Skip to main content

Querying RUM logs

Real User Monitoring SDKs send logs to the Coralogix Ingress API using a predefined JSON format that maintains a consistent structure across all logs. This uniformity makes it easy to query RUM logs with DataPrime, as all log types share the same overarching schema.

Each RUM log includes a common set of fields applicable to all event types. In addition, each specific event type has its own nested object containing fields unique to that event.

Currently, based on the enabled instrumentation, both browser and mobile SDKs can generate the following types of events:

  • resources
  • error
  • network-request
  • user-interaction
  • longtask
  • log
  • web-vitals
  • dom
  • custom-measurement
  • screenshot

Where RUM data is stored​

RUM data is stored in its own dataset, default/rum.events. Every field path on this page is written as it appears in that dataset.

RUM data used to be written into default/logs alongside your application logs, and every RUM field carried a cx_rum. prefix. Accounts move to default/rum.events one at a time, so both layouts are in use today. When an account moves, the prefix is dropped: cx_rum.event_context.type becomes event_context.type.

To check which applies to your account, open the dataset selector in the query builder and look for default/rum.events. If your RUM events appear there, use the paths on this page exactly as written. If your RUM data is still in default/logs, add the cx_rum. prefix to every path on this page.

Note

There is no double write. Once an account moves, RUM data is written only to default/rum.events, and the cx_rum. paths no longer exist in default/logs. Anything still pointing at the old paths returns no results. See Updating saved queries after the move.

Shared fields​

These fields are included in all RUM logs, regardless of the event type. They provide contextual details such as session, event metadata, user identity, and environment information.

Full pathDescriptionExample valueField
Session context
session_context.ip_geoip.ipUser's IP address49.249.153.150ip
session_context.ip_geoip.ip_ipaddrAlternative IP address49.249.153.150ip_ipaddr
session_context.ip_geoip.location_geopoint.latLatitude of user location21.9974lat
session_context.ip_geoip.location_geopoint.lonLongitude of user location79.0011lon
session_context.ip_geoip.continent_nameContinent nameAsiacontinent_name
session_context.ip_geoip.country_nameCountry nameIndiacountry_name
session_context.ip_geoip.city_nameCity nameDelhicity_name
session_context.ip_geoip.postal_codePostal code90210postal_code
session_context.ip_geoip.is_localIs IP localFALSEis_local
session_context.browserBrowser nameChromebrowser
session_context.browserVersionBrowser version136.0.0.0browserVersion
session_context.deviceDevice typeDesktopdevice
session_context.hasRecordingCurrent session has recordingFALSEhasRecording
session_context.hasScreenshotCurrent session has screenshotFALSEhasScreenshot
session_context.onlyWithErrorModeError mode onlyFALSEonlyWithErrorMode
session_context.osOperating systemMacOSos
session_context.osVersionOS version10.15.7osVersion
session_context.prev_session.hasRecordingPrevious session had recordingTRUEprev_session_hasRecording
session_context.prev_session.hasScreenshotPrevious session had screenshotFALSEprev_session_hasScreenshot
session_context.prev_session.session_creation_datePrevious session creation time1748503307441prev_session_creation_date
session_context.prev_session.session_idPrevious session IDbfcd4bf5-c4ff-48fb-99d4-b1af603707e4prev_session_id
session_context.session_creation_dateCurrent session creation time1748514787150session_creation_date
session_context.session_idCurrent session IDc664895a-63d7-4997-ad88-ce753974ca3asession_id
session_context.user_agentUser agent stringMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36user_agent
session_context.user_idUser ID1234user_id
session_context.user_nameUser nameAviv Alushuser_name
session_context.x_forwarded_forForwarded IPs49.249.153.150,163.116.212.40x_forwarded_for
Event context
event_context.severityEvent severity3event_severity
event_context.typeEvent typeuser-interactionevent_type
Labels
labels.cxFeatureGroupIdFeature group IDdata-explorationcxFeatureGroupId
labels.cxFeatureIdFeature IDlogs-explorercxFeatureId
labels.releaseIdRelease IDweb-app@866faa56releaseId
Page context
page_context.page_fragmentsPage fragmentsquery-new/archive-logspage_fragments
page_context.page_urlPage URLhttps://zupee-prd.app.coralogix.in/#/query-new/archive-logs?id=A9JBQSSgVyIl1jtNbPHbf&page=0page_url
page_context.page_url_blueprintBlueprint URLhttps://zupee-prd.app.coralogix.in/#/query-new/archive-logs?id=A9JBQSSgVyIl1jtNbPHbf&page=0page_url_blueprint
page_context.referrerReferrerreferrer
General metadata
browser_sdk.versionSDK version2.8.3browser_sdk_version
environmentDeployment environmentmumbaisaasenvironment
platformPlatformbrowserplatform
timestampTimestamp1748514789996timestamp
version_metadata.app_nameApp nameweb-appapp_name
version_metadata.app_versionApp version866faa56app_version

User interactions​

Tracks user actions such as clicks and inputs to understand behavior and flow.

Full pathDescriptionExample valueField
event_context.severitySeverity level of the event (e.g., 1–5)3severity
event_context.typeType of the eventuser-interactiontype
interaction_context.element_classesCSS classes of interacted elementcx-input-field ng-untouched ng-pristine ng-validelement_classes
interaction_context.element_idElement IDcx-input-3element_id
interaction_context.event_nameInteraction event nameclickevent_name
interaction_context.target_elementHTML element targetedINPUTtarget_element
interaction_context.target_element_inner_textInner text of target elementtarget_element_inner_text
interaction_context.target_element_typeType of target elementtexttarget_element_type

Network requests​

Records details of XHR and fetch requests to monitor API usage and latency.

Full pathDescriptionExample valueField
event_context.severityEvent severity3severity
event_context.typeType of event detectednetwork-requestevent_type
network_request_context.durationDuration of the network request680request_duration
network_request_context.methodHTTP methodPOSTrequest_method
network_request_context.urlFull request URLhttps://ng-api-grpc.cx498.coralogix.com/com.coralogix.schemastore.v1.SchemaStoreService/SubmitUsageStatsrequest_url
network_request_context.status_codeHTTP response status code200status_code
timestampTimestamp of the event1748510384932timestamp
traceIdTrace identifier for observability8a6eb6a6131e8680c9b36cdeb424ccc4traceId
spanIdSpan identifier for tracing7b32e31e2275c1b4spanId

Errors​

Captures JavaScript errors and exceptions to help identify and resolve issues impacting the user experience.

Full pathDescriptionExample valueField
error_context.error_messageError message textERROR Cannot read properties of undefined (reading 'map')error_message
error_context.original_stacktraceOriginal JavaScript stack traceArray of 10 stack frames (see details below)original_stacktrace

Resources​

Logs the loading of external assets (like images, scripts, and stylesheets) to measure resource performance.

Full pathDescriptionExample valueField
event_context.severitySeverity level (info/warning)3severity
event_context.typeType of the eventresourcestype
resource_context.connectEndEnd of the connection phase67021.59999990463connectEnd
resource_context.connectStartStart of the connection67021.59999990463connectStart
resource_context.decodedBodySizeSize of decoded response body3993decodedBodySize
resource_context.deliveryTypeResource delivery type(empty)deliveryType
resource_context.domainLookupEndEnd of DNS lookup67021.59999990463domainLookupEnd
resource_context.domainLookupStartStart of DNS lookup67021.59999990463domainLookupStart
resource_context.durationTotal resource load time175.5duration
resource_context.encodedBodySizeSize of compressed body1375encodedBodySize
resource_context.entryTypeType of performance entryresourceentryType
resource_context.fetchStartStart of fetch67021.59999990463fetchStart
resource_context.finalResponseHeadersStartTime headers were received67196.79999995232finalResponseHeadersStart
resource_context.firstInterimResponseStartInterim response timing0firstInterimResponseStart
resource_context.fragmentsAssociated JS chunkchunk-K6NU6CD3.jsfragments
resource_context.initiatorTypeWhat triggered the resource loadscriptinitiatorType
resource_context.nameResource URLhttps://cdn.jsdelivr.net/npm/[email protected]/lodash.min.jsname
resource_context.nextHopProtocolProtocol used (HTTP/2)h2nextHopProtocol
resource_context.redirectEndEnd of redirect (if any)0redirectEnd
resource_context.redirectStartStart of redirect (if any)0redirectStart
resource_context.renderBlockingStatusWhether this blocked renderingnon-blockingrenderBlockingStatus
resource_context.requestStartTime request started67024.09999990463requestStart
resource_context.responseEndTime full response received67197.09999990463responseEnd
resource_context.responseStartTime response started67196.79999995232responseStart
resource_context.responseStatusHTTP status code200responseStatus
resource_context.secureConnectionStartStart of secure TLS handshake67021.59999990463secureConnectionStart
resource_context.serverTimingServer timing info[]serverTiming
resource_context.startTimeStart time of resource timing measurement67021.59999990463startTime
resource_context.transferSizeTotal bytes transferred (including headers)1675transferSize
resource_context.workerStartStart of any service worker involvement0workerStart

Long task​

Detects main thread blocking operations to surface performance bottlenecks.

Full pathDescriptionExample valueField
event_context.severitySeverity level (e.g., info = 1, warning = 3, error = 5)3severity
event_context.typeType of RUM eventlongtasktype
longtask_context.durationTime the task blocked the main thread (in ms)84duration
longtask_context.entryTypeType of performance entrylongtaskentryType
longtask_context.idUnique identifier for the long task5885bbfc-cefa-4e33-aa9d-bbd3acf75c30id
longtask_context.nameSource of the long task (usually self or cross-origin)selfname
longtask_context.startTimeWhen the long task began (in ms since page load)3473.5startTime

Web vitals​

Reports key performance metrics like LCP, FID, and CLS to assess the core user experience.

Full pathDescriptionExample valueField
event_context.severityEvent severity level (e.g., info = 1, warning = 3, error = 5)3severity
event_context.typeType of the eventweb-vitalstype
web_vitals_context.nameWeb vital type (Largest Contentful Paint)LCPname
web_vitals_context.valueMeasured LCP value in milliseconds18224value (ms)
web_vitals_context.ratingPerformance rating based on metric thresholdspoorrating
web_vitals_context.attribution.elementRenderDelayTime from page load to element render17605.4elementRenderDelay (ms)
web_vitals_context.attribution.lcpEntry.renderTimeTime from navigation start to LCP render18224renderTime (ms)
web_vitals_context.attribution.lcpEntry.sizeSize of the largest element contributing to LCP20160size (bytes)
web_vitals_context.attribution.timeToFirstByteTTFB value from navigation timing618.6timeToFirstByte (ms)
web_vitals_context.navigationTypeType of navigation (navigate, reload, etc.)navigatenavigationType
web_vitals_context.navigationIdIdentifier for navigation event1navigationId
web_vitals_context.idUnique identifier for the web vital metricv4-1748520702813-3468299023131id

Document navigation timings​

When web_vitals_context.name is LT, the event carries the browser's PerformanceNavigationTiming entry alongside the fields above, so the whole document load sequence is queryable. Use these to find the slowest phase of a page load, or to separate a slow document from a slow render.

Full pathDescriptionExample valueField
web_vitals_context.activationStartTime between a prerendered document starting and being activated92.1activationStart (ms)
web_vitals_context.domInteractiveWhen the document became interactive313.9domInteractive (ms)
web_vitals_context.domContentLoadedEventStartImmediately before the DOMContentLoaded handler ran544domContentLoadedEventStart (ms)
web_vitals_context.domContentLoadedEventEndImmediately after the DOMContentLoaded handler finished544.1domContentLoadedEventEnd (ms)
web_vitals_context.domCompleteThe document and every sub-resource finished loading583.2domComplete (ms)
web_vitals_context.loadEventStartWhen the document's load event started583.2loadEventStart (ms)
web_vitals_context.loadEventEndWhen the document's load event finished583.4loadEventEnd (ms)
web_vitals_context.unloadEventStartImmediately before the previous document's unload handler ran0unloadEventStart (ms)
web_vitals_context.unloadEventEndImmediately after the previous document's unload handler finished0unloadEventEnd (ms)
web_vitals_context.redirectCountRedirects since the last non-redirect navigation0redirectCount
web_vitals_context.urlThe document URL the timings belong tohttps://coralogix.com/url
web_vitals_context.valueTotal page load time583.4value (ms)

navigationType and type both appear on these events and hold the same value - navigate, reload, back_forward or prerender - because the SDK copies the performance entry in whole and then derives navigationType from its type.

Memory usage​

Reports the browser's memory consumption, broken down by what is holding it. Collected on an interval when memoryUsageConfig is enabled, and only in a secure context, since it relies on measureUserAgentSpecificMemory.

Full pathDescriptionExample valueField
event_context.typeType of the eventmemory-usagetype
memory_usage_context.bytesTotal memory consumption across all objects10485760bytes
memory_usage_context.breakdown.bytesMemory consumed by one group of objects2097152bytes
memory_usage_context.breakdown.typesObject types in that group, such as DOM, JavaScript or shared workers["DOM"]types
memory_usage_context.breakdown.attribution.urlURL of the frame or worker the memory is attributed tohttps://coralogix.com/url
memory_usage_context.breakdown.attribution.scopeScope the memory belongs to, such as a window or a workerWindowscope

Mobile vitals​

Reports automatically collected performance metrics such as CPU, memory, frames-per-second (fps), and app start-up times to assess mobile app responsiveness. For more details, see Mobile Vitals.

Full pathDescriptionExample valueField
event_context.severityEvent severity level (e.g., info = 1, warning = 3, error = 5)3severity
event_context.typeType of the eventmobile-vitalstype
mobile_vitals_context.nameSpecific mobile vital metric namecpu_usagename
mobile_vitals_context.typeHigh-level metric categorycputype
mobile_vitals_context.valueMeasured value of the metric0.02value
mobile_vitals_context.unitsUnit of measurement for the valuepercentage, mb, msunits
mobile_vitals_context.uuidUnique identifier for the metric samplea3a7532f-1c8d-4c02-86f4-6f7b5aefa2a1uuid

Log​

Provides general-purpose logging for application events and custom developer insights.

Full pathDescriptionExample valueField
event_context.severitySeverity level of the event (e.g., 1–5)3severity
event_context.typeType of the eventlogtype
event_context.sourceSource of the logcodesource
event_context.severityEvent severity1event_severity
event_context.sourceEvent sourcecodeevent_source
event_context.typeEvent typelogevent_type
log_context.data.event.log.customTriggerData.actionTypeLog action typeOtherlog_actionType
log_context.data.event.log.customTriggerData.extraData.exceptionInfo.error.statusCodeLog error status code5log_statusCode
log_context.data.event.log.customTriggerData.extraDataLog extra data as JSON objectMock not foundlog_statusMessage
log_context.data.event.log.customTriggerData.messageLog message[custom-dashboards] platform-overview.component - handleDataLoadingError: {"statusCode":5,"statusMessage":"Mock not found","metadata":{"map":{}}} - failedlog_message
log_context.data.event.triggerTypeLog trigger typecustomlog_triggerType
log_context.data.event.severityLog severity: 1-61log_severity
log_context.data.messageLog context message[custom-dashboards] platform-overview.component - handleDataLoadingError: {"statusCode":5,"statusMessage":"Mock not found","metadata":{"map":{}}} - failedlog_context_message

DOM​

Logs changes and structures in the Document Object Model for advanced session analysis.

Full pathDescriptionExample valueField
event_context.severitySeverity level of the event (e.g., 1–5)3severity
event_context.typeType of the eventdomtype
snapshot_context.actionCountNumber of user actions recorded0actionCount
snapshot_context.errorCountNumber of errors recorded0errorCount
snapshot_context.hasRecordingIndicates if recording existstruehasRecording
snapshot_context.hasScreenshotIndicates if screenshot existsfalsehasScreenshot
snapshot_context.viewCountNumber of views recorded1viewCount

Custom measurement​

Allows developers to send specific measurements relevant to their application logic.

Full pathDescriptionExample valueField
event_context.severitySeverity level of the event (e.g., 1–5)3severity
event_context.typeType of the eventcustom-measurementtype
custom_measurement_context.nameName of the custom measurementRUM errors page loadedname
custom_measurement_context.valueValue of the custom measurement167value

Screenshot​

Captures visual snapshots during user sessions for enhanced debugging and replay context.

Full pathDescriptionExample valueField
event_context.severitySeverity level of the event (e.g., 1–5)3severity
event_context.typeType of the eventscreenshottype
screenshot_context.descriptionReason or description for the screenshotcreating a screenshot due to an error!description
screenshot_context.idUnique identifier for the screenshot event2c54846d-4a52-47dc-8911-cec10bf962b8id

Updating saved queries after the move​

Alerts, dashboards, events2metrics rules, and saved views are not updated automatically when your account moves to default/rum.events. Update each one yourself:

  1. Point it at default/rum.events instead of default/logs.
  2. Remove the cx_rum. prefix from every field reference. In DataPrime, $d.cx_rum.event_context.type becomes $d.event_context.type.

Alerts​

Once your account has moved, the Application dropdown on an alert that runs on default/logs no longer lists your RUM applications, because the RUM data is no longer in that dataset.

Set the alert's Dataset to default/rum.events and filter on the application in the query itself:

version_metadata.app_name:"frontend-livefeed" AND event_context.type:"error"

For how dataset selection works on an alert, see Dataset alerts.

Dashboards, events2metrics, and saved views​

Each of these stores the dataset and the field paths it was built with, so both need updating:

  • Dashboards: repoint each widget's data source to default/rum.events and drop the prefix from every field in the query, the filters, and the group-by.
  • Events2metrics: repoint the rule at default/rum.events and update the field paths in its query and labels. Metrics already generated under the old rule keep the labels they were written with.
  • Saved views and custom filters: update the dataset and the field paths together. A view saved against default/logs keeps working, but returns no RUM data.
Last updated on