CSV Export Columns
Reference the columns in Mondoo CSV exports and how they differ from the JSONL schema.
When you export data from Mondoo to a storage destination in CSV format, each export run writes one CSV file per record type. The first row of each file is a header row. The columns carry the same data as the JSONL records described in the JSONL schema reference, with the differences on this page.
General differences from JSONL
- Empty values. A value that's
nullin JSONL is an empty cell in CSV. - Timestamps. Dates and times use RFC 3339 format, for example
2026-09-29T17:21:00Z. - Risk factors. The
risk_factorscolumn holds only the risk factor names, separated by semicolons (;), because names can contain spaces. JSONL records hold an array of objects withid,mrn, andname. - Lists. Other list values (such as vulnerability references and control check references) are joined with spaces.
- Nested objects. Labels, annotations, evidence, and sources are written as JSON strings inside the cell.
- Column order. Columns are positional. New columns are only ever appended at the end of a file, so tools that read columns by position keep working.
Assets
The assets file identifies each asset with the mrn column only. Unlike JSONL records, it has no asset_mrn column. When you join asset rows to other CSV files, match the assets file's mrn column to their asset_mrn column.
Columns, in order:
mrn, name, platform_name, error, created_at, score_updated_at, updated_at, labels, annotations, asset_id, space_id, space_mrn, space_name, exported_at, time_travel_id, url, base_score, risk_score, risk_value, risk_factors, security_base_score, security_risk_score, vuln_base_score, vuln_risk_score, eol_status, eol_date, eol_plan, preview_risk_score, preview_risk_value, last_cnspec_scan_time, last_upstream_scan_time, worst_sla_state, sla_over_critical, sla_over_high, sla_over_medium, sla_over_low, sla_nearing_critical, sla_nearing_high, sla_nearing_medium, sla_nearing_low, sla_within_critical, sla_within_high, sla_within_medium, sla_within_low
Packages
Four package columns have different names than their JSONL properties:
| JSONL property | CSV column | CSV value |
|---|---|---|
name | package_name | Package name |
version | package_version | Installed package version |
vuln_mrns | vuln_mrn | MRNs of the vulnerabilities, separated by spaces |
vuln_ids | vuln_id | IDs of the vulnerabilities, separated by spaces |
Columns, in order:
asset_mrn, vuln_mrn, vuln_id, package_name, package_version, fixed_version, first_detected_on, resolved_on, cvss_score, cvss_severity, asset_id, space_id, space_mrn, space_name, exported_at, time_travel_id, base_score, risk_score, risk_value, risk_factors, asset_name, remediation, evidence, evidence_total_count
Vulnerabilities
The vulnerabilities file uses the JSONL property names, with these value differences:
cve_refsholds only the CVE IDs, separated by spaces. JSONL records hold an array of objects withidandmrn.referencesholds the reference URLs, separated by spaces.cvss_vectoris wrapped in single quotes (for example'CVSS:3.1/AV:N/...') so spreadsheet tools don't reinterpret it.
Columns, in order:
asset_mrn, vuln_mrn, vuln_id, type, summary, first_detected_on, resolved_on, published_date, cvss_score, cvss_severity, asset_id, asset_name, space_id, space_mrn, space_name, exported_at, time_travel_id, url, base_score, risk_score, risk_value, risk_factors, references, cvss_vector, cve_refs, risk_severity, remediation, evidence, epss_score, epss_percentile, sources, preview_risk_score, preview_risk_value, sla_state, sla_rating, sla_started_at, sla_warn_at, sla_deadline, sla_days_to_resolve, sla_resolved_within
Check results
In the checks file, the score column holds the check's base score, and the data column holds the check's assessment (the same value as the assessment column).
Columns, in order:
asset_mrn, query_mrn, title, mql, data, score, status, modified_at, failed_at, base_score, risk_score, risk_value, asset_id, space_id, space_mrn, space_name, assessment, severity, remediation, enforcement_state, exported_at, preview_risk_score, preview_risk_value
Query results
The data column holds the query output as a JSON string.
Columns, in order:
asset_mrn, query_mrn, title, mql, data, asset_id, space_id, space_mrn, space_name, exported_at
Controls
The check_refs and query_refs columns hold the check and query MRNs, separated by spaces.
Columns, in order:
space_mrn, space_id, space_name, entity_mrn, entity_id, control_mrn, title, state, exported_at, modified_at, failed_at, base_score, check_refs, query_refs, remediation