Remote Device Security Posture Logs

This dataset provides detailed logs of security posture assessments and incident alerts from remote employee devices, including compliance status, vulnerability counts by severity, incident details, and remediation actions. It enables cybersecurity teams to monitor device health, identify high-risk trends, and ensure policy compliance across a distributed workforce. The dataset is ideal for proactive threat detection, compliance auditing, and security operations analytics.

  • last updated 23 Jan 2026
  • by GoMask
The brief that made it

Continuous monitoring of remote device security compliance

Sample rows

preview · 8 of 120 rows · all 24 columns
log_idstringincident_severitystringcompliance_issues_countintegerincident_alertbooleandevice_osstringdevice_idstringemployee_idstringassessment_timestampdatetimeos_versionstringdevice_typestringlocation_citystringlocation_statestringlocation_countrystringcompliance_statusstringvulnerabilities_detected_countintegercritical_vulnerabilities_countintegerhigh_vulnerabilities_countintegermedium_vulnerabilities_countintegerlow_vulnerabilities_countintegerincident_typestringremediation_statusstringremediation_timestampdatetimeassessed_bystringincident_descriptionstring
LOG-00001none0falseWindows 10DEV-00001EMP-10012024-06-01T10:34:21Z10.0.19045laptopSan FranciscoCAUSAcompliant00000nonenot_requiredblankauto_scanner_07blank
LOG-00002none0falsemacOS 14DEV-00002EMP-10122024-06-02T15:22:17Z14.4laptopSeattleWAUSAcompliant11000nonenot_requiredblankauto_scanner_03blank
LOG-00003high7trueWindows 7DEV-00003EMP-10022024-06-03T08:12:05Z6.1.7601desktopBerlinblankGermanynon-compliant104321malwarependingblanksec_ops_02Malware detected in user profile on June 3rd.
LOG-00004critical6trueUbuntu 22.04DEV-00004EMP-10132024-06-03T19:55:39Z22.04.3desktopOsloblankNorwaynon-compliant72221unauthorized_accessin_progressblanksec_ops_05Unauthorized access to system resources detected.
LOG-00005none0falseWindows 10DEV-00005EMP-10032024-06-02T13:19:30Z10.0.19045laptopChicagoILUSAcompliant00000nonenot_requiredblankauto_scanner_01blank
LOG-00006none3falseAndroid 13DEV-00006EMP-10222024-06-04T11:03:42Z13.0smartphoneDelhiblankIndianon-compliant21010nonependingblankauto_scanner_09blank
LOG-00007none0falsemacOS 13DEV-00007EMP-10042024-06-05T16:41:19Z13.2laptopLondonblankUKcompliant10010nonenot_requiredblankauto_scanner_10blank
LOG-00008none0falseiOS 17DEV-00008EMP-10232024-06-05T20:08:37Z17.3smartphoneDublinblankIrelandcompliant21010nonenot_requiredblankauto_scanner_12blank

What the 120 rows show

from the 120-row sample

Critical (incident severity) stands out: mean compliance_issues_count is 433.4, against 2.3 for the rest.

  • 38%incident_alert = true
  • 0median compliance_issues_count
  • 2compliance statuses
  • 4remediation statuses
  • 5device types
  • 7incident types
Mean compliance_issues_count by incident_severity120 rows
0400800433.4critical14 rows8.0high25 rows3.3medium6 rows0.39none75 rows
compliance_issues_count120 rows, in bands of 100
06012011400000000605001,000compliance_issues_count →

Median 0, from 0 to 999.

device_os120 rows · top 10 of 21 values
  1. Windows 1033
  2. macOS 1411
  3. Windows 8.110
  4. Debian 129
  5. Ubuntu 22.048
  6. Windows 77
  7. Android 136
  8. macOS 136
  9. Windows 115
  10. Android 145
24 columns by typefrom the column list below
  • string 15
  • integer 6
  • datetime 2
  • boolean 1

Columns

24 columns in four groups
blueprint · 24 columns
columntypedescriptionexample
Text 15 columns
log_idstringUnique identifier for each security posture log entryuniqueLOG-00001
device_idstringUnique identifier for the remote employee's deviceDEV-00001
employee_idstringUnique identifier for the employee using the deviceEMP-1001
device_osstringOperating system running on the device (e.g., Windows 10, macOS 13, Ubuntu 22.04)Windows 10
os_versionstringVersion number of the device's operating system10.0.19045
device_typestringType of device (e.g., laptop, desktop, tablet, smartphone)laptop · desktop · tablet · smartphone · otherlaptop
location_citystringCity where the device was located during the assessmentoptionalSan Francisco
location_statestringState or region where the device was located during the assessmentoptionalCA
location_countrystringCountry where the device was located during the assessmentoptionalUSA
compliance_statusstringIndicates whether the device is compliant with company security policiescompliant · non-compliant · unknowncompliant
incident_typestringType of security incident detected (e.g., malware, unauthorized access, data exfiltration); null if no incident7 values · optionalnone
incident_severitystringSeverity level of the incident (e.g., critical, high, medium, low); null if no incidentcritical · high · medium · low · none · optionalnone
incident_descriptionstringDetailed description of the security incident; null if no incidentoptionalMalware detected in user …
remediation_statusstringCurrent status of remediation actions taken (e.g., pending, in_progress, resolved, not_required)pending · in_progress · resolved · not_requirednot_required
assessed_bystringIdentifier or name of the system or analyst who performed the assessmentauto_scanner_07
Numbers 6 columns
compliance_issues_countintegerNumber of compliance issues detected during the assessment0 or more0
vulnerabilities_detected_countintegerTotal number of vulnerabilities detected on the device0 or more0
critical_vulnerabilities_countintegerNumber of critical vulnerabilities detected on the device0 or more0
high_vulnerabilities_countintegerNumber of high severity vulnerabilities detected on the device0 or more0
medium_vulnerabilities_countintegerNumber of medium severity vulnerabilities detected on the device0 or more0
low_vulnerabilities_countintegerNumber of low severity vulnerabilities detected on the device0 or more0
Dates and times 2 columns
assessment_timestampdatetimeDate and time when the security posture assessment was performed2024-06-01T10:34:21Z
remediation_timestampdatetimeDate and time when remediation was completed; null if not resolvedoptional2024-06-07T12:02:15Z
True or false 1 column
incident_alertbooleanIndicates if a security incident alert was triggered during the assessmentfalse

Use it for

  • incident alert38%45 of 120 rowsmean compliance issue…433.4crit…8.0high3.3medi…0.39none

    A technology dashboard

    The incident_alert rate, compliance_issues_count by incident_severity and a breakdown of device_os. Excel, Power BI or Tableau.

  • Why do the 14 critical rows have a mean compliance_issues_count of 433.4?

    A root-cause class exercise

    Hand out the rows and one question. The answer is in the data, not in the brief.

  • A software demo

    Believable logs with device_id, employee_id and assessment_timestamp to fill a screen in front of a buyer.

Not quite right?

Make it yours.

Same 24 columns, your size and your rules. See 20 rows before you pay.

Preview 20 rows free

10,000 rows of yours: $12.99One-time. No subscription. All prices

This dataset120 rows24 columns
Yours10,000 rows24 columnslocation_city: UK only

blueprint · remote-device-security-posture-logs

Behind this dataset

Same schema. As many rows as you need.

These 120 rows came out of a blueprint — 24 columns with generation rules behind each one. Open it in Data Factory to retune a column, add your own, wire in foreign keys, and run it at the size you actually need.

Rules it was built with
  • Each row represents a daily device scan for a remote user.
  • Include device type, OS version, compliance status, and detected vulnerabilities.
  • Record security incident alerts and remediation status if triggered.
  • Mark devices that fail compliance for 3+ consecutive days.
  • Capture anonymized user department to support trend analysis.
Rows
Open the blueprint in Data Factory

1 credit per row. New accounts start with 25 free credits.

Exports
CSV, JSON, JSONL, Parquet, SQL, Excel, TSV, XML
Licence
yours to use, including commercially
API slug
remote-device-security-posture-logs

What should your data show?

Preview 20 rows free
No signup. No card.