Remote Device Security Posture Logs
This dataset provides detailed logs of security posture assessments and incident alerts from remote employee devices, including compliance status, vulnerability counts by severity, incident details, and remediation actions. It enables cybersecurity teams to monitor device health, identify high-risk trends, and ensure policy compliance across a distributed workforce. The dataset is ideal for proactive threat detection, compliance auditing, and security operations analytics.
Sample rows
preview · 8 of 120 rows · all 24 columns| log_idstring | incident_severitystring | compliance_issues_countinteger | incident_alertboolean | device_osstring | device_idstring | employee_idstring | assessment_timestampdatetime | os_versionstring | device_typestring | location_citystring | location_statestring | location_countrystring | compliance_statusstring | vulnerabilities_detected_countinteger | critical_vulnerabilities_countinteger | high_vulnerabilities_countinteger | medium_vulnerabilities_countinteger | low_vulnerabilities_countinteger | incident_typestring | remediation_statusstring | remediation_timestampdatetime | assessed_bystring | incident_descriptionstring |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| LOG-00001 | none | 0 | false | Windows 10 | DEV-00001 | EMP-1001 | 2024-06-01T10:34:21Z | 10.0.19045 | laptop | San Francisco | CA | USA | compliant | 0 | 0 | 0 | 0 | 0 | none | not_required | blank | auto_scanner_07 | blank |
| LOG-00002 | none | 0 | false | macOS 14 | DEV-00002 | EMP-1012 | 2024-06-02T15:22:17Z | 14.4 | laptop | Seattle | WA | USA | compliant | 1 | 1 | 0 | 0 | 0 | none | not_required | blank | auto_scanner_03 | blank |
| LOG-00003 | high | 7 | true | Windows 7 | DEV-00003 | EMP-1002 | 2024-06-03T08:12:05Z | 6.1.7601 | desktop | Berlin | blank | Germany | non-compliant | 10 | 4 | 3 | 2 | 1 | malware | pending | blank | sec_ops_02 | Malware detected in user profile on June 3rd. |
| LOG-00004 | critical | 6 | true | Ubuntu 22.04 | DEV-00004 | EMP-1013 | 2024-06-03T19:55:39Z | 22.04.3 | desktop | Oslo | blank | Norway | non-compliant | 7 | 2 | 2 | 2 | 1 | unauthorized_access | in_progress | blank | sec_ops_05 | Unauthorized access to system resources detected. |
| LOG-00005 | none | 0 | false | Windows 10 | DEV-00005 | EMP-1003 | 2024-06-02T13:19:30Z | 10.0.19045 | laptop | Chicago | IL | USA | compliant | 0 | 0 | 0 | 0 | 0 | none | not_required | blank | auto_scanner_01 | blank |
| LOG-00006 | none | 3 | false | Android 13 | DEV-00006 | EMP-1022 | 2024-06-04T11:03:42Z | 13.0 | smartphone | Delhi | blank | India | non-compliant | 2 | 1 | 0 | 1 | 0 | none | pending | blank | auto_scanner_09 | blank |
| LOG-00007 | none | 0 | false | macOS 13 | DEV-00007 | EMP-1004 | 2024-06-05T16:41:19Z | 13.2 | laptop | London | blank | UK | compliant | 1 | 0 | 0 | 1 | 0 | none | not_required | blank | auto_scanner_10 | blank |
| LOG-00008 | none | 0 | false | iOS 17 | DEV-00008 | EMP-1023 | 2024-06-05T20:08:37Z | 17.3 | smartphone | Dublin | blank | Ireland | compliant | 2 | 1 | 0 | 1 | 0 | none | not_required | blank | auto_scanner_12 | blank |
| LOG-00009 | critical | 11 | true | Debian 12 | DEV-00009 | EMP-1005 | 2024-06-06T09:45:44Z | 12.5 | desktop | Paris | blank | France | non-compliant | 13 | 5 | 4 | 3 | 1 | ransomware | resolved | 2024-06-07T12:02:15Z | sec_ops_04 | Ransomware infection detected in system files. |
| LOG-00010 | medium | 2 | true | Fedora 39 | DEV-00010 | EMP-1024 | 2024-06-07T07:28:55Z | 39.0 | tablet | Reykjavik | blank | Iceland | non-compliant | 2 | 0 | 1 | 1 | 0 | phishing | resolved | 2024-06-07T09:12:34Z | sec_ops_01 | Phishing attempt detected in email client. |
| LOG-00011 | high | 6 | true | Windows 8.1 | DEV-00011 | EMP-1006 | 2024-06-08T14:58:09Z | 6.3.9600 | desktop | Toronto | ON | Canada | non-compliant | 7 | 3 | 1 | 2 | 1 | malware | pending | blank | sec_ops_07 | Malware detected in Downloads folder. |
| LOG-00012 | none | 0 | false | iOS 16 | DEV-00012 | EMP-1025 | 2024-06-09T11:25:40Z | 16.5 | tablet | New York | NY | USA | compliant | 1 | 0 | 0 | 1 | 0 | none | not_required | blank | auto_scanner_11 | blank |
| LOG-00013 | none | 1 | false | Windows 11 | DEV-00013 | EMP-1007 | 2024-06-09T21:14:12Z | 11.0.22621 | tablet | Mumbai | blank | India | non-compliant | 1 | 0 | 1 | 0 | 0 | none | pending | blank | auto_scanner_14 | blank |
| LOG-00014 | none | 0 | false | Windows 10 | DEV-00014 | EMP-1008 | 2024-06-10T17:07:28Z | 10.0.19045 | laptop | Austin | TX | USA | compliant | 0 | 0 | 0 | 0 | 0 | none | not_required | blank | auto_scanner_05 | blank |
| LOG-00015 | critical | 999 | true | Chrome OS | DEV-00015 | EMP-1026 | 2024-06-11T09:33:53Z | 121.0.6167.85 | other | McMurdo Station | blank | Antarctica | non-compliant | 999 | 200 | 299 | 300 | 200 | unauthorized_access | pending | blank | sec_ops_10 | Critical unauthorized access attempts from remote IP. |
| LOG-00016 | none | 0 | false | Android 12 | DEV-00016 | EMP-1009 | 2024-06-12T13:46:59Z | 12.0 | tablet | Cape Town | blank | South Africa | compliant | 1 | 0 | 0 | 1 | 0 | none | not_required | blank | auto_scanner_16 | blank |
| LOG-00017 | none | 0 | false | Windows 10 | DEV-00017 | EMP-1010 | 2024-06-13T18:21:11Z | 10.0.19045 | laptop | blank | blank | USA | compliant | 1 | 0 | 0 | 0 | 1 | none | not_required | blank | auto_scanner_13 | blank |
| LOG-00018 | critical | 999 | true | Solaris 11 | DEV-00018 | EMP-1027 | 2024-06-14T12:35:18Z | 11.4.22 | other | Palmer Station | blank | Antarctica | non-compliant | 999 | 250 | 250 | 299 | 200 | other | pending | blank | sec_ops_09 | Multiple critical vulnerabilities detected in legacy system. |
| LOG-00019 | none | 0 | false | macOS 13 | DEV-00019 | EMP-1011 | 2024-06-15T07:29:05Z | 13.1 | laptop | Boston | MA | USA | compliant | 0 | 0 | 0 | 0 | 0 | none | not_required | blank | auto_scanner_06 | blank |
| LOG-00020 | high | 9 | true | Windows 7 | DEV-00020 | EMP-1028 | 2024-06-16T15:19:44Z | 6.1.7601 | desktop | Montreal | QC | Canada | non-compliant | 12 | 4 | 3 | 4 | 1 | malware | in_progress | blank | sec_ops_06 | Malware signature found in system memory. |
What the 120 rows show
from the 120-row sampleCritical (incident severity) stands out: mean compliance_
- 38%incident_
alert = true - 0median compliance_
issues_ count - 2compliance statuses
- 4remediation statuses
- 5device types
- 7incident types
Median 0, from 0 to 999.
- string 15
- integer 6
- datetime 2
- boolean 1
Columns
24 columns in four groups| column | type | description | example |
|---|---|---|---|
| Text 15 columns | |||
log_id | string | Unique identifier for each security posture log entryunique | LOG-00001 |
device_id | string | Unique identifier for the remote employee's device | DEV-00001 |
employee_id | string | Unique identifier for the employee using the device | EMP-1001 |
device_os | string | Operating system running on the device (e.g., Windows 10, macOS 13, Ubuntu 22.04) | Windows 10 |
os_version | string | Version number of the device's operating system | 10.0.19045 |
device_type | string | Type of device (e.g., laptop, desktop, tablet, smartphone)laptop · desktop · tablet · smartphone · other | laptop |
location_city | string | City where the device was located during the assessmentoptional | San Francisco |
location_state | string | State or region where the device was located during the assessmentoptional | CA |
location_country | string | Country where the device was located during the assessmentoptional | USA |
compliance_status | string | Indicates whether the device is compliant with company security policiescompliant · non-compliant · unknown | compliant |
incident_type | string | Type of security incident detected (e.g., malware, unauthorized access, data exfiltration); null if no incident7 values · optional | none |
incident_severity | string | Severity level of the incident (e.g., critical, high, medium, low); null if no incidentcritical · high · medium · low · none · optional | none |
incident_description | string | Detailed description of the security incident; null if no incidentoptional | Malware detected in user … |
remediation_status | string | Current status of remediation actions taken (e.g., pending, in_progress, resolved, not_required)pending · in_progress · resolved · not_required | not_required |
assessed_by | string | Identifier or name of the system or analyst who performed the assessment | auto_scanner_07 |
| Numbers 6 columns | |||
compliance_issues_count | integer | Number of compliance issues detected during the assessment0 or more | 0 |
vulnerabilities_detected_count | integer | Total number of vulnerabilities detected on the device0 or more | 0 |
critical_vulnerabilities_count | integer | Number of critical vulnerabilities detected on the device0 or more | 0 |
high_vulnerabilities_count | integer | Number of high severity vulnerabilities detected on the device0 or more | 0 |
medium_vulnerabilities_count | integer | Number of medium severity vulnerabilities detected on the device0 or more | 0 |
low_vulnerabilities_count | integer | Number of low severity vulnerabilities detected on the device0 or more | 0 |
| Dates and times 2 columns | |||
assessment_timestamp | datetime | Date and time when the security posture assessment was performed | 2024-06-01T10:34:21Z |
remediation_timestamp | datetime | Date and time when remediation was completed; null if not resolvedoptional | 2024-06-07T12:02:15Z |
| True or false 1 column | |||
incident_alert | boolean | Indicates if a security incident alert was triggered during the assessment | false |
Use it for
A technology dashboard
The incident_
alert rate, compliance_ issues_ count by incident_ severity and a breakdown of device_ os. Excel, Power BI or Tableau. Why do the 14 critical rows have a mean compliance_
issues_ count of 433.4? A root-cause class exercise
Hand out the rows and one question. The answer is in the data, not in the brief.
- Logs120LOG-000010noneLOG-000037highLOG-000046critical
A software demo
Believable logs with device_
id, employee_ id and assessment_ timestamp to fill a screen in front of a buyer.
blueprint · remote-device-security-posture-logs
Behind this dataset
Same schema. As many rows as you need.
These 120 rows came out of a blueprint — 24 columns with generation rules behind each one. Open it in Data Factory to retune a column, add your own, wire in foreign keys, and run it at the size you actually need.
- Each row represents a daily device scan for a remote user.
- Include device type, OS version, compliance status, and detected vulnerabilities.
- Record security incident alerts and remediation status if triggered.
- Mark devices that fail compliance for 3+ consecutive days.
- Capture anonymized user department to support trend analysis.
1 credit per row. New accounts start with 25 free credits.
- Exports
- CSV, JSON, JSONL, Parquet, SQL, Excel, TSV, XML
- Licence
- yours to use, including commercially
- API slug
- remote-device-security-posture-logs