---
title: Types of data captured
description: Splunk for PingIntelligence captures attack data. The attack event captures the components listed in the following table:
component: pingintelligence
version: 5.1
page_id: pingintelligence:pingintelligence_dashboard:pingintelligence_data_captured
canonical_url: https://docs.pingidentity.com/pingintelligence/5.1/pingintelligence_dashboard/pingintelligence_data_captured.html
revdate: April 26, 2024
---

# Types of data captured

Splunk for PingIntelligence captures attack data. The attack event captures the components listed in the following table:

| **Field**                | **Description**                                                                                       |
| ------------------------ | ----------------------------------------------------------------------------------------------------- |
| timestamp                | epoch timestamp                                                                                       |
| protocol                 | HTTP(s) /Websocket (ws)                                                                               |
| attack\_id               | PingIntelligence [Attack ID](../abs_ai_engine/pingintelligence_attack_types_rest_websocket_apis.html) |
| description              | Description of the attack                                                                             |
| attack\_bucket           | Attack on an API or a DDoS attack                                                                     |
| attack\_scope            | Single or multiple APIs                                                                               |
| attacked\_api            | Name of the API. In case of multiple API, MULTI\_API is reported                                      |
| attack\_identifier\_type | Username, API Key, OAuth token, Cookie, or IP address                                                 |
| attack\_key              | Details of APIKEY or Cookie                                                                           |
| attack\_value            | Value of the client identifier.                                                                       |
