---
title: Types of data captured
description: Splunk for PingIntelligence captures attack data.
component: pingintelligence
version: 5.2
page_id: pingintelligence:pingintelligence_reference_guide:pingintelligence_data_captured
canonical_url: https://docs.pingidentity.com/pingintelligence/5.2/pingintelligence_reference_guide/pingintelligence_data_captured.html
revdate: April 3, 2024
---

# Types of data captured

Splunk for PingIntelligence captures attack data.

The attack event captures the components listed in the following table:

| Field                        | Description                                                                          |
| ---------------------------- | ------------------------------------------------------------------------------------ |
| **timestamp**                | epoch timestamp                                                                      |
| **protocol**                 | HTTP(s) /Websocket (ws)                                                              |
| **attack\_id**               | PingIntelligence [attack ID](pingintelligence_attack_types_rest_websocket_apis.html) |
| **description**              | Description of the attack.                                                           |
| **attack\_bucket**           | Attack on an API or a DDoS attack.                                                   |
| **attack\_scope**            | Single or multiple APIs.                                                             |
| **attacked\_api**            | Name of the API. In case of multiple APIs, MULTI\_API is reported.                   |
| **attack\_identifier\_type** | Username, API Key, OAuth token, Cookie, or IP address.                               |
| **attack\_key**              | Details of APIKEY or Cookie.                                                         |
| **attack\_value**            | Value of the client identifier.                                                      |
