Skip to main content

macOS Telemetry Schema

This page documents the complete schema for all telemetry event types collected by Workshop from Santa agents on macOS.

Each event type below is also the table-name prefix in SQL queries: Execution fields live in execution_2025, execution_202501, or execution_20250125 (see table naming). Columns drift across Santa versions, so DESCRIBE execution_20250125 on your own data is the authoritative list.

Contents​

Event tables

Common types

ProcessID, UserInfo, GroupInfo, Hash, Stat, FileInfoLight, FileInfo, CodeSignature, CertificateInfo, Entitlement, EntitlementInfo, ProcessInfoLight, ProcessInfo, FileDescriptor, SocketAddress, GraphicalSession

Base Fields​

FieldTypeDescription
EventIDtextUnique identifier for the event
MachineIDtextThe unique machine ID (host UUID)
HostnametextThe hostname of the machine at the time of the event
BootSessionUUIDtextUnique identifier for the boot session
EventTimetimestampWhen the event occurred
ProcessedTimetimestampWhen Workshop processed the event
OperatingSystemtextThe platform the telemetry came from, always macos in these tables

Process Events​

execution​

Process execution events.

FieldTypeDescription
InstigatorProcessInfoLightParent process
TargetProcessInfoExecuted process
ScriptFileInfoThe script that was being executed, if applicable
WorkingDirectoryFileInfoThe working directory
Argstext arrayCommand-line arguments
Envstext arrayEnvironment variables
FDsFileDescriptor arrayThe open file descriptors at time of execution
FDListTruncatedbooleanWhether the list in FDs is truncated
DecisiontextThe decision that was made by Santa, e.g. DECISION_ALLOW
ReasontextThe reason that Santa made the decision it did, e.g. REASON_CERT
ModetextSanta's client mode at the time of the event, e.g. MODE_MONITOR
CertificateInfoCertificateInfoThe common name and hash of the leaf certificate that signed this binary, if applicable
ExplaintextPossible additional context related to this execution
QuarantineURLtextThe URL the binary was downloaded from, if known
OriginalPathtextThe original on-disk path of the target executable, applies when binaries are translocated (https://developer.apple.com/forums/thread/724969)
EntitlementInfoEntitlementInfoThe entitlements attached to this binary
RuleIDnumberThe ID of the rule that produced the decision, if applicable
StaticRulebooleanWhether the decision came from a static (configuration profile) rule
AuditReturnbooleanWhether the decision was made in audit (non-blocking) mode
TemporaryMonitorModebooleanWhether the reported Mode came from an active Temporary Monitor Mode session rather than the configured client mode

fork​

Process fork events.

FieldTypeDescription
InstigatorProcessInfoLightParent process
ChildProcessInfoLightChild processes

exit​

Process termination events.

FieldTypeDescription
InstigatorProcessInfoLightExiting process
ExitCodenumberExit code of the process (set when process exits normally)
SignalednumberSignal number that terminated the process (set when terminated by signal)
StoppednumberSignal number that stopped the process (set when stopped by signal)

proc_suspend_resume​

Process suspend and resume events.

FieldTypeDescription
InstigatorProcessInfoLightThe process that initiated the suspend/resume action
TargetProcessInfoThe process being suspended or resumed
TypetextThe type of action, e.g. TYPE_SUSPEND

codesigning_invalidated​

Code signature invalidation events.

FieldTypeDescription
InstigatorProcessInfoLightProcess with invalidated signature

File System Events​

close​

File close events.

FieldTypeDescription
InstigatorProcessInfoLightThe process closing the file
TargetFileInfoThe file being closed
ModifiedbooleanWhether file was modified

file_access​

File access monitoring events.

FieldTypeDescription
InstigatorProcessInfoThe process accessing the file
TargetFileInfoThe file being accessed
PolicyVersiontextThe version of the file-access policy
PolicyNametextThe name of the file-access policy
AccessTypetextThe type of event that attempted access, e.g. ACCESS_TYPE_UNLINK
PolicyDecisiontextThe decision that was made, e.g. POLICY_DECISION_ALLOWED_AUDIT_ONLY
OperationIDtextUnique operation identifier, used to link a single operation when a single operation violates multiple policies
RuleIDnumberThe ID of the file-access rule that produced the decision, if applicable

rename​

File rename/move events.

FieldTypeDescription
InstigatorProcessInfoLightThe process that is renaming the file
SourceFileInfoThe source file
TargettextThe destination path
TargetExistedbooleanWhether or not the destination path already existed

Hard link creation events.

FieldTypeDescription
InstigatorProcessInfoLightThe process making the link
SourceFileInfoThe source file
TargettextLink path

File deletion events.

FieldTypeDescription
InstigatorProcessInfoLightThe process unlinking the file
TargetFileInfoThe deleted file info

clone​

File clone (copy-on-write) events.

FieldTypeDescription
InstigatorProcessInfoLightProcess performing the clone
SourceFileInfoSource file
TargettextClone destination

exchangedata​

Atomic data exchange between files events.

FieldTypeDescription
InstigatorProcessInfoLightProcess performing the exchange
File1FileInfoFirst file
File2FileInfoSecond file

copyfile​

File copy events.

FieldTypeDescription
InstigatorProcessInfoLightThe process performing the copy
SourceFileInfoThe source file
TargettextThe destination path
TargetExistedbooleanWhether or not the destination path already existed
ModenumberThe mode of the copied file
FlagsnumberThe copyfile flags for the operation

Authentication & Session Events​

authentication​

Authentication attempts. Exactly one of the subtype fields is populated, depending on the authentication method.

FieldTypeDescription
SuccessbooleanAuthentication result
ODOpenDirectory subtypeOpenDirectory authentication data, when the attempt used it
TouchIDTouchID subtypeTouch ID authentication data, when the attempt used it
TokenToken subtypeToken authentication data, when the attempt used it
AutoUnlockAutoUnlock subtypeAuto unlock authentication data, when the attempt used it

OpenDirectory subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess performing the authentication
TriggerProcessProcessInfoLightProcess that triggered the authentication
TriggerIDProcessIDProcess ID of the trigger process
RecordTypetextOpenDirectory record type
RecordNametextOpenDirectory record name
NodeNametextOpenDirectory node name
DBPathtextPath to the OpenDirectory database

TouchID subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess performing the authentication
TriggerProcessProcessInfoLightProcess that triggered the authentication
TriggerIDProcessIDProcess ID of the trigger process
ModetextTouch ID mode
UserUserInfoUser being authenticated

Token subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess performing the authentication
TriggerProcessProcessInfoLightProcess that triggered the authentication
TriggerIDProcessIDProcess ID of the trigger process
PubkeyHashtextHash of the public key
TokenIDtextToken identifier
KerberosPrincipaltextKerberos principal

AutoUnlock subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess performing the authentication
UserInfoUserInfoUser being authenticated
TypetextAuto unlock type

login_logout​

Console login/logout events. This event type has subtypes for login and logout.

Login subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess handling the login
SuccessbooleanWhether login was successful
FailureMessagetextError message if login failed
UserUserInfoUser logging in

Logout subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess handling the logout
UserUserInfoUser logging out

login_window_session​

GUI session events. This event type has subtypes for different session actions.

Login subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess handling the session login
UserUserInfoUser logging in
GraphicalSessionGraphicalSessionGraphical session information

Logout subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess handling the session logout
UserUserInfoUser logging out
GraphicalSessionGraphicalSessionGraphical session information

Lock subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess handling the session lock
UserUserInfoUser whose session is being locked
GraphicalSessionGraphicalSessionGraphical session information

Unlock subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess handling the session unlock
UserUserInfoUser whose session is being unlocked
GraphicalSessionGraphicalSessionGraphical session information

open_ssh​

SSH authentication events. This event type has subtypes for SSH login and logout.

Login subtype:

FieldTypeDescription
InstigatorProcessInfoLightSSH daemon process
ResulttextAuthentication result
SourceSocketAddressSource address of the SSH connection
UserUserInfoUser attempting to log in

Logout subtype:

FieldTypeDescription
InstigatorProcessInfoLightSSH daemon process
SourceSocketAddressSource address of the SSH connection
UserUserInfoUser logging out

Security Events​

allowlist​

Binary allowlist addition events.

FieldTypeDescription
InstigatorProcessInfoLightProcess that added the binary to the allowlist
TargetFileInfoBinary being added to the allowlist

bundle​

Bundle hash events.

FieldTypeDescription
FileHashHashHash of the individual file
BundleHashHashHash of the entire bundle
BundleNametextName of the bundle
BundleIDtextBundle identifier
BundlePathtextPath to the bundle
PathtextPath to the file within the bundle

gatekeeper_override​

Gatekeeper bypass events.

FieldTypeDescription
InstigatorProcessInfoLightProcess that bypassed Gatekeeper
TargetFileInfoFile that was allowed to run despite Gatekeeper
CodeSignatureCodeSignatureCode signing information

tcc_modification​

TCC (Transparency, Consent, and Control) database modification events.

FieldTypeDescription
InstigatorProcessInfoLightProcess modifying TCC database
ServicetextTCC service being modified (e.g., camera, microphone)
IdentitytextIdentity being granted/revoked access
IdentityTypetextType of identity (bundle ID, path, etc.)
EventTypetextType of modification event
AuthorizationRighttextAuthorization right being modified
AuthorizationReasontextReason for the authorization change
TriggerProcessProcessInfoLightProcess that triggered the modification
TriggerIDProcessIDProcess ID of the trigger process
ResponsibleProcessProcessInfoLightProcess responsible for the modification
ResponsibleIDProcessIDProcess ID of the responsible process

xprotect​

XProtect malware detection and remediation events. This event type has subtypes for detection and remediation.

Detected subtype:

FieldTypeDescription
InstigatorProcessInfoLightXProtect process that detected the malware
SignatureVersiontextVersion of the XProtect signature that detected the malware
MalwareIdentifiertextIdentifier for the detected malware
IncidentIdentifiertextUnique identifier for this detection incident
DetectedPathtextPath where malware was detected

Remediated subtype:

FieldTypeDescription
InstigatorProcessInfoLightXProtect process that remediated the malware
SignatureVersiontextVersion of the XProtect signature
MalwareIdentifiertextIdentifier for the remediated malware
IncidentIdentifiertextUnique identifier for this remediation incident
ActionTypetextType of remediation action taken
SuccessbooleanWhether remediation was successful
ResultDescriptiontextDescription of the remediation result
RemediatedPathtextPath that was remediated
RemediatedProcessIDProcessIDProcess ID of the remediated process, if applicable

screen_sharing​

Screen sharing connection events. This event type has subtypes for attach and detach.

Attach subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess handling the screen sharing connection
SuccessbooleanWhether the connection was successful
SourceSocketAddressSource address of the connection
ViewertextIdentifier of the viewer
AuthenticationTypetextType of authentication used
AuthenticationUserUserInfoUser that authenticated
SessionUserUserInfoUser whose session is being shared
ExistingSessionbooleanWhether connecting to an existing session
GraphicalSessionGraphicalSessionGraphical session information

Detach subtype:

FieldTypeDescription
InstigatorProcessInfoLightProcess handling the disconnection
SourceSocketAddressSource address of the connection
ViewertextIdentifier of the viewer
GraphicalSessionGraphicalSessionGraphical session information

System Events​

disk​

Disk mount/unmount events.

FieldTypeDescription
ActiontextWhether the disk appeared or disappeared, e.g. ACTION_APPEARED
MounttextThe path the disk is mounted at
VolumetextThe name of the volume that was attached
BSDNametextThe BSD name of the disk (e.g. /dev/disk2s1)
FStextThe filesystem on the disk
ModeltextDevice vendor and model information
SerialtextThe serial number of the attached disk
BustextThe bus path/protocol of the attached disk
DMGPathtextThe path of the backing disk image, if the disk is a disk image
AppearancetimestampThe time the device appeared/disappeared
MountFromtextThe path mounted from
EncryptedbooleanWhether the disk is encrypted

launch_item​

Launch item registration/removal events.

FieldTypeDescription
InstigatorProcessInfoLightProcess handling the launch item registration
ActiontextWhether a launch item was added or removed, e.g. ACTION_ADD
TriggerProcessProcessInfoLightThe process that triggered registration (one of TriggerProcess or TriggerID will be set)
TriggerIDProcessIDProcess ID that triggered registration (one of TriggerProcess or TriggerID will be set)
RegistrantProcessProcessInfoLightThe app that registered the launch item (may be set)
RegistrantIDProcessIDProcess ID of the app that registered the launch item (may be set)
ItemTypetextThe kind of item that was registered, e.g. ITEM_TYPE_AGENT, ITEM_TYPE_DAEMON
LegacybooleanWhether or not the launch item is a legacy plist
ManagedbooleanWhether or not the launch item is managed by MDM
ItemUserUserInfoUser information related to the launch item
ItemPathtextThe location of the launch item
AppPathtextThe path of the app the launch item is attributed to
ExecutablePathtextIf available, the associated executable path from the launch item plist

Network Events​

network_activity​

Network connection activity events. Each row represents a single network connection associated with a process.

FieldTypeDescription
ProcessProcessInfoThe process that initiated or received the flow
IDtextUnique identifier for this flow
HashtextHash of the flow
RemoteAddresstextRemote IP address
RemotePortnumberRemote port number
RemoteHostnametextRemote hostname, if known
LocalAddresstextLocal IP address
LocalPortnumberLocal port number
ProtocolRawnumberIANA protocol number
ProtocoltextProtocol name (e.g., TCP, UDP)
SocketFamilytextSocket family (e.g., SOCKET_FAMILY_INET)
DirectiontextFlow direction (e.g., DIRECTION_OUTBOUND)
DecisiontextThe decision that was made for the flow
DecisionTiertextThe tier that produced the decision
RuleIDnumberThe ID of the rule that produced the decision, if applicable
RuleNametextThe name of the rule that produced the decision, if applicable
BytesInboundnumberNumber of bytes received
BytesOutboundnumberNumber of bytes sent
StartTimetimestampWhen the flow started
CloseTimetimestampWhen the flow closed
info

LocalAddress is often 0.0.0.0 or :: for outbound flows. Santa records the flow when macOS first reports it, before macOS chooses the local interface.

RemoteHostname is present when the app resolved the hostname through Network framework, NSURLSession, or system DNS, or when another app resolved it shortly before. It is usually empty when the app connects to an IP address directly or uses its own DNS resolver. For hosts behind a CDN, the hostname can be a different name for the same address.

Inventory Events​

Unlike every other table on this page, inventory tables are not populated by the continuous telemetry stream. They are produced on demand by the Package Inventory command (Hosts → Commands → Run command), which asks each targeted host to run a read-only scan and upload the results into its normal telemetry prefix. A host that has never been scanned has no rows.

Two consequences worth knowing when querying:

  • BootSessionUUID is always empty. An on-demand scan isn't tied to a boot session.
  • EventTime is the scan time, not the time a package was installed — the scan observes current state and has no visibility into when it came to be.

packages​

One row per package discovered on a host. Every ecosystem shares this single table, distinguished by Ecosystem, so a fleet-wide query needs no unions.

FieldTypeDescription
EventIDtextUnique identifier for the inventory record
MachineIDtextThe unique machine ID (host UUID)
HostnametextThe hostname of the scanned host
BootSessionUUIDtextAlways empty because an inventory scan is not tied to a boot session
EventTimetimestampWhen the inventory scan observed the package
ProcessedTimetimestampWhen Workshop processed the inventory record
OperatingSystemtextThe platform the scanned host is running
RecordTypetextAlways package in this table
RunIDtextIdentifier shared by every row from one scan; use it to isolate a single scan's results
ProfiletextScan profile that produced the row: baseline, project, or deep
Ecosystemtextnpm, pypi, go, rubygems, packagist, mcp, editor-extension, browser-extension, homebrew, agent-skill, or nix
PackageNametextPackage name as written in the manifest or lock file
NormalizedNametextEcosystem-normalized name — join on this rather than PackageName
VersiontextInstalled version. Empty when no exact version could be determined
ProjectPathtextRoot of the project the package belongs to, for project-scoped finds
RootKindtextWhy the containing directory was walked: global_package_root, user_package_root, project_root, editor_extension_root, browser_extension_root, mcp_config_root, homebrew_root, nix_root, agent_skill_root, deep_home_root, or unknown
InstallScopetextEcosystem-specific dependency scope (e.g. prod/dev for npm and pnpm, indirect for Go modules)
PackageManagertextManager that installed the package (e.g. npm, pnpm, homebrew, firefox-extension)
SourceTypetextKind of evidence the row came from (e.g. package.json, browser-extension)
SourceFiletextPath to the manifest, lock file, or metadata file the row was read from
DirectDependencybooleanWhether the package is directly depended on rather than transitive. Null when the ecosystem can't distinguish
HasLifecycleScriptsbooleanWhether the package declares install-time lifecycle scripts — these execute on install, so they are a supply-chain execution surface
LifecycleScriptstext arrayNames of the declared lifecycle scripts
ConfidencetextHow certain the identification is: high; medium when the name or version had to be inferred; or low when the row records that something is present without identifying what it is — an MCP server entry with no resolvable package, or an agent skill with no upstream source
RequestedSpectextFor MCP entries configured by spec, the requested selector (e.g. @playwright/mcp@latest) with PackageName normalized to the bare name
LocalAliastextLocal name assigned in a config file, where that differs from the package it resolves to. Set only for mcp (the key under mcpServers) and agent-skill (the local skill name)

Common Nested Types​

The following types are used throughout the telemetry schema to represent shared data structures.

ProcessID​

Unique identifier for a process during OS runtime.

FieldTypeDescription
PIDnumberProcess ID
PIDVersionnumberProcess ID version for tracking across PID reuse

UserInfo​

User identification information.

FieldTypeDescription
UIDnumberUser ID
NametextUser name

GroupInfo​

Group identification information.

FieldTypeDescription
GIDnumberGroup ID
NametextGroup name

Hash​

Cryptographic hash information.

FieldTypeDescription
TypetextHash algorithm (e.g., HASH_ALGO_SHA256)
HashtextHash value

Stat​

File metadata from stat(2) syscall.

FieldTypeDescription
DevnumberDevice ID
ModenumberFile mode and permissions
NlinknumberNumber of hard links
InonumberInode number
UserUserInfoFile owner
GroupGroupInfoFile group
RdevnumberDevice ID for special files
AccessTimetimestampLast access time
ModificationTimetimestampLast modification time
ChangeTimetimestampLast status change time
BirthTimetimestampCreation time
SizenumberFile size in bytes
BlocksnumberNumber of blocks allocated
BlksizenumberBlock size for filesystem I/O
FlagsnumberUser defined flags
GennumberFile generation number

FileInfoLight​

Basic file information with path only.

FieldTypeDescription
PathtextFile path
TruncatedbooleanWhether the path was truncated

FileInfo​

Comprehensive file information.

FieldTypeDescription
PathtextFile path
TruncatedbooleanWhether the path was truncated
StatStatFile metadata
HashHashFile content hash

CodeSignature​

Code signing information.

FieldTypeDescription
CDHashtextCode directory hash (hex)
SigningIDtextSigning identifier
TeamIDtextTeam identifier
SigningTimetimestampSigning timestamp
SecureSigningTimetimestampSecure timestamp from signing

CertificateInfo​

Certificate information for signed code.

FieldTypeDescription
HashHashCertificate hash
CommonNametextCertificate common name

Entitlement​

Individual entitlement key-value pair.

FieldTypeDescription
KeytextEntitlement key
ValuetextEntitlement value

EntitlementInfo​

Collection of process entitlements.

FieldTypeDescription
EntitlementsFilteredbooleanWhether the entitlements list was filtered
EntitlementsEntitlement arrayList of entitlements

ProcessInfoLight​

Lightweight process information.

FieldTypeDescription
IDProcessIDProcess identifier
ParentIDProcessIDParent process identifier
OriginalParentPIDnumberOriginal parent PID (before reparenting)
GroupIDnumberProcess group ID
SessionIDnumberSession ID
EffectiveUserUserInfoEffective user
EffectiveGroupGroupInfoEffective group
RealUserUserInfoReal user
RealGroupGroupInfoReal group
ExecutableFileInfoLightExecutable file path
Annotationstext arrayNames of the annotations added to the process by CEL rules via add_annotation(), sorted

ProcessInfo​

Full process information.

FieldTypeDescription
IDProcessIDProcess identifier
ParentIDProcessIDParent process identifier
ResponsibleIDProcessIDResponsible process identifier
OriginalParentPIDnumberOriginal parent PID (before reparenting)
GroupIDnumberProcess group ID
SessionIDnumberSession ID
EffectiveUserUserInfoEffective user
EffectiveGroupGroupInfoEffective group
RealUserUserInfoReal user
RealGroupGroupInfoReal group
IsPlatformBinarybooleanWhether this is a platform binary
IsESClientbooleanWhether this is an Endpoint Security client
CodeSignatureCodeSignatureCode signing information
CSFlagsnumberCode signing flags
ExecutableFileInfoExecutable file information
TTYFileInfoLightAssociated TTY device
StartTimetimestampProcess start time
Annotationstext arrayNames of the annotations added to the process by CEL rules via add_annotation(), sorted

FileDescriptor​

An open file descriptor.

FieldTypeDescription
FDnumberFile descriptor number
FDTypetextThe type of file descriptor, e.g. FD_TYPE_PIPE
PipeIDnumberThe unique ID of the pipe, when the descriptor is a pipe

SocketAddress​

A network socket address.

FieldTypeDescription
AddressbytesThe socket address
TypetextThe address type, e.g. SOCKET_ADDRESS_TYPE_IPV4

GraphicalSession​

A graphical (windowed) session identifier.

FieldTypeDescription
IDnumberGraphical session identifier