Run ReportsContinuous Data ExportsSchema Reference

CSV Export Columns

Reference the columns in Mondoo CSV exports and how they differ from the JSONL schema.

When you export data from Mondoo to a storage destination in CSV format, each export run writes one CSV file per record type. The first row of each file is a header row. The columns carry the same data as the JSONL records described in the JSONL schema reference, with the differences on this page.

General differences from JSONL

  • Empty values. A value that's null in JSONL is an empty cell in CSV.
  • Timestamps. Dates and times use RFC 3339 format, for example 2026-09-29T17:21:00Z.
  • Risk factors. The risk_factors column holds only the risk factor names, separated by semicolons (;), because names can contain spaces. JSONL records hold an array of objects with id, mrn, and name.
  • Lists. Other list values (such as vulnerability references and control check references) are joined with spaces.
  • Nested objects. Labels, annotations, evidence, and sources are written as JSON strings inside the cell.
  • Column order. Columns are positional. New columns are only ever appended at the end of a file, so tools that read columns by position keep working.

Assets

The assets file identifies each asset with the mrn column only. Unlike JSONL records, it has no asset_mrn column. When you join asset rows to other CSV files, match the assets file's mrn column to their asset_mrn column.

Columns, in order:

mrn, name, platform_name, error, created_at, score_updated_at, updated_at, labels, annotations, asset_id, space_id, space_mrn, space_name, exported_at, time_travel_id, url, base_score, risk_score, risk_value, risk_factors, security_base_score, security_risk_score, vuln_base_score, vuln_risk_score, eol_status, eol_date, eol_plan, preview_risk_score, preview_risk_value, last_cnspec_scan_time, last_upstream_scan_time, worst_sla_state, sla_over_critical, sla_over_high, sla_over_medium, sla_over_low, sla_nearing_critical, sla_nearing_high, sla_nearing_medium, sla_nearing_low, sla_within_critical, sla_within_high, sla_within_medium, sla_within_low

Packages

Four package columns have different names than their JSONL properties:

JSONL propertyCSV columnCSV value
namepackage_namePackage name
versionpackage_versionInstalled package version
vuln_mrnsvuln_mrnMRNs of the vulnerabilities, separated by spaces
vuln_idsvuln_idIDs of the vulnerabilities, separated by spaces

Columns, in order:

asset_mrn, vuln_mrn, vuln_id, package_name, package_version, fixed_version, first_detected_on, resolved_on, cvss_score, cvss_severity, asset_id, space_id, space_mrn, space_name, exported_at, time_travel_id, base_score, risk_score, risk_value, risk_factors, asset_name, remediation, evidence, evidence_total_count

Vulnerabilities

The vulnerabilities file uses the JSONL property names, with these value differences:

  • cve_refs holds only the CVE IDs, separated by spaces. JSONL records hold an array of objects with id and mrn.
  • references holds the reference URLs, separated by spaces.
  • cvss_vector is wrapped in single quotes (for example 'CVSS:3.1/AV:N/...') so spreadsheet tools don't reinterpret it.

Columns, in order:

asset_mrn, vuln_mrn, vuln_id, type, summary, first_detected_on, resolved_on, published_date, cvss_score, cvss_severity, asset_id, asset_name, space_id, space_mrn, space_name, exported_at, time_travel_id, url, base_score, risk_score, risk_value, risk_factors, references, cvss_vector, cve_refs, risk_severity, remediation, evidence, epss_score, epss_percentile, sources, preview_risk_score, preview_risk_value, sla_state, sla_rating, sla_started_at, sla_warn_at, sla_deadline, sla_days_to_resolve, sla_resolved_within

Check results

In the checks file, the score column holds the check's base score, and the data column holds the check's assessment (the same value as the assessment column).

Columns, in order:

asset_mrn, query_mrn, title, mql, data, score, status, modified_at, failed_at, base_score, risk_score, risk_value, asset_id, space_id, space_mrn, space_name, assessment, severity, remediation, enforcement_state, exported_at, preview_risk_score, preview_risk_value

Query results

The data column holds the query output as a JSON string.

Columns, in order:

asset_mrn, query_mrn, title, mql, data, asset_id, space_id, space_mrn, space_name, exported_at

Controls

The check_refs and query_refs columns hold the check and query MRNs, separated by spaces.

Columns, in order:

space_mrn, space_id, space_name, entity_mrn, entity_id, control_mrn, title, state, exported_at, modified_at, failed_at, base_score, check_refs, query_refs, remediation

On this page