Asset Export Schema
Reference the asset object schema and properties used in Mondoo JSONL exports.
This is the schema Mondoo uses when exporting asset data to JSONL.
Asset type
object
Asset properties
space_mrn property
Mondoo identifier for the space containing the asset
space_mrn
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
space_id property
Unique identifier for the space containing the asset
space_id
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
space_name property
Name of the space containing the asset
space_name
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
asset_id property
Space-unique asset identifier
asset_id
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
mrn property
Globally unique asset MRN. Deprecated: use asset_mrn instead.
mrn
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
asset_mrn property
Globally unique asset MRN
asset_mrn
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
name property
Asset display name
name
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
platform_name property
Name of the asset's platform
platform_name
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
error property
Error message if scan failed
error
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
created_at property
Asset creation time. This is a date-time string matching RFC 3339, section 5.6.
created_at
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
score_updated_at property
Timestamp when the score of this asset was last updated. This is a date-time string matching RFC 3339, section 5.6.
score_updated_at
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
updated_at property
Timestamp when this asset was last updated. This is a date-time string matching RFC 3339, section 5.6.
updated_at
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
labels property
Metadata that Mondoo collects from assets (such as cloud tags and Kubernetes labels)
labels
| Type | Required? | Nullable? |
|---|---|---|
| Object | Yes | No |
annotations property
Metadata that Mondoo users add to assets
annotations
| Type | Required? | Nullable? |
|---|---|---|
| Object | Yes | No |
exported_at property
Timestamp when this data was exported. This is a date-time string matching RFC 3339, section 5.6.
exported_at
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
time_travel_id property
Point-in-time query ID
time_travel_id
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
url property
Console URL for the asset
url
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
risk_factors property
Read Risk Factor Export Schema.
base_score property
Calculated base score (0-100)
base_score
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
risk_score property
Risk score (0-100)
risk_score
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
risk_value property
Derived value: 100 - risk_score
risk_value
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
preview_risk_score property
Risk score from a preview version of the Mondoo risk scoring model (0-100). Null when no preview score is available.
preview_risk_score
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | Yes |
preview_risk_value property
Derived value: 100 - preview_risk_score. Null when preview_risk_score is null.
preview_risk_value
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | Yes |
security_base_score property
Security-specific base score
security_base_score
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
security_risk_score property
Security-specific risk score
security_risk_score
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
vuln_base_score property
Vulnerability-specific base score
vuln_base_score
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
vuln_risk_score property
Vulnerability-specific risk score
vuln_risk_score
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
eol_status property
Whether the asset platform is end-of-life. Null when unknown.
eol_status
| Type | Required? | Nullable? |
|---|---|---|
| Boolean | Yes | Yes |
eol_date property
Date the platform enters (or entered) end-of-life status. This is a date-time string matching RFC 3339, section 5.6.
eol_date
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | Yes |
eol_plan property
Support plan type: standard, ubuntu-pro, els, esu, ltss, or sles-sap
eol_plan
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
last_cnspec_scan_time property
Time a cnspec scan last finished uploading results for this asset. Null when cnspec has never reported a completed scan. This is a date-time string matching RFC 3339, section 5.6.
last_cnspec_scan_time
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | Yes |
last_upstream_scan_time property
Time of the most recent scan from an upstream third-party scanner (such as SentinelOne, Microsoft Defender, or CrowdStrike). Null when no upstream scan has occurred. This is a date-time string matching RFC 3339, section 5.6.
last_upstream_scan_time
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | Yes |
worst_sla_state property
Worst SLA position among the asset's open CVE findings as of the export run: over, nearing, within, or none
worst_sla_state
| Type | Required? | Nullable? |
|---|---|---|
| String | Yes | No |
sla_over_critical property
Number of open CVE findings rated critical that are past their SLA deadline
sla_over_critical
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
sla_over_high property
Number of open CVE findings rated high that are past their SLA deadline
sla_over_high
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
sla_over_medium property
Number of open CVE findings rated medium that are past their SLA deadline
sla_over_medium
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
sla_over_low property
Number of open CVE findings rated low that are past their SLA deadline
sla_over_low
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
sla_nearing_critical property
Number of open CVE findings rated critical inside their SLA warning window, not yet past the deadline
sla_nearing_critical
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
sla_nearing_high property
Number of open CVE findings rated high inside their SLA warning window, not yet past the deadline
sla_nearing_high
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
sla_nearing_medium property
Number of open CVE findings rated medium inside their SLA warning window, not yet past the deadline
sla_nearing_medium
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
sla_nearing_low property
Number of open CVE findings rated low inside their SLA warning window, not yet past the deadline
sla_nearing_low
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
sla_within_critical property
Number of open CVE findings rated critical with an SLA, not yet in the warning window
sla_within_critical
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
sla_within_high property
Number of open CVE findings rated high with an SLA, not yet in the warning window
sla_within_high
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
sla_within_medium property
Number of open CVE findings rated medium with an SLA, not yet in the warning window
sla_within_medium
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |
sla_within_low property
Number of open CVE findings rated low with an SLA, not yet in the warning window
sla_within_low
| Type | Required? | Nullable? |
|---|---|---|
| Integer | Yes | No |