Run ReportsContinuous Data ExportsSchema Reference

Export JSONL Schema

Understand the JSONL schema structure for assets, risks, vulnerabilities, and check results in Mondoo exports.

When you export data from Mondoo in JSONL format, each line is a JSON object that follows one of the schemas below. Use this reference to understand the structure of exported data when building custom integrations, dashboards, or data pipelines.

  • Asset. One record per asset Mondoo has scanned, including identifiers, platform, labels, risk scores, end-of-life status, and SLA counts.

  • Check result. One record per (asset, policy check) pair, including pass/fail state, severity, scores, and the check's MQL.

  • Vulnerability. One record per (asset, CVE) pair, including CVSS metrics, EPSS data, risk scores, and SLA status.

  • Package. One record per vulnerable package on an asset, including the installed and fixed versions and the vulnerabilities that affect it.

  • Risk factor. Contextual risk factors applied to a finding (Internet-facing, EOL, In use, and so on).

  • Query result. One record per query pack query that ran against an asset, with the structured query output.

  • Control. One record per (asset, compliance control) pair, including the control state, score, and the checks and queries that map to it.

Export file names

In storage destinations such as Amazon S3, Azure Blob Storage, and Google Cloud Storage, each export run writes one file per record type. File names follow the pattern TIMESTAMP-SPACE_ID-TYPE.jsonl (or .csv for CSV exports), where TIMESTAMP is the run time in YYYYMMDDhhmmss format and TYPE identifies the records in the file:

TYPERecords
assetsAsset
checksCheck result
vulnVulnerability
packagesPackage
queriesQuery result
controlsControl

Risk factors don't have a file of their own. They're embedded in the asset, vulnerability, and package records.

On this page