Table Queryables

Selector Queryables Table

These are queryables that return tables.

Table Queryables

Table QueryableQueryable CategoryDescriptionKey usageTypical Render Views
audit_logsAudit logsTable of Audit logsAuditing and compliance Monitoring: Trackers users, and their key actions on S2AP and timestamps.Table
configs_diffConfig change monitoringTracks if a device config has changed from a previous snapshot. Ex. Ip address changed of a deviceConfiguration change monitoring: Operators can monitor configuration changes to be able to pin point causes of issues.Honeycomb, line-plot
correlation_eventsCorrelated InsightsTable that stores correlated events metadata, the records in this table are correlated and anchored by specific labels to improve event grouping.Correlated Insights: Used to monitor correlated events to get a comprehensive view of root cause of issuesTable
correlations_summaryCorrelated InsightsTable that stores the summary of correlated events used in the correlations graph and dashboardsTable
device_event_patternsDevice EventsTable that stores structured log event patterns from networking devices. Event patterns are categorized as .. to facilitate trend analysis and automated correlation.Log Pattern Analysis: Used for analysing network event patterns from logsTable
device_events_mlDevice EventsTable that stores structured log event stream from networking devices that have been processed and modeled using Machine Learning. Unlike raw logs, these events are categorized (e.g., Interface Flap, BGP Peer Down) to facilitate trend analysis and automated correlation.Log Pattern Analysis: Used for analysing network event patterns from logsTable
device_events_pattern_groupsDevice EventsTable that stores structured log event patterns and groups from networking devices. Event pattern groups are categorized to facilitate trend analysis and automated correlation.Log Pattern Analysis: Used for analysing network event patterns from logsTable
device_logsDevice LogsTable that stores the raw logs ingested from the network devices. This contains the original log messages, timestamps, and severity levels without the ML modeling layer.Raw logs analysis and troubleshootingHoneycomb, line-plot
devicediscoveryDevice DiscoveryTable that contains the raw device discovery inventoryTable
interface_database_inventoryInterface InventoryMetastore Inventory table containing detailed information about network interfaces. It provides metadata such as interface names, descriptions, speeds, types, and connected remote devices.Contextualize interface metrics with interface config metadataTable
ipsec_logsTable
ipsec_reason_events_mlIPSec stateTable that stores IPsec events informationTable
isp_inventoryISP Inventory TableTable that stores key isp information for devicesISP inventory:Table
layer2_topologyLayer 2 TopologyTable containing Layer 2 topology data.Layer 2 Topology InventoryTable, Topology map
lldp_tableLLDPTable that holds LLDP inventory (Link Layer Discovery Protocol)LLDP Monitoring: Operators use LLDP to discover device topologies, and build a topology mapTable
s2_device_inventoryDevice InventoryMetastore inventory table containing detailed metadata about all network devices. It serves as the source of truth for device attributes like Vendor, Model, Operating System, Site, Location, and Roles.Contextualize metrics and logs with device metadataTable
s2_if_metatagsInterface MetadataInterface metadata?Table
s2_query_traceQuery MetadataThis table stores query details such as S2QL or Natural Language queries, usage metrics, user who executed the query and the time to return a response.Query monitoring: Operators use this to track details around the queries being executed by users, their usage and the performance of those queriesTable
s2_snow_incidentsService Now IncidentsTable that stores the SNOW incidents dataSNOW Incident monitoringTable
s2_snow_incidents_analysisService Now IncidentsTable that has Service Now Incidents data for incident analysis dashboardsSNOW Incident monitoringTable
s2_snow_inventoryService Now IncidentsTable that stores the SNOW incidents dataSNOW Incident monitoringTable
snmptrap_default_eventSNMP TrapsLanding table for initial ingestion of SNMP trapsSNMP Trap monitoringTable
synthetics_topologySyntheticsTable that has the synthetics probe inventory.Table
sys_logsDevice LogsTable that stores the raw system log stream ingested from the network devices. This stream contains the original log messages, timestamps, and severity levels without the ML modeling layer.Raw logs analysis and troubleshootingHoneycomb, line-plot
topology_bgpTopology StateTable that stores BGP topology dataTopology State: Operators use this to get BGP Topology informationTable, Topology Map
topology_isisTopology StateTable that stores ISIS topology dataTopology State: Operators use this to get ISIS Topology information.Table, Topology Map
topology_l3vpnTopology StateTable that stores L3VPN topology dataTopology State: Operators use this to get L3VPN Topology information.Table, Topology Map
topology_ldpTopology StateTable that stores LDP topology dataTopology State: Operators use this to get LDP Topology information.Table, Topology Map
topology_ospfTopology StateTable that stores OSPF topology dataTopology State: Operators use this to get OSPF Topology information.Table, Topology Map