Table Queryables
Selector Queryables Table
These are queryables that return tables.
Table Queryables
| Table Queryable | Queryable Category | Description | Key usage | Typical Render Views |
|---|---|---|---|---|
| audit_logs | Audit logs | Table of Audit logs | Auditing and compliance Monitoring: Trackers users, and their key actions on S2AP and timestamps. | Table |
| configs_diff | Config change monitoring | Tracks if a device config has changed from a previous snapshot. Ex. Ip address changed of a device | Configuration change monitoring: Operators can monitor configuration changes to be able to pin point causes of issues. | Honeycomb, line-plot |
| correlation_events | Correlated Insights | Table that stores correlated events metadata, the records in this table are correlated and anchored by specific labels to improve event grouping. | Correlated Insights: Used to monitor correlated events to get a comprehensive view of root cause of issues | Table |
| correlations_summary | Correlated Insights | Table that stores the summary of correlated events used in the correlations graph and dashboards | Table | |
| device_event_patterns | Device Events | Table that stores structured log event patterns from networking devices. Event patterns are categorized as .. to facilitate trend analysis and automated correlation. | Log Pattern Analysis: Used for analysing network event patterns from logs | Table |
| device_events_ml | Device Events | Table that stores structured log event stream from networking devices that have been processed and modeled using Machine Learning. Unlike raw logs, these events are categorized (e.g., Interface Flap, BGP Peer Down) to facilitate trend analysis and automated correlation. | Log Pattern Analysis: Used for analysing network event patterns from logs | Table |
| device_events_pattern_groups | Device Events | Table that stores structured log event patterns and groups from networking devices. Event pattern groups are categorized to facilitate trend analysis and automated correlation. | Log Pattern Analysis: Used for analysing network event patterns from logs | Table |
| device_logs | Device Logs | Table that stores the raw logs ingested from the network devices. This contains the original log messages, timestamps, and severity levels without the ML modeling layer. | Raw logs analysis and troubleshooting | Honeycomb, line-plot |
| devicediscovery | Device Discovery | Table that contains the raw device discovery inventory | Table | |
| interface_database_inventory | Interface Inventory | Metastore Inventory table containing detailed information about network interfaces. It provides metadata such as interface names, descriptions, speeds, types, and connected remote devices. | Contextualize interface metrics with interface config metadata | Table |
| ipsec_logs | Table | |||
| ipsec_reason_events_ml | IPSec state | Table that stores IPsec events information | Table | |
| isp_inventory | ISP Inventory Table | Table that stores key isp information for devices | ISP inventory: | Table |
| layer2_topology | Layer 2 Topology | Table containing Layer 2 topology data. | Layer 2 Topology Inventory | Table, Topology map |
| lldp_table | LLDP | Table that holds LLDP inventory (Link Layer Discovery Protocol) | LLDP Monitoring: Operators use LLDP to discover device topologies, and build a topology map | Table |
| s2_device_inventory | Device Inventory | Metastore inventory table containing detailed metadata about all network devices. It serves as the source of truth for device attributes like Vendor, Model, Operating System, Site, Location, and Roles. | Contextualize metrics and logs with device metadata | Table |
| s2_if_metatags | Interface Metadata | Interface metadata? | Table | |
| s2_query_trace | Query Metadata | This table stores query details such as S2QL or Natural Language queries, usage metrics, user who executed the query and the time to return a response. | Query monitoring: Operators use this to track details around the queries being executed by users, their usage and the performance of those queries | Table |
| s2_snow_incidents | Service Now Incidents | Table that stores the SNOW incidents data | SNOW Incident monitoring | Table |
| s2_snow_incidents_analysis | Service Now Incidents | Table that has Service Now Incidents data for incident analysis dashboards | SNOW Incident monitoring | Table |
| s2_snow_inventory | Service Now Incidents | Table that stores the SNOW incidents data | SNOW Incident monitoring | Table |
| snmptrap_default_event | SNMP Traps | Landing table for initial ingestion of SNMP traps | SNMP Trap monitoring | Table |
| synthetics_topology | Synthetics | Table that has the synthetics probe inventory. | Table | |
| sys_logs | Device Logs | Table that stores the raw system log stream ingested from the network devices. This stream contains the original log messages, timestamps, and severity levels without the ML modeling layer. | Raw logs analysis and troubleshooting | Honeycomb, line-plot |
| topology_bgp | Topology State | Table that stores BGP topology data | Topology State: Operators use this to get BGP Topology information | Table, Topology Map |
| topology_isis | Topology State | Table that stores ISIS topology data | Topology State: Operators use this to get ISIS Topology information. | Table, Topology Map |
| topology_l3vpn | Topology State | Table that stores L3VPN topology data | Topology State: Operators use this to get L3VPN Topology information. | Table, Topology Map |
| topology_ldp | Topology State | Table that stores LDP topology data | Topology State: Operators use this to get LDP Topology information. | Table, Topology Map |
| topology_ospf | Topology State | Table that stores OSPF topology data | Topology State: Operators use this to get OSPF Topology information. | Table, Topology Map |