Wire format and vendor field documentation for each benchmarked log source.
Wire format and vendor field documentation for the sources in the
benchmark tables. Format selects the reduction
method: JSON sources reserialize to CSV at
60–68%, and
fixed-order formats trim by dropping named fields.
Links resolve as of 17 July 2026. Cisco and Red Hat block automated link
checks — open those by hand. Volume-driver notes need a human check
before client-facing use. Sample log lines appear only where a direct fetch
confirmed them character for character.
Zscaler NSS feeds carry no fixed field order. An administrator composes the
output from a feed template, so the field dictionary rather than a sample line
defines the contract.
These sources still need a verified field reference. Cisco and Red Hat block
automated checks, so their entries above carry a documentation URL that a human
opens; the sources below need both the URL and a format confirmed by a direct
read.
Okta System Log, Azure Activity, Azure NSG flow, and Entra ID sign-in
GCP VPC Flow, GCP Cloud Audit, and Google Workspace audit
CrowdStrike Falcon Data Replicator, Microsoft Defender for Endpoint,
SentinelOne, and Carbon Black
Blue Coat ProxySG, Netskope, Cloudflare Logpush, Akamai, and Squid
Snort, Cisco IOS and NX-OS device syslog, Cisco ISE, and Cisco Umbrella
Kubernetes audit and container logs, web server access logs, DHCP, F5 APM,
and NetScaler
vSphere metrics — the reference belongs to ESXi and vCenter syslog. Aria
Operations for Logs consumes logs rather than emitting them