groq x_ai self_hosted . Others accepted.
  • Up to 64 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Generative AI provider. OpenTelemetry: gen_ai.provider.name.
gen_ai.request.frequency_penaltynumberNo constraint beyond its type.Frequency penalty setting. OpenTelemetry: gen_ai.request.frequency_penalty.
gen_ai.request.max_tokenswhole number
  • 0 or greater
Maximum tokens requested. OpenTelemetry: gen_ai.request.max_tokens.
gen_ai.request.modeltext
  • Up to 128 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Model requested (claude-opus-5, gpt-4o, llama-3.1-70b). OpenTelemetry: gen_ai.request.model.
gen_ai.request.presence_penaltynumberNo constraint beyond its type.Presence penalty setting. OpenTelemetry: gen_ai.request.presence_penalty.
gen_ai.request.seedwhole numberNo constraint beyond its type.Seed for deterministic generation. OpenTelemetry: gen_ai.request.seed.
gen_ai.request.stop_sequencesarrayNo constraint beyond its type.Stop sequences requested. OpenTelemetry: gen_ai.request.stop_sequences.
gen_ai.request.streamtrue or falseNo constraint beyond its type.Whether the response was streamed. OpenTelemetry: gen_ai.request.stream.
gen_ai.request.temperaturenumber
  • 0 or greater
Temperature setting. OpenTelemetry: gen_ai.request.temperature.
gen_ai.request.top_knumber
  • 0 or greater
Top-k sampling setting. OpenTelemetry: gen_ai.request.top_k.
gen_ai.request.top_pnumber
  • 0 or greater
  • 1 or less
Top-p sampling setting. OpenTelemetry: gen_ai.request.top_p.
gen_ai.response.finish_reasonsarrayNo constraint beyond its type.Why generation stopped (stop, length, tool_calls, content_filter). OpenTelemetry: gen_ai.response.finish_reasons.
gen_ai.response.idtext
  • Up to 256 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Provider's identifier for the completion. OpenTelemetry: gen_ai.response.id.
gen_ai.response.modeltext
  • Up to 128 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Model that actually generated the response (may differ from the request by routing or aliasing). OpenTelemetry: gen_ai.response.model.
gen_ai.system_instructionsarrayNo constraint beyond its type.System instructions given to the model. OpenTelemetry: gen_ai.system_instructions. Can be sent hashed instead.
gen_ai.tool.call.argumentstextNo constraint beyond its type.Arguments passed to the tool (any JSON). OpenTelemetry: gen_ai.tool.call.arguments. Personal data. Can be sent hashed instead.
gen_ai.tool.call.idtext
  • Up to 256 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Tool call identifier. OpenTelemetry: gen_ai.tool.call.id.
gen_ai.tool.call.resulttextNo constraint beyond its type.Result returned by the tool (any JSON). OpenTelemetry: gen_ai.tool.call.result. Personal data. Can be sent hashed instead.
gen_ai.tool.nametext
  • Up to 256 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Tool the model invoked. OpenTelemetry: gen_ai.tool.name.
gen_ai.tool.typetext
  • Commonly: function extension datastore . Others accepted.
  • Up to 32 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Kind of tool. OpenTelemetry: gen_ai.tool.type.
gen_ai.usage.input_tokenswhole number
  • 0 or greater
Input tokens consumed. OpenTelemetry: gen_ai.usage.input_tokens.
gen_ai.usage.output_tokenswhole number
  • 0 or greater
Output tokens generated. OpenTelemetry: gen_ai.usage.output_tokens.
gen_ai.usage.reasoning.output_tokenswhole number
  • 0 or greater
Output tokens spent on reasoning. OpenTelemetry: gen_ai.usage.reasoning.output_tokens.
gen_ai.workflow.nametext
  • Up to 256 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Workflow the operation belongs to. OpenTelemetry: gen_ai.workflow.name.

Network, HTTP and TLS

Where the request came from and how it arrived.

FieldAcceptsConstraintsNotes
client.addresstext
  • Up to 256 characters
  • OpenTelemetry address: IPv4, IPv6, hostname, or a Unix domain socket path.
  • Exact pattern^(?:(?:(?:25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])\.){3}(?:25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])|(?:[0-9A-Fa-f]{1,4}:){7}[0-9A-Fa-f]{1,4}|(?:[0-9A-Fa-f]{1,4}:){1,7}:|(?:[0-9A-Fa-f]{1,4}:){1,6}:[0-9A-Fa-f]{1,4}|(?:[0-9A-Fa-f]{1,4}:){1,5}(?::[0-9A-Fa-f]{1,4}){1,2}|(?:[0-9A-Fa-f]{1,4}:){1,4}(?::[0-9A-Fa-f]{1,4}){1,3}|(?:[0-9A-Fa-f]{1,4}:){1,3}(?::[0-9A-Fa-f]{1,4}){1,4}|(?:[0-9A-Fa-f]{1,4}:){1,2}(?::[0-9A-Fa-f]{1,4}){1,5}|[0-9A-Fa-f]{1,4}:(?::[0-9A-Fa-f]{1,4}){1,6}|:(?:(?::[0-9A-Fa-f]{1,4}){1,7}|:)|[Ff][Ee]80:(?::[0-9A-Fa-f]{0,4}){0,4}%[0-9A-Za-z]+|::(?:[Ff]{4}(?::0{1,4})?:)?(?:(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9])\.){3}(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9])|(?:[0-9A-Fa-f]{1,4}:){1,4}:(?:(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9])\.){3}(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9])|(?=.{1,253}$)[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?(?:\.[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?)*\.?|/[^\u0000-\u0020]*)$
Address of the client as observed by the application: IPv4, IPv6, hostname or Unix socket. OpenTelemetry: client.address. Personal data.
client.portwhole number
  • 0 or greater
  • 65535 or less
Client port. OpenTelemetry: client.port.
dns.answersarrayNo constraint beyond its type.IPv4 or IPv6 addresses resolved during the lookup. OpenTelemetry: dns.answers.
dns.question.nametext
  • Up to 253 characters
  • DNS hostname (RFC 1123 labels, optional trailing dot, 253 chars max).
  • Exact pattern^(?=.{1,253}$)[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?(?:\.[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?)*\.?$
The name being queried, as submitted. OpenTelemetry: dns.question.name.
http.request.methodtext
  • Up to 16 characters
  • HTTP request method in upper case (GET, POST, _OTHER).
  • Exact pattern^[A-Z_]{1,16}$
HTTP request method. OpenTelemetry: http.request.method.
http.response.status_codewhole number
  • 100 or greater
  • 599 or less
HTTP response status code. OpenTelemetry: http.response.status_code.
network.directionone of a fixed set
  • Must be one of: inbound outbound internal
Direction of the traffic relative to the application (enTrail; not OpenTelemetry's network.io.direction, which is per interface).
network.patharrayNo constraint beyond its type.Ordered hops the request passed through (proxy chain / X-Forwarded-For), client first (enTrail).
network.protocol.nametext
  • Commonly: http grpc ssh postgresql mysql smb amqp mqtt ldap . Others accepted.
  • Up to 32 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
OSI application layer protocol. OpenTelemetry: network.protocol.name.
network.protocol.versiontext
  • Up to 16 characters
  • Numeric version like 1.1, 2, 1.3.
  • Exact pattern^[0-9]+(?:\.[0-9]+)*$
Protocol version, e.g. 1.1, 2. OpenTelemetry: network.protocol.version.
network.transportone of a fixed set
  • Must be one of: tcp udp quic pipe unix
OSI transport layer. OpenTelemetry: network.transport.
network.typeone of a fixed set
  • Must be one of: ipv4 ipv6
OSI network layer. OpenTelemetry: network.type.
server.addresstext
  • Up to 256 characters
  • OpenTelemetry address: IPv4, IPv6, hostname, or a Unix domain socket path.
  • Exact pattern^(?:(?:(?:25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])\.){3}(?:25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])|(?:[0-9A-Fa-f]{1,4}:){7}[0-9A-Fa-f]{1,4}|(?:[0-9A-Fa-f]{1,4}:){1,7}:|(?:[0-9A-Fa-f]{1,4}:){1,6}:[0-9A-Fa-f]{1,4}|(?:[0-9A-Fa-f]{1,4}:){1,5}(?::[0-9A-Fa-f]{1,4}){1,2}|(?:[0-9A-Fa-f]{1,4}:){1,4}(?::[0-9A-Fa-f]{1,4}){1,3}|(?:[0-9A-Fa-f]{1,4}:){1,3}(?::[0-9A-Fa-f]{1,4}){1,4}|(?:[0-9A-Fa-f]{1,4}:){1,2}(?::[0-9A-Fa-f]{1,4}){1,5}|[0-9A-Fa-f]{1,4}:(?::[0-9A-Fa-f]{1,4}){1,6}|:(?:(?::[0-9A-Fa-f]{1,4}){1,7}|:)|[Ff][Ee]80:(?::[0-9A-Fa-f]{0,4}){0,4}%[0-9A-Za-z]+|::(?:[Ff]{4}(?::0{1,4})?:)?(?:(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9])\.){3}(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9])|(?:[0-9A-Fa-f]{1,4}:){1,4}:(?:(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9])\.){3}(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9])|(?=.{1,253}$)[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?(?:\.[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?)*\.?|/[^\u0000-\u0020]*)$
Address of the server the request went to. OpenTelemetry: server.address.
server.portwhole number
  • 0 or greater
  • 65535 or less
Server port. OpenTelemetry: server.port.
tls.client.hash.sha256text
  • SHA-256 digest, hex, either case.
  • Exact pattern^[A-Fa-f0-9]{64}$
SHA-256 fingerprint of the client certificate. OpenTelemetry: tls.client.hash.sha256.
tls.protocol.versiontext
  • Up to 16 characters
  • Numeric version like 1.1, 2, 1.3.
  • Exact pattern^[0-9]+(?:\.[0-9]+)*$
TLS version negotiated, e.g. 1.3. OpenTelemetry: tls.protocol.version.
url.domaintext
  • Up to 253 characters
  • DNS hostname (RFC 1123 labels, optional trailing dot, 253 chars max).
  • Exact pattern^(?=.{1,253}$)[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?(?:\.[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?)*\.?$
Domain extracted from the URL. OpenTelemetry: url.domain.
url.fulltext
  • Up to 8192 characters
  • Absolute URI: scheme, colon, no whitespace.
  • Exact pattern^[A-Za-z][A-Za-z0-9+.-]*:[^\u0000-\u0020]*$
Absolute URL including query. May contain PII. OpenTelemetry: url.full. Personal data. Can be sent hashed instead.
url.pathtext
  • Up to 4096 characters
  • URI path component starting with /, without query or fragment.
  • Exact pattern^/[^\u0000-\u0020?#]*$
The URI path component. OpenTelemetry: url.path.
user_agent.originaltext
  • Up to 1024 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
User-agent string as received. The box also parses it into server fields. OpenTelemetry: user_agent.original.

Device, browser and session

The thing in someone's hands, and the session it belonged to.

FieldAcceptsConstraintsNotes
browser.languagetext
  • Up to 35 characters
  • BCP 47 language tag (en, en-US, zh-Hant-TW).
  • Exact pattern^[A-Za-z]{2,3}(?:-[A-Za-z0-9]{2,8})*$
Preferred language of the user (navigator.language). OpenTelemetry: browser.language.
browser.mobiletrue or falseNo constraint beyond its type.Whether the browser reports running on a mobile device. OpenTelemetry: browser.mobile.
browser.nametext
  • Up to 64 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Browser name as claimed by the client (Chrome, Safari). The box also derives it from user_agent.original; a mismatch is an anomaly signal.
browser.platformtext
  • Up to 64 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Platform reported by UA client hints (Windows, macOS, Android). OpenTelemetry: browser.platform.
browser.versiontext
  • Up to 64 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Browser version as claimed by the client.
device.hostnametext
  • Up to 253 characters
  • DNS hostname (RFC 1123 labels, optional trailing dot, 253 chars max).
  • Exact pattern^(?=.{1,253}$)[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?(?:\.[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?)*\.?$
Network hostname of the device.
device.idtext
  • Up to 256 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Stable device identifier. OpenTelemetry: device.id.
device.local_iptext
  • Up to 64 characters
  • IPv4 or IPv6 address.
  • Exact pattern^(?:(?:(?:25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])\.){3}(?:25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])|(?:[0-9A-Fa-f]{1,4}:){7}[0-9A-Fa-f]{1,4}|(?:[0-9A-Fa-f]{1,4}:){1,7}:|(?:[0-9A-Fa-f]{1,4}:){1,6}:[0-9A-Fa-f]{1,4}|(?:[0-9A-Fa-f]{1,4}:){1,5}(?::[0-9A-Fa-f]{1,4}){1,2}|(?:[0-9A-Fa-f]{1,4}:){1,4}(?::[0-9A-Fa-f]{1,4}){1,3}|(?:[0-9A-Fa-f]{1,4}:){1,3}(?::[0-9A-Fa-f]{1,4}){1,4}|(?:[0-9A-Fa-f]{1,4}:){1,2}(?::[0-9A-Fa-f]{1,4}){1,5}|[0-9A-Fa-f]{1,4}:(?::[0-9A-Fa-f]{1,4}){1,6}|:(?:(?::[0-9A-Fa-f]{1,4}){1,7}|:)|[Ff][Ee]80:(?::[0-9A-Fa-f]{0,4}){0,4}%[0-9A-Za-z]+|::(?:[Ff]{4}(?::0{1,4})?:)?(?:(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9])\.){3}(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9])|(?:[0-9A-Fa-f]{1,4}:){1,4}:(?:(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9])\.){3}(?:25[0-5]|(?:2[0-4]|1?[0-9])?[0-9]))$
Device's local network address.
device.mactext
  • 48-bit MAC address, colon or hyphen separated.
  • Exact pattern^(?:[0-9A-Fa-f]{2}[:-]){5}[0-9A-Fa-f]{2}$
MAC address of the device. Personal data. Can be sent hashed instead.
device.managedtrue or falseNo constraint beyond its type.Whether the device is enrolled in device management (MDM).
device.manufacturertext
  • Up to 128 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Device manufacturer (Apple, Dell). OpenTelemetry: device.manufacturer.
device.model.identifiertext
  • Up to 128 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Machine-readable model identifier (MacBookPro18,3). OpenTelemetry: device.model.identifier.
device.model.nametext
  • Up to 128 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Marketing model name (MacBook Pro 16-inch). OpenTelemetry: device.model.name.
device.nametext
  • Up to 253 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Device name.
device.os.nametext
  • Up to 64 characters
  • Single line of text: spaces allowed, no control characters or line breaks.
  • Exact pattern^[^\u0000-\u001F\u007F-\u009F]+$
Operating system name of the actor's device (Windows, macOS, Linux, iOS, Android). enTrail field: OpenTelemetry os.* describes the telemetry host, not the actor's device.
device.os.versiontext
  • Up to 64 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Operating system version.
device.screen.heightwhole number
  • 1 or greater
Screen height in CSS pixels.
device.screen.pixel_rationumber
  • 0 or greater
Device pixel ratio.
device.screen.widthwhole number
  • 1 or greater
Screen width in CSS pixels.
device.typeone of a fixed set
  • Must be one of: computer phone tablet server iot other
Kind of device.
session.idtext
  • Up to 128 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Session the event belongs to. OpenTelemetry: session.id.
session.previous_idtext
  • Up to 128 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
The previous session id for this actor, when known (session renewal chains). OpenTelemetry: session.previous_id.

Data subject

For access and erasure requests about a person.

FieldAcceptsConstraintsNotes
data_subject.idtext
  • Up to 512 characters
  • Opaque identifier: no whitespace, no control characters. Fits UUIDs, ARNs, SIDs, emails-as-ids, URNs.
  • Exact pattern^[^\u0000-\u0020\u007F-\u00A0]+$
Identifier of the person whose personal data the event involves. Used by TRACE and access requests. Personal data. Can be sent hashed instead.
data_subject.typetext
  • Up to 64 characters
  • Machine token: letters, digits, dot, underscore, plus, colon, hyphen; no spaces.
  • Exact pattern^[A-Za-z0-9][A-Za-z0-9._+:-]*$
Kind of person whose personal data the event involves (patient, customer, employee). Distinct from actor (who acted) and target (what was acted on).

Your own fields

Fields outside this list are kept, sealed and queryable — they are simply not interpreted. To have your own names understood, a mapping profile translates them to these on the way in, and we write it for you today from a sample of your log lines.

Coming soon: defining and mapping your own custom fields yourself, in the console.

When this list changes

Field definitions are versioned and signed. New versions download automatically, and the box owner chooses when to adopt one, so a change never breaks a working integration overnight. A minor version only adds fields; removing one, or changing what an existing field means, requires a major version. Deprecated fields keep working with a warning and a stated removal version.