Run ReportsContinuous Data ExportsSchema Reference

Asset Export Schema

Reference the asset object schema and properties used in Mondoo JSONL exports.

This is the schema Mondoo uses when exporting asset data to JSONL.

Asset type

object

Asset properties

PropertyTypeRequired?Nullable?
space_mrnstringYesNo
space_idstringYesNo
space_namestringYesNo
asset_idstringYesNo
mrnstringYesNo
asset_mrnstringYesNo
namestringYesNo
platform_namestringYesNo
errorstringYesNo
created_atstringYesNo
score_updated_atstringYesNo
updated_atstringYesNo
labelsobjectYesNo
annotationsobjectYesNo
exported_atstringYesNo
time_travel_idstringYesNo
urlstringYesNo
risk_factorsJSONYesNo
base_scoreintegerYesNo
risk_scoreintegerYesNo
risk_valueintegerYesNo
preview_risk_scoreintegerYesYes
preview_risk_valueintegerYesYes
security_base_scoreintegerYesNo
security_risk_scoreintegerYesNo
vuln_base_scoreintegerYesNo
vuln_risk_scoreintegerYesNo
eol_statusbooleanYesYes
eol_datestringYesYes
eol_planstringYesNo
last_cnspec_scan_timestringYesYes
last_upstream_scan_timestringYesYes
worst_sla_statestringYesNo
sla_over_criticalintegerYesNo
sla_over_highintegerYesNo
sla_over_mediumintegerYesNo
sla_over_lowintegerYesNo
sla_nearing_criticalintegerYesNo
sla_nearing_highintegerYesNo
sla_nearing_mediumintegerYesNo
sla_nearing_lowintegerYesNo
sla_within_criticalintegerYesNo
sla_within_highintegerYesNo
sla_within_mediumintegerYesNo
sla_within_lowintegerYesNo

space_mrn property

Mondoo identifier for the space containing the asset

space_mrn

TypeRequired?Nullable?
StringYesNo

space_id property

Unique identifier for the space containing the asset

space_id

TypeRequired?Nullable?
StringYesNo

space_name property

Name of the space containing the asset

space_name

TypeRequired?Nullable?
StringYesNo

asset_id property

Space-unique asset identifier

asset_id

TypeRequired?Nullable?
StringYesNo

mrn property

Globally unique asset MRN. Deprecated: use asset_mrn instead.

mrn

TypeRequired?Nullable?
StringYesNo

asset_mrn property

Globally unique asset MRN

asset_mrn

TypeRequired?Nullable?
StringYesNo

name property

Asset display name

name

TypeRequired?Nullable?
StringYesNo

platform_name property

Name of the asset's platform

platform_name

TypeRequired?Nullable?
StringYesNo

error property

Error message if scan failed

error

TypeRequired?Nullable?
StringYesNo

created_at property

Asset creation time. This is a date-time string matching RFC 3339, section 5.6.

created_at

TypeRequired?Nullable?
StringYesNo

score_updated_at property

Timestamp when the score of this asset was last updated. This is a date-time string matching RFC 3339, section 5.6.

score_updated_at

TypeRequired?Nullable?
StringYesNo

updated_at property

Timestamp when this asset was last updated. This is a date-time string matching RFC 3339, section 5.6.

updated_at

TypeRequired?Nullable?
StringYesNo

labels property

Metadata that Mondoo collects from assets (such as cloud tags and Kubernetes labels)

labels

TypeRequired?Nullable?
ObjectYesNo

annotations property

Metadata that Mondoo users add to assets

annotations

TypeRequired?Nullable?
ObjectYesNo

exported_at property

Timestamp when this data was exported. This is a date-time string matching RFC 3339, section 5.6.

exported_at

TypeRequired?Nullable?
StringYesNo

time_travel_id property

Point-in-time query ID

time_travel_id

TypeRequired?Nullable?
StringYesNo

url property

Console URL for the asset

url

TypeRequired?Nullable?
StringYesNo

risk_factors property

Read Risk Factor Export Schema.

base_score property

Calculated base score (0-100)

base_score

TypeRequired?Nullable?
IntegerYesNo

risk_score property

Risk score (0-100)

risk_score

TypeRequired?Nullable?
IntegerYesNo

risk_value property

Derived value: 100 - risk_score

risk_value

TypeRequired?Nullable?
IntegerYesNo

preview_risk_score property

Risk score from a preview version of the Mondoo risk scoring model (0-100). Null when no preview score is available.

preview_risk_score

TypeRequired?Nullable?
IntegerYesYes

preview_risk_value property

Derived value: 100 - preview_risk_score. Null when preview_risk_score is null.

preview_risk_value

TypeRequired?Nullable?
IntegerYesYes

security_base_score property

Security-specific base score

security_base_score

TypeRequired?Nullable?
IntegerYesNo

security_risk_score property

Security-specific risk score

security_risk_score

TypeRequired?Nullable?
IntegerYesNo

vuln_base_score property

Vulnerability-specific base score

vuln_base_score

TypeRequired?Nullable?
IntegerYesNo

vuln_risk_score property

Vulnerability-specific risk score

vuln_risk_score

TypeRequired?Nullable?
IntegerYesNo

eol_status property

Whether the asset platform is end-of-life. Null when unknown.

eol_status

TypeRequired?Nullable?
BooleanYesYes

eol_date property

Date the platform enters (or entered) end-of-life status. This is a date-time string matching RFC 3339, section 5.6.

eol_date

TypeRequired?Nullable?
StringYesYes

eol_plan property

Support plan type: standard, ubuntu-pro, els, esu, ltss, or sles-sap

eol_plan

TypeRequired?Nullable?
StringYesNo

last_cnspec_scan_time property

Time a cnspec scan last finished uploading results for this asset. Null when cnspec has never reported a completed scan. This is a date-time string matching RFC 3339, section 5.6.

last_cnspec_scan_time

TypeRequired?Nullable?
StringYesYes

last_upstream_scan_time property

Time of the most recent scan from an upstream third-party scanner (such as SentinelOne, Microsoft Defender, or CrowdStrike). Null when no upstream scan has occurred. This is a date-time string matching RFC 3339, section 5.6.

last_upstream_scan_time

TypeRequired?Nullable?
StringYesYes

worst_sla_state property

Worst SLA position among the asset's open CVE findings as of the export run: over, nearing, within, or none

worst_sla_state

TypeRequired?Nullable?
StringYesNo

sla_over_critical property

Number of open CVE findings rated critical that are past their SLA deadline

sla_over_critical

TypeRequired?Nullable?
IntegerYesNo

sla_over_high property

Number of open CVE findings rated high that are past their SLA deadline

sla_over_high

TypeRequired?Nullable?
IntegerYesNo

sla_over_medium property

Number of open CVE findings rated medium that are past their SLA deadline

sla_over_medium

TypeRequired?Nullable?
IntegerYesNo

sla_over_low property

Number of open CVE findings rated low that are past their SLA deadline

sla_over_low

TypeRequired?Nullable?
IntegerYesNo

sla_nearing_critical property

Number of open CVE findings rated critical inside their SLA warning window, not yet past the deadline

sla_nearing_critical

TypeRequired?Nullable?
IntegerYesNo

sla_nearing_high property

Number of open CVE findings rated high inside their SLA warning window, not yet past the deadline

sla_nearing_high

TypeRequired?Nullable?
IntegerYesNo

sla_nearing_medium property

Number of open CVE findings rated medium inside their SLA warning window, not yet past the deadline

sla_nearing_medium

TypeRequired?Nullable?
IntegerYesNo

sla_nearing_low property

Number of open CVE findings rated low inside their SLA warning window, not yet past the deadline

sla_nearing_low

TypeRequired?Nullable?
IntegerYesNo

sla_within_critical property

Number of open CVE findings rated critical with an SLA, not yet in the warning window

sla_within_critical

TypeRequired?Nullable?
IntegerYesNo

sla_within_high property

Number of open CVE findings rated high with an SLA, not yet in the warning window

sla_within_high

TypeRequired?Nullable?
IntegerYesNo

sla_within_medium property

Number of open CVE findings rated medium with an SLA, not yet in the warning window

sla_within_medium

TypeRequired?Nullable?
IntegerYesNo

sla_within_low property

Number of open CVE findings rated low with an SLA, not yet in the warning window

sla_within_low

TypeRequired?Nullable?
IntegerYesNo

On this page