Public Wi-Fi Incident Event Log

This dataset provides detailed event logs of incidents occurring on municipally-operated public Wi-Fi networks, including incident types, severity, affected locations, device information, and response actions. It enables smart city teams to monitor network health, analyze security trends, and evaluate response protocols, supporting both operational management and strategic network improvements.

  • last updated 30 Jan 2026
  • by GoMask
The brief that made it

Real-time monitoring and triage of public Wi-Fi incidents

Sample rows

preview · 8 of 85 rows · all 23 columns
incident_idstringincident_statusstringdowntime_minutesfloatlocation_statestringevent_timestampdatetimenetwork_idstringnetwork_namestringlocation_namestringlocation_street_addressstringlocation_citystringlocation_postal_codestringlocation_countrystringincident_typestringincident_severitystringreported_bystringuser_device_macstringuser_device_typestringuser_ip_addressstringactions_takenstringresolved_timestampdatetimeresponse_time_minutesfloataffected_users_countintegerdescriptionstring
INC00001investigating0IL2024-06-03T09:12:00WIFI-001Central Park WiFiCentral Park123 Park AveSpringfield62701USAconnectivity_issuemediumuser_report7A:2B:4C:9F:1D:02smartphone192.168.1.45Network diagnostics initiated, user notified.blank127User unable to connect to WiFi near playground. Signal appears weak.
INC00002escalated20IL2024-06-03T10:07:43WIFI-002Library Public WiFiDowntown Library456 Main StSpringfield62702USAsecurity_threathighautomated_monitoringBD:33:FA:7E:91:AClaptop10.0.0.88Traffic isolated, security team notified.blank5.53Unusual network traffic detected, possible malware communication.
INC00003resolved2OH2024-06-03T11:22:15WIFI-003Transit WiFiUnion Station789 Transit BlvdColumbus43215USAbandwidth_abusemediumautomated_monitoring8C:55:2D:4B:1E:FFtablet10.10.10.102Bandwidth limited, user notified.2024-06-03T12:00:55712High bandwidth usage detected, streaming services.
INC00004closed0WI2024-06-03T13:04:10WIFI-004City Hall WiFiCity Hall101 Civic CenterMadison53703USAdevice_blockedlowstaff_observation45:EF:12:46:89:DAIoT_device172.16.0.44Device blocked, log updated.2024-06-03T13:20:10101Unauthorized IoT device detected and blocked.
INC00005open0WI2024-06-03T14:15:22WIFI-005Riverside WiFiRiverside Park202 River RdMadison53704USAconnectivity_issuemediumuser_reportF3:9D:3B:22:44:0Asmartphone192.168.1.67Network scan scheduled.blank154Spotty connectivity reported in the north picnic area.
INC00006investigating0OH2024-06-03T15:08:16WIFI-006Community Center WiFiEastside Community Center303 Center StColumbus43216USAcontent_violationhighexternal_alertblankunknownblankContent filter reviewed, staff notified.blank201External agency flagged inappropriate content access.
INC00007resolved15OH2024-06-03T16:40:57WIFI-007Transit WiFiUnion Station789 Transit BlvdColumbus43215USAconnectivity_issuelowstaff_observationblankunknownblankMaintenance completed.2024-06-03T16:55:1028Brief network downtime during scheduled maintenance.
INC00008escalated60WI2024-06-03T18:02:34WIFI-008City Hall WiFiCity Hall101 Civic CenterMadison53703USAsecurity_threatcriticalautomated_monitoring72:AA:5F:99:04:CBlaptop172.16.0.55Admin access blocked, incident escalated.blank42Detected brute-force login attempt on admin portal.

What the 85 rows show

from the 85-row sample

Escalated (incident status) stands out: mean downtime_minutes is 37.2, against 4.3 for the rest.

  • 0.0median downtime_minutes
  • 4location countries
  • 4incident severities
  • 4reported_by values
  • 5user device types
  • 6incident types
Mean downtime_minutes by incident_status85 rows
020404.7open22 rows4.5invest…11 rows4.4resolv…21 rows3.7closed19 rows37.2escala…12 rows
downtime_minutes85 rows, in bands of 10
0357063104111504070downtime_minutes →

Median 0.0, from 0.0 to 70.0.

location_state79 rows with a value · 6 left blank
  1. OH16
  2. WI16
  3. IL12
  4. NY6
  5. CA6
  6. MA6
  7. ON6
  8. NSW6
  9. BC5
23 columns by typefrom the column list below
  • string 18
  • integer 1
  • float 2
  • datetime 2

Columns

23 columns in three groups
blueprint · 23 columns
columntypedescriptionexample
Text 18 columns
incident_idstringUnique identifier for the incident event.uniqueINC00001
network_idstringUnique identifier of the public Wi-Fi network where the incident occurred.WIFI-001
network_namestringHuman-readable name of the Wi-Fi network.Central Park WiFi
location_namestringName or description of the physical location (e.g., park, library, transit station) where the network is deployed.Central Park
location_street_addressstringStreet address of the incident location.optional123 Park Ave
location_citystringCity where the incident occurred.11 citiesSpringfield
location_statestringState or province of the incident location.9 states · optionalIL
location_postal_codestringPostal or ZIP code of the incident location.optional62701
location_countrystringCountry where the incident occurred.4 countriesUSA
incident_typestringCategory of incident (e.g., connectivity_issue, security_threat, content_violation, device_blocked, bandwidth_abuse).6 valuesconnectivity_issue
incident_severitystringSeverity level of the incident (e.g., low, medium, high, critical).low · medium · high · criticalmedium
incident_statusstringCurrent status of the incident (e.g., open, investigating, resolved, closed, escalated).open · investigating · resolved · closed · escalatedinvestigating
reported_bystringSource of the incident report (e.g., automated_monitoring, user_report, staff_observation, external_alert).4 valuesuser_report
user_device_macstringMAC address of the user device involved in the incident (if applicable).optional7A:2B:4C:9F:1D:02
user_device_typestringType of user device involved (e.g., smartphone, laptop, tablet, IoT_device).smartphone · laptop · tablet · IoT_device · unknown · optionalsmartphone
user_ip_addressstringIP address assigned to the user device during the incident (if applicable).optional192.168.1.45
descriptionstringDetailed description of the incident, including observed symptoms and context.optionalUser unable to connect to…
actions_takenstringActions taken in response to the incident (e.g., device blocked, bandwidth limited, user notified, escalated to security team).optionalNetwork scan scheduled.
Numbers 3 columns
response_time_minutesfloatTime in minutes between incident detection and first response action.0 or more · optional12
downtime_minutesfloatTotal duration in minutes that the network or affected service was unavailable due to the incident.0 or more · optional0
affected_users_countintegerEstimated number of users affected by the incident.0 or more · optional7
Dates and times 2 columns
event_timestampdatetimeDate and time when the incident was detected or reported.2024-06-03T09:12:00
resolved_timestampdatetimeDate and time when the incident was resolved or closed.optional2024-06-03T12:00:55

Use it for

  • median downtim…0.085 rowsmean downtime minutes…4.7open4.5inve…4.4reso…3.7clos…

    A technology dashboard

    Downtime_minutes by incident_status and a breakdown of location_state. Excel, Power BI or Tableau.

  • Why do the 12 escalated rows have a mean downtime_minutes of 37.2?

    A root-cause class exercise

    Hand out the rows and one question. The answer is in the data, not in the brief.

  • A software demo

    Believable incidents with event_timestamp, network_id and network_name to fill a screen in front of a buyer.

Not quite right?

Make it yours.

Same 23 columns, your size and your rules. See 20 rows before you pay.

Preview 20 rows free

10,000 rows of yours: $12.99One-time. No subscription. All prices

This dataset85 rows23 columns
Yours10,000 rows23 columnslocation_name: UK only

blueprint · public-wi-fi-incident-event-log

Behind this dataset

Same schema. As many rows as you need.

These 85 rows came out of a blueprint — 23 columns with generation rules behind each one. Open it in Data Factory to retune a column, add your own, wire in foreign keys, and run it at the size you actually need.

Rules it was built with
  • Each event is tied to a unique network hotspot ID.
  • Incident types include unauthorized access, bandwidth abuse, hardware malfunction, and suspected malware.
  • Severity levels are categorized as Low, Medium, or High.
  • Resolution timestamps are only present if status is 'Resolved'.
  • Repeat incidents at the same hotspot must show escalation in severity if unresolved after 2 events.
Rows
Open the blueprint in Data Factory

1 credit per row. New accounts start with 25 free credits.

Exports
CSV, JSON, JSONL, Parquet, SQL, Excel, TSV, XML
Licence
yours to use, including commercially
API slug
public-wi-fi-incident-event-log

What should your data show?

Preview 20 rows free
No signup. No card.